Ensurepass

QUESTION 301

Your network contains an Active Directory domain named contoso.com. The domain contains a

domain controller named DC1 that runs Windows Server 2012 R2. DC1 is backed up daily. The

domain has the Active Directory Recycle Bin enabled. During routine maintenance, you delete

500 inactive user accounts and 100 inactive groups. One of the deleted groups is named Group1.

Some of the deleted user accounts are members of some of the deleted groups. For

documentation purposes, you must provide a list of the members of Group1 before the group

was deleted. You need to identify the names of the users who were members of Group1 prior to

its deletion. You want to achieve this goal by using the minimum amount of administrative effort.

What should you do first?

 

  1. Mount the most recent Active Directory backup.

  2. Reactivate the tombstone of Group1.

  3. Perform an authoritative restore of Group1.

  4. Use the Recycle Bin to restore Group1.

 

Correct Answer: A

 

 

QUESTION 302

Your network contains an Active Directory domain named contoso.com. All domain controllers

run either Windows Server 2008 or Windows Server 2008 R2. You deploy a new domain

controller named DC1 that runs Windows Server 2012 R2. You log on to DC1 by using an account

that is a member of the Domain Admins group. You discover that you cannot create Password

Settings objects (PSOs) by using Active Directory Administrative Center. You need to ensure that

you can create PSOs from Active Directory Administrative Center. What should you do?

 

  1. Modify the membership of the Group Policy Creator Owners group.

  2. Transfer the PDC emulator operations master role to DC1.

  3. Upgrade all of the domain controllers that run Window Server 2008.

  4. Raise the functional level of the domain.

 

Correct Answer: D

 

 

QUESTION 303

Your network contains an Active Directory domain named contoso.com. The Active Directory

Recycle bin is enabled for contoso.com. A support technician accidentally deletes a user account

named User1. You need to restore the User1 account. Which tool should you use?

 

  1. Ldp

  2. Esentutl

  3. Active Directory Administrative Center

  4. Ntdsutil

Correct Answer: C

 

 

QUESTION 304

Your network contains an Active Directory domain named contoso.com. You need to install and

configure the Web Application Proxy role service. What should you do?

 

  1. Install the Active Directory Federation Services server role and the Remote Access server role

on different servers.

  1. Install the Active Directory Federation Services server role and the Remote Access server role

on the same server.

  1. Install the Web Server (IIS) server role and the Application Server server role on the same

server.

  1. Install the Web Server (IIS) server role and the Application Server server role on different

servers.

 

Correct Answer: A

 

 

QUESTION 305

Your network contains an Active Directory domain named contoso.com. The domain contains

three servers. The servers are configured as shown in t
he following table.

 

70-411-demo-190

 

You need to ensure that end-to-end encryption is used between clients and Server2 when the

clients connect to the network by using DirectAccess. Which two actions should you perform?

(Each correct answer presents part of the solution. Choose two.)

 

  1. From the Remote Access Management Console, reload the configuration.

  2. Add Server2 to a security group in Active Directory.

  3. Restart the IPSec Policy Agent service on Server2.

  4. From the Remote Access Management Console, modify the Infrastructure Servers settings.

  5. From the Remote Access Management Console, modify the Application Servers settings.

 

Correct Answer: DE

 

 

QUESTION 306

Your network contains an Active Directory domain named contoso.com. All user accounts for the

marketing department reside in an organizational unit (OU) named OU1. All user accounts for the

finance department reside in an organizational unit (OU) named OU2. You create a Group Policy

object (GPO) named GPO1. You link GPO1 to OU2. You configure the Group Policy preference of

GPO1 to add a shortcut named Link1 to the desktop. You discover that when a user signs in, the

Link1 is not added to the desktop. You need to ensure that when a user signs in, Link1 is added to

the desktop. What should you do?

 

  1. Enforce GPO1.

  2. Enable loopback processing in GPO1.

  3. Modify the Link1 shortcut preference of GPO1.

  4. Modify the Security Filtering settings of GPO1.

 

Correct Answer: B

 

 

QUESTION 307

Your network contains an Active Directory domain named contoso.com. All client computers run

Windows 8.1. The network contains a shared folder named FinancialData that contains five files.

You need to ensure that the FinancialData folder and its contents are copied to all of the client

computers. Which two Group Policy preferences should you configure? (Each correct answer

presents part of the solution. Choose two.)

 

  1. Shortcuts

  2. Network Shares

  3. Environment

  4. Folders

  5. Files

 

Correct Answer: DE

 

 

QUESTION 308

Your network contains an Active Directory domain named contoso.com. All domain controllers

run Windows Server 2012 R2. The domain contains 500 client computers that run Windows 8.1

Enterprise and Microsoft Office 2013. You implement a Group Policy central store. You need to

modify the default Microsoft Office 2013 Save As location for all client computers. The solution

must minimize administrative effort. What should you configure in a Group Policy object (GPO)?

 

  1. The Group Policy preferences

  2. An application control policy

  3. The Administrative Templates

  4. The Software Installation settings

Correct Answer: D

 

 

QUESTION 309

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named NPS1 that has the Network Policy Server server role installed. All servers run

Windows Server 2012 R2. You install the Remote Access server role on 10 servers. You need to

ensure that all of the Remote Access servers use the same network policies. Which two actions

should you perform? (Each correct answer presents part of the solution. Choose two.)

 

  1. Configure each Remote Access server to use the Routing and Remote Access service (RRAS)

to authenticate connection requests.

  1. On NPS1, create a remote RADIUS server group. Add all of the Remote Access servers to the

remote RADIUS server group.

  1. On NPS1, create a new connection request policy and add a Tunnel-Type and a Service-Type

condition.

  1. Configure each Remote Access server to use a RADIUS server named NPS1.

  2. On NPS1, create a RADIUS client template and use the template to create RADIUS clients.

 

Correct Answer: CD

 

 

QUESTION 310

HOTSPOT

Your network contains an Active Directory named contoso.com. You have users named User1 and user2. The Network Access Permission for User1 is set to Control access through NPS Network Policy. The Network Access Permission for User2 is set to Allow access.

 

A policy named Policy1 is shown in the Policy1 exhibit.

 

70-411-demo-191

 

A policy named Policy2 is shown in the Policy2 exhibit.

70-411-demo-192

 

A policy named Policy3 is shown in the Policy3 exhibit.

 

70-411-demo-193

 

For each of the following statements, select Yes if the statement is true. Otherwise, select No. Each correct selection is worth one point.

 

Hot Area:

70-411-demo-194

 

Correct Answer:

70-411-demo-195

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-411 Real Exam

Try Microsoft MCSA 70-411 Free Demo

Comments are closed.