QUESTION 1

Your network contains an Active Directory domain named contoso.com. The functional level of the forest is Windows Server 2008 R2. Computer accounts for the marketing department are in an organizational unit (OU) named Departments\Marketing\Computers. User accounts for the marketing department are in an OU named Departments\Marketing\Users. All of the marketing user accounts are members of a global security group named MarketingUsers. All of the marketing computer accounts are members of a global security group named MarketingComputers. In the domain, you have Group Policy objects (GPOs) as shown in the exhibit. You create two Password Settings objects named PSO1 and PSO2. PSO1 is applied to MarketingUsers. PSO2 is applied to MarketingComputers. The minimum password length is defined for each policy as shown in the following table.

 

70-411-demo-2

 

You need to identify the minimum password length required for each marketing user. What should you identify?

70-411-demo-3

 

  1. 5

  2. 6

  3. 7

  4. 10

  5. 12

 

Correct Answer: D

 -----------------------

 

QUESTION 2

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012. You have a Group Policy object (GPO) named GPO1 that contains several custom Administrative templates. You need to filter the GPO to display only settings that will be removed from the registry when the GPO falls out of scope. The solution must only display settings that are either enabled or disabled and that have a comment. How should you configure the filter?

 

To answer, select the appropriate options below. Select three.

 

70-411-demo-4

 

  1. Set Managed to: Yes

  2. Set Managed to: No

  3. Set Managed to: Any

  4. Set Configured to: Yes

  5. Set Configured to: No

  6. Set Configured to: Any

  7. Set Commented to: Yes

  8. Set Commented to: No

  9. Set Commented to: Any

 

Correct Answer: ADG

 

-----------------

 

QUESTION 3

Your network contains an Active Directory domain named contoso.com. You have several Windows PowerShell scripts that execute when users log on to their client computer. You need to ensure that all of the scripts execute completely before the users can access their desktop. Which setting should you configure?

 

To answer, select the appropriate setting in the answer area.

 

Hot Area:

70-411-demo-5

 

Correct Answer:

70-411-demo-6

 

 

 

 

 

 

 

QUESTION 4

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named dcl.contoso.com. You discover that the Default Domain Policy Group Policy objects (GPOs) and the Default Domain Controllers Policy GPOs were deleted. You need to recover the Default Domain Policy and the Default Domain Controllers Policy GPOs. What should you run?

 

  1. dcgpofix.exe /target:domain

  2. gpfixup.exe /dc:dc1.contoso.co,n

  3. dcgpofix.exe /target:both

  4. gptixup.exe /oldnb:contoso /newnb:dc1

 

Correct Answer: C

 

 

QUESTION 5

Your network contains an Active Directory domain named contoso.com. Domain controllers run either Windows Server 2008, Windows Server 2008 R2, or Windows Server 2012. You have a Password Settings object (PSOs) named PSO1. You need to view the settings of PSO1. Which tool should you use?

 

  1. Group Policy Management

  2. Server Manager

  3. Get-ADAccountResultantPasswordReplicationPolicy

  4. Active Directory Administrative Center

 

Correct Answer: D

 

 

QUESTION 6

Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. You need to prevent all of the GPOs at the site level and at the domain level from being applied to users and computers in an organizational unit (OU) named OU1. You want to achieve this goal by using the minimum amount of Administrative effort. What should you use?

 

  1. dcgpofix

  2. Get-GPOReport

  3. Gpfixup

  4. Gpresult

  5. Gptedit.msc

  6. Import-GPO

  7. Import-GPO

  8. Restore-GPO

  9. Set-GPInheritance

  10. Set-GPLink

  11. Set-GPPermission

  12. Gpupdate

  13. Add-ADGroupMember

 

Correct Answer: I

 

 

QUESTION 7

Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. You have two GPOs linked to an organizational unit (OU) named OU1. You need to change the precedence order of the GPOs. What should you use?

 

  1. dcgpofix

  2. Get-GPOReport

  3. Gpfixup

  4. Gpresult

  5. Gptedit.msc

  6. Import-GPO

  7. Restore-GPO

  8. Set-GPInheritance

  9. Set-GPLink

  10. Set-GPPermission

  11. Gpupdate

  12. Add-ADGroupMember

 

Correct Answer: I

 

 

QUESTION 8

Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. You need to provide an Administrator named Admin1 with the ability to create GPOs in the domain. The solution must not provide Admin1 with the ability to link GPOs. What should you use?

 

  1. dcgpofix

  2. Get-GPOReport

  3. Gpfixup

  4. Gpresult

  5. Gptedit.msc

  6. Import-GPO

  7. Restore-GPO

  8. Set-GPInheritance

  9. Set-GPLink

  10. Set-GPPermission

  11. Gpupdate

  12. Add-ADGroupMember

 

Correct Answer: J

 

 

QUESTION 9

Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. The domain contains a GPO named GPO1. GPO1 contains several Group Policy preferences. You need to view all of the preferences configured in GPO1. What should you use?

 

  1. dcgpofix

  2. Get-GPOReport

  3. Gpfixup

  4. Gpresult

  5. Gptedit.msc

  6. Import-GPO

  7. Restore-GPO

  8. Set-GPInheritance

  9. Set-GPLink

  10. Set-GPPermission

  11. Gpupdate

  12. Add-ADGroupMember

 

Correct Answer: B

 

 

QUESTION 10

Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. A network Administrator accidentally deletes the Default Domain Policy GPO. You do not have a backup of any of the GPOs. You need to recreate the Default Domain Policy GPO. What should you use?

 

  1. dcgpofix

  2. Get-GPOReport

  3. Gpfixup

  4. Gptedit.msc

  5. Import-GPO

  6. Restore-GPO

  7. Set-GPInheritance

  8. Set-GPLink

  9. Set-GPPermission

  10. Gpupdate

  11. Add-ADGroupMember

 

Correct Answer: A

 

QUESTION 11

Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. The domain is renamed to adatum.com. Group Policies no longer function correctly. You need to ensure that the existing GPOs are applied to users and computers. You want to achieve this goal by using the minimum amount of Administrative effort. What should you use?

 

  1. dcgpofix

  2. Get-GPOReport

  3. Gpfixup

  4. Gpresult

  5. Gptedit.msc

  6. Import-GPO

  7. Restore-GPO

  8. Set-GPInheritance

  9. Set-GPLink

  10. Set-GPPermission

  11. Gpupdate

  12. Add-ADGroupMember

 

Correct Answer: C

 

 

QUESTION 12

Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. The domain contains a top-level organizational unit (OU) for each department. A group named Group1 contains members from each department. You have a GPO named GPO1 that is linked to the domain. You need to configure GPO1 to apply settings to Group1 only. What should you use?

 

  1. dcgpofix

  2. Get-GPOReport

  3. Gpfixup

  4. Gpresult

  5. Gptedit.msc

  6. Import-GPO

  7. Restore-GPO

  8. Set-GPInheritance

  9. Set-GPLink

  10. Set-GPPermission

  11. Gpupdate

  12. Add-ADGroupMember

 

Correct Answer: J

 

 

QUESTION 13

Your network contains an Active Directory domain named contoso.com. A user named User1 creates a central store and opens the Group Policy Management Editor as shown in the exhibit. You need to ensure that the default Administrative Templates appear in GPO1. What should you do?

 

70-411-demo-7

 

  1. Link a WMI filter to GPO1.

  2. Add User1 to the Group Policy Creator Owners group.

  3. Configure Security Filtering in GPO1.

  4. Copy files from %Windir%\PolicyDefinitions to the central store.

 

Correct Answer: D

 

 

QUESTION 14

Your network contains a single Active Directory domain named contoso.com. The domain contains an Active Directory site named Site1 and an organizational unit (OU) named OU1. The domain contains a client computer named Client1 that is located in OU1 and Site1. You create five Group Policy objects (GPO). The GPOs are configured as shown in the following table.

 

70-411-demo-8

 

You need to identify in which order the GPOs will be applied to Client1. In which order should you arrange the listed GPOs?

 

To answer, move all GPOs from the list of GPOs to the answer area and arrange them in the correct order.

 

Select and Place:

70-411-demo-9

 

Correct Answer:

70-411-demo-10

 

 

QUESTION 15

Your network contains an Active Directory domain named contoso.com. Domain controllers run either Windows Server 2008, Windows Server 2008 R2, or Windows Server 2012. You have a Password Settings object (PSOs) named PSO1. You need to view the settings of PSO1. Which tool should you use?

 

  1. Get-ADFineGrainedPasswordPolicy

  2. Get-ADAccountResultantPasswordReplicationPolicy

  3. Get-ADDomainControllerPasswordReplicationPolicy

  4. Get-ADDefaultDomainPasswordPolicy

 

Correct Answer: A

 

 

QUESTION 16

Your network contains a production Active Directory forest named contoso.com and a test Active Directory forest named test.contoso.com. There is no network connectivity between contoso.com and test.contoso.com. The test.contoso.com domain contains a Group Policy object (GPO) named GPO1. You need to apply the settings in GPO1 to the contoso.com domain. Which four actions should you perform?

 

To answer, move the four appropriate actions from the list of actions to the answer area and arrange them in the correct order.

 

Select and Place:

70-411-demo-11

 

Correct Answer:

70-411-demo-12

 

 

QUESTION 17

Your network contains an Active Directory domain named contoso.com. All user accounts reside in an organizational unit (OU) named OU1. All of the users in the marketing department are members of a group named Marketing. All of the users in the human resources department are members of a group named HR. You create a Group Policy object (GPO) named GPO1. You link GP01 to OU1. You configure the Group Policy preferences of GPO1 to add two shortcuts named Link1 and Link2 to the desktop of each user. You need to ensure that Link1 only appears on the desktop of the users in Marketing and that Link2 only appears on the desktop of the users in HR.

What should you configure?

 

  1. Item-level targeting

  2. Group Policy Inheritance

  3. Security Filtering

  4. WMI Filtering

 

Correct Answer: A

 

 

QUESTION 18

Your network contains a single Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. The domain contains 400 desktop computers that run Windows 8 and 10 desktop computers that run Windows XP Service Pack 3 (SP3). All new desktop computers that are added to the domain run Windows 8. All of the desktop computers are located in an organizational unit (OU) named OU1. You create a Group Policy object (GPO) named GPO1. GPO1 contains startup script settings. You link GPO1 to OU1. You need to ensure that GPO1 is applied only to computers that run Windows XP SP3. What should you do?

 

  1. Modify the Security settings of OU1.

  2. Run the Set-GPLink cmdlet and specify the -target parameter.

  3. Create and link a WMI filter to GPO1.

  4. Run the Set-GPInheritance cmdlet and specify the -target parameter.

 

Correct Answer: C

 

 

QUESTION 19

Your network contains an Active Directory domain named contoso.com. The domain contains 30 user accounts that are used for network administration. The user accounts are members of a domain global group named Group1. You identify the security requirements for the 30 user accounts as shown in the following table.

 

70-411-demo-13

 

You need to identify which settings must be implemented by using a Password Settings object (PSO) and which settings must be implemented by modifying the properties of the user accounts. What should you identify?

 

To answer, configure the appropriate settings in the dialog box in the answer area.

 

Hot Area:

70-411-demo-14

 

Correct Answer:

70-411-demo-15

 

 

 

QUESTION 20

Computer1 is located in an OU, and the GPO1, User1 is another OU, and as GPO2, to ensure you can apply GPO1 to User1 should be how to do?

 

  1. Security filtering

  2. Inheritance

  3. Gpupdate

  4. GPO

 

Correct Answer: A

 

 

QUESTION 21

Your network contains an Active Directory domain named contoso.com. All client computers run Windows 8 Pro. You have a Group Policy object (GPO) named GP1. GP1 is linked to the domain. GP1 contains the Windows Internet Explorer 10 and 11 Internet Settings. The settings are shown in the exhibit.

 

70-411-demo-16[4]

 

Users report that when they open Windows Internet Explorer, the home page is NOT set to

http://www.contoso.com.

 

You need to ensure that the home page is set to http://www.contoso.com the next time users log

on to the domain. What should you do?

 

  1. On each client computer, run gpupdate.exe.

  2. Open the Internet Explorer 10 and 11 Internet Settings, and then press F5.

  3. Open the Internet Explorer 10 and 11 Internet Settings, and then modify the Tabs settings.

  4. On each client computer, run Invoke-GPupdate.

 

Correct Answer: A

 

 

QUESTION 22

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. You have a Group Policy object (GPO) named GPO1 that contains hundreds of settings. GPO1 is linked to an organizational unit (OU) named OU1. OU1 contains 200 client computers. You plan to unlink GPO1 from OU1. You need to identify which GPO settings will be removed from the computers after GPO1 is unlinked from OU1. Which two GPO settings should you identify? (Each correct answer presents part of the solution. Choose two.)

 

  1. The managed Administrative Template settings

  2. The unmanaged Administrative Template settings

  3. The System Services security settings

  4. The Event Log security settings

  5. The Restricted Groups security settings

 

Correct Answer: AD

 

 

QUESTION 23

Your network contains an Active Directory domain named contoso.com. The domain contains an organizational unit (OU) named IT and an OU named Sales. All of the help desk user accounts are located in the IT OU. All of the sales user accounts are located in the Sales OU. The Sales OU contains a global security group named G_Sales. The IT OU contains a global security group named G_HelpDesk.

 

You need to ensure that members of G_HelpDesk can perform the following tasks:

 

 

What should you do?

 

  1. Run the Set-ADFinecrainedPasswordPolicy cmdlet and specify the -identity parameter.

  2. Right-click the IT OU and select Delegate Control.

  3. Right-click the Sales OU and select Delegate Control.

  4. Run the Set-ADAccountPassword cmdlet and specify the -identity parameter.

 

Correct Answer: C

 

 

QUESTION 24

Your network contains an Active Directory domain named contoso.com. The domain contains 30 organizational units (OUs). You need to ensure that a user named User1 can link Group Policy Objects (GPOs) in the domain. What should you do?

 

  1. From the Active Directory Users and Computers, add User1 to the Network Configuration Operators group.

  2. From the Group Policies Management, click the contoso.com node and modify the Delegation settings.

  3. From the Group Policies Management, click the Group policy Objects node and modify the Delegation settings.

  4. From the Active Directory Users and Computers, add User1 to the Group Policy Creator Owners group.

 

Correct Answer: B

 

 

QUESTION 25

Your network contains a single Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. The domain contains 400 desktop computers that run Windows 8 and 10 desktop computers that run Windows XP Service Pack 3 (SP3). All new desktop computers that are added to the domain run Windows 8. All of the desktop computers are located in an organizational unit (OU) named OU1. You create a Group Policy object (GPO) named GPO1. GPO1 contains startup script settings. You link GPO1 to OU1. You need to ensure that GPO1 is applied only to computers that run Windows XP SP3. What should you do?

 

  1. Modify the Security settings of OU1.

  2. Run the Set-GPLink cmdlet and specify the -target parameter.

  3. Create and link a WMI filter to GPO1.

  4. Run the Set-GPInheritance cmdlet and specify the -target parameter.

 

Correct Answer: C

 

 

 

 

QUESTION 26

DRAG DROP

Your network contains an Active Directory domain named contoso.com. All client computers run Windows 7. Group Policy objects (GPOs) are linked to the domain as shown in the exhibit.

 

70-411-demo-17[4]

 

GP02 contains user configurations only and GP03 contains computer configurations only.

 

You need to configure the GPOs to meet the following requirements:

 

 

What should you do?

 

To answer, drag the appropriate setting to the correct GPO. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

 

Select and Place:

70-411-demo-18[4]

 

Correct Answer:

70-411-demo-19[4]

 

 

QUESTION 27

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. The domain contains 500 client computers that run Windows 8 Enterprise. You implement a Group Policy central store. You have an application named App1. App1 requires that a custom registry setting be deployed to all of the computers. You need to deploy the custom registry setting. The solution must minimize administrator effort. What should you configure in a Group Policy object (GPO)?

 

  1. The Administrative Templates

  2. An application control policy

  3. The Group Policy preferences

  4. The Software Installation settings

 

Correct Answer: C

 

 

QUESTION 28

Your network contains two Active Directory forests named contoso.com and adatum.com. All domain controllers run Windows Server 2012. The adatum.com domain contains a Group Policy object (GPO) named GPO1. An administrator from adatum.com backs up GPO1 to a USB flash drive. You have a domain controller named dc1.contoso.com. You insert the USB flash drive in dc1.contoso.com. You need to identify the domain-specific reference in GPO1. What should you do?

 

  1. From Group Policy Management, run the Group Policy Results Wizard.

  2. From the Migration Table Editor, click Populate from GPO.

  3. From Group Policy Management, run the Group Policy Modeling Wizard.

  4. From the Migration Table Editor, click Populate from Backup.

 

Correct Answer: D

 

 

QUESTION 29

Your network contains an Active Directory domain named contoso.com. All client computers run Windows Vista Service Pack 2 (SP2). All client computers are in an organizational unit (OU) named 0U1. All user accounts are in an OU named OU2. All users log on to their client computer by using standard user accounts. A Group Policy object (GPO) named GPO1 is linked to OU1. A GPO named GP02 is linked to 0U2. You need to apply advanced audit policy settings to all of the client computers. What should you do?

 

  1. In GPO1, configure a startup script that runs auditpol.exe.

  2. In GPO2, configure a logon script that runs auditpol.exe.

  3. In GPO1, configure the Advanced Audit Policy Configuration settings.

  4. In GPO2, configure the Advanced Audit Policy Configuration settings.

 

Correct Answer: A

 

 

QUESTION 30

Your network contains an Active Directory domain named contoso.com. Domain controllers run either Windows Server 2008, Windows Server 2008 R2, or Windows Server 2012. You have a Password Settings object (PSOs) named PSO1. You need to view the settings of PSO1. Which tool should you use?

 

  1. Group Policy Management

  2. Get-ADFineGrainedPasswordPolicy

  3. Get-ADDefaultDomainPasswordPolicy

  4. Server Manager

 

Correct Answer: B

 


QUESTION 31

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. An organizational unit (OU) named OU1 contains 200 client computers that run Windows 8 Enterprise. A Group Policy object (GPO) named GPO1 is linked to OU1. You make a change to GPO1. You need to force all of the computers in OU1 to refresh their Group Policy settings immediately. The solution must minimize administrative effort. Which tool should you use?

 

  1. Group Policy Object Editor

  2. The Secedit command

  3. Group Policy Management Console (GPMC)

  4. Active Directory Users and Computers

 

Correct Answer: C

 

 

QUESTION 32

HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012. The domain contains some test client computers that run either Windows XP, Windows Vista, Windows 7, or Windows 8. The computer accounts for the test computers are located in an organizational unit (OU) named OU1.

You have a Group Policy object (GPO) named GP01 linked to OU1. GPO1 is used to assign several applications to the test computers. You need to ensure that when the test computers in OU1 restart, you can see which application installation is running currently. Which setting should you modify in GPO1?

 

To answer, select the appropriate setting in the answer area.

 

Hot Area:

70-411-demo-20

 

Correct Answer:

70-411-demo-21

QUESTION 33

Your network contains an Active Directory domain named contoso.com. The domain contains a Web server named www.contoso.com. The Web server is available on the Internet. You implement DirectAccess by using the default configuration. You need to ensure that users never attempt to connect to www.contoso.com by using DirectAccess. The solution must not prevent the users from using DirectAccess to access other resources in contoso.com. Which settings should you configure in a Group Policy object (GPO)?

 

  1. Name Resolution Policy

  2. DNS Client

  3. Network Connections

  4. DirectAccess Client Experience Settings

 

Correct Answer: A

 

 

QUESTION 34

You have a DNS server named Server1. Server1 has a primary zone named contoso.com. Zone Aging/Scavenging is configured for the contoso.com zone. One month ago, an Administrator removed a server named Server2 from the network. You discover that a static resource record for Server2 is present in contoso.com. Resource records for decommissioned client computers are removed automatically from contoso.com. You need to ensure that the static resource records for all of the servers are removed automatically from contoso.com. What should you modify?

 

  1. The Security settings of the static resource records

  2. The Expires after value of contoso.com

  3. The Record time stamp value of the static resource records

  4. The time-to-live (TTL) value of the static resource records

 

Correct Answer: C

 

 

QUESTION 35

You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access server role installed. You need to configure the ports on Server1 to ensure that client computers can establish VPN connections to Server1 by using TCP port 443. What should you modify?

 

To answer, select the appropriate object in the answer area.

 

Hot Area:

70-411-demo-22

 

Correct Answer:

70-411-demo-23

 

 

QUESTION 36

Your network contains two Active Directory domains named contoso.com and adatum.com. The network contains a server named Server1 that runs Windows Server 2012. Server1 has the DNS Server server role installed. Server1 has a copy of the contoso.com DNS zone. You need to configure Server1 to resolve names in the adatum.com domain. The solution must meet the following requirements:

 

 

Which type of zone should you create?

 

  1. Primary

  2. Secondary

  3. Reverse lookup

  4. Stub

 

Correct Answer: D

 

 

QUESTION 37

Your network contains two servers named Server1 and Server2. Both servers run Windows Server 2012 and have the DNS Server role installed. On Server1, you create a standard primary zone named contoso.com. You need to ensure that Server2 can host a secondary zone for contoso.com. What should you do from Server1?

 

  1. Add Server2 as a name server.

  2. Convert contoso.com to an Active Directory-integrated zone.

  3. Create a zone delegation that points to Server2.

  4. Create a trust anchor named Server2.

 

Correct Answer: A

 

 

QUESTION 38

You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access server role installed. On Server1, you create a network policy named Policy1. You need to configure Policy1 to apply only to VPN connections that use the L2TP protocol. What should you configure in Policy1?

 

  1. The Tunnel Type

  2. The Service Type

  3. The NAS Port Type

  4. The Framed Protocol

 

Correct Answer: A

 

 

QUESTION 39

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012. All client computers run Windows 8 Enterprise. DC1 contains a Group Policy object (GPO) named GPO1. You need to deploy a VPN connection to all users. What should you configure from User Configuration in GPO1?

 

  1. Preferences/Control Panel Settings/Network Options

  2. Policies/Administrative Templates/Windows Components/Windows Mobility Center

  3. Policies/Administrative Templates/Network/Windows Connect Now

  4. Policies/Administrative Templates/Network/Network Connections

 

Correct Answer: A

 

 

QUESTION 40

Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012. All sales users have laptop computers that run Windows 8. The sales computers are joined to the domain. All user accounts for the sales department are in an organizational unit (OU) named Sales_OU. A Group Policy object (GPO) named GPO1 is linked to Sales_OU. You need to configure a dial-up connection for all of the sales users. What should you configure from User Configuration in GPO1?

 

  1. Policies/Administrative Templates/Network/Windows Connect Now

  2. Policies/Administrative Templates/Windows Components/Windows Mobility Center

  3. Preferences/Control Panel Settings/Network Options

  4. Policies/Administrative Templates/Network/Network Connections

 

Correct Answer: C

 

 

QUESTION 41

HOTSPOT

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All domain controllers run Windows Server 2012 and are configured as DNS servers. All DNS zones are Active Directory-integrated. Active Directory Recycle Bin is enabled. You need to modify the amount of time deleted objects are retained in the Active Directory Recycle Bin. Which naming context should you use?

 

To answer, select the appropriate naming context in the answer area.

Hot Area:

70-411-demo-24

 

Correct Answer:

70-411-demo-25

 

 

QUESTION 42

Your network contains an Active Directory domain named contoso.com. You have a standard primary zone names contoso.com. You need to ensure that only users who are members of a group named Group1 can create DNS records in the contoso.com zone. All other users must be prevented from creating, modifying, or deleting DNS records in the zone. What should you do first?

 

  1. Run the Zone Signing Wizard for the zone.

  2. From the properties of the zone, change the zone type.

  3. Run the new Delegation Wizard for the zone.

  4. From the properties of the zone, modify the Start of Authority (SOA) record.

 

Correct Answer: B

 

 

QUESTION 43

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1. DC1 is a DNS server for contoso.com. The properties of the contoso.com zone are configured as shown in the exhibit.

 

70-411-demo-26

 

The domain contains a server named Server1 that is part of a workgroup named Workgroup. Server1 is configured to use DC1 as a DNS server. You need to ensure that Server1 dynamically registers a host (A) record in the contoso.com zone. What should you configure?

 

  1. The Dynamic updates setting of the contoso.com zone.

  2. The workgroup name of Server1.

  3. The primary DNS suffix of Server1.

  4. The Security settings of the contoso.com zone.

 

Correct Answer: C

 

 

QUESTION 44

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. One of the domain controllers is named DC1. The DNS zone for the contoso.com zone is Active Directory-intergrated and has the default settings. A server named Server1 is a DNS server that runs a UNIX-based operating system. You plan to use Server1 as a secondary DNS server for the contoso.com zone. You need to ensure that Server1 can host a secondary copy of the contoso.com zone. What should you do?

 

  1. From Windows PowerShell, run the Set-DnsServerSetting cmdlet and specify DC1 as a target.

  2. From DNS Manager, modify the Zone Transfers settings of the contoso.com zone.

  3. From DNS Manager, modify the replication scope of the contoso.com zone.

  4. From DNS manager, modify the Security settings of the contoso.com zone.

 

Correct Answer: B

 

 

QUESTION 45

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012. All client computers run Windows 8 Enterprise. DC1 contains a Group Policy object (GPO) named GPO1. You need to deploy a VPN connection to all users. What should you configure from Users Configuration in GPO1?

 

  1. Policies/Administrative Templates/Network/Network Connections

  2. Policies/Administrative Templates/Network/Windows Connect Now

  3. Preferences/Control Panel Settings/Network Options

  4. Policies/Administrative Templates/Windows Components/Windows Mobility Centre

 

Correct Answer: C

 

 

 

 

 

 

 

 

QUESTION 46

You have a server named Server1 that has the Web Server (IIS) server role installed. You obtain a Web Server certificate. You need to configure a website on Server1 to use Secure Socket Layer (SSL). To which store should you import the certificate?

 

To answer, select the appropriate store in the answer area.

 

Hot Area:

70-411-demo-27

 

Correct Answer:

70-411-demo-28

 

 

QUESTION 47

Your network contains an Active Directory domain named contoso.com. The domain contains six domain controllers named DC1, DC2, DC3, DC4, DC5, and DC6. Each domain controller has the DNS Server server role installed and hosts an Active Directory-integrated zone for contoso.com. You plan to create a new Active Directory-integrated zone named litwareinc.com that will be used for testing. You need to ensure that the new zone will be available only on DC5 and DC6. What should you do first?

 

  1. Create an application directory partition.

  2. Change the zone replication scope.

  3. Create an Active Directory connection object.

  4. Create an Active Directory site link.

 

Correct Answer: A

 

 

QUESTION 48

Your network contains a DNS server named Server1 that runs Windows Server 2012. Server1 has a zone named contoso.com. The network contains a server named Server2 that runs Windows Server 2008 R2. Server1 and Server2 are members of an Active Directory domain named contoso.com. You change the IP address of Server2. Several hours later, some users report that they cannot connect to Server2. On the affected users’ client computers, you flush the DNS client resolver cache, and the users successfully connect to Server2. You need to reduce the amount of time that the client computers cache DNS records from contoso.com. Which value should you modify in the Start of Authority (SOA) record?

 

To answer, select the appropriate setting in the answer area.

 

Hot Area:

70-411-demo-29

 

Correct Answer:

70-411-demo-30

 

 

QUESTION 49

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012. You enable and configure Routing and Remote Access (RRAS) on Server1. You create a user account named User1. You need to ensure that User1 can establish VPN connections to Server1. What should you do?

 

  1. Create a network policy.

  2. Modify the members of the Remote Management Users group.

  3. Create a connection request policy.

  4. Add a RADIUS client.

 

Correct Answer: A

 

  

QUESTION 50

Your network contains an Active Directory domain named fabrikam.com. You implement DirectAccess and an IKEv2 VPN. You need to view the properties of the VPN connection. Which connection properties should you view?

 

To answer, select the appropriate connection properties in the answer area.

 

Hot Area:

70-411-demo-31

 

Correct Answer:

70-411-demo-32

 

 

QUESTION 51

The contoso.com domain contains a DNS server named Server1 that host a primary zone. Server2 contains a secondary zone for the contoso.com domain. You need to configure how long Server2 queries Server1 to renew the zone. What should you configure?

 

  1. Refresh interval

  2. Restart DNS

  3. Forwarders

  4. Stub zone

 

Correct Answer: A

 

 

QUESTION 52

You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access server role installed. On Server1, you create a network policy named PPTP_Policy. You need to configure PPTP_Policy to apply only to VPN connections that use the PPTP protocol. What should you configure in PPTP_Policy?

 

  1. The Service Type

  2. The Tunnel Type

  3. The Framed Protocol

  4. The NAS Port Type

 

Correct Answer: B

 

 

QUESTION 53

Your network contains a RADIUS server named Server1. You install a new server named Server2 that runs Windows Server 2012 and has Network Policy Server (NPS) installed. You need to ensure that all accounting requests for Server2 are forwarded to Server1. On Server2, you configure a Connection Request Policy. What else should you configure on Server2?

 

To answer, select the appropriate node in the answer area.

 

Hot Area:

70-411-demo-33

 

Correct Answer:

70-411-demo-34

 

 

QUESTION 54

Your network contains two Active Directory forests named contoso.com and adatum.com. The contoso.com forest contains a server named server1.contoso.com. The adatum.com forest contains a server named server2.adatum.com. Both servers have the Network Policy Server role service installed. The network contains a server named Server3. Server3 is located in the perimeter network and has the Network Policy Server role service installed. You plan to configure Server3 as an authentication provider for several VPN servers. You need to ensure that RADIUS requests received by Server3 for a specific VPN server are always forwarded to server1.contoso.com. Which two should you configure on Server3? (Each correct answer presents part of the solution. Choose two.)

 

  1. Network policies

  2. Remote RADIUS server groups

  3. Connection authorization policies

  4. Remediation server groups

  5. Connection request policies

 

Correct Answer: BE

 

  

QUESTION 55

Your network contains an Active Directory domain named fabrikam.com. You implement DirectAccess. You need to view the properties of the DirectAccess connection. Which connection properties should you view?

 

To answer, select the appropriate connection properties in the answer area.

 

Hot Area:

70-411-demo-35

 

Correct Answer:

70-411-demo-36

 

 

QUESTION 56

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012. You enable and configure Routing and Remote Access (RRAS) on Server1. You create a user account named User1. You need to ensure that User1 can establish VPN connections to Server1. What should you do?

 

  1. Add a RADIUS client.

  2. Create a connection request policy.

  3. Modify the members of the Remote Management Users group.

  4. Modify the Dial-in setting of User1.

 

Correct Answer: D

 

 

QUESTION 57

Your network contains an Active Directory forest. The forest contains two domains named contoso.com and fabrikam.com. All of the DNS servers in both of the domains run Windows Server 2012. The network contains two servers named Server1 and Server2. Server1 hosts an Active Directory-integrated zone for contoso.com. Server2 hosts an Active Directory-integrated zone for fabrikam.com. Server1 and Server2 connect to each other by using a WAN link. Client computers that connect to Server1 for name resolution cannot resolve names in fabrikam.com. You need to configure Server1 to support the resolution of names in fabrikam.com. The solution must ensure that users in contoso.com can resolve names in fabrikam.com if the WAN link fails. What should you do on Server1?

 

  1. Add a forwarder.

  2. Create a conditional forwarder.

  3. Create a secondary zone.

  4. Create a stub zone.

 

Correct Answer: C

 

 

QUESTION 58

Your network contains two servers named Server1 and Server2. Both servers run Windows Server 2012 and have the DNS Server role installed. Server1 hosts a primary zone for contoso.com. Server2 hosts a secondary zone for contoso.com. The zone is not configure to notify secondary servers of changes automatically. You update several records on Server1. You need to force the replication of the contoso.com zone records from Server1 to Server2. What should you do from Server2?

 

  1. Right-click Server2 and click Update Server Data Files.

  2. Right-click Server2 and click Refresh.

  3. Right-click the contoso.com zone and click Reload.

  4. Right-click the contoso.com zone and click Transfer from Master.

 

Correct Answer: D

 

 

QUESTION 59

Your network contains an Active Directory domain named contoso.com. All client computers run Windows 8. Your company has users who work from home. Some of the home users have desktop computers. Other home users have laptop computers. All of the computers are joined to the domain. All of the computer accounts are members of a group named Group1. Currently, the home users access the corporate network by using a PPTP VPN. You implement DirectAccess by using the default configuration and you specify Group1 as the DirectAccess client group. The home users who have desktop computers report that they cannot use DirectAccess to access the corporate network. The home users who have laptop computers report that they can use DirectAccess to access the corporate network. You need to ensure that the home users who have desktop computers can access the network by using DirectAccess. What should you modify?

 

  1. The security settings of the computer accounts for the desktop computers

  2. The membership of the R.AS and IAS Servers group

  3. The WMI filter for Direct Access Client Settings GPO

  4. The conditions of the Connections to Microsoft Routing and Remote Access server policy

 

Correct Answer: C

 

 

QUESTION 60

You have a DNS server named Server1 that has a Server Core Installation on Windows Server 2012. You need to view the time-to-live (TTL) value of a name server (NS) record that is cached by the DNS Server service on Server1. What should you run?

 

  1. Show-DNSServerCache

  2. dnscacheugc.exe

  3. ipconfiq.exe /displaydns

  4. nslookup.exe

 

Correct Answer: A

 

QUESTION 61

Your network contains a single Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that hosts the primary DNS zone for contoso.com. All servers dynamically register their host names. You install the new Web servers that host identical copies of your company’s intranet website. The servers are configured as shown in the following table.

 

70-411-demo-37

 

You need to use DNS records to load balance name resolution queries for intranet.contoso.com between the two Web servers. What is the minimum number of DNS records that you should create manually?

 

  1. 1

  2. 2

  3. 3

  4. 4

 

Correct Answer: B

 

 

QUESTION 62

You have a Direct Access Server named Server1 running Server 2012. You need to add prevent users from accessing websites from an Internet connection. What should you configure?

 

  1. Split Tunneling

  2. Security Groups

  3. Force Tunneling

  4. Network Settings

 

Correct Answer: C

 

 

QUESTION 63

You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access server role installed. You need to configure the ports on Server1 to ensure that client computers can establish VPN connections to Server1. The solution must NOT require the use of certificates or pre-shared keys. What should you modify?

 

To answer, select the appropriate object in the answer area.

 

Hot Area:

70-411-demo-38

Correct Answer:

70-411-demo-39

 

 

 

QUESTION 64

Your network contains an Active Directory domain named contoso.com. The domain does not contain a certification authority (CA). All servers run Windows Server 2012. All client computers run Windows 8. You need to add a data recovery agent for the Encrypting File System (EFS) to the domain. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two).

 

  1. From the Default Domain Controllers policy, select Create Data Recovery Agent.

  2. From the Default Domain Controllers policy, select Add Data Recovery Agent.

  3. From Windows PowerShell, run Get-Certificate.

  4. From the Default Domain Policy, select Add Data Recovery Agent.

  5. From a command prompt, run cipher.exe.

  6. From the Default Domain Policy, select Create Data Recovery Agent.

 

Correct Answer: DE

 

 

QUESTION 65

Your network contains multiple Active Directory sites. You have a Distributed File System (DFS) namespace that has a folder target in each site. You discover that some client computers connect to DFS targets in other sites. You need to ensure that the client computers only connect to a DFS target in their respective site. What should you modify?

 

  1. the properties of the Active Directory site links

  2. the properties of the Active Directory sites

  3. the delegation settings of the namespace

  4. the referral settings of the namespace

 

Correct Answer: D

 

 

QUESTION 66

Your network contains an Active Directory domain named contoso.com. You have a failover cluster named Cluster1. All of the nodes in Cluster1 have BitLocker Drive Encryption (BitLocker) installed. You plan to add a new volume to the shared storage of Cluster1. You need to add the new volume to the shared storage. The solution must meet the following requirements:

 

 

Which three actions should you perform?

 

To answer, move the three appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Select and Place:

70-411-demo-40

 

Correct Answer:

70-411-demo-41

 

 

QUESTION 67

Your network contains an Active Directory domain named contoso.com. The domain functional level in Windows Server 2008. All domain controllers run Windows Server 2008 R2. The domain contains a file server named Server1 that runs Windows Server 2012. Server1 has a BitLocker Drive Encryption (BitLocker)-encrypted drive. Server1 uses a trusted Platform Module (TPM) chip. You enable the Turn on TPM backup to Active Directory Domain Services policy setting by using a Group Policy object (GPO). You need to ensure that you can back up the BitLocker recovery information to Active Directory. What should you do?

 

  1. Upgrade a domain controller to Windows 2012.

  2. Enable the Store BitLocker recovery information in the Active Directory Services (Windows Server2008 and Windows Vista) policy settings.

  3. Raise the forest functional level to Windows 2008 R2.

  4. Add a BitLocker data recovery agent

 

Correct Answer: B

 

 

 

QUESTION 68

Your company has a main office and a branch office. The main office is located in Seattle. The branch office is located in Montreal. Each office is configured as an Active Directory site. The network contains an Active Directory domain named adatum.com. The Seattle office contains a file server named Server1. The Montreal office contains a file server named Server2. The servers run Windows Server 2012 and have the File and Storage Services server role, the DFS Namespaces role service, and the DFS Replication role service installed. Server1 and Server2 each have a share named Share1 that is replicated by using DFS Replication. You need to ensure that users connect to the replicated folder in their respective office when they connect to \\contoso.com\Share1. Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

 

  1. Share and publish the replicated folder.

  2. Modify the Referrals settings.

  3. Create a new topology.

  4. Create a namespace.

  5. Create a replication connection.

 

Correct Answer: ABD

 

 

QUESTION 69

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the File Server Resource Manager role service installed. Each time a user receives an access-denied message after attempting to access a folder on Server1, an email notification is sent to a distribution list named DL1. You create a folder named Folder1 on Server1, and then you configure custom NTFS permissions for Folder 1. You need to ensure that when a user receives an access-denied message while attempting to access Folder1, an email notification is sent to a distribution list named DL2. The solution must not prevent DL1 from receiving notifications about other access-denied messages. What should you do?

 

  1. From File Explorer, modify the Classification tab of Folder1.

  2. From the File Server Resource Manager console, modify the Email Notifications settings.

  3. From the File Server Resource Manager console, set a folder management property.

  4. From File Explorer, modify the Customize tab of Folder1.

 

Correct Answer: C

 

 

 

 

 

 

 

QUESTION 70

You have a server named Server1 that runs Windows Server 2012. An administrator creates a quota as shown in the Quota exhibit.

 

70-411-demo-42

 

You run the dir command as shown in the dir exhibit.

 

70-411-demo-43

 

You need to ensure that D:\Folder1 can only consume 100 MB of disk space. What should you do?

 

  1. From File Server Resource Manager, edit the existing quota.

  2. From the properties of drive D, enable quota management.

  3. From the Services console, set the Startup Type of the Optimize drives service to Automatic.

  4. From File Server Resource Manager, create a new quota.

 

Correct Answer: D

 

QUESTION 71

Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012. The domain contains an organizational unit (OU) named FileServers_OU. FileServers_OU contains the computer accounts for all of the file servers in the domain. You need to audit the users who successfully access shares on the file servers. Which audit category should you configure?

 

To answer, select the appropriate category in the answer area.

 

Hot Area:

70-411-demo-44

 

Correct Answer:

70-411-demo-45

 

 

 

 

QUESTION 72

Your network contains an Active Directory domain named contoso.com. The domain does not contain a certification authority (CA). All servers run Windows Server 2012. All client computers run Windows 8. You need to add a data recovery agent for the Encrypting File System (EFS) to the domain. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

 

  1. From Windows PowerShell, run Get-Certificate.

  2. From the Default Domain Controllers Policy, select Create Data Recovery Agent.

  3. From the Default Domain Policy, select Add Data Recovery Agent.

  4. From a command prompt, run cipher.exe.

  5. From the Default Domain Policy, select Create Data Recovery Agent.

  6. From the Default Domain Controllers Policy, select Add Data Recovery Agent.

 

Correct Answer: CD

 

 

QUESTION 73

Your network contains an Active Directory domain named contoso.com. The domain contains three domain controllers. The domain controllers are configured as shown in the following table.

 

70-411-demo-46

 

You are creating a Distributed File System (DFS) namespace as shown in the exhibit.

70-411-demo-47

 

You need to identify which configuration prevents you from creating a DFS namespace in Windows Server 2008 mode. Which configuration should you identify?

 

  1. The location of the PDC emulator role

  2. The functional level of the domain

  3. The operating system on Server1 and Server3

  4. The location of the RID master role

 

Correct Answer: B

 

 

QUESTION 74

Your network contains multiple Active Directory sites. You have a Distributed File System (DFS) namespace that has a folder target in each site. You discover that some client computers connect to DFS targets in other sites. You need to ensure that the client computers only connect to a DFS target in their respective site. What should you modify?

 

  1. The properties of the Active Directory sites

  2. The properties of the Active Directory site links

  3. The delegation settings of the namespace

  4. The referral settings of the namespace

Correct Answer: D

 

 

QUESTION 75

Your network contains an Active Directory domain named adatum.com. The domain contains five servers. The servers are configured as shown in the following table.

 

70-411-demo-48

 

All desktop computers in adatum.com run Windows 8 and are configured to use BitLocker Drive Encryption (BitLocker) on all local disk drives. You need to deploy the Network Unlock feature. The solution must minimize the number of features and server roles installed on the network. To which server should you deploy the feature?

 

  1. Server3

  2. Server1

  3. DC2

  4. Server2

  5. DC1

 

Correct Answer: B

 

 

QUESTION 76

You have a server named Server1 that runs Windows Server 2012. Server1 has the File Server Resource Manager role service installed. Server1 has a folder named Folder1 that is used by the sales department. You need to ensure that an email notification is sent to the sales manager when a File Screening Audit report is generated. What should you configure on Server1?

 

  1. A file screen exception

  2. A file group

  3. A storage report task

  4. A file screen

 

Correct Answer: C

 

 

QUESTION 77

Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2. Both servers run Windows Server 2012. Both servers have the File and Storage Services server role. The DFS Namespaces role service, and the DFS Replication role service installed. Server1 and Server2 are part of a Distributed File System (DFS) Replication group named Group1. Server1 and Server2 are separated by a low-speed WAN connection. You need to limit the amount of bandwidth that DFS can use to replicate between Server1 and Server2. What should you modify?

 

  1. The cache duration of the namespace

  2. The staging quota of the replicated folder

  3. The referral ordering of the namespace

  4. The schedule of the replication group

 

Correct Answer: D

 

 

QUESTION 78

Your network contains an Active Directory domain named adatum.com. The domain contains five servers. The servers are configured as shown in the following table.

 

70-411-demo-49

 

All desktop computers in adatum.com run Windows 8 and are configured to use BitLocker Drive Encryption (BitLocker) on all local disk drives. You need to deploy the Network Unlock feature. The solution must minimize the number of features and server roles installed on the network. To which server should you deploy the feature?

 

  1. DC1

  2. DC2

  3. Server1

  4. Server2

 

Correct Answer: C

 

 

QUESTION 79

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012. Server1 has the File Server Resource Manager role service installed. You configure a quota threshold as shown in the exhibit.

 

70-411-demo-50

 

You need to ensure that a user named User1 receives an email notification when the threshold is exceeded. What should you do?

 

  1. Configure the File Server Resource Manager Options.

  2. Modify the members of the Performance Log Users group.

  3. Create a performance counter alert.

  4. Create a classification rule.

 

Correct Answer: A

 

 

QUESTION 80

Your network contains an Active Directory domain named contoso.com. The domain contains a file server named Server1 that runs Windows Server 2012. You view the effective policy settings of Server1 as shown in the exhibit.

 

70-411-demo-51

 

On Server1, you have a folder named C:\Share1 that is shared as Share1. Share1 contains confidential data. A group named Group1 has full control of the content in Share1. You need to ensure that an entry is added to the event log whenever a member of Group1 deletes a file in Share1. What should you configure?

 

  1. The Audit File System setting of Servers GPO.

  2. The Sharing settings of C:\Share1.

  3. The Security settings of C:\Share1.

  4. The Audit File Share setting of Servers GPO.

 

Correct Answer: C

QUESTION 81

You have a server named Server1 that runs Windows Server 2012. Server1 has the File Server Resource Manager role service installed. Server1 has a folder named Folder1 that is used by the human resources department. You need to ensure that an email notification is sent immediately to the human resources manager when a user copies an audio file or a video file to Folder1. What should you configure on Server1?

 

  1. A file screen

  2. A file screen exception

  3. A file group

  4. A storage report task

 

Correct Answer: A

 

 

QUESTION 82

Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2. Both servers run Windows Server 2012. Both servers have the File and Storage Services server role, the DFS Namespace role service, and the DFS Replication role service installed. Server1 and Server2 are part of a Distributed File System (DFS) Replication group named Group1. Server1 and Server2 are connected by using a high-speed LAN connection. You need to minimize the amount of processor resources consumed by DFS Replication. What should you do?

 

  1. Reduce the bandwidth usage.

  2. Disable Remote Differential Compression (RDC).

  3. Modify the staging quota.

  4. Modify the replication schedule.

 

Correct Answer: B

 

 

QUESTION 83

Your domain has contains a Windows 8 computer name Computer1 using BitLocker. The E:\ drive is encrypted and currently locked. You need to unlock the E:\ drive with the recovery key stored on C:\. What should you run?

 

  1. Unlock-BitLocker

  2. Suspend-BitLocker

  3. Enable-BitLockerAutoUnloc

  4. Disable-BitLocker

 

Correct Answer: A

 

 

QUESTION 84

Your company has a main office and two branch offices. The main office is located in New York. The branch offices are located in Seattle and Chicago. The network contains an Active Directory domain named contoso.com. An Active Directory site exists for each office. Active Directory site links exist between the main office and the branch offices. All servers run Windows Server 2012.

The domain contains three file servers. The file servers are configured as shown in the following table.

 

70-411-demo-52

 

You implement a Distributed File System (DFS) replication group named ReplGroup. ReplGroup is used to replicate a folder on each file server. ReplGroup uses a hub and spoke topology. NYC-SVR1 is configured as the hub server. You need to ensure that replication can occur if NYC-SVR1 fails. What should you do?

 

  1. Create an Active Directory site link.

  2. Modify the properties of ReplGroup.

  3. Create an Active Directory site link bridge.

  4. Create a connection in ReplGroup.

 

Correct Answer: D

 

 

QUESTION 85

You have a server named Server1 that runs Windows Server 2012. On Server1, you configure a custom Data Collector Set (DCS) named DCS1. DCS1 is configured to store performance log data in C:\Logs. You need to ensure that the contents of C:\Logs are deleted automatically when the folder reaches 100 MB in size. What should you configure?

 

  1. A File Server Resource Manager (FSRM) quota on the C:\Logs folder

  2. A File Server Resource Manager (FSRM) file screen on the C:\Logs folder

  3. A schedule for DCS1

  4. The Data Manager settings of DCS1

Correct Answer: D

 

 

QUESTION 86

Your network contains and active Directory domain named contoso.com. The doman contains a server named Server1 that runs Windows Server 2012. A local account named Admin1 is a member of the Administrators group on Server1. You need to generate an audit event whenever Admin1 is denied access to a file or folder. What should you run?

 

  1. auditpol.exe /set /user:admin1 /category:”detailed tracking” /failure:enable

  2. auditpol.exe /set/user:admin1 /failure:enable

  3. auditpol.exe /resourcesacl /set /type:keyauditpol.exe /resourcesacl /set /type: /access:ga

  4. auditpol.exe /resourcesacl /set /type:file /user:admin1 /failure

 

Correct Answer: D

 

 

QUESTION 87

Your network contains and Active Directory domain named contoso.com. The domain contains a file server named server1 that runs windows Server 2012. You view the effective policy settings of server1 as shown in the exhibit.

 

70-411-demo-53

 

You need to ensure that an entry is added to the event log whenever a local user account is created or deleted on server1. What should you do?

 

  1. In Servers GPO, modify the Advanced Audit Configuration Settings.

  2. On Server1, attach a task to the security log.

  3. In Servers GPO, modify the Audit Policy settings.

  4. On Server1, attach a task to the system log.

 

Correct Answer: A

 

 

QUESTION 88

On the DFS replication your receive a wrap error on the sysvol on domain controller 4. Which 3 steps should you do to recover this error in the correct order?

 

  1. Stop FSR

  2. Start FSR

  3. Edit the computer object in AD

  4. Edit the registry

  5. Stop DFSR

  6. Start DFRS

 

Correct Answer: ABD

 

 

QUESTION 89

Your network contains an Active Directory domain named contoso.com. The domain functional level is Windows Server 2008. All domain controllers run Windows Server 2008 R2. The domain contains a file server named Server1 that runs Windows Server 2012. Server1 has a BitLocker Drive Encryption (BitLocker)-encrypted drive. Server1 uses a Trusted Platform Module (TPM) chip. You enable the Turn on TPM backup to Active Directory Domain Services policy setting by using a Group Policy object (GPO). You need to ensure that you can back up the BitLocker recovery information to Active Directory. What should you do?

 

  1. Raise the forest functional level to Windows Server 2008 R2.

  2. Enable the Configure the level of TPM owner authorization information available to the operating system policy setting and set the Operating system managed TPM authentication level to None.

  3. Add a BitLocker data recovery agent.

  4. Import the TpmSchemaExtension.ldf and TpmSchemaExtensionACLChanges.ldf schema

extensions to the Active Directory schema.

 

Correct Answer: D

 

 

QUESTION 90

Your network contains an Active Directory domain named contoso.com. The domain contains 2 WSUS servers, ServerA and ServerB. ServerB is a replica server of ServerA. You need to configure WSUS to report data from SERVERB to SERVERA. What should you configure?

 

  1. Update Reports

  2. Synchronization

  3. Computer Groups

  4. Reporting Rollup

 

Correct Answer: D

QUESTION 91

Your network contains an Active Directory domain named adatum.com. You have a Group Policy object (GPO) that configures the Windows Update settings. Currently, client computers are configured to download updates from Microsoft Update servers. Users choose when the updates are installed. You need to configure all client computers to install Windows updates automatically. Which setting should you configure in the GPO?

 

To answer, select the appropriate setting in the answer area.

 

Hot Area:

70-411-demo-54

 

Correct Answer:

70-411-demo-55

 

 

QUESTION 92

Your network contains and Active Directory domain named contoso.com. The domain contains a member server named Server1. All servers run Server 2012. You need to collect the error events from all the servers on Server1. The solution ensure that when new servers are added to the domain, their error events are collected automatically on Server1. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

 

  1. On Server1, create a source computer initiated subscription.

  2. From a Group Policy object (GPO), configure the Configure forwarder resource usage

settings.

  1. From a Group Policy object (GPO), configure the Configure target Subscription Manager

settings.

  1. On Server1, create a collector initiated subscription.

 

Correct Answer: AC

 

 

QUESTION 93

Your network contains an Active Directory domain called contoso.com. The domain contains a member server named Server1. Server1 runs Windows Server 2012. You enable the EventLog-Application event trace session. You need to set the maximum size of the log file used by the trace session to 10 MB. From which tab should you perform the configuration?

 

To answer, select the appropriate tab in the answer area.

 

Hot Area:

70-411-demo-56

 

Correct Answer:

70-411-demo-57

 

 

QUESTION 94

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows server 2012. Server1 has the Windows Server Update Services server role installed. You need to use the Group Policy object (GPO) to assign members to a computer group. Which setting should you configure in the GPO?

 

To answer, select the appropriate setting in the answer area.

 

Hot Area:

70-411-demo-58

 

Correct Answer:

70-411-demo-59

 

 

  

QUESTION 95

You have Windows Server 2012 installation media that contains a file named Install.wim. You need to identify which images are present in Install.wim. What should you do?

 

  1. Run imagex.exe and specify the/verify parameter.

  2. Run imagex.exe and specify the /ref parameter.

  3. Run dism.exe and specify the /get-mountedwiminfo parameter.

  4. Run dism.exe and specify the /get-imageinfo parameter.

 

Correct Answer: D

 

 

QUESTION 96

Your network contains an Active Directory domain named contoso.com. The domain contains two member servers named Server1 and Server2. All servers run Windows Server 2012. Server1 and Server2 are nodes in a Hyper-V cluster named Cluster1. Cluster1 hosts 10 virtual machines. All of the virtual machines run Windows Server 2012 and are members of the domain. You need to ensure that the first time a service named Service1 fails on a virtual machine, the virtual machine is moved to a different node. You configure Service1 to be monitored from Failover Cluster Manager. What should you configure on the virtual machine?

 

  1. From the Recovery settings of Service1, set the First failure recovery action to Restart the Service.

  2. From the General settings, modify the Service status.

  3. From the Recovery settings of Service1, set the First failure recovery action to Take No Action.

  4. From the General settings, modify the Startup type.

 

Correct Answer: C

 

  

QUESTION 97

DRAG DROP

Your network contains an Active Directory domain named contoso.com. The domain contains two member servers named Server1 and Server2. All servers run Windows Server 2012. You generalize Server2. You install the Windows Deployment Services (WDS) server role on Server1.

You need to capture an image of Server2 on Server1. Which three actions should you perform?

 

To answer, move the three appropriate actions from the list of actions to the answer area and arrange them in the correct order.

 

Select and Place:

70-411-demo-60

 

Correct Answer:

70-411-demo-61

 

QUESTION 98

Your network contains an Active Directory domain named contoso.com. The domain contains a member server that runs Windows Server 2012 and has the Windows Deployment Services (WDS) server role installed. You create a new multicast session in WDS and connect 50 client computers to the session. When you open the Windows Deployment Services console, you discover that all of the computers are listed as pending devices. You need to ensure that any of the computers on the network can join a multicast transmission without requiring administrator approval. What should you configure?

 

To answer, select the appropriate tab in the answer area.

 

Hot Area:

70-411-demo-62

 

Correct Answer:

70-411-demo-63

 

 

QUESTION 99

Your network contains two servers named Server1 and Server2 that run Windows Server 2012. Server1 and Server2 have the Windows Server Update Services server role installed. Server1 synchronizes from Microsoft Update. Server2 is a Windows Server Update Services (WSUS) replica of Server1. You need to configure replica downstream servers to send Server1 summary information about the computer update status. What should you do?

 

  1. From Server1, configure Reporting Rollup.

  2. From Server2, configure Reporting Rollup.

  3. From Server1, configure Email Notifications.

  4. From Server2, configure Email Notifications.

 

Correct Answer: A

 

 

QUESTION 100

Your network contains an Active Directory domain named adatum.com. Client computers are deployed by using Windows Deployment Services (WDS). From Active Directory Users and Computers on a domain controller named DO, you attempt to create a new computer account as shown in the exhibit.

 

70-411-demo-64

 

You need to ensure that you configure computer accounts as managed accounts when you create the computer accounts from Active Directory Users and Computers. What should you do on DC1?

 

  1. Install the User Interfaces and Infrastructure feature.

  2. From the View menu in Active Directory Users and Computers, select Users, Contacts, Groups, and Computers as containers.

  3. Install the Windows Deployment Services Tools role administration tool.

  4. From the View menu in Active Directory Users and Computers, select Advanced Features.

 

Correct Answer: C


QUESTION 101

You have a server named Server1 that runs Windows Server 2012. On Server1, you configure a custom Data Collector Set (DCS) named DCS1. You need to ensure that all performance log data that is older than 30 days is deleted automatically. What should you configure?

 

  1. a File Server Resource Manager (FSRM) quota on the %Systemdrive%\PerfLogs folder

  2. a schedule for DCS1

  3. the Data Manager settings of DCS1

  4. a File Server Resource Manager (FSRM) file screen on the %Systemdrive%\PerfLogs folder

 

Correct Answer: C

 

 

QUESTION 102

You have a server named Server1 that runs Windows Server 2012. You create a custom Data Collector Set (DCS) named DCS1.

 

You need to configure DCS1 to meet the following requirements:

 

  • Automatically run a program when the amount of total free disk space on Server1 drops below 10 percent of capacity.

  • Log the current values of several registry settings.

 

Which two should you configure in DCS1? (Each correct answer presents part of the solution. Choose two.)

 

  1. System configuration information

  2. A performance counter

  3. Event trace data

  4. A Performance Counter Alert

 

Correct Answer: AD

 

 

QUESTION 103

Your network contains an Active Directory domain named contoso.com. All client computers connect to the Internet by using a server that has Microsoft Forefront Threat Management Gateway (TMG) installed. You deploy a server named Server1 that runs Windows Server 2012.

You install the Windows Server Update Services server role on Server1. From the Windows Server Update Services Configuration Wizard, you click Start Connecting and you receive an HTTP error message. You need to configure Server1 to download Windows updates from the Internet. What should you do?

 

  1. From the Update Services console, modify the Synchronization Schedule options.

  2. From Windows Internet Explorer, modify the Connections settings.

  3. From Windows Internet Explorer, modify the Security settings.

  4. From the Update Services console, modify the Update Source and Proxy Server options.

 

Correct Answer: D

 

 

QUESTION 104

Your network contains an Active Directory domain named corp.contoso.com. The domain contains two member servers named Server1 and Edge1. Both servers run Windows Server 2012. Your company wants to implement a central location where the system events from all of the servers in the domain will be collected. From Server1, a network technician creates a collector-initiated subscription for Edge1. You discover that Server1 does not contain any events from Edge1. You view the runtime status of the subscription as shown in the exhibit.

 

70-411-demo-65

 

You need to ensure that the system events from Edge1 are collected on Server1. What should you modify?

 

To answer, select the appropriate object in the answer area.

 

Hot Area:

70-411-demo-66

 

Correct Answer:

70-411-demo-67

 

 

QUESTION 105

Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that runs Windows Server 2012. Server1 has the Windows Server Updates Services server role installed and is configured to download updates from the Microsoft Update servers. You need to ensure that Server1 downloads express installation files from the Microsoft Update servers. What should you do from the Update Services console?

 

  1. From the Automatic Approvals options, configure the Update Rules settings.

  2. From the Products and Classifications options, configure the Classifications settings.

  3. From the Products and Classifications options, configure the Products settings.

  4. From the Update Files and Languages options, configure the Update Files settings.

 

Correct Answer: D

 

 

 

 

 

QUESTION 106

You have a VHD that contains an image of Windows Server 2012. You plan to apply updates to the image. You need to ensure that only updates that can install without requiring a restart are installed. Which DISM option should you use?

 

  1. /PreventPending

  2. /Apply-Unattend

  3. /Cleanup-Image

  4. /Add-ProvisionedAppxPackage

 

Correct Answer: A

 

 

QUESTION 107

Your network contains an Active Directory domain named adatum.com. The domain contains a server named WDS1 that runs Windows Server 2012. You install the Windows Deployment Services server role on WDS1. You have a virtual machine named VM1 that runs Windows Server 2012. VM1 has several line-of-business applications installed. You need to create an image of VM1 by using Windows Deployment Services. Which type of image should you add to VM1 first?

 

  1. Capture

  2. Install

  3. Discovery

  4. Boot

 

Correct Answer: D

 

 

QUESTION 108

You have a server named Server1 that runs Windows Server 2012. Server1 has the Windows Server Update Services server role installed. You need to configure Windows Server Update Services (WSUS) to support Secure Sockets Layer (SSL). Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

 

  1. Run the wsusutil.exe command.

  2. From Internet Information Services (IIS) Manager, modify the bindings of the WSUS website.

  3. From Internet Information Services (IIS) Manager, modify the connection strings of the WSUS website.

  4. Run the iisreset.exe command.

  5. Install a server certificate.

 

Correct Answer: ABE

 

 

QUESTION 109

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012. Server1 has the Windows Server Update Services server role installed. You have a Group Policy object (GPO) that configures the Windows Update settings. You need to modify the GPO to configure all client computers to install Windows updates every Wednesday at 01:00. Which setting should you configure in the GPO?

 

To answer, select the appropriate setting in the answer area.

 

Hot Area:

70-411-demo-68

 

Correct Answer:

70-411-demo-69

 

 

 

 

QUESTION 110

Your network contains a domain controller named DC1 that runs Windows Server 2012. You create a custom Data Collector Set (DCS) named DCS1. You need to configure DCS1 to collect the following information:

 

  • The amount of Active Directory data replicated between DC1 and the other domain controllers

  • The current values of several registry settings

 

Which two should you configure in DCS1? (Each correct answer presents part of the solution. Choose two.)

 

  1. Event trace data

  2. System configuration information

  3. A Performance Counter Alert

  4. A Performance Counter

 

Correct Answer: BC

 

QUESTION 111

You have a VHD that contains an image of Windows Server 2012. You need to apply an update package to the image. Which DISM option should you use?

 

  1. /Add-ProvisionedAppxPackage

  2. /Cleanup-Image

  3. /Add-Package

  4. /Apply-Unattend

 

Correct Answer: C

 

 

QUESTION 112

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 and a server named Server2 that has the File Services server role installed. You install the Windows Deployment Services server role on Server1. You plan to use Server2 as a reference computer. You need to create an image of Server2 by using Windows Deployment Services. Which type of image should you add to Server1 first?

 

  1. Boot

  2. Discovery

  3. Install

  4. Capture

 

Correct Answer: A

 

 

QUESTION 113

You have a server named Server1 that runs Windows Server 2012. Server1 has the Windows Server Update Services roll installed. Server1 stores update files locally in C:\Updates. You need to change the location in which the updates files are stored to D:\Updates. What should you do?

 

  1. From the Update Services Console, run the Windows Server Update Services Configuration

Wizard.

  1. From the command prompt, run wsusutil.exe and specify the movecontent parameter.

  2. From the command prompt, run wsusutil.exe and specify the export parameter.

  3. From the Update Services Console, configure the update Files and Languages option.

 

Correct Answer: B

 

 

QUESTION 114

You have Site1 with 400 desktops and Site2 with 150 desktops. You have a WSUS Server to deploy updates for both sites. You need to make sure that all computers in the same site will have the same updates. What should you configure?

 

  1. Computer Groups

  2. Security Groups

  3. Synchronization Options

  4. Classifications

 

Correct Answer: A

 

 

QUESTION 115

You have a WDS server named Server1 on Windows Server 2012. You need to automate the WDS deployment. Which Tab should you configure?

 

  1. Boot Properties

  2. Client Properties

  3. Network Settings

  4. PXE Response Settings

 

Correct Answer: B

 

 

 

 

QUESTION 116

You are an admin. You have wsus with 2 sites which contain computers. You want to have the ability to update the computers per site or together. Which 3 steps do you do?

 

  1. Create computer groups in wsus

  2. Create synchronization options

  3. Create GPO and configure updates

  4. Under Tasks, click Synchronize now

 

Correct Answer: ABC

 

 

QUESTION 117

Which of the options should you configure for a WDS pre-staged computer name? You should select 2 of the 4 check boxes.

 

  1. GUID o MAC-address preceding with nulls

  2. WdsClientUnattend

  3. Give the minimum required permission to a user who wants to promote a RODC.

  4. ReferralServer

 

Correct Answer: AC

 

 

QUESTION 118

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2008 R2. You plan to test Windows Server 2012 by using native-boot virtual hard disks (VHDs). You attach a new VHD to Server1. You need to install Windows Server 2012 in the VHD. What should you do?

 

  1. Run dism.exe and specify the /apply-image parameter.

  2. Run dism.exe and specify the /append-image parameter.

  3. Run imagex.exe and specify the /export parameter.

  4. Run imagex.exe and specify the /append parameter.

 

Correct Answer: A

 

 

QUESTION 119

You have a server named Admin1 that runs Windows Server 2012. On Admin1, you configure a custom Data Collector Set (DCS) named DCS1. DCS1 is configured to store performance log data in C:\Logs. You need to ensure that the contents of C:\Logs are deleted automatically when the folder reaches 100 MB in size. What should you configure?

 

  1. A File Server Resource Manager (FSRM) quota on the C:\Logs folder

  2. A File Server Resource Manager (FSRM) file screen on the C:\Logs folder

  3. A schedule for DCS1

  4. The Data Manager settings of DCS1

 

Correct Answer: D

 

 

QUESTION 120

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 and a server named Server2 that has the File Services server role installed. You install the Windows Deployment Services server role on Server1. You plan to use Server2 as a reference computer. You need to create an image of Server2 by using Windows Deployment Services. Which type of image should you add to Server1 first?

 

  1. Install

  2. Boot

  3. Discovery

  4. Capture

 

Correct Answer: B

 

QUESTION 121

You have a server named Server1 that runs Windows Server 2012. You create a Data Collector Set (DCS) named DCS1. You need to configure DCS1 to log data to D:\logs. What should you do?

 

  1. Right-click DCS1 and click Properties.

  2. Right-click DCS1 and click Save template.

  3. Right-click DCS1 and click Data Manager.

  4. Right-click DCS1 and click Export list.

 

Correct Answer: A

 

 

QUESTION 122

You have a server named WSUS1 that runs Windows Server 2012. WSUS1 has the Windows Server Update Services server role installed and has one volume. You add a new hard disk to WSUS1 and then create a volume on the hard disk. You need to ensure that the Windows Server Update Services (WSUS) update files are stored on the new volume. What should you do?

 

  1. From a command prompt, run wsusutil.exe and specify the movecontent parameter.

  2. From the Update Services console, run the Windows Server Update Services Configuration Wizard.

  3. From the Update Services console, configure the Update Files and Languages option.

  4. From a command prompt, run wsusutil.exe and specify the export parameter.

 

Correct Answer: A

 

 

QUESTION 123

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012. Server1 has the DHCP Server role installed. The network contains 400 client computers that run Windows 8. All of the client computers are joined to the domain and are configured DHCP clients. You install a new server named Server2 that runs Windows Server 2012. On Server2, you install the Network Policy Server role service and you configure Network Access Protection (NAP) to use the DHCP enforcement method. You need to ensure that Server1 only provides a valid default gateway to computers that pass the system health validation. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

 

  1. From the DHCP console, configure the 016 Swap Server option.

  2. From the DHCP console, create a new policy.

  3. From the NAP Client Configuration console, enable the DHCP Quarantine Enforcement Client.

  4. From the DHCP console, enable NAP on all scopes.

  5. From Server Manager, install the Network Policy Server role service.

 

Correct Answer: DE

 

 

QUESTION 124

Your network contains an Active Directory domain named adatum.com. The domain contains a server named Server1 that runs Windows Server 2012. Server1 is configured as a Network Policy Server (NPS) server and as a DHCP server. You need to ensure that only computers that send a statement of health are checked for Network Access Protection (NAP) health requirements. Which two settings should you configure? (Each correct answer presents part of the solution. Choose two.)

 

  1. The Called Station ID constraints

  2. The MS-Service Class conditions

  3. The Health Policies conditions

  4. The NAS Port Type constraints

  5. The NAP-Capable Computers conditions

 

Correct Answer: CE

 

 

 

QUESTION 125

Your network contains an Active Directory domain named contoso.com. All client computers run Windows 8 Pro. You have a Group Policy object (GPO) named GP1. GP1 is linked to the domain. GP1 contains the Windows Internet Explorer 10 and 11 Internet Settings. The settings are shown in the exhibit.

 

70-411-demo-70

 

Users report that when they open Windows Internet Explorer, the home page is NOT set to http://www.contoso.com.

 

You need to ensure that the home page is set to http://www.contoso.com the next time users log on to the domain. What should you do?

 

  1. On each client computer, run gpupdate.exe.

  2. Open the Internet Explorer 10 and 11 Internet Settings, and then press F5.

  3. Open the Internet Explorer 10 and 11 Internet Settings, and then modify the Tabs settings.

  4. On each client computer, run Invoke-GPupdate.

 

Correct Answer: B

 

QUESTION 126

Your network is configured as shown in the exhibit. (Click the Exhibit button.)

 

70-411-demo-71

 

Server1 regularly accesses Server2. You discover that all of the connections from Server1 to Server2 are routed through Router1. You need to optimize the connection path from Server1 to Server2. Which route command should you run on Server1?

 

  1. Route add -p 10.10.10.0 MASK 255.255.255.0 10.10.10.1 METRIC 50

  2. Route add -p 10.10.10.0 MASK 255.255.255.0 172.23.16.2 METRIC 100

  3. Route add -p 10.10.10.12 MASK 255.255.255.0 10.10.10.1 METRIC 100

  4. Route add -p 10.10.10.12 MASK 255.255.255.0 10.10.10.0 METRIC 50

 

Correct Answer: B

 

 

QUESTION 127

Your network contains two Active Directory forests named adatum.com and contoso.com. The network contains three servers. The servers are configured as shown in the following table.

 

70-411-demo-72

 

You need to ensure that connection requests from adatum.com users are forwarded to Server2 and connection requests from contoso.com users are forwarded to Server3. Which two should you configure in the connection request policies on Server1? (Each correct answer presents part of the solution. Choose two.)

 

  1. The Authentication settings

  2. The User Name condition

  3. The Standard RADIUS Attributes settings

  4. The Identity Type condition

  5. The Location Groups condition

 

Correct Answer: AB

 

 

QUESTION 128

Your network contains two Active Directory forests named adatum.com and contoso.com. The network contains three servers. The servers are configured as shown in the following table.

 

70-411-demo-73

 

You need to ensure that connection requests from adatum.com users are forwarded to Server2 and connection requests from contoso.com users are forwarded to Server3. Which two should you configure in the connection request policies on Server1? (Each correct answer presents part of the solution. Choose two.)

 

  1. The Standard RADIUS Attributes settings

  2. The Location Groups condition

  3. The User Name condition

  4. The Identity Type condition

  5. The Authentication settings

 

Correct Answer: CE

 

 

QUESTION 129

You have installed Routing and Remote Access on Server1 what should you configure next to use it as a NAT server.

 

  1. Add New Interface

  2. Create Static Route

  3. Configure the IPv4 DHCP Relay Agent

  4. Configure the IPv6 DHCP Relay Agent

 

Correct Answer: A

 

 

QUESTION 130

Your network contains four Network Policy Server (NPS) servers named Server1, Server2, Server3, and Server4. Server1 is configured as a RADIUS proxy that forwards connection request to a remote RADIUS server group named Group1. You need to ensure that Server2 and Server3 receive connection requests. Server4 must only receive connection requests if both Server2 and Server3 are unavailable. How should you configure Group1?

 

  1. Change the Weight of Server2 and Server3 to 10

  2. Change the Weight of Server4 to 10

  3. Change the Priority of Server2 and Server3 to 10

  4. Change the Priority of Server4 to 10

 

Correct Answer: D

 

QUESTION 131

Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012. The domain contains two servers. The servers are configured as shown in the following table.

 

70-411-demo-74

 

All client computers run Windows 8 Enterprise. You plan to deploy Network Access Protection (NAP) by using IPSec enforcement. A Group Policy object (GPO) named GPO1 is configured to deploy a trusted server group to all of the client computers. You need to ensure that the client computers can discover HRA servers automatically. Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

 

  1. On DC1, create a service location (SRV) record.

  2. On Server2, configure the EnableDiscovery registry key.

  3. On all of the client computers, configure the EnableDiscovery registry key.

  4. In a GPO, modify the Request Policy setting for the NAP Client Configuration.

  5. On DC1, create an alias (CNAME) record.

 

Correct Answer: ACD

 

 

QUESTION 132

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012. Server1 has the Network Policy Server role service installed. You plan to configure Server1 as a Network Access Protection (NAP) health policy server for VPN enforcement by using the Configure NAP wizard. You need to ensure that you can configure the VPN enforcement method on Server1 successfully. What should you install on Server1 before you run the Configure NAP wizard?

 

  1. The Host Credential Authorization Protocol (HCAP)

  2. A system health validator (SHV)

  3. The Remote Access server role

  4. A Computer certificate

 

Correct Answer: D

 

 

QUESTION 133

You deploy two servers named Server1 and Server2. You install Network Policy Server (NPS) on both servers. On Server1, you configure the following NPS settings:

 

 

You export the NPS configurations to a file and import the file to Server2. You need to ensure that the NPS configurations on Server2 are the same as the NPS configurations on Server1. Which settings should you manually configure on Server2?

 

  1. SQL Server Logging Properties

  2. Connection Request Policies

  3. RADIUS Clients

  4. Network Policies

 

Correct Answer: A

 

  

QUESTION 134

You have a server named Server1 that has the Network Policy and Access Services server role installed. You plan to configure Network Policy Server (NPS) on Server1 to use certificate-based authentication for VPN connections. You obtain a certificate for NPS. You need to ensure that NPS can perform certificate-based authentication. To which store should you import the certificate?

 

To answer, select the appropriate store in the answer area.

 

Hot Area:

70-411-demo-75

 

Correct Answer:

70-411-demo-76

 

 

QUESTION 135

Your network contains an Active Directory domain named contoso.com. The domain contains a RADIUS server named Server1 that runs Windows Server 2012. You add a VPN server named Server2 to the network. On Server1, you create several network policies. You need to configure Server1 to accept authentication requests from Server2. Which tool should you use on Server1?

 

  1. Connection Manager Administration Kit (CMAK).

  2. Routing and Remote Access

  3. Network Policy Server (NPS)

  4. Set-RemoteAccessRadius

 

Correct Answer: C

  

 

QUESTION 136

Your network contains a RADIUS server named Server1. You install a new server named Server2 that runs Windows Server 2012 and has Network Policy Server (NPS) installed. You need to ensure that all accounting requests for Server2 are forwarded to Server1. On Server2, you create a new remote RADIUS server group named Group1 that contains Server1. What should you configure next on Server2?

 

To answer, select the appropriate node in the answer area.

 

Hot Area:

70-411-demo-77

 

Correct Answer:

70-411-demo-78

 

 

QUESTION 137

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1. Server1 has the DHCP Server role and the Network Policy Server role service installed. Server1 contains three non-overlapping scopes named Scope1, Scope2, and Scope3. Server1 currently provides the same Network Access Protection (NAP) settings to the three scopes. You modify the settings of Scope1 as shown in the exhibit.

 

70-411-demo-79

 

You need to configure Server1 to provide unique NAP enforcement settings to the NAP non- compliant DHCP clients from Scope1.

What should you create?

 

  1. A network policy that has the MS-Service Class condition

  2. A network policy that has the Identity Type condition

  3. A connection request policy that has the Identity Type condition

  4. A connection request policy that has the Service Type condition

 

Correct Answer: A

 

 

QUESTION 138

HOTSPOT

You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access server role installed. You have a client named Client1 that is configured as an 802.1X supplicant. You need to configure Server1 to handle authentication requests from Client1. The solution must minimize the number of authentication methods enabled on Server1. Which authentication method should you enable?

 

To answer, select the appropriate authentication method in the answer area.

 

Hot Area:

70-411-demo-80

 

Correct Answer:

70-411-demo-81

 

 

QUESTION 139

DRAG DROP

Your network contains an Active Directory domain named adatum.com. The domain contains a server named Server1 that runs Windows Server 2012. Server1 is configured as a Network Policy Server (NPS) server and as a DHCP server. You need to log all DHCP clients that have Windows Firewall disabled. Which three actions should you perform in sequence?

 

To answer, move the three appropriate actions from the list of actions to the answer area and arrange them in the correct order.

 

  1. Create a connection request policy

  2. Create Network Policy

  3. Create remediation server group

  4. Create Windows Security Health Validator (VSHV)

  5. Create a health Policy

 

Correct Answer: BCD

 

  

QUESTION 140

DRAG DROP

Your network contains an Active Directory domain named adatum.com. The domain contains a server named Server1 that runs Windows Server 2012. Server1 is configured as a Network Policy Server (NPS) server and as a DHCP server. You need to log all DHCP clients that have Windows Firewall disabled. Which three actions should you perform in sequence?

 

To answer, move the three appropriate actions from the list of actions to the answer area and arrange them in the correct order.

 

Select and Place:

70-411-demo-82

 

Correct Answer:

70-411-demo-83

 

QUESTION 141

HOTSPOT

You have a server named LON-SVR1 that runs Windows Server 2012. LON-SVR1 has the Remote Access server role installed. LON-SVR1 is located in the perimeter network. The IPv4 routing table on LON-SVR1 is configured as shown in the following exhibit.

 

70-411-demo-84

 

Your company purchases an additional router named Router1. Router1 has an interface that connects to the perimeter network and an interface that connects to the Internet. The IP address of the interface that connects to the perimeter network is 172.16.0.2. You need to ensure that LON-SVR1 will route traffic to the Internet by using Router1 if the current default gateway is unavailable. How should you configure the static route on LON-SVR1?

 

To answer, select the appropriate static route in the answer area.

 

Hot Area:

70-411-demo-85

 

Correct Answer:

70-411-demo-86

 

 

QUESTION 142

Force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL

 

  1. dfsgui.msc

  2. ultrasound

  3. rplmon

  4. frsutil

 

Correct Answer: C

 

 

QUESTION 143

I am using a Domain Admins account to run the console and the service is running under local system. I try approve Requests from Pending devices, then I got notice Access Denied, (Windows Server 2003 R2). And why Architecture x64, clients are x86? Is that the reason and how to fix it?

 

  1. Open WDS and right click on the server and select properties. Then click on the tab “PXE Response settings” and select respond to all (known and unknown) client. And also select the little checkbox below.

 

  1. You need to grant permissions on the OU in which you want to create machine accounts for the WDS Server Machine Account.

 

  1. To grant permissions to approve a pending computer.

Open Active Directory Users and Computers.

Right-click the OU where you are creating prestaged computer accounts, and then select Delegate Control.

On the first screen of the wizard, click Next.

Change the object type to include computers.

Add the computer object of the Windows Deployment Services server, and then click Next.

Select Create a Custom task to delegate.

Select Only the following objects in the folder. Then select the Computer Objects check box, select Create selected objects in this folder, and click Next.

In the Permissions box, select the Write all Properties check box, and click Finish.

 

  1. Define the OU path to add systems in WDS.

Delegate Computer object create or greater rights to the WDS server for the OU.

Delegate computer object create rights to your account or simply use a domain admin account to logon.

 

Correct Answer: C

 

 

QUESTION 144

Force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL

 

  1. ldp

  2. dfsgui.msc

  3. ultrasound

  4. rplmon

 

Correct Answer: D

 

 

QUESTION 145

How to give the minimum required permission to a user who wants to promote a RODC.

 

  1. member of the Domain Admins group

  2. allowed to attach the server to the RODC computer account

  3. Local admin

  4. organization admin

 

Correct Answer: BC

 

QUESTION 146

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. A domain controller named DC1 has the ADMX Migrator tool installed. You have a custom Administrative Template file on DC1 named Template1.adm. You need to add a custom registry entry to Template1.adm by using the ADMX Migrator tool. Which action should you run first?

 

  1. New Category

  2. Load Template

  3. New Policy Setting

  4. Generate ADMX from ADM

 

Correct Answer: D

 

 

QUESTION 147

HOTSPOT

Your network contains an Active Directory domain named contoso.com. You need to audit access to removable storage devices. Which audit category should you configure?

 

To answer, select the appropriate category in the answer area.

 

Hot Area:

70-411-demo-87

 

Correct Answer:

70-411-demo-88

 

 

QUESTION 148

Your network contains an Active Directory domain named adatum.com. You need to audit changes to the files in the SYSVOL shares on all of the domain controllers. The solution must minimize the amount of SYSVOL replication traffic caused by the audit. Which two settings should you configure? (Each correct answer presents part of the solution. Choose two.)

 

  1. Audit Policy\Audit system events

  2. Advanced Audit Policy Configuration\DS Access

  3. Advanced Audit Policy Configuration\Global Object Access Auditing

  4. Audit Policy\Audit object access

  5. Audit Policy\Audit directory service access

  6. Advanced Audit Policy Configuration\Object Access

 

Correct Answer: DF

 

 

QUESTION 149

HOTSPOT

Your network contains an Active Directory domain named contoso.com. You have several Windows PowerShell scripts that execute when client computers start. When a client computer starts, you discover that it takes a long time before users are prompted to log on. You need to reduce the amount of time it takes for the client computers to start. The solution must not prevent scripts from completing successfully. Which setting should you configure?

 

To answer, select the appropriate setting in the answer area.

 

Hot Area:

70-411-demo-89

 

Correct Answer:

70-411-demo-90

 

 

 

 

 

QUESTION 150

DRAG DROP

You are a network administrator of an Active Directory domain named contoso.com. You have a server named Server1 that runs Windows Server 2012. Server1 has the Web Server (IIS) server role installed. Server1 will host a web site at URL https://secure.contoso.com. The application pool identity account of the web site will be set to a domain user account named AppPool1. You need to identify the setspn.exe command that you must run to configure the appropriate Service Principal Name (SPN) for the web site. What should you run?

 

To answer, drag the appropriate objects to the correct location. Each object may be used once, more than once, or not at all.

 

Select and Place:

70-411-demo-91

 

Correct Answer:

70-411-demo-92

 

QUESTION 151

DRAG DROP

Your network contains an Active Directory domain named contoso.com. You deploy a web-based application named App1 to a server named Server1. App1 uses an application pool named AppPool1. AppPool1 uses a domain user account named User1 as its identity. You need to configure Kerberos constrained delegation for User1. Which three actions should you perform?

 

To answer, move the three appropriate actions from the list of actions to the answer area and arrange them in the correct order

 

Select and Place:

70-411-demo-93

 

Correct Answer:

70-411-demo-94

 

 

 

 

 

QUESTION 152

HOTSPOT

Your network contains an Active Directory domain called contoso.com. The domain contains a domain controller named DC1 that runs Windows server 2012. The domain contains some test client computers that run either Windows XP, Windows Vista, Windows 7, or Windows 8. The computer accounts for the test computers are located in an organizational unit (OU) named OU1.

You have a Group Policy object (GPO) named GPO1 linked to OU1. GPO1 is used to assign several applications to the test computers. You need to ensure that when the test computers in OU1 restart, you can see which application installation is running currently. Which setting should you modify in GPO1?

 

To answer, select the appropriate setting in the answer area.

 

Hot Area:

70-411-demo-95

 

Correct Answer:

70-411-demo-96

 

 

QUESTION 153

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. The domain contains 500 client computers that run Windows 8 Enterprise. You implement a Group Policy central store. You have an application named App1. App1 requires that a custom registry setting be deployed to all of the computers. You need to deploy the custom registry setting. The solution must minimize administrator effort. What should you configure in a Group Policy object (GPO)?

 

  1. The Administrative Templates

  2. An application control policy

  3. The Group Policy preferences

  4. Software installation setting

 

Correct Answer: C

 

 

QUESTION 154

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012. You create an Active Directory snapshot of DC1 each day. You need to view the contents of an Active Directory snapshot from two days ago. What should you do first?

 

  1. Run the dsamain.exe command.

  2. Stop the Active Directory Domain Services (AD DS) service.

  3. Run the ntdsutil.exe command.

  4. Start the Volume Shadow Copy Service (VSS).

 

Correct Answer: C

 

 

QUESTION 155

Your network contains an Active Directory domain named adatum.com. All domain controllers run Windows Server 2012. The domain contains a virtual machine named DC2. On DC2, you run Get-ADDCCloningExcludedApplicationList and receive the output shown in the following table.

 

70-411-demo-97

 

You need to ensure that you can clone DC2. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

 

  1. Create an empty file named CustomDCClonesAllowList.xml

 

  1. Add the following information to the DCCloneConfigSchema.xsd file:

<AllowList>

<Allow>

<Name>App1</Name>

<Type>Service</Type>

</Allow>

</AllowList>

 

  1. Create a filename DCCloneConfig.xml that contains the following information:

<AllowList>

<Allow>

<Name>App1</Name>

<Type>Service</Type>

</Allow>

</AllowList>

 

  1. Create a filename CustomDCCloneAllowList.xml that contains the following information:

<AllowList>

<Allow>

<Name>App1</Name>

<Type>Service</Type>

</Allow>

</AllowList>

 

  1. Create an empty file named DCCloneConfig.xml

 

Correct Answer: DE

 

 

QUESTION 156

Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server1. Server1 has the Web Server (IIS) server role installed. On Server1, you install a managed service account named Service1. You attempt to configure the World Wide Web Publishing Service as shown in the exhibit.

 

70-411-demo-98

 

You receive the following error message: “The account name is invalid or does not exist, or the password is invalid for the account name specified.” You need to ensure that the World Wide Web Publishing Service can log on by using the managed service account. What should you do?

 

  1. Specify contoso\service1$ as the account name.

  2. Specify [email protected] as the account name.

  3. Reset the password for the account.

  4. Enter and confirm the password for the account.

 

Correct Answer: A

 

 

QUESTION 157

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. You pre-create a read-only domain controller (P.QDC) account named RODC1. You export the settings of RODC1 to a file named File1.txt. You need to promote RODC1 by using File1.txt. Which tool should you use?

 

  1. The Dcpromo command

  2. The Install-WindowsFeature cmdlet

  3. The Install-ADDSDomainController cmdlet

  4. The Add-WindowsFeature cmdlet

  5. The Dism command

 

Correct Answer: A

 

 

QUESTION 158

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2008 R2. The domain contains three servers that run Windows Server 2012.

The servers are configured as shown in the following table.

 

70-411-demo-99

 

Server1 and Server2 are configured in a Network Load Balancing (NLB) cluster. The NLB cluster hosts a website named Web1 that uses an application pool named App1. Web1 uses a database named DB1 as its data store. You create an account named User1. You configure User1, as the identity of App1. You need to ensure that contoso.com domain users accessing Web1 connect to DB1 by using their own credentials. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

 

  1. Configure the delegation settings of Server3.

  2. Create a Service Principal Name (SPN) for User1.

  3. Configure the delegation settings of User1.

  4. Create a matching Service Principal Name (SPN) for Server1 and Server2.

  5. Configure the delegation settings of Server1 and Server2.

 

Correct Answer: BE

 

 

QUESTION 159

Your network contains an Active Directory domain named contoso.com. Domain controllers run either Windows Server 2003, Windows Server 2008 R2, or Windows Server 2012. A support technician accidentally deletes a user account named User1. You need to use tombstone reanimation to restore the User1 account. Which tool should you use?

 

  1. Ntdsutil

  2. Ldp

  3. Esentutl

  4. Active Directory Administrative Center

 

Correct Answer: B

 

 

QUESTION 160

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC4 that runs Windows Server 2012. You create a DCCloneConfig.xml file. You need to clone DC4. Where should you place DCCloneConfig.xml on DC4?

 

  1. %Systemroot%\SYSVOL

  2. %Programdata%\Microsoft

  3. %Systemroot%\NTDS

  4. %Systemdrive%

 

Correct Answer: C

 

QUESTION 161

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1. You run ntdsutil as shown in the exhibit.

 

70-411-demo-100

 

You need to ensure that you can access the contents of the mounted snapshot. What should you do?

 

  1. From a command prompt, run dsamain.exe -dbpath

c:\$snap_201204131056_volumec$\windows\ntds\ntds.dit – Idapport 33389.

  1. From a command prompt, run dsamain.exe -dbpath

c:\$snap_201204131056_volumec$\windows\ntds\ntds.dit – Idapport 389.

  1. From the snapshot context of ntdsutil, run activate instance “NTDS”.

  2. From the snapshot context of ntdsutil, run mount (79f94f82-5926-4f44-8af0-2f56d827a57d).

 

Correct Answer: A

 

 

QUESTION 162

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1. On DC1, you add a new volume and you stop the Active Directory Domain Services (AD DS) service. You run ntdsutil.exe and you set NTDS as the active instance. You need to move the Active Directory database to the new volume. Which Ntdsutil context should you use?

 

  1. Configurable Settings

  2. Partition management

  3. IFM

  4. Files

 

Correct Answer: D

 

 

QUESTION 163

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. On all of the domain controllers, Windows is installed in C:\Windows and the Active Directory database is located in D:\Windows\NTDS\. All of the domain controllers have a third-party application installed. The operating system fails to recognize that the application is compatible with domain controller cloning. You verify with the application vendor that the application supports domain controller cloning. You need to prepare a domain controller for cloning. What should you do?

 

  1. In D:\Windows\NTDS\, create an XML file named DCCloneConfig.xml and add the application information to the file.

  2. In D:\Windows\NTDS\, create an XML file named CustomDCCloneAllowList.xml and add the application information to the file.

  3. In the root of a USB flash drive, add the application information to an XML file named DefaultDCCloneAllowList.xml.

  4. In D:\Windows\NTDS, create an XML file named DefaultDCCloneAllowList.xml and add the application information to the file.

Correct Answer: B

 

 

QUESTION 164

HOTSPOT

You have a server named Server1 that has the Web Server (IIS) server role installed. You obtain a Web Server certificate. You need to configure a website on Server1 to use Secure Sockets Layer (SSL). To which store should you import the certificate?

 

Hot Area:

70-411-demo-101

 

Correct Answer:

70-411-demo-102

 

 

QUESTION 165

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. On all of the domain controllers, Windows is installed in C:\Windows and the Active Directory database is located in D:\Windows\NTDS\. All of the domain controllers have a third-party application installed. The operating system fails to recognize that the application is compatible with domain controller cloning. You verify with the application vendor that the application supports domain controller cloning. You need to prepare a domain controller for cloning. What should you do?

 

  1. In the root of a USB flash drive, add the application information to an XML file named DefaultDCCloneAllowList.xml.

  2. In C:\Windows\system32\sysprep\actionfiles\, add the application information to an XML file named Specialize .xml.

  3. In D:\Windows\NTDS\, create an XML file named CustomDCCloneAllowList.xml and add the application information to the file.

  4. In C:\Windows\system32\sysprep\actionfiles\add the application information to an XML file named Respecialize .xml.

 

Correct Answer: C

 

 

QUESTION 166

Your network contains an Active Directory domain named contoso.com. You create a user account named User1. The properties of User1 are shown in the exhibit.

 

70-411-demo-103

 

You plan to use the User1 account as a service account. The service will forward authentication requests to other servers. You need to ensure that you can view the Delegation tab from the properties of the User1 account. What should you do first?

 

  1. Modify the Security settings of User1.

  2. Modify the user principal name (UPN) of User1.

  3. Configure a Service Principal Name (SPN) for User1.

  4. Configure the Name Mappings of User1.

 

Correct Answer: C

 

 

QUESTION 167

Your network contains an Active Directory domain named adatum.com. The domain contains a domain controller named DC1. On DC1, you create a new volume named E. You restart DC1 in Directory Service Restore Mode. You open ntdsutil.exe and you set NTDS as the active instance. You need to move the Active Directory logs to E:\NTDS\. Which Ntdsutil context should you use?

 

  1. IFM

  2. Configurable Settings

  3. Partition management

  4. Files

 

Correct Answer: D

 

 

QUESTION 168

Your network contains an Active Directory domain named contoso.com. The domain contains six domain controllers. The domain controllers are configured as shown in the following table.

 

70-411-demo-104

 

The network contains a server named Server1 that has the Hyper-V server role installed. DC6 is a virtual machine that is hosted on Server1. You need to ensure that you can clone DC6. Which FSMO role should you transfer to DC2?

 

  1. Infrastructure Master

  2. RID Master

  3. Domain Naming Master

  4. PDC emulator

Correct Answer: D

 

 

QUESTION 169

Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server1. Server1 runs Windows Server 2012 and has the Hyper-V server role installed. Server1 hosts 10 virtual machines. A virtual machine named VM1 runs Windows Server 2012 and hosts a processor-intensive application names App1. Users report that App1 responds more slowly than expected. You need to monitor the processor usage on VM1 to identify whether changes must be made to the hardware settings of VM1. Which performance object should you monitor on Server1?

 

  1. Processor

  2. Hyper-V Hypervisor Root Virtual Processor

  3. Hyper-V Hypervisor Logical Processor

  4. Process

  5. Hyper-V Hypervisor Virtual Processor

 

Correct Answer: E

 

 

QUESTION 170

The contoso.com domain contains 2 domain controllers running Server 2012, AD recycle bin is enabled for the domain. DC1 is configured to take AD snapshots daily, DC2 is set to take snapshots weekly. Someone deletes a group containing 100 users, you need to recover this group. What should you do?

 

  1. Authoritative Restore

  2. Non Authoritative Restore

  3. Tombstone Reanimation

  4. Modify attribute isdeleted=true

 

Correct Answer: C

 

QUESTION 181

Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server1. Server1 runs Windows Server 2012 and has the Hyper-V server role installed. Server1 hosts 10 virtual machines. A virtual machine named VM1 runs Windows Server 2012 and hosts a processor-intensive application named Appl. Users report that App1 responds more slowly than expected. You need to monitor the processor usage on VM1 to identify whether changes must be made to the hardware settings of VM1. Which performance object should you monitor on Server1?

 

  1. Processor

  2. Hyper-V Hypervisor Virtual Processor

  3. Hyper-V Hypervisor Root Virtual Processor

  4. Process

  5. Hyper-V Hypervisor Logical Processor

 

Correct Answer: B

 

 

QUESTION 182

Your network contains an Active Directory domain named adatum.com. The domain contains 10 domain controllers that run Windows Server 2012.

 

You plan to create a new Active Directory-integrated zone named contoso.com.

You need to ensure that the new zone will be replicated to only four of the domain controllers.

 

What should you do first?

 

  1. Create an Active Directory connection object.

  2. Create an application directory partition.

  3. Change the zone replication scope.

  4. Create an Active Directory site link.

 

Correct Answer: B

 

 

QUESTION 183

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. You pre-create a read-only domain controller (P.QDC) account named RODC1. You export the settings of RODC1 to a file named Filel.txt. You need to promote RODC1 by using Filel.txt. Which tool should you use?

 

  1. The Install-WindowsFeature cmdlet

  2. The Add-WindowsFeature cmdlet

  3. The Dism command

  4. The Install-ADDSDomainController cmdlet

  5. the Dcpromo command

 

Correct Answer: E

 

 

QUESTION 184

How to configure IIS to change the authentication (kerberos or ntlm)

 

Solution:

cscript adsutil.vbs set w3svc/WebSite/root/NTAuthenticationProviders “Negotiate,NTLM”

 

  1. True

  2. False

 

Correct Answer: A

 

 

QUESTION 185

You need to enable three of your domain controllers as global catalog servers. Where would you configure the domain controllers as global catalogs?

 

  1. Forest, NTDS settings

  2. Domain, NTDS settings

  3. Site, NTDS settings

  4. Server, NTDS settings

 

Correct Answer: D

  

 

QUESTION 186

You are the network administrator for your organization. Your company uses a Windows Server 2012 Enterprise certification authority to issue certificates. You need to start using key archival. What should you do?

 

  1. Implement a distribution CRL.

  2. Install the smart card key retrieval.

  3. Implement a Group Policy object (GPO) that enables the Online Certificate Status Protocol (OCSP) responder.

  4. Archive the private key on the server.

 

Correct Answer: D

 

 

QUESTION 187

You wants to change the memory of a virtual machine that is currently powered up. What does he need to do?

 

  1. Shut down the virtual machine, use the virtual machine’s settings to change the memory, and start it again.

  2. Use the virtual machine’s settings to change the memory.

  3. Pause the virtual machine, use the virtual machine’s settings to change the memory, and resume it.

  4. Save the virtual machine, use the virtual machine’s settings to change the memory, and resume it.

 

Correct Answer: A

 

 

QUESTION 188

You need to stop an application from running in Task Manager. Which tab would you use to stop an application from running?

 

  1. Performance

  2. Users

  3. Options

  4. Details

 

Correct Answer: D

 

  

QUESTION 189

You upgraded all of your locations to Windows Server 2012 and implemented the routing capability built into the servers. You chose to implement RIP. After implementing the routers, you discover that routes that you don’t want your network to consider are updating your RIP routing tables. What can you do to control which networks the RIP routing protocol will communicate with on your network?

 

  1. Configure TCP/IP filtering.

  2. Configure RIP route filtering.

  3. Configure IP packet filtering.

  4. Configure RIP peer filtering.

  5. There is no way to control this behavior.

 

Correct Answer: B

 

 

QUESTION 190

Your company has offices in five locations around the country. Most of the users’ activity is local to their own network. Occasionally, some of the users in one location need to send confidential information to one of the other four locations or to retrieve information from one of them. The communication between the remote locations is sporadic and relatively infrequent, so you have configured RRAS to use demand-dial lines to set up the connections. Management’s only requirement is that any communication between the office locations be appropriately secured. Which of the following steps should you take to ensure compliance with this requirement? (Choose all that apply.)

 

  1. Configure CHAP on all the RRAS servers.

  2. Configure PAP on all the RRAS servers.

  3. Configure MPPE on all the RRAS servers.

  4. Configure L2TP on all the RRAS servers.

  5. Configure MS-CHAPv2 on all the RRAS servers.

 

Correct Answer: CE

QUESTION 171

You have a RODC named Server1 running Server 2012. You need to add a RODC Administrator. How do you complete the task?

 

  1. dsmgmt.exe

  2. ntdsutil

  3. Add user to Local Administrator Group on Server1

  4. Use Security Group and modify RODC Delegated Administrator

 

Correct Answer: D

 

 

QUESTION 172

DRAG DROP

Your network contains an Active Directory domain named contoso.com. You need to create an AD Snapshot. Which four actions should you perform?

 

To answer, move the four appropriate actions from the list of actions to the answer area and arrange them in the correct order.

 

Select and Place:

70-411-demo-105

 

Correct Answer:

70-411-demo-106

 

 

  

QUESTION 173

DRAG DROP

Your network contains an Active Directory forest named contoso.com. All domain controllers run Windows Server 2008 R2. The schema is upgraded to Windows Server 2012. Contoso.com contains two servers. The servers are configured as shown in the following table.

 

70-411-demo-107

 

Server 1 and Server2 host a load-balanced application pool named AppPool1. You need to ensure that AppPool1 uses a group Managed Service Account as its identity. Which 3 actions should you perform?

 

Select and Place:

70-411-demo-108

 

Correct Answer:

70-411-demo-109

 

 

 

 

QUESTION 174

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All domain controllers run Windows Server 2012. The domain contains two domain controllers. The domain controllers are configured as shown in the following table.

 

70-411-demo-110

 

Active Directory Recycle Bin is enabled. You discover that a support technician accidentally removed 100 users from an Active Directory group named Group1 an hour ago. You need to restore the membership of Group1. What should you do?

 

  1. Recover the items by using Active Directory Recycle Bin.

  2. Modify the Recycled attribute of Group1.

  3. Perform tombstone reanimation.

  4. Perform an authoritative restore.

 

Correct Answer: C

 

 

QUESTION 175

Your network contains an Active Directory domain named contoso.com. The domain contains a read-only domain controller (RODC) named RODC1. You create a global group named RODC_Admins. You need to provide the members of RODC_Admins with the ability to manage the hardware and the software on RODC1. The solution must not provide RODC_Admins with the ability to manage Active Directory objects. What should you do?

 

  1. From Active Directory Users and Computers, configure the Managed By settings of the RODC1 account.

  2. From Active Directory Sites and Services, run the Delegation of Control Wizard

  3. From a command prompt, run the dsmgmt local roles command.

  4. From a command prompt, run the dsadd computer command.

 

Correct Answer: C

 

 

 

 

QUESTION 176

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. In a remote site, a support technician installs a server named DC10 that runs Windows Server 2012. DC10 is currently a member of a workgroup. You plan to promote DC10 to a read-only domain controller (RODC). You need to ensure that a user named Contoso/User1 can promote DC10 to a RODC in the contoso.com domain. The solution must minimize the number of permissions assigned to User1. What should you do?

 

  1. Join DC10 to the domain. Modify the properties of the DC10 computer account.

  2. From Active Directory Administrative Center, pre-create an RODC computer account.

  3. Join DC10 to the domain. Run dsmod and specify the /server switch.

  4. From Active Directory Administrative Center, modify the security settings of the Domain Controllers organizational unit (OU).

 

Correct Answer: B

 

 

QUESTION 177

HOTSPOT

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All domain controllers run Windows Server 2012 and are configured as DNS servers. All DNS zones are Active Directory-integrated. Active Directory Recycle Bin is enabled. You need to modify the amount of time deleted objects are retained in the Active Directory Recycle Bin. Which naming context should you use?

 

To answer, select the appropriate naming context in the answer area.

 

Hot Area:

70-411-demo-111

Correct Answer:

70-411-demo-112

 

 

QUESTION 178

Your network contains an Active Directory domain named contoso.com. The domain contains six domain controllers. The domain controllers are configured as shown in the following table.

 

70-411-demo-113

 

The network contains a server named Server1 that has the Hyper-V server role installed. DC6 is a virtual machine that is hosted on Server1. You need to ensure that you can clone DC6. What should you do?

 

  1. Transfer the schema master to DC6.

  2. Transfer the schema master to DC4.

  3. Transfer the PDC emulator to DC2.

  4. Transfer the PDC emulator to DC5.

Correct Answer: C

 

 

QUESTION 179

Your network contains an Active Directory forest named contoso.com. All servers run Windows Server 2012. You need to create a custom Active Directory application partition. Which tool should you use?

 

  1. Dsadd

  2. Dsmod

  3. Netdom

  4. Ntdsutil

 

Correct Answer: D

 

 

QUESTION 180

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. The domain contains two servers. The servers are configured as shown in the following table.

 

70-411-demo-114

 

Server1 and Server2 host a load-balanced website named Web1. Web1 runs by using an

application pool named WebApp1. WebApp1 uses a group Managed Service Account named

gMSA1 as its identity. Domain users connect to Web1 by using either the name

webl.contoso.com or the alias myweb.contoso.com. You discover the following:

 

  • When the users access Web1 by using webl.contoso.com, they authenticate by using

Kerberos.

  • When the users access Web1 by using myweb.contoso.com, they authenticate by using

NTLM.

 

You need to ensure that the users can authenticate by using Kerberos when they connect by

using myweb.contoso.com. What should you do?

 

  1. Modify the properties of the WebApp1 application pool.

  2. Run the Add-ADComputerServiceAccount cmdlet.

  3. Modify the properties of the Web1 website.

  4. Modify the properties of the gMSA1 service account.

 

Correct Answer: B