Achieve New Updated (September) Microsoft 70-411 Examination Questions 271-280

Ensurepass

 

QUESTION 271

You work as a network administrator at EnsuerPass.com. EnsurePass.com has an Active Directory Domain Services (AD DS) domain name EnsurePass.com. All servers in the EnsurePass.com domain have Microsoft Windows Server 2012 R2 installed.

 

The computer accounts for all file servers are located in an organizational unit (OU) named DataOU.

 

You are required to track user access to shared folders on the file servers.

 

Which of the following actions should you consider?

 

A.

You should configure auditing of Account Logon events for the DataOU.

B.

You should configure auditing of Object Access events for the DataOU.

C.

You should configure auditing of Global Object Access Auditing events for the DataOU.

D.

You should configure auditing of Directory Service Access events for the DataOU.

D.

You should configure auditing of Privilege Use events for the DataOU.

 

Correct Answer: B

 

 

QUESTION 272

You have installed Routing and Remote Access on Server1 what should you configure next to use it as a NAT server.

 

A.

Add New Interface

B.

Create Static Route

C.

Configure the IPv4 DHCP Relay Agent

D.

Configure the IPv6 DHCP Relay Agent

 

Correct Answer: A

 

 

QUESTION 273

You deploy two servers named Server1 and Server2. You install Network Policy Server (NPS) on both servers. On Server1, you configure the following NPS settings:

 

clip_image002RADIUS Clients

clip_image002[1]Network Policies

clip_image002[2]Connection Request Policies

clip_image002[3]SQL Server Logging Properties

 

You export the NPS configurations to a file and import the file to Server2. You need to ensure that the NPS configurations on Server2 are the same as the NPS configurations on Server1. Which settings should you manually configure on Server2?

A.

SQL Server Logging Properties

B.

Connection Request Policies

C.

RADIUS Clients

D.

Network Policies

 

Correct Answer: A

 

 

QUESTION 274

Force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL

 

A.

dfsgui.msc

B.

ultrasound

C.

rplmon

D.

frsutil

 

Correct Answer: C

 

 

QUESTION 275

I am using a Domain Admins account to run the console and the service is running under local system. I try approve Requests from Pending devices, then I got notice Access Denied, (Windows Server 2003 R2). And why Architecture x64, clients are x86? Is that the reason and how to fix it?

 

A.

Open WDS and right click on the server and select properties. Then click on the tab “PXE Response settings” and select respond to all (known and unknown) client. And also select the little checkbox below.

B.

You need to grant permissions on the OU in which you want to create machine accounts for the WDS Server Machine Account.

C.

To grant permissions to approve a pending computer.

Open Active Directory Users and Computers.

Right-click the OU where you are creating prestaged computer accounts, and then select Delegate Control.

On the first screen of the wizard, click Next.

Change the object type to include computers.

Add the computer object of the Windows Deployment Services server, and then click Next.

Select Create a Custom task to delegate.

Select Only the following objects in the folder. Then select the Computer Objects check box, select Create selected objects in this folder, and click Next. In the Permissions box, select the Write all Properties check box, and click Finish.

D.

Define the OU path to add systems in WDS.

Delegate Computer object create or greater rights to the WDS server for the OU. Delegate computer object create rights to your account or simply use a domain admin account to logon.

 

Correct Answer: C

 

 

QUESTION 276

Force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL

 

A.

ldp

B.

dfsgui.msc

C.

ultrasound

D.

rplmon

 

Correct Answer: D

 

 

QUESTION 277

How to give the minimum required permission to a user who wants to promote a RODC.

 

A.

member of the Domain Admins group

B.

allowed to attach the server to the RODC computer account

C.

Local admin

D.

organization admin

 

Correct Answer: BC

 

 

QUESTION 278

HOTSPOT

Your network contains an Active Directory domain named contoso.com. You need to audit access to removable storage devices. Which audit category should you configure?

 

To answer, select the appropriate category in the answer area.

 

clip_image003

 

Correct Answer:

clip_image004

 

 

QUESTION 279

DRAG DROP

Your network contains an Active Directory domain named contoso.com. You deploy a web-based application named App1 to a server named Server1. App1 uses an application pool named AppPool1. AppPool1 uses a domain user account named User1 as its identity. You need to configure Kerberos constrained delegation for User1. Which three actions should you perform?

 

To answer, move the three appropriate actions from the list of actions to the answer area and arrange them in the correct order

 

clip_image006

 

Correct Answer:

clip_image008

 

 

QUESTION 280

HOTSPOT

Your network contains an Active Directory domain called contoso.com. The domain contains a domain controller named DC1 that runs Windows server 2012. The domain contains some test client computers that run either Windows XP, Windows Vista, Windows 7, or Windows 8. The computer accounts for the test computers are located in an organizational unit (OU) named OU1. You have a Group Policy object (GPO) named GPO1 linked to OU1. GPO1 is used to assign several applications to the test computers. You need to ensure that when the test computers in OU1 restart, you can see which application installation is running currently. Which setting should you modify in GPO1?

 

To answer, select the appropriate setting in the answer area.

 

clip_image009

 

Correct Answer:

clip_image010

 

 

Free VCE & PDF File for Microsoft 70-411 Real Exam

Instant Access to Free VCE Files: MCSE|MCSA|MCITP…
Instant Access to Free PDF Files: MCSE|MCSA|MCITP…