Braindumps Microsoft MCSD Dumps

70-410,70-411,70-412,70-413,70-414,70-417,70-461,70-462,70-463,70-464,70-465,70-480,70-483,70-486,70-487

Home » [Free] 2017(Sep) EnsurePass Braindumps Microsoft 70-411 Dumps with VCE and PDF 41-50

[Free] 2017(Sep) EnsurePass Braindumps Microsoft 70-411 Dumps with VCE and PDF 41-50

EnsurePass
2017 Sep Microsoft Official New Released 70-411
100% Free Download! 100% Pass Guaranteed!
http://www.EnsurePass.com/70-411.html

Administering Windows Server 2012

Question No: 41 – (Topic 1)

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2 and has the Network Policy Server role service installed.

An administrator creates a RADIUS client template named Template1. You create a RADIUS client named Client1 by using Template 1.

You need to modify the shared secret for Client1. What should you do first?

  1. Configure the Advanced settings of Template1.

  2. Set the Shared secret setting of Template1 to Manual.

  3. Clear Enable this RADIUS client for Client1.

  4. Clear Select an existing template for Client1.

Answer: D Explanation:

Clear checkmark for Select an existing template in the new client wizard. In New RADIUS Client, in Shared secret, do one of the following:

Bullet Ensure that Manual is selected, and then in Shared secret, type the strong password that is also entered on the RADIUS client. Retype the shared secret in Confirm shared secret.

Ensurepass 2017 PDF and VCE

Ensurepass 2017 PDF and VCE

Question No: 42 – (Topic 1)

Your network contains an Active Directory domain named contoso.com. You need to install and configure the Web Application Proxy role service.

What should you do?

  1. Install the Active Directory Federation Services server role and the Remote Access server role on different servers.

  2. Install the Active Directory Federation Services server role and the Remote Access server role on the same server.

  3. Install the Web Server (IIS) server role and the Application Server server role on the same server.

  4. Install the Web Server (IIS) server role and the Application Server server role on different servers.

Answer: A Explanation:

Web Application Proxy is a new Remote Access role service in Windows Server庐 2012 R2.

Ensurepass 2017 PDF and VCE

Question No: 43 – (Topic 1)

Your network contains an Active Directory forest. The forest contains two domains named contoso.com and fabrikam.com. All of the DNS servers in both of the domains run Windows Server 2012 R2.

The network contains two servers named Server1 and Server2. Server1 hosts an Active

Directory-integrated zone for contoso.com. Server2 hosts an Active Directory-integrated zone for fabrikam.com. Server1 and Server2 connect to each other by using a WAN link.

Client computers that connect to Server1 for name resolution cannot resolve names in fabnkam.com.

You need to configure Server1 to support the resolution of names in fabnkam.com. The solution must ensure that users in contoso.com can resolve names in fabrikam.com if the WAN link fails.

What should you do on Server1?

  1. Create a stub zone.

  2. Add a forwarder.

  3. Create a secondary zone.

  4. Create a conditional forwarder.

Answer: C Explanation:

http: //technet. microsoft. com/en-us/library/cc771898. aspx

When a zone that this DNS server hosts is a secondary zone, this DNS server is a secondary source for information about this zone. The zone at this server must be obtained from another remote DNS server computer that also hosts the zone.

With secondary, you have ability to resolve records from the other domain even if its DNS servers are temporarily unavailable.

While secondary zones contain copies of all the resource records in the corresponding zone on the master name server, stub zones contain only three kinds of resource records: A copy of the SOA record for the zone.

Copies of NS records for all name servers authoritative for the zone. Copies of A records for all name servers authoritative for the zone.

References:

http: //www. windowsnetworking. com/articles-tutorials/windows-2003/DNS_Stub_Zones. html

http: //technet. microsoft. com/en-us/library/cc771898. aspx

http: //redmondmag. com/Articles/2004/01/01/The-Long-and-Short-of-Stub-Zones. aspx?Page=2

Question No: 44 – (Topic 1)

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2.

In a remote site, a support technician installs a server named DC10 that runs Windows Server 2012 R2. DC10 is currently a member of a workgroup.

You plan to promote DC10 to a read-only domain controller (RODC).

You need to ensure that a user named Contoso\User1 can promote DC10 to a RODC in the contoso.com domain. The solution must minimize the number of permissions assigned to User1.

What should you do?

  1. From Active Directory Users and Computers, run the Delegation of Control Wizard on the contoso.com domain object.

  2. From Active Directory Administrative Center, pre-create an RODC computer account.

  3. From Ntdsutil, run the local roles command.

  4. Join DC10 to the domain. Run dsmod and specify the /server switch.

    Answer: B Explanation:

    A staged read only domain controller (RODC) installation works in two discrete phases:

    1. Staging an unoccupied computer account

    2. Attaching an RODC to that account during promotion

      Reference: Install a Windows Server 2012 R2 Active Directory Read-Only Domain Controller (RODC)

      Question No: 45 – (Topic 1)

      Your company has a main office and two branch offices. The main office is located in New York. The branch offices are located in Seattle and Chicago.

      The network contains an Active Directory domain named contoso.com. An Active Directory site exists for each office. Active Directory site links exist between the main office and the branch offices. All servers run Windows Server 2012 R2.

      The domain contains three file servers. The file servers are configured as shown in the following table.

      Ensurepass 2017 PDF and VCE

      You implement a Distributed File System (DFS) replication group named ReplGroup.

      ReplGroup is used to replicate a folder on each file server. ReplGroup uses a hub and spoke topology. NYC-SVR1 is configured as the hub server.

      You need to ensure that replication can occur if NYC-SVR1 fails. What should you do?

      1. Create an Active Directory site link bridge.

      2. Create an Active Directory site link.

      3. Modify the properties of Rep1Group.

      4. Create a connection in Rep1Group.

Answer: D Explanation:

Unsure about this answer. D:

Ensurepass 2017 PDF and VCE

A:

The Bridge all site links option in Active Directory must be enabled. (This option is available in the Active Directory Sites and Services snap-in.) Turning off Bridge all site links can affect the ability of DFS to refer client computers to target computers that have the least expensive connection cost. An Intersite Topology Generator that is running Windows Server 2003 relies on the Bridge all site links option being enabled to generate the intersite cost matrix that DFS requires for its site-costing functionality. If you turn off this option, you must create site links between the Active Directory sites for which you want DFS to calculate accurate site costs.

Any sites that are not connected by site links will have the maximum possible cost. For more information about site link bridging, see “Active Directory Replication Topology Technical Reference.”

Ensurepass 2017 PDF and VCE

Reference:

http: //faultbucket. ca/2012/08/fixing-a-dfsr-connection-problem/ http: //faultbucket. ca/2012/08/fixing-a-dfsr-connection-problem/ http: //technet. microsoft. com/en-us/library/cc771941. aspx

Question No: 46 – (Topic 1)

You have a server named Server1 that runs Windows Server 2012 R2.

An administrator creates a quota as shown in the Quota exhibit. (Click the Exhibit button.)

Ensurepass 2017 PDF and VCE

You run the dir command as shown in the Dir exhibit. (Click the Exhibit button.)

Ensurepass 2017 PDF and VCE

You need to ensure that D:\Folder1 can only consume 100 MB of disk space. What should you do?

  1. From File Server Resource Manager, create a new quota.

  2. From File Server Resource Manager, edit the existing quota.

  3. From the Services console, set the Startup Type of the Optimize drives service to Automatic.

  4. From the properties of drive D, enable quota management.

    Answer: A Explanation:

    1. In Quota Management, click the Quota Templates node.

    2. In the Results pane, select the template on which you will base your new quota.

    3. Right-click the template and click Create Quota from Template (or select Create Quota from Template from the Actions pane). This opens the Create Quota dialog box with the summary properties of the quota template displayed.

    4. Under Quota path, type or browse to the folder that the quota will apply to.

    5. Click the Create quota on path option. Note that the quota properties will apply to the entire folder.

      Note: To create an auto apply quota, click the Auto apply template and create quotas on existing and new subfolders option. For more information about auto apply quotas, see Create an Auto Apply Quota.

    6. Under Drive properties from this quota template, the template you used in step 2 to create your new quota is preselected (or you can select another template from the list). Note that the template#39;s properties are displayed under Summary of quota properties.

    7. Click Create.

      Create a new Quota on path, without using the auto apply template and create quota on existing and new subfolders.

      Ensurepass 2017 PDF and VCE

      Ensurepass 2017 PDF and VCE

      Ensurepass 2017 PDF and VCE

      Reference: http: //technet.microsoft.com/en-us/library/cc755603(v=ws.10).aspx

      Question No: 47 HOTSPOT – (Topic 1)

      You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the Remote Access server role installed.

      You have a client named Client1 that is configured as an 802. IX supplicant.

      You need to configure Server1 to handle authentication requests from Client1. The solution must minimize the number of authentication methods enabled on Server1.

      Which authentication method should you enable? To answer, select the appropriate authentication method in the answer area.

      Ensurepass 2017 PDF and VCE

      Answer:

      Ensurepass 2017 PDF and VCE

      Explanation:

      Ensurepass 2017 PDF and VCE

      Microsoft庐 Windows庐 uses EAP to authenticate network access for Point-to-Point Protocol (PPP) connections (dial-up and virtual private network) and for IEEE 802.1X-based network access to authenticating Ethernet switches and wireless access points (APs).

      Question No: 48 – (Topic 1)

      Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 P.2. Server1 has the Network Policy and Access Services server role installed.

      You plan to deploy 802. lx authentication to secure the wireless network.

      You need to identify which Network Policy Server (NPS) authentication method supports certificate-based mutual authentication for the 802.1x deployment.

      Which authentication method should you identify?

      1. MS-CHAP

      2. PEAP-MS-CHAPv2

      3. EAP-TLS

      4. MS-CHAP v2

Answer: C Explanation:

802.1X uses EAP, EAP-TLS, EAP-MS-CHAP v2, and PEAP authentication methods:

->EAP (Extensible Authentication Protocol) uses an arbitrary authentication method, such as certificates, smart cards, or credentials.

->EAP-TLS (EAP-Transport Layer Security) is an EAP type that is used in certificate- based security environments, and it provides the strongest authentication and key determination method.

->EAP-MS-CHAP v2 (EAP-Microsoft Challenge Handshake Authentication Protocol version 2) is a mutual authentication method that supports password-based user or computer authentication.

->PEAP (Protected EAP) is an authentication method that uses TLS to enhance the security of other EAP authentication protocols.

Question No: 49 – (Topic 1)

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2.

You have a Group Policy object (GPO) named GPO1 that contains hundreds of settings. GPO1 is linked to an organizational unit (OU) named OU1. OU1 contains 200 client computers.

You plan to unlink GPO1 from OU1.

You need to identify which GPO settings will be removed from the computers after GPO1 is unlinked from OU1.

Which two GPO settings should you identify? (Each correct answer presents part of the solution. Choose two.)

  1. The managed Administrative Template settings

  2. The unmanaged Administrative Template settings

  3. The System Services security settings

  4. The Event Log security settings

  5. The Restricted Groups security settings

Answer: A,D Explanation:

There are two kinds of Administrative Template policy settings: Managed and Unmanaged . The Group Policy service governs Managed policy settings and removes a policy setting when it is no longer within scope of the user or computer.

References:

http: //technet. microsoft. com/en-us/library/cc778402(v=ws. 10). aspx http: //technet. microsoft. com/en-us/library/bb964258. aspx

Question No: 50 – (Topic 1)

You manage a server that runs Windows Server 2012 R2. The server has the Windows Deployment Services server role installed.

You have a desktop computer that has the following configuration:

->Computer name: Computer1

->Operating system: Windows 8

->MAC address: 20-CF-30-65-D0-87

->GUID: 979708BF-C04B-4525-9FE0-C4150BB6C618

You need to configure a pre-staged device for Computer1 in the Windows Deployment Services console.

Which two values should you assign to the device ID? (Each correct answer presents a complete solution. Choose two.)

A. 20CF3065D08700000000000000000000

B. 979708BFC04B45259FE0C4150BB6C618

C. 979708BF-C04B-452S-9FE0-C4150BB6C618

D. 0000000000000000000020CF306SD087

E. 00000000-0000-0000-0000-C41S0BB6C618

Answer: C,D Explanation:

In the text box, type the client computer#39;s MAC address preceded with twenty zeros or the globally unique identifier (GUID) in the format: {XXXXXXXX-XXXX-XXXX-XXX- XXXXXXXXXXXX}.

  • To add or remove pre-staged client to/from AD DS, specify the name of the computer or the device ID, which is a GUID, media access control (MAC) address, or Dynamic Host Configuration Protocol (DHCP) identifier associated with the computer.

  • Example: Remove a device by using its ID from a specified domain

This command removes the pre-staged device that has the specified ID. The cmdlet searches the domain named TSQA.contoso.com for the device.

Windows PowerShell

PS C:\gt; Remove-WdsClient -DeviceID quot;5a7a1def-2e1f-4a7b-a792-ae5275b6ef92quot; -Domain

-DomainName quot;TSQA.contoso.comquot;

100% Free Download!
Download Free Demo:70-411 Demo PDF
100% Pass Guaranteed!
Download 2017 EnsurePass 70-411 Full Exam PDF and VCE

EnsurePass ExamCollection Testking
Lowest Price Guarantee Yes No No
Up-to-Dated Yes No No
Real Questions Yes No No
Explanation Yes No No
PDF VCE Yes No No
Free VCE Simulator Yes No No
Instant Download Yes No No

2017 EnsurePass IT Certification PDF and VCE

[Free] 2017(Sep) EnsurePass Braindumps Microsoft 70-411 Dumps with VCE and PDF 51-60
[Free] 2017(Sep) EnsurePass Braindumps Microsoft 70-411 Dumps with VCE and PDF 31-40

Name of author

Name: admin