QUESTION: 18
You work as a Network Administrator at Site.com. Site.com has an Active Directory Domain Services (AD DS) domain named Site.com. All servers in the Site.com
domain have Microsoft Windows Server 2012 R2 installed.
Mia works as an IT Technician at Site.com. Mia is not a member of the Domain Admins group.
You need to enable Mia to link existing Group Policy objects (GPOs) in the domain. Mia must not be able to modify existing GPOs.
Your solution must minimize the administrative privileges assigned to Mia. Which two of the following actions would achieve the desired result? (Choose two possible answers).
A. Click the Group Policy Objects node in Group Policy Management and add Mia under the Delegation tab.
B. Click the domain node in Group Policy Management and add Mia under the Delegation tab.
C. Right-click the domain node in Active Directory Users and Computers and select Delegate Control.
D. Add Mia to the Group Policy Creator Owners group in Active Directory Users and Computers.
E. In Active Directory Users and Computers, add Mia to the Managed By tab in the properties of the Domain Controllers group.
Answer: B,C
Thursday, 16 March 2017
Monday, 6 February 2017
70-411 Sample Question
QUESTION: 17
You work as a Network Administrator at Site.com. Site.com has an Active Directory Domain Services (AD DS) domain named Site.com. All servers in the Site.com domain have Microsoft Windows Server 2012 R2 installed and all client computers have either Windows 7 Professional or Windows 8 Pro installed.
A group policy object (GPO) is assigned to an organizational unit (OU) named Sales. The GPO assigns several settings to the computers in the Sales department. Some users complain that it takes a long time for their computers to start up or shut down.
You suspect that group policy processing may be the cause of the issue. You want to configure the computers in the Sales department to display status messages that reflect each step in the process of starting, shutting down, logging on, or logging off the system. How can you configure the computers to display the required information?
A. You should enable the "Activate Shutdown Event Tracker System State Data feature" setting in the GPO.
B. You should enable the "Display Shutdown Event Tracker" setting in the GPO.
C. You should disable the "Remove Boot / Shutdown / Logon / Logoff status messages" setting in the GPO.
D. You should enable the "Display Highly Detailed Status Messages" setting in the GPO.
Answer: D
You work as a Network Administrator at Site.com. Site.com has an Active Directory Domain Services (AD DS) domain named Site.com. All servers in the Site.com domain have Microsoft Windows Server 2012 R2 installed and all client computers have either Windows 7 Professional or Windows 8 Pro installed.
A group policy object (GPO) is assigned to an organizational unit (OU) named Sales. The GPO assigns several settings to the computers in the Sales department. Some users complain that it takes a long time for their computers to start up or shut down.
You suspect that group policy processing may be the cause of the issue. You want to configure the computers in the Sales department to display status messages that reflect each step in the process of starting, shutting down, logging on, or logging off the system. How can you configure the computers to display the required information?
A. You should enable the "Activate Shutdown Event Tracker System State Data feature" setting in the GPO.
B. You should enable the "Display Shutdown Event Tracker" setting in the GPO.
C. You should disable the "Remove Boot / Shutdown / Logon / Logoff status messages" setting in the GPO.
D. You should enable the "Display Highly Detailed Status Messages" setting in the GPO.
Answer: D
Monday, 23 January 2017
70-411 Sample Question
QUESTION: 16
You work as a Network Administrator at Site.com. Site.com has an Active Directory Domain Services (AD DS) domain named Site.com. All servers in the Site.com domain have Microsoft Windows Server 2012 R2 installed. You need to configure a remote access solution to enable client computers to access network resources. You install a Windows Server 2012 R2 server named Site-SR09. You install the Remote Access server role on Site-SR09. You need to configure Site-SR09 to accept authentication requests from computers using 802.1X. Which authentication method should you configure Site-SR09 to use?
A. EAP
B. MS-CHAP v2
C. CHAP
D. PAP
E. Machine certificate authentication for IKEv2
Answer: A
You work as a Network Administrator at Site.com. Site.com has an Active Directory Domain Services (AD DS) domain named Site.com. All servers in the Site.com domain have Microsoft Windows Server 2012 R2 installed. You need to configure a remote access solution to enable client computers to access network resources. You install a Windows Server 2012 R2 server named Site-SR09. You install the Remote Access server role on Site-SR09. You need to configure Site-SR09 to accept authentication requests from computers using 802.1X. Which authentication method should you configure Site-SR09 to use?
A. EAP
B. MS-CHAP v2
C. CHAP
D. PAP
E. Machine certificate authentication for IKEv2
Answer: A
Wednesday, 28 December 2016
70-411 Sample Question
QUESTION: 15
You work as a Network Administrator at Site.com. Site.com has an Active Directory Domain Services (AD DS) domain named Site.com. All servers in the Site.com domain have Microsoft Windows Server 2012 R2 installed. Site.com has a Sales department. An OU exists for the Sales department.
The OU contains the user and computer accounts for the Sales department. A shadow group named SalesSG is configured for the Sales OU and contains all objects within the Sales OU. A password settings object (PSO) named SalesPSO is applied to the SalesSG group. You want to view the settings of SalesPSO. How can you view the settings of SalesPSO?
A. You should run the Get-ADDefaultDomainPasswordPolicy cmdlet.
B. You should run the Get- ADAccountPassword cmdlet.
C. You should run the Get-ADFineGrainedPasswordPolicy cmdlet.
D. You should run the Get-ADDefaultDomainPasswordPolicy cmdlet.
Answer: C
You work as a Network Administrator at Site.com. Site.com has an Active Directory Domain Services (AD DS) domain named Site.com. All servers in the Site.com domain have Microsoft Windows Server 2012 R2 installed. Site.com has a Sales department. An OU exists for the Sales department.
The OU contains the user and computer accounts for the Sales department. A shadow group named SalesSG is configured for the Sales OU and contains all objects within the Sales OU. A password settings object (PSO) named SalesPSO is applied to the SalesSG group. You want to view the settings of SalesPSO. How can you view the settings of SalesPSO?
A. You should run the Get-ADDefaultDomainPasswordPolicy cmdlet.
B. You should run the Get- ADAccountPassword cmdlet.
C. You should run the Get-ADFineGrainedPasswordPolicy cmdlet.
D. You should run the Get-ADDefaultDomainPasswordPolicy cmdlet.
Answer: C
Thursday, 15 December 2016
70-411 Sample Question
QUESTION: 14
You work as a Network Administrator at Site.com. Site.com has an Active Directory Domain Services (AD DS) domain named Site.com. All servers on the network have Windows Server 2012 R2 installed.
DirectAccess is enabled on the network using the default configuration. You want the DirectAccess clients to use DirectAccess whenever they access the Internet. Which of the following actions should you take?
A. You should run the Set-DAClientExperienceConfiguration cmdlet.
B. You should run the run the netsh -c advfirewall command.
C. You should modify the external IP address assigned to the Web server.
D. You should configure the force tunneling settings for DirectAccess clients.
Answer: D
You work as a Network Administrator at Site.com. Site.com has an Active Directory Domain Services (AD DS) domain named Site.com. All servers on the network have Windows Server 2012 R2 installed.
DirectAccess is enabled on the network using the default configuration. You want the DirectAccess clients to use DirectAccess whenever they access the Internet. Which of the following actions should you take?
A. You should run the Set-DAClientExperienceConfiguration cmdlet.
B. You should run the run the netsh -c advfirewall command.
C. You should modify the external IP address assigned to the Web server.
D. You should configure the force tunneling settings for DirectAccess clients.
Answer: D
Tuesday, 9 August 2016
70-411 Sample Question
QUESTION: 13
Your network contains a Hyper-V host named Hyperv1. Hyperv1 runs Windows Server 2012 R2. Hyperv1 hosts four virtual machines named VM1, VM2, VM3, and VM4.All of the virtual machines run Windows Server 2008 R2. You need to view the amount of memory resources and processor resources that VM4 currently uses. Which tool should you use on Hyperv1?
A. Resource Monitor
B. Task Manager
C. Hyper-V Manager
D. Windows System Resource Manager (WSRM)
Answer : C
Monday, 25 July 2016
70-411 Sample Question
QUESTION: 12
Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2. One of the domain controllers is named DC1.The DNS zone for the contoso.com zone is Active Directory-integrated and has the default settings.A server named Server1 is a DNS server that runs a UNIX-based operating system.You plan to use Server1 as a secondary DNS server for the contoso.com zone.You need to ensure that Server1 can host a secondary copy of the contoso.com zone.What should you do?
A. From Windows PowerShell, run the Set-DnsServerPrimaryZone cmdlet and specify the contoso.com zone as a target.
B. From DNS Manager, modify the Security settings of DC1
C. From DNS Manager, modify the replication scope of the contoso.com zone
D. From DNS Manager, modify the Advanced settings of DC1.
Answer : A
Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2. One of the domain controllers is named DC1.The DNS zone for the contoso.com zone is Active Directory-integrated and has the default settings.A server named Server1 is a DNS server that runs a UNIX-based operating system.You plan to use Server1 as a secondary DNS server for the contoso.com zone.You need to ensure that Server1 can host a secondary copy of the contoso.com zone.What should you do?
A. From Windows PowerShell, run the Set-DnsServerPrimaryZone cmdlet and specify the contoso.com zone as a target.
B. From DNS Manager, modify the Security settings of DC1
C. From DNS Manager, modify the replication scope of the contoso.com zone
D. From DNS Manager, modify the Advanced settings of DC1.
Answer : A
Subscribe to:
Posts (Atom)