Microsoft 70-663 Actual Free Exam Questions & Community Discussion

  • Exam Code/Number: 70-663
  • Exam Name/Title: Pro: Designing and Deploying Messaging Solutions with Microsoft Exchange Server 2010
  • Certification Provider: Microsoft
  • Corresponding Certification: MCTS
  • Exam Questions: 275
  • Updated On: Aug 22, 2026
A corporate environment includes Active Directory Domain Services (AD DS). The environment consists of an internal network and a perimeter network. AD DS is deployed only on the internal network.
The company intends to utilize a service providers cloud-based Exchange Server 2010 SP1 email service.
You have the following requirements:
-Maximize the security of the design.
-Use the minimum permissions required to perform directory synchronization.
-You need to recommend a solution for directory synchronization between the corporate environment and the service providers environment.
Which two actions should you recommend? (Each correct answer presents part of the solution. Choose two.)
Correct Answer: A,D Vote an answer
Explanation: Only visible for EduDump members. You can sign-up / login (it's free).
You have an Exchange Server 2003 organization. Users access public folders by using Microsoft Office Outlook 2003 and Outlook Web Access. You plan to transition the organization to Exchange Server 2010.
You need to ensure that users can access public folders after their mailboxes have been moved to Exchange Server 2010.
What should you do?
Correct Answer: D Vote an answer
Explanation: Only visible for EduDump members. You can sign-up / login (it's free).
You have an Exchange Server 2010 organization. Your company has a relationship with another company. The partner company has an Exchange Server 2010 organization.
You need to recommend a security solution to meet the following requirements:
-Ensure that all e-mail delivery between your servers and the partner company's servers is encrypted Ensure that all communication between your servers and the partner company's servers is authenticated What should you include in the solution?
Correct Answer: C Vote an answer
Explanation: Only visible for EduDump members. You can sign-up / login (it's free).
You need to recommend a solution that meets the archiving requirements of Fabrikam. What should you include in the recommendation?
Case Study Title (Case Study): Fabrikam Inc
Company Overview
Fabrikam Inc. is a leading manufacturer of children's toys.
Physical Locations
Fabrikam has a main office in Seattle and a manufacturing plant in Los Angeles. The offices connect to each other by using a heavily congested high-speed WAN link. Each office has a dedicated connection to the Internet. Research and development personnel are located in both the Seattle office and the Los Angeles office.
Existing Environment
Active Directory Environment
Fabrikam has an Active Directory forest that contains one domain name fabrikam.com. The Active Directory forest has the following configurations:
-An Active Directory site exists for each office.
-All domain controllers run Windows Server 2003 x86 Service Pack 2 (SP2).
-The functional level of the forest and the domain is Windows Server 2003 interim.
-All of the user accounts for the users in the Seattle office are located in an organizational unit (OU) named Users\Seattle.
-All of the user accounts for the users in the Los Angeles offices are located in an organizational unit (OU) named Users\Los Angeles.
-Both offices have a help desk staff. The help desk staff in each office is responsible for managing all of the users in its respective office.
Messaging Environment
Fabrikam has an Exchange Server 2003 Service Pack 2 (SP2) organization that has the following configurations:
-A 500-MB mailbox quota for all users
-An SMTP connector that has the following configurations:
-Address space: *
-Delivery: DNS
-Local bridgehead: SEA-BE-1
Fabrikam has a partner company named Tailspin Toys; The Fabrikam Exchange servers are configured as ETRN servers for tailspintoys.com.
The Exchange organization contains four servers. The servers are configured as shown in the following table.

Requirements Business Goals
Fabrikam has the following business goals:
-Minimize hardware costs.
-Minimize administrative effort.
-Minimize WAN link utilization between the two offices.
Planned Changes
-Fabrikam plans to migrate to Exchange Server 2010 Service Pack 1 (SP1).
-You plan to deploy a Hub Transport server named SEA-HUB-1 in the Seattle site.
-You plan to deploy a Hub Transport server named LA-HUB-1 in the Los Angeles site.
Archiving Requirements
Email messages that are older than 180 days must be moved automatically to a distinct mailbox database.
Security Requirements
Fabrikam must meet the following security requirements:
-Anti-spam filtering must be performed on all email messages before the messages enter the network.
-The help desk staff must be prevented from modifying user accounts for users located in remote offices.
-The number of permissions assigned to the members of a group named Exchange Server
-Troubleshooters must be minimized.
Redundancy Requirements
Fabrikam must meet the following redundancy requirements:
-A copy of all the mailbox databases must exist in both sites.
-The impact on users must be minimized if a single server fails.
-Users must be able to send and receive messages if a single server fails.
-All of the mailbox databases must be available if the WAN link fails between the offices.
Problem Statements
-The WAN link between the Seattle office and the Los Angeles office is heavily congested. During
-normal business hours, the average round-trip time for packets to travel across the WAN link is 200 ms.
-The portable computer of the manager of the accounting department recently experienced a hard disk failure. The hard disk failure resulted in the loss of more than two years of email and other personal data.
Correct Answer: B Vote an answer
Explanation: Only visible for EduDump members. You can sign-up / login (it's free).
You have an Exchange Server 2010 organization.
Your company's compliance policy states that the following occurs when a user leaves the company:
The user account is disabled The user account and mailbox are deleted after six months All e-mail messages in the mailbox are retained for three years You need to recommend a solution to retain the e-mail messages of users who leave the company.
-The solution must meet the following requirements:
Ensure that a group named Group1 can manage the process
Minimize disk space required to store the mailbox database
What should you recommend?
Correct Answer: A Vote an answer
Your network contains a single Active Directory domain named contoso.com.
You plan to deploy a new Exchange Server 2010 Service Pack 1 (SP1) organization. You identify the administrative model for the Exchange organization as shown in the following table.

You need to identity which groups must be assigned to Group1 and Group2 to support the planned
administrative model.
The solution must minimize the number of rights assigned to each group.
Which security groups and role groups should you assign to Group1 and Group2?
To answer, drag the appropriate security groups or role groups to the correct group in the answer area.
Select and Place:
Correct Answer:

Explanation:
I agree with Group 2 answer and with Organization management point of Group 1
-Domain Admins is not right here as it is more than required.
-Account Operator group in the domain is required to be able to create user accounts.
Organization management Admin can do everything :
Administrators who are members of the Organization Management role group have administrative access to the entire Exchange 2010 organization and can perform almost any task against any Exchange 2010 object, with some exceptions, such as the Discovery Management role.
So the only missing or required permission here to perform the required tasks are:
Stop / Restart system or services and system updates. As local administrator group you can do that.
================================
Previous Answer was:
Group 1:
Domain Admins Group in the domain.
Organization Management role group.
Group 2:
Recipient management role group.
Group 1 needs to be able to do the following:
-Restore mailboxes
-Stop and Restart both Servers and Services
-Create mailbox database
-Install Operating System Updates
-Manage Certificates
I don't agree with the need for this group to be a member of the Account Operators group. This is a domain account that allows local logon to domain controllers and they can create user account accounts. Group 1 as I read the question needs to logon to exchange servers and manage the local exchange server. Therefore I think they just need to be members of the Administrative Group on each Exchange Server.
Group 2 needs to be able to do the following:
-create mail - enabled users
-create distribution lists
-delete distribution lists
In order for group 2 to complete their tasks they will need to have recipient management role and the Organization Role
Account Operators is a local group that grants limited account creation privileges to a user. Members of this group can create and modify most types of accounts, including those of users, local groups, and global groups. They can also log on locally to domain controllers. However, Account Operators can't manage the Administrator user account, the user accounts of administrators, or the group accounts Administrators, Server Operators, Account Operators, Backup Operators, and Print Operators. Account Operators also can't modify user rights.
The Recipient Management management role group is one of several built-in role groups that make up the Role Based Access Control (RBAC) permissions model in Microsoft Exchange Server 2010. Role groups are assigned one or more management roles that contain the permissions required to perform a given set of tasks. The members of a role group are granted access to the management roles assigned to the role group. For more information about role groups, see Understanding Management Role Groups. Administrators who are members of the Recipient Management role group have administrative access to create or modify Microsoft Exchange Server 2010 recipients within the Exchange 2010 organization.
Help Desk - The Help Desk management role group gives members permissions that are typically required by members of a help desk, such as modifying users' details such as their address and phone number.
Organization Management - The Organization Management role group is synonymous with the Exchange Full Administrator role in Exchange 2003 and the Exchange Organization Administrators role in Exchange 2007. Essentially, membership of this management role group gives the user the ability to perform pretty much any task in Exchange 2010, with the main missing task being the ability to perform mailbox searches; that itself is achieved via the Discovery Management role group.
Domain Admins - This group is automatically added to the corresponding Administrators group in every domain in the forest. It has complete control over all domain controllers and all directory content stored in the domain and it can modify the membership of all administrative accounts in the domain.
The permissions granularity issue was improved in Exchange 2007. The Exchange Full Administrator role found in Exchange 2000 and Exchange 2003 became known as the Exchange Organization Administrators role in Exchange 2007 and still gave administrators full access to all Exchange objects in the entire organization. The Exchange View-Only Administrators role also remained, giving administrators read-only access to the entire Exchange organization.
There were effectively three new additions to the Exchange 2007 roles:
-Exchange Recipient Administrators - Allowed administrators to modify Exchange settings on users, groups, contacts and public folders
-Exchange Public Folder Administrators -Was introduced in Exchange 2007 Service Pack 1 and as its name suggests allowed administrators to manage public folders
-Exchange Server Administrators - Allowed administrators to fully manage a particular Exchange 2007 server as long as they were also a member of the local Administrators group on that server
Although the permissions model in Exchange 2007 was a vast improvement over those models found in earlier versions of Exchange, it still wasn't able to satisfy a lot of the administrative scenarios found in various organizations. Essentially, the roles in Exchange 2007 still offered too much administrative power to administrators in a decentralized Exchange organization and it was therefore difficult to limit the permissions available to certain administrators. Although it was possible to implement a split permissions model in Exchange 2007 by modifying Access Control Lists (ACLs), this was a complex procedure that could sometimes result in errors and issues that were difficult to troubleshoot.
The design of Exchange 2010 has needed to take into account the more demanding and granular permissions requirements of organizations. Exchange 2010 now supports a model where specialist users can be granted specific Exchange permissions required to perform their duties. For example, there may be the scenario where a compliance officer within a company needs to conduct a search across all employees' mailboxes for legal reasons, or perhaps a member of the Human Resources department needs to update user information in Active Directory that is seen on the properties of users' mailboxes. In these example cases, the relevant specialist user should only be given the rights to perform the required task and should not be assigned, for example, additional rights that could allow them to affect the overall configuration of the Exchange environment.
Management Role Groups -In Exchange 2010, Microsoft has made the task of assigning a series of common permissions to administrative and specialist users very easy by providing 11 default management role groups. By placing a user or group into a management role group, the management roles associated with that management role group are assigned accordingly thereby giving the user or group the relevant permissions. The term role holder is used by Microsoft to denote the administrative or specialist user that is added to the management role group. These 11 default management role groups are created during Exchange 2010 setup. Specifically, these management role groups are created when Exchange 2010 setup runs the Active Directory preparation steps that can be performed individually by running the Exchange 2010 setup.com program with the /PrepareAD switch. The management role groups can be seen in the Microsoft Exchange Security Groups Organizational Unit (OU) that is created in the root domain during the Exchange setup process. You can see this OU and the groups within it in Figure 1. Note that of the 16 groups shown in Figure 1, only 11 are management role groups; these are highlighted.

A member of LOCAL\Administrators is a far cry from a BUILTIN\Administrators, and here are the two primary reasons why:
One - BUILTIN\Administrators is not stored locally to a single DC - its membership is in the Active Directory, in the CN=Builtin,DC=domain,DC=com container. The contents of this container are replicated to all domain controllers. Therefore, adding a user to a member of this group on one DC makes them a member of the group on all DCs. (A member server has a local accounts database called a SAM that is not visible to the domain.)
Two - Since BUILTIN\Administrators gives local Administrator permissions to its members - they can do anything on any DC in the domain. Anything. Making themselves a Domain Administrator is a trivial exercise.
A final note of caution: it is now widely recognized that forests are the security boundaries in Active Directory, not domains (regardless of what the original Windows 2000 Server A/D documentation said). Domains are simply administrative boundaries. As a corollary to item two above, once a person is a domain administrator, it is fairly easy to become an enterprise administrator.
A corporate environment includes Exchange Server 2010. The Exchange Server environment includes one Mailbox server, one Client Access server, and one Hub Transport server. One Edge Transport server resides in the perimeter network.
You are designing a disaster recovery solution for the Edge Transport server. The solution must provide the ability to perform the following tasks:
-Restore the Edge Transport server configuration.
-Restore log files and transport queue databases.
-Backup and restore only the minimum amount of data.
You need to recommend a solution that meets the requirements.
What should you recommend?
Correct Answer: C Vote an answer
Explanation: Only visible for EduDump members. You can sign-up / login (it's free).
You need to recommend changes to the network infrastructure to meet the security requirements of A, Datum.
What should you recommend creating?
Case Study Title (Case Study): Litware, Inc
Company Overview
Litware, Inc. is a manufacturing company.
Physical Locations
The company has offices in Bangkok and Tokyo. Each office has a sales department. All network support staff is located in the Bangkok office.
Existing Environment
Litware has a forest that contains a single domain named litwareinc.com. An Active Directory site exists for
each office. The sites connect to each other by using a high-speed WAN link. The WAN link has an
average net available bandwidth of 15 percent during business hours.
The domain contains three domain controllers. The domain controllers are configured as shown in the
following table.

The network has an Exchange Server 2010 Service Pack 1 (SP1) organization that contains four servers. The servers are configured as shown in the following table.

All of the servers have the following hardware configurations:
-32 GB of RAM
-Two dual quad-core Intel Xeon processors
-Two 1-gigabit per second network adapters
-One RAID 10 disk array that has 12 300-GB, 1S,000-RPM SAS disks for data
-One RAID 1 disk array that has two 73-GB, 10,000-RPM SAS disks for program files
-One RAID 1 disk array that has two 73-GB, 10,000-RPM SAS disks for the operating system
Requirements
Business Goals
Litware has the following general requirements that must be considered for all technology deployments:
-Minimize costs whenever possible.
-Minimize administrative effort whenever possible.
-Minimize traffic on the WAN link between the Bangkok and Tokyo offices.
Planned Changes
Litware acquires a management company named A, Datum Corporation. A, Datum has 2,500 employees.
A, Datum has the following email infrastructure:
-A sales department, in which 150 employees work
-A third-party email infrastructure that is used for IMAP4 and SMTP
-Three other departments that use the SMTP domains ofadatum.com, asia.adatum.com, and
contoso.com. Users are assigned only one email address that uses the SMTP domain of their
department
You plan to deploy a new Exchange Server 2010 SP1 organization for A, Datum. The new email infrastructure must meet the following implementation requirements:
-All employees must have access to their mailbox if a single server fails.
-Sales department employees must use Windows Internet Explorer 8 to access their mailbox,
-Sales department employees must be prevented from accessing the calendar or journal features of Outlook Web App.
-All employees who do not work in the sales department must have access to all of the Outlook Web App features.
-All email messages sent to recipients outside of A, Datum must have a return address in the
[email protected] format.
-The administration of the A, Datum Exchange organization must be performed by a dedicated team of administrators.
-The Exchange administration team for A, Datum must be distinct from the Exchange administration team of Litware.
The new email infrastructure for A, Datum must meet the following security requirements:
-Litware administrators must be prevented from viewing or modifying the settings of the mailboxes of A, Datum users.
-All inbound and outbound Internet email to and from the A, Datum domains must be routed through the Hub Transport servers of Litware.
-All email messages that contain financial information must be encrypted automatically while in transit and the recipients of the messages must be prevented from forwarding them to users outside of the company' s financial department.
Compliance Requirements
Litware must meet the following compliance requirements:
-Each email message sent by an attorney from the Litware legal department must be approved by the manager of the legal department.
-Attorneys must be able to classify email messages as "attorney-client privileged".
-All email messages classified as "attorney-client privileged" must contain a legal disclaimer
automatically.
User Requirements
All users who have a portable computer use Microsoft Outlook 2010 when they work online and offline.
When the users work offline, they must be able to read existing email messages and create new email
messages.
Users who have a large mailbox must minimize the amount of hard disk space used by the mailbox on their
portable computer.
Correct Answer: D Vote an answer
A corporate environment includes Exchange Server 2007 SP2 and Active Directory Domain Services (AD DS). Journaling is in use for all inbound and outbound email messages. The company intends to transition to Exchange Server 2010 SP1.
During the coexistence, you will have the following requirements:
-Export new journal and transport rules created in the Exchange Server 2007 SP2 system.
-Ensure that the exported rules are available for import in the Exchange Server 2010 SP1 environment.
You need to recommend a solution that meets the requirements.
Which two actions should you recommend? (Each correct answer presents part of the solution. Choose two.)
Correct Answer: A,B Vote an answer
Explanation: Only visible for EduDump members. You can sign-up / login (it's free).
0
0
0
10