70-411 | Your network contains an Active Directory domain…

Question: 24

Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. You need to provide an Administrator named Admin1 with the ability to create GPOs in the domain. The solution must not provide Admin1 with the ability to link GPOs. What should you use?

A. dcgpofix
B. Get-GPOReport
C. Gpfixup
D. Gpresult
E. Gptedit.msc
F. Import-GPO
G. Restore-GPO
H. Set-GPInheritance
I. Set-GPLink
J. Set-GPPermission
K. Gpupdate
L. Add-ADGroupMember

Answer: J

70-411 | Active Directory Domain Services (AD DS) domain…

Question: 23

You work as a Network Administrator at Site.com. Site.com has an Active Directory Domain Services (AD DS) domain named Site.com. All servers in the Site.com domain have Microsoft Windows Server 2012 R2 installed and all client computers have Windows 8 Pro installed.

Site.com has a Sales department. An organizational unit (OU) exists for the Sales department and contains the user and computer accounts for the department. A group policy object (GPO) named SalesGPO is linked to the Sales OU and applies settings to the Sales users and their computers. You modify some settings in SalesGPO. You need to apply the new settings to the users and computers in the Sales OU as quickly as possible. Which two of the following tools could you use? (Choose two possible answers).

A. You should use the Group Policy Management Console (GPMC).
B. You should use the Invoke-GPUpdate cmdlet.
C. You should use the Active Directory Sites and Services.
D. You should use the Get-GPO cmdlet.
E. You should use the Secedit command.
F. You should use the Set-GPLink cmdlet.

Answer: A,B

70-411 | You work as a Network Administrator…

Question: 22

You work as a Network Administrator at Site.com. Site.com has an Active Directory Domain Services (AD DS) domain named Site.com. All servers in the Site.com domain have Microsoft Windows Server 2012 R2 installed and all client computers have Windows 8 Pro installed.

Site.com has users that often work away from the office at customer sites or from home. You have been asked to implement a remote access solution to enable remote users to connect to the network when they are working away from the office. The remote access solution must ensure that users can connect to the network using TCP port 443.

You install the Routing and Remote Access role on a Windows Server 2012 R2 server. Which VPN solution should you implement?

A. Point-to-Point Tunneling Protocol (PPTP).
B. Layer 2 Tunneling Protocol (L2TP).
C. Secure Socket Tunneling Protocol (SSTP).
D. DirectAccess.

Answer: C

70-411 | Your network contains an Active….

Question: 21

Your network contains an Active Directory domain named contoso.com. You need to create a certificate template for the BitLocker Drive Encryption (BitLocker) Network Unlock feature. Which Cryptography setting of the certificate template should you modify? To answer, select the appropriate setting in the answer area.

Solution:

Cryptographic provider that supports RSA (Microsoft Software Key Storage Provider)

A. True
B. False

Answer: A

What should you do?

Question: 32

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the File Server Resource Manager role service installed.
Each time a user receives an access-denied message after attempting to access a folder on Server1, an email notification is sent to a distribution list named DLL.
You create a folder named Folder1 on Server1, and then you configure custom NTFS permissions for Folder1.
You need to ensure that when a user receives an access-denied message while attempting to access Folder1, an email notification is sent to a distribution list named DL2. The solution must not prevent DL1 from receiving notifications about other access-denied messages.
What should you do?

A. From the File Server Resource Manager console, create a local classification property.
B. From Server Manager, run the New Share Wizard to create a share for Folder1 by selecting the SMB Share – Applications option.
C. From the File Server Resource Manager console, modify the Access-Denied Assistance settings.
D. From the File Server Resource Manager console, set a folder management property.

Answer: D

70-411 | Your network contains an Active Directory domain named adatum.com.The domain contains a member server named Server1 and 10 web servers.

Question : 31

Your network contains an Active Directory domain named adatum.com.The domain contains a member server named Server1 and 10 web servers.All of the web servers are in an organizational unit (OU) named WebServers_OU.All of the servers run Windows Server 2012 R2.On Server1,you need to collect the error events from all of the web servers.The solution must ensure that when new web servers are added to WebServers _OU,their error events are collected automatically on Server1.What should you do?

A. On Server1, create a source computer initiated subscription. From a Group Policy object
(GPO), configure the Configure target Subscription Manager setting.
B. On Server1, create a source computer initiated subscription. From a Group Policy object
(GPO), configure the Configure forwarder resource usage setting.
C. On Server1, create a collector initiated subscription. From a Group Policy object (GPO),
configure the Configure forwarder resource usage setting.
D. On Server1, create a collector initiated subscription. From a Group Policy object (GPO),
configure the Configure target Subscription Manager setting.

Answer : A

70-411 | You have a server named Server1 that runs Windows Server 2012 R2. You create a Data Collector Set (DCS) named DCS1.You need to configure DCS1 to log data to D:\logs.What should you do?

Question : 30

You have a server named Server1 that runs Windows Server 2012 R2. You create a Data Collector Set (DCS) named DCS1.You need to configure DCS1 to log data to D:\logs.What should you do?

A. Right-click DCS1 and click Properties.
B. Right-click DCS1 and click Export list. . .
C. Right-click DCS1 and click Data Manager. . .
D. Right-click DCS1 and click Save template. . .

Answer: A

70-411 Sample Question : 13

Question : 13

You have a server named Server1 that runs Windows Server 2012 R2.You create a Data Collector Set (DCS) named DCS1.You need to configure DCS1 to log data to D:\logs.What should you do?

A. Right-click DCS1 and click Properties.
B. Right-click DCS1 and click Save template…
C. Right-click DCS1 and click Data Manager…
D. Right-click DCS1 and click Export list…

Answer: A

70-411 Sample Question : 12

Question : 12

Your network contains two Active Directory forests named contoso.com and dev.contoso.com.The contoso.com forest contains a domain controller named DC1. The dev.contoso.com forest contains a domain controller named DC2. Each domain contains an organizational unit (OU) named OU1.Dev.contoso.com has a Group Policy object (GPO) named GPO1. GPO1 contains 200 settings,including several settings that have network paths. GPO1 is linked to OU1.You need to copy GPO1 from dev.contoso.com to contoso.com.What should you do first on DC2?

A.From the Group Policy Management console, right-click GPO1 and select Copy.
B.Run the mtedit.exe command and specify the /Domaintcontoso.com /DC:DC 1 parameter.
C.Run the Save-NetGpocmdlet.
D.Run the Backup-Gpocmdlet.

Answer:A

70-411 Sample Question : 11

Question : 11

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2. One of the domain controllers is named DC1.The DNS zone for the contoso.com zone is Active Directory-integrated and has the default settings.A server named Server1 is a DNS server that runs a UNIX-based operating system.You plan to use Server1 as a secondary DNS server for the contoso.com zone.You need to ensure that Server1 can host a secondary copy of the contoso.com zone.What should you do?

A. From Windows PowerShell, run the Set-DnsServerPrimaryZone cmdlet and specify the contoso.com zone as a target.
B. From DNS Manager, modify the Security settings of DC1
C. From DNS Manager, modify the replication scope of the contoso.com zone
D. From DNS Manager, modify the Advanced settings of DC1.

Answer : A

70-411 Sample Question : 10

Question : 10

You are hired by ABC.com to administrate a Microsoft Windows Server 2012 domain named ABC.com. ABC.com utilizes a computer named ABC-DC01 configured as a Web server and domain controller.During the course of the week you receive instruction to configure order in which three group policy objects (GPOs) named KingPolicy, TestPolicy and ABCPolicy are applied.Which action should be taken?

A. You should consider utilizing Gpfixup and Gpupdate commands.

B. You should consider utilizing Gpresult and Restore-GPO commands.

C. You should consider utilizing Add-ADGroupMember and Get-GPOReport commands.

D. You should consider utilizing the Set-GPLink command.

Answer: D

70-411 Sample Question : 9

Question : 9

You are hired by ABC.com to administrate a Microsoft Windows Server 2012 domain named ABC.com. ABC.com utilizes a computer named ABC-DC01 for running several administrative tasks.ABC.com wants you to create a process for recording registry setting values and Directory Services replication data. You start configuring a Data Collector Set (DCS) named KingTrace.What additional action should be taken?

A. You should consider configuring the KingTrace data collector set for Event trace data and a Performance Counter Alert.

B. You should consider configuring the KingTrace data collector set for a Performance Counter and System Configuration information.

C. You should consider configuring the KingTrace data collector set for system configuration information and event trace data.

D. You should consider configuring the KingTrace data collector set for a performance counter alert and system configuration information.

Answer: A

70-411 Sample Question : 8

Question : 8

You are hired by ABC.com to administrate a Microsoft Windows Server 2012 domain named ABC.com. ABC.com utilizes several administrative templates via Group Policy.You must provide a solution for reviewing active and inactive Group Policy settings containing comments.Which action can be utilized to filter out of scope Group Policy Objects to view only settings to be removed from registry? (Choose all that apply)

A. You should configure the Configured Filter Options to No.

B. You should configure the Commented Filter Options to No.

C. You should configure the Managed Filter Options to Yes.

D. You should configure the Commented Filter Options to Yes.

E. You should configure the Configured Filter Options to Any.

F. You should configure the Managed Filter Options to Any.

Answer: C,D,E

70-411 Sample Question : 7

Question : 7

You work as the network administrator for a Microsoft Windows Server 2008 domain named ABC.com. ABC.com has a Development division which utilizes two organizational units (OU) named DevelopUsers and DevelopComputers for user and computer account storage. The Development division user and computer accounts are configured as members of global security groups named DevUsers and DevComputers.During the course of the week you configure two Password Settings objects for Development division members named CredSettings01 and CredSettings02. You additionally configure a minimum password length of 10 for CredSettings01 and 9 for CredSettings02. ABC.com wants you to determine the required password length minimum for Development division users. What minimum password length should be configured for CredSettings01 applied to DevUsers?

A. You should configure the minimum password length to 9.

B. You should configure the minimum password length to 10.

C. You should configure the minimum password length to 5.

D. You should configure the minimum password length to 4.

Answer: B

70-411 Sample Question : 6

Question : 6

You are hired by ABC.com to administrate a Microsoft Windows Server 2012 forests named ABC.com and weyland.com. The forest utilize three computers named ABC-DC01, WEYLANDDC01 and ABC-SR01.ABC-SR01 is configured as a DHCP and VPN Server and ABC-DC01 is configured as the DNS,Web and NPS server whilst WEYLAND-DC01 is configured as the File server and NPS server.Which action should be taken to ensure connection requests are forwarded from ABC-DC01 to WEYLAND-DC01?

A. You should consider modifying the Location Groups and Identity Type conditions of the connection request policies.

B. You should consider modifying the Authentication settings and Standard RADIUS Attributes settings of the connection request policies.

C. You should consider modifying the User Name and Location Groups condition of the

connection request policies.

D. You should consider modifying the Authentication settings and User Name conditions of the connection request policies.

Answer: A

Search Words: 70-411 Exam real exam questions answers practice test braindumps, free Q&A online dumps download and free 70-411 Exam discount coupon code available.