Ensurepass

QUESTION 281

Your network contains an Active Directory domain named contoso.com. You have a Group Policy object (GPO) named GP1 that is linked to the domain. GP1 contains a software restriction policy that blocks an Application named App1. You have a workgroup computer named Computer1 that runs Windows 8. A local Group Policy on Computer1 contains an Application control policy that allows App1. You join Computer1 to the domain. You need to prevent App1 from running on Computer1. What should you do?

 

A.      From Group Policy Management, add an Application control policy to GP1.

B.      From Group Policy Management, enable the Enforced option on GP1.

C.      In the local Group Policy of Computer1, configure a software restriction policy.

D.      From Computer1, run gpupdate /force.

 

Correct Answer: A

 

 

QUESTION 282

Your network contains an Active Directory domain named contoso.com. The domain contains an Application server named Server1. Server1 runs Windows Server 2012. Server1 is configured as an FTP server. Client computers use an FTP Application named App1.exe. App1.exe uses TCP port 21 as the control port and dynamically requests a data port. On Server1, you create a firewall rule to allow connections on TCP port 21. You need to configure Server1 to support the client connections from App1.exe. What should you do?

 

A.      Run netsh firewall addportopening TCP 21 dynamicftp.

B.      Create a tunnel connection security rule.

C.      Create an outbound firewall rule to allow App1.exe.

D.      Create an inbound firewall rule to allow App1.exe.

E.       Run netshadvfirewall set global statefulftp enable.

F.       Run Set-NetFirewallRule -DisplayNameDynamicFTP -Profile Domain

 

Correct Answer: A

 

 

QUESTION 283

HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains an organizational unit (OU) named OU1 as shown in the OU1 exhibit.

clip_image002

 

The membership of Group1 is shown in the Group1 exhibit.

 

clip_image003

 

You configure GPO1 to prohibit access to Control Panel. GPO1 is linked to OU1 as shown in the GPO1 exhibit.

 

clip_image005

 

Select Yes if the statement can be shown to be true based on the available information; otherwise select No. Each correct selection is worth one point.

 

Hot Area:

clip_image007

 

Correct Answer:

clip_image009

 

 

QUESTION 284

Your network contains an Active Directory domain named adatum.com. You discover that when users join computers to the domain, the computer accounts are created in the Computers container. You need to ensure that when users join computers to the domain, the computer accounts are automatically created in an organizational unit (OU) named All_Computers. What should you do?

 

A.      From Ldp, configure the properties of the Computers container.

B.      From Windows PowerShell, run the Move-ADObjectcmdlet.

C.      From ADSI Edit, configure the properties of the Computers container.

D.      From a command prompt, run the redircmp.exe command.

 

Correct Answer: D

 

 

QUESTION 285

Your company has a main office and four branch offices. The main office contains a server named Server1 that runs Windows Server 2012. The IP configuration of each office is configured as shown in the following table.

 

clip_image010

 

You need to add a single static route on Server1 to ensure that Server1 can communicate with the hosts on all of the subnets. Which command should you run?

 

A.      route.exe add -p 192.168.0.0 mask 255.255.248.0 172.31.255.254

B.      route.exe add -p 192.168.12.0 mask 255.255.252.0 172.31.255.254

C.      route.exe add -p 192.168.8.0 mask 255.255.252.0 172.31.255.254

D.      route.exe add -p 192.168.12.0 mask 255.255.255.0 172.31.255.254

 

Correct Answer: B

 

 

QUESTION 286

Your network contains two Active Directory forests named contoso.com and adatum.com. Each forest contains one domain. A two-way forest trust exists between the forests. The forests use the address spaces shown in the following table.

 

clip_image011

 

From a computer in the contoso.com domain, you can perform reverse lookups for the servers in the contoso.com domain, but you cannot perform reverse lookups for the servers in the adatum.com domain. From a computer in the adatum.com domain, you can perform reverse lookups for the servers in both domains. You need to ensure that you can perform reverse lookups for the servers in the adatum.com domain from the computers in the contoso.com domain. What should you create?

 

A.      a delegation

B.      a trust point

C.      a conditional forwarder

D.      a GlobalNames zone

 

Correct Answer: C

 

 

QUESTION 287

Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server 2012. Server2 establishes an IPSec connection to Server1. You need to view which authentication method was used to establish the initial IPSec connection. What should you do?

 

A.      From Windows Firewall with Advanced Security, view the quick mode security association.

B.      From Event Viewer, search the Application Log for events that have an ID of 1704.

C.      From Event Viewer, search the Security Log for events that have an ID of 4672.

D.      From Windows Firewall with Advanced Security, view the main mode security association.

 

Correct Answer: D

 

 

QUESTION 288

HOTSPOT

You have a Group Policy object (GPO) named Server Audit Policy. The settings of the GPO are shown in the Settings exhibit.

 

clip_image013

 

The scope of the GPO is shown in the Scope exhibit.

clip_image015

 

The domain contains a group named Group1. The membership of Group1 is shown in the Group1 exhibit.

 

clip_image016

 

Select Yes if the statement can be shown to be true based on the available information; otherwise select No. Each correct selection is worth one point.

 

Hot Area:

clip_image018

 

Correct Answer:

clip_image020

 

 

QUESTION 289

Your network contains an Active Directory domain named contoso.com. You have a Group Policy object (GPO) named GPO1 that contains several user settings. GPO1 is linked to an organizational unit (OU) named OU1. The help desk reports that GPO1App1ies to only some of the users in OU1. You open Group Policy Management as shown in the exhibit.

 

clip_image022

 

You need to configure GPO1 to App1y to all of the users in OU1. What should you do?

 

A.      Modify the Security settings of GPO1.

B.      Disable Block Inheritance on OU1.

C.      Modify the GPO status of GPO1.

D.      Enforce GPO1.

 

Correct Answer: A

 

 

QUESTION 290

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012. On a server named Server2, you perform a Server Core Installation of Windows Server 2012. You join Server2 to the contoso.com domain.

You need to ensure that you can manage Server2 by using the Computer Management console on Server1. What should you do on Server2?

 

A.      Install Remote Server Administration Tools (RSAT).

B.      Install Windows Management Framework.

C.      Run sconfig.exe and configure remote management.

D.      Run sconfig.exe and configure Remote Server Administration Tools (RSAT).

 

Correct Answer: C

 

 

Comments are closed.