Braindumps Microsoft MCSD Dumps

70-410,70-411,70-412,70-413,70-414,70-417,70-461,70-462,70-463,70-464,70-465,70-480,70-483,70-486,70-487

Home » [Free] 2017(May) Ensurepass Examcollection Microsoft 70-744 Real Tests 21-30

[Free] 2017(May) Ensurepass Examcollection Microsoft 70-744 Real Tests 21-30

Ensurepass
2017 May Microsoft Official New Released 70-744 Q&As
100% Free Download! 100% Pass Guaranteed!
http://www.ensurepass.com/70-744.html

Securing Windows Server 2016

QUESTION 21

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

 

After you answer a question in this section, you will NOT be able to return to It. As a result, these questions will not appear in the review screen.

 

Your network contains an Active Directory forest named contoso.com. All servers run Windows Server 2016. The forest contains 2#W client computers that run Windows 10. All client computers are deployed rom a customized Windows image.

 

You need to deploy 10 Pnvileged Access Workstations (PAWs). The solution must ensure that administrators can access several client applications used by all users.

 

Solution: You deploy 10 physical computers and configure each wie as a virtualization host. You deploy the operating system on each host by using the customized Windows image. On each host you create a guest virtual machine and configure the virtual machine as a PAW.

 

Does this meet the goal?

 

A.

Yes

B.

No

 

Correct Answer: B

 

 

QUESTION 22

Note: This question is port of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question In the series. Each question is Independent of the other questions In this series. Information and details provided in a question apply only to that question.

 

Vour network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2016 and a Nano Server named Nano1.

 

Nano1 has two volumes named C and D.

 

You are signed in to Server1.

 

You need to configure Data Deduplication on Nano1.

 

Which tool should you use?

 

A.

File Explorer

B.

Shared Folders

C.

Server Manager

D.

Disk Management

E.

Storage Explorer

F.

Computer Management

G.

System Configuration

H.

File Server Resource Manager (FSRM)

 

Correct Answer: A

QUESTION 23

Note: This question is part of a series of questions that present the same scenario. Each question In the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

 

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear In the review screen.

 

Your network contains an Active Directory domain named contow.com. All servers run Windows Server 2016. All client computers run Windows 10.

 

The relevant objects in the domain are configured as shown in the following table.

 

clip_image001

 

You need to assign User1 the right to restore files and folders on Server1 and Server2.

 

Solution: You create a Group Policy object (GPO), link it to the Operations Users OU, and modify the Users Rights Assignment in the GPO.

 

Does this meet the goal?

 

A.

Yes

B.

No

 

Correct Answer: B

 

 

QUESTION 24

Your network contains an Active Directory domain named contoso.com. The domain contains 100 servers.

 

You deploy the Local Administrator Password Solution (LAPS) to the network.

 

You deploy a new server named FinanceServer5, and join FinanceServerS to the domain.

 

You need to ensure that the passwords of the local administrators of FinanceServer5 are available to the LAPS administrators.

 

What should you do?

 

A.

On FinanceServerS, register AdmPwd.dll.

B.

On FmanceServerS, install the LAPS Windows PowerShell module.

C.

In the domain, modify the permissions for the computer account of FmanceServer5.

D.

In the domain, modify the permissions of the Domain Controllers organizational unit (OU).

 

Correct Answer: B

 

 

 

QUESTION 25

Vout network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2016.

 

The domain contains a server named Serverl that has Microsoft Security Compliance Manager (SCM) 4.0 installed.

 

You export the baseline shown in the following exhibit.

 

clip_image002

 

You have a server named Server2 that is a member of a workgroup.

 

You copy the (2617e9b1-9672-492b-aefa-0505054848c2) folder to Server2.

 

You need to deploy the baseline settings to Server2.

 

What should you do?

 

A.

Download, install, and then fun the Lgpo.exe command.

B.

From Group Policy Management import a Group Policy object (GPO).

C.

From Windows PowerShell, run the Restore-GPO cmdlet.

D.

From Windows PowerShell, run the Import-GPO cmdlet.

E.

From a command prompt run the secedit.exe command and specify the /import parameter.

 

Correct Answer: D

 

 

QUESTION 26

Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.

 

Start of repeated scenario

 

Your network contains an Active Directory domain named contoso.com. The functional level of the forest and the domain is Windows Server 2008 R2.

 

The domain contains the servers configured as shown in the following table.

 

clip_image003

 

All servers run Windows Server 2016. All client computers run Windows 10.

 

You have an organizational unit (OU) named Marketing that contains the computers in the marketing department You have an OU named Finance that contains the computers in the finance department. You have an OU named AppServers that contains application servers. A Group Policy object (GPO) named GP1 is linked to the Marketing OU. A GPO named GP2 is linked to the AppServers OU.

 

You install Windows Defender on Nano1.

 

End of repeated scenario

 

You plan to implement BitLocker Drive Encryption (BitLocker) on the operating system volumes of the application servers.

 

You need to ensure that the BitLocker recovery keys are stored in Active Directory.

 

Which Group Policy setting should you configure?

 

A.

System cryptography; Force strong key protection (or user keys stored on the computer

B.

Store Bittocker recovery information in Active Directory Domain Services (Windows Server 2008 and Windows Vista)

C.

System cryptography: Use FIPS compliant algorithms for encryption, hashing and signing

D.

Choose how BitLocker-protected operating system drives can be recovered

 

Correct Answer: C

 

 

QUESTION 27

HOTSPOT

Your network contains two Active Directory forests named contoso.com and adatum.com. Contoso.com contains a Hyper-V host named Server1. Server1 is a member of a group named HyperHosts. Adatum.com contains a server named Server2. Server1 and Server2 run Windows Server 2016.

 

Contoso.com trusts adatum.com.

 

You plan to deploy shielded virtual machines to Server1 and to configure Admin-trusted attestation on Server2.

 

Which component should you install and which cmdlet should you run on Server2?

 

To answer, select the appropriate options in the answer area.

 

clip_image004

 

Correct Answer:

clip_image005

 

 

QUESTION 28

Note: Thts question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

 

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

 

Your network contains an Active Directory domain named contoso.com. The domain contains a computer named Computer1 that runs Windows 10. Computer1 connects to a home network and a corporate network.

 

The corporate network uses the 172.16.0.0/24 address space internally.

 

Computerl runs an application named App1 that listens to port 8080.

 

You need to prevent connections to App1 when Computer1 is connected to the home network.

 

Solution: From Windows Firewall in the Control Panel, you add an application and allow the application to communicate through the firewall on a Private network.

 

Does this meet the goal?

 

A.

Yes

B.

No

 

Correct Answer: B

 

 

QUESTION 29

Your network contains an Active Directory domain named contoso.com. The domain contains five servers. All servers run Windows Server 2016.

 

A new secunty policy states that you must modify the infrastructure to meet the following requirements:

 

clip_image007Limit the nghts of administrators.

clip_image007[1]Minimize the attack surface of the forest.

clip_image007[2]Support Multi-Factor authentication for administrators.

 

You need to recommend a solution that meets the new secunty policy requirements.

 

What should you recommend deploying?

 

A.

an administrative forest

B.

domain isolation

C.

an administrative domain in contoso.com

D.

the Local Administrator Password Solution (LAPS)

 

Correct Answer: A

 

 

QUESTION 30

Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.

 

Start of repeated scenario

 

Your network contains an Active Directory domain named contoso.com. The functional level of the forest and the domain is Windows Server 2008 R2.

 

The domain contains the servers configured as shown in the following table.

 

clip_image008

 

All servers run Windows Server 2016. All client computers run Windows 10.

 

You have an organizational unit (OU) named Marketing that contains the computers in the marketing department You have an OU named finance that contains the computers in the finance department You have an OU named AppServers that contains application servers. A Group Policy object (GPO) named GP1 is linked to the Marketing OU. A GPO named GP2 is linked to the AppServers OU.

You install Windows Defender on Nano1.

 

End of repeated scenario

 

You need to exclude D:\Folder1 on Nano1 from being scanned by Windows Defender.

 

Which cmdlet should you run?

 

A.

Set-StorageSetting

B.

Set-FsrmFileScreenException

C.

Set-MpPreference

D.

Set-DtcAdvancedSetting

 

Correct Answer: A

100% Free Download!
—Download Free Demo:70-744 Demo PDF
100% Pass Guaranteed!
Download 2017 Ensurepass 70-744 Full Exam PDF and VCE Q&As:50
—Get 10% off your purchase! Copy it:TJDN-947R-9CCD [2017.05.01-2017.05.31]

Ensurepass ExamCollection Testking
Lowest Price Guarantee Yes No No
Up-to-Dated Yes No No
Real Questions Yes No No
Explanation Yes No No
PDF + VCE Yes No No
Free VCE Simulator Yes No No
Instant Download Yes No No

2017 Ensurepass IT Certification PDF and VCE

HOT EXAM!
[Free] 2017(May) Ensurepass Examcollection Microsoft 70-744 Real Tests 11-20

Name of author

Name: admin