Do you want to pass the 70-411 examsavior exam? What are the new questions of the latest 70-411 exam? Braindumps 70-411 VCE dumps and 70-411 PDF dumps will tell you all about the 70-411 examsavior exam.Here are the examsavior newest and covered all new added questions and answers, which will help you 100% passing 70-411 examsavior exam.Hurry up and get the free exam from here!
NOW FREE DOWNLOAD
QUESTION 41
Your network contains an Active Directory domain named contoso.com.
The domain contains a RADIUS server named Server1 that runs Windows Server 2012.
You add a VPN server named Server2 to the network. On Server1, you create several network policies.
You need to configure Server1 to accept authentication requests from Server2. Which tool should you use on Server1?
A. Add-RemoteAccessRadius
B. New-NpsRadiusClient
C. Remote Access Management Console
D. Routing and Remote Access
E. Server Manager
Correct Answer: B
Section: 4. Configure a Network Policy Server infrastructure
Explanation
Explanation/Reference:
Notes:
We must make known to Server2 Server1 as a RADIUS client. To this end, the console NPS or the cmdlet can New NpsRadiusClient be used. The
following call specifies Server2 as a RADIUS client with the name Server2 fixed and specifies that Server2 is NAP-capable
New-NpsRadiusClient -Name “Server2” –Address “server2.certbase.de” –NapCompatible $True
QUESTION 42
You have a server that runs Windows Server 2012. You have an offline image named Windows2012.vhd that contains an installation of Windows Server
2012.
You plan to apply several updates to Windows2012.vhd.
You need to mount Windows2012.vhd to H:\. Which tool should you use?
A. Device Manager
B. Diskpart
C. Mountvol
Your network contains an Active Directory domain named contoso.com.
The domain contains a RADIUS server named Server1 that runs Windows Server 2012.
You add a VPN server named Server2 to the network. On Server1, you create several network policies.
You need to configure Server1 to accept authentication requests from Server2. Which tool should you use on Server1?
A. Add-RemoteAccessRadius
B. New-NpsRadiusClient
C. Remote Access Management Console
D. Routing and Remote Access
E. Server Manager
Correct Answer: B
Section: 4. Configure a Network Policy Server infrastructure
Explanation
Explanation/Reference:
Notes:
We must make known to Server2 Server1 as a RADIUS client. To this end, the console NPS or the cmdlet can New NpsRadiusClient be used. The
following call specifies Server2 as a RADIUS client with the name Server2 fixed and specifies that Server2 is NAP-capable
New-NpsRadiusClient -Name “Server2” –Address “server2.certbase.de” –NapCompatible $True
QUESTION 42
You have a server that runs Windows Server 2012. You have an offline image named Windows2012.vhd that contains an installation of Windows Server
2012.
You plan to apply several updates to Windows2012.vhd.
You need to mount Windows2012.vhd to H:\. Which tool should you use?
A. Device Manager
B. Diskpart
C. Mountvol
D. Server Manager
Correct Answer: B
Section: 1. Deploy and manage server images
Explanation
Explanation/Reference:
Notes:
We can snap-in Disk Management or the command-line tool use Diskpart.exe to create virtual Festplatttendateien and to mount. The following
exemplary DiskPart command line can the system an existing virtual disk will be added:
select vdisk file= Windows2012.vhd
attach vdisk
assign letter=H
QUESTION 43
Your network contains an Active Directory forest named contoso.com. The forest contains two sites named Main and Branch.
The Main site contains 400 desktop computers and the Branch site contains 150 desktop computers.
All of the desktop computers run Windows 8. In Main, the network contains a member server named Server1 that runs Windows Server 2012.
You install the Windows Server Update Services server role on Server1.
You need to ensure that Windows updates obtained from Windows Server Update Services (WSUS) are the same for the computers in each
site.
You want to achieve this goal by using the minimum amount of administrative effort. What should you do?
A. From the Update Services console, create computer groups.
B. From the Update Services console, configure the Computers options.
C. From the Group Policy Management console, configure the Windows Update settings.
D. From the Group Policy Management console, configure the Windows Anytime Upgrade settings.
E. From the Update Services console, configure the Synchronization Schedule options.
Correct Answer: C
Section: 1. Deploy and manage server images
Explanation
Correct Answer: B
Section: 1. Deploy and manage server images
Explanation
Explanation/Reference:
Notes:
We can snap-in Disk Management or the command-line tool use Diskpart.exe to create virtual Festplatttendateien and to mount. The following
exemplary DiskPart command line can the system an existing virtual disk will be added:
select vdisk file= Windows2012.vhd
attach vdisk
assign letter=H
QUESTION 43
Your network contains an Active Directory forest named contoso.com. The forest contains two sites named Main and Branch.
The Main site contains 400 desktop computers and the Branch site contains 150 desktop computers.
All of the desktop computers run Windows 8. In Main, the network contains a member server named Server1 that runs Windows Server 2012.
You install the Windows Server Update Services server role on Server1.
You need to ensure that Windows updates obtained from Windows Server Update Services (WSUS) are the same for the computers in each
site.
You want to achieve this goal by using the minimum amount of administrative effort. What should you do?
A. From the Update Services console, create computer groups.
B. From the Update Services console, configure the Computers options.
C. From the Group Policy Management console, configure the Windows Update settings.
D. From the Group Policy Management console, configure the Windows Anytime Upgrade settings.
E. From the Update Services console, configure the Synchronization Schedule options.
Correct Answer: C
Section: 1. Deploy and manage server images
Explanation
Explanation/Reference:
Notes:
In the section Computer Configuration \ Administrative Templates \ Windows Components \ Windows Update a GPO (GPOs) can be configured
at a central location all the relevant settings for the Windows Update configuration of the desktop computer.
Notes:
In the section Computer Configuration \ Administrative Templates \ Windows Components \ Windows Update a GPO (GPOs) can be configured
at a central location all the relevant settings for the Windows Update configuration of the desktop computer.
![NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE](http://www.hotitexam.com/wp-content/uploads/2016/08/image-234.png)
QUESTION 44
Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All domain controllers run Windows Server
Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All domain controllers run Windows Server
2012.
The domain contains two domain controllers.
The domain controllers are configured as shown in the following table.
The domain contains two domain controllers.
The domain controllers are configured as shown in the following table.
![NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE](http://www.hotitexam.com/wp-content/uploads/2016/08/image-244.png)
You discover that a support technician accidentally removed 100 users from an Active Directory group named Group1 an hour ago.
You need to restore the membership of Group1.
What should you do?
A. Apply a virtual machine snapshot to DC2.
B. Perform an authoritative restore.
C. Perform a non-authoritative restore.
D. Perform tombstone reanimation.
Correct Answer: B
Section: 5. Configure and manage Active Directory
Explanation
Explanation/Reference:
Notes:
In order to we need to restore the membership of Group1 perform an authoritative restore of the group Group1.
For an authoritative restore of Active Directory objects, you must perform a non-authoritative restore first. After the non-authoritative restore, you may not
normally have to restart the domain controller.
You need to restore the membership of Group1.
What should you do?
A. Apply a virtual machine snapshot to DC2.
B. Perform an authoritative restore.
C. Perform a non-authoritative restore.
D. Perform tombstone reanimation.
Correct Answer: B
Section: 5. Configure and manage Active Directory
Explanation
Explanation/Reference:
Notes:
In order to we need to restore the membership of Group1 perform an authoritative restore of the group Group1.
For an authoritative restore of Active Directory objects, you must perform a non-authoritative restore first. After the non-authoritative restore, you may not
normally have to restart the domain controller.
You must enter the domain controller instead start in the mode for restoring the Active Directory directory services and the command ntdsutil
authoritative restore use to characterize the desired objects as authoritative for replication.
If the recovered objects not marked as authoritative, they would at the next removed replication or set back to the status before the non-authoritative
restore.
QUESTION 45
Your network contains an Active Directory forest named contoso.com.
The forest contains two domains named contoso.com and childl.contoso.com.
All domain controllers run Windows Server 2012. The domain contains four domain controllers.
The domain controllers are configured as shown in the following table.
authoritative restore use to characterize the desired objects as authoritative for replication.
If the recovered objects not marked as authoritative, they would at the next removed replication or set back to the status before the non-authoritative
restore.
QUESTION 45
Your network contains an Active Directory forest named contoso.com.
The forest contains two domains named contoso.com and childl.contoso.com.
All domain controllers run Windows Server 2012. The domain contains four domain controllers.
The domain controllers are configured as shown in the following table.
![NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE](http://www.hotitexam.com/wp-content/uploads/2016/08/image-247.png)
You open Active Directory Users and Computers on a client computer and connect to DC1.
You display the members of a group named Group1 as shown in the Group1 Members exhibit.
You display the members of a group named Group1 as shown in the Group1 Members exhibit.
![NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE](http://www.hotitexam.com/wp-content/uploads/2016/08/image-250.png)
When you view the properties of a user named User102, you receive the error message shown in the Error exhibit.
![NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE](http://www.hotitexam.com/wp-content/uploads/2016/08/image-253.png)
The error message does not display for any other members of Group1.
You need to identify which domain controller causes the issue shown in the error message.
Which domain controller should you identify?
A. DC1
B. DC2
C. DC10
D. DC11
Correct Answer: B
Section: 5. Configure and manage Active Directory
Explanation
Explanation/Reference:
Notes:
The infrastructure master updates the names of security principals from other domains that are added in groups of his own domain. For example, if a
user from one domain is a member of a group in a second domain and the user’s name is changed in the first domain, the second domain is not notified
that the user’s name must be updated in the membership list of the group. Because domain controllers do not replicate security principals in one domain
to another domain controller in another domain, the second domain is not set in the absence of an infrastructure master about the change in
knowledge.
You need to identify which domain controller causes the issue shown in the error message.
Which domain controller should you identify?
A. DC1
B. DC2
C. DC10
D. DC11
Correct Answer: B
Section: 5. Configure and manage Active Directory
Explanation
Explanation/Reference:
Notes:
The infrastructure master updates the names of security principals from other domains that are added in groups of his own domain. For example, if a
user from one domain is a member of a group in a second domain and the user’s name is changed in the first domain, the second domain is not notified
that the user’s name must be updated in the membership list of the group. Because domain controllers do not replicate security principals in one domain
to another domain controller in another domain, the second domain is not set in the absence of an infrastructure master about the change in
knowledge.
The infrastructure master constantly monitors group memberships. It searches for security principals from other domains. If such a security principal is
found, a check with the domain of the security principal is performed to ensure the updating of information. If the information is out of date, the
infrastructure master performs an update and then replicates the change to the other domain controllers in its domain. There are two exceptions to this
rule.
First, when it comes to global catalog server in every domain controller, the domain controller with the infrastructure master role is insignificant because
the information is to be replicated regardless of the domain of global catalogs. Second, if the forest has only one domain, the domain controller with the
infrastructure master role is insignificant because security principals from other domains are present.
Use as infrastructure master a domain controller that is used simultaneously as a global catalog server. If the infrastructure master and global catalog
are created on the same domain controller, the infrastructure master can not be used. The infrastructure master will never find obsolete data. Therefore,
never changes to the other domain controllers are replicated in the domain.
QUESTION 46
Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012. The domain contains a file server named
Server1.
All client computers run Windows 8. Users share the client computers and frequently log on to different client computers.
You need to ensure that when the users save files in the Documents folder, the files are saved automatically to \\Server1\Users\.
The solution must minimize the amount of network traffic that occurs when the users log on to the client computers.
What should you do?
A. From a Group Policy object (GPO), configure the Folder Redirection settings.
B. From the properties of each user account, configure the Home folder settings.
C. From the properties of each user account, configure the User profile settings.
D. From a Group Policy object (GPO), configure the Drive Maps preference.
Correct Answer: A
Section: 2. Configure file and print services
Explanation
Explanation/Reference:
Last update: 15/09/2015
Based on the actual exam and checked with an Premium account.
“This was wrong according to the premium file. Before was the C.”
found, a check with the domain of the security principal is performed to ensure the updating of information. If the information is out of date, the
infrastructure master performs an update and then replicates the change to the other domain controllers in its domain. There are two exceptions to this
rule.
First, when it comes to global catalog server in every domain controller, the domain controller with the infrastructure master role is insignificant because
the information is to be replicated regardless of the domain of global catalogs. Second, if the forest has only one domain, the domain controller with the
infrastructure master role is insignificant because security principals from other domains are present.
Use as infrastructure master a domain controller that is used simultaneously as a global catalog server. If the infrastructure master and global catalog
are created on the same domain controller, the infrastructure master can not be used. The infrastructure master will never find obsolete data. Therefore,
never changes to the other domain controllers are replicated in the domain.
QUESTION 46
Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012. The domain contains a file server named
Server1.
All client computers run Windows 8. Users share the client computers and frequently log on to different client computers.
You need to ensure that when the users save files in the Documents folder, the files are saved automatically to \\Server1\Users\.
The solution must minimize the amount of network traffic that occurs when the users log on to the client computers.
What should you do?
A. From a Group Policy object (GPO), configure the Folder Redirection settings.
B. From the properties of each user account, configure the Home folder settings.
C. From the properties of each user account, configure the User profile settings.
D. From a Group Policy object (GPO), configure the Drive Maps preference.
Correct Answer: A
Section: 2. Configure file and print services
Explanation
Explanation/Reference:
Last update: 15/09/2015
Based on the actual exam and checked with an Premium account.
“This was wrong according to the premium file. Before was the C.”
![NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE](http://www.hotitexam.com/wp-content/uploads/2016/08/image-255.png)
Notes:
With the Folder Redirection allows you to redirect to a new location, for example to a network share the location of specific folders within user profiles..
Folder Redirection is used in the management of user profiles and roaming user profiles. You can configure the folder redirection by using Group Policy
Management Console to redirect specific user profile folders and to edit policy settings for folder redirection.
User settings and user files are typically stored in the local user in the User folder profile. The access to the files in the local user profile can only be
made from the current computer. It is therefore difficult for users with more than one computer to work with the data and synchronize settings between
multiple computers.
By configuring the Folder Redirection allows you to redirect the path of a folder to a new location. The path can be a folder on the local computer or a
directory on a network file share. Users have the ability to use the documents on a server as if the documents were stored on the local hard disk. The
documents in the folder are available to the user from any computer on the network.
QUESTION 47
Your network contains a server named Server1 that has the Network Policy and Access Services server role installed. All of the network access servers’
forward connection requests to Server1.
You create a new network policy on Server1. You need to ensure that the new policy applies only to connection requests from Microsoft RAS servers
that are located on the 192.168.0.0/24 subnet.
Which two configurations should you performing?
(Each correct answer presents part of the solution. Choose two.)
A. Set the MS-RAS Vendor ID condition to $teelHead.
B. Set the Called Station ID constraint to 192.168.0.
C. Set the Client IP4 Address condition to 192.168.0.0/24.
D. Set the MS-RAS Vendor ID condition to ^311$.
E. Set the Called Station ID constraint to 192.168.0.0/24.
F. Set the Client IP4 Address condition to 192.168.0.
Correct Answer: DF
Section: 4. Configure a Network Policy Server infrastructure
Explanation
Explanation/Reference:
Notes:
For each network policy at least one configured condition is required. The Network Policy Server Network Policy Server (NPS) provides many condition
With the Folder Redirection allows you to redirect to a new location, for example to a network share the location of specific folders within user profiles..
Folder Redirection is used in the management of user profiles and roaming user profiles. You can configure the folder redirection by using Group Policy
Management Console to redirect specific user profile folders and to edit policy settings for folder redirection.
User settings and user files are typically stored in the local user in the User folder profile. The access to the files in the local user profile can only be
made from the current computer. It is therefore difficult for users with more than one computer to work with the data and synchronize settings between
multiple computers.
By configuring the Folder Redirection allows you to redirect the path of a folder to a new location. The path can be a folder on the local computer or a
directory on a network file share. Users have the ability to use the documents on a server as if the documents were stored on the local hard disk. The
documents in the folder are available to the user from any computer on the network.
QUESTION 47
Your network contains a server named Server1 that has the Network Policy and Access Services server role installed. All of the network access servers’
forward connection requests to Server1.
You create a new network policy on Server1. You need to ensure that the new policy applies only to connection requests from Microsoft RAS servers
that are located on the 192.168.0.0/24 subnet.
Which two configurations should you performing?
(Each correct answer presents part of the solution. Choose two.)
A. Set the MS-RAS Vendor ID condition to $teelHead.
B. Set the Called Station ID constraint to 192.168.0.
C. Set the Client IP4 Address condition to 192.168.0.0/24.
D. Set the MS-RAS Vendor ID condition to ^311$.
E. Set the Called Station ID constraint to 192.168.0.0/24.
F. Set the Client IP4 Address condition to 192.168.0.
Correct Answer: DF
Section: 4. Configure a Network Policy Server infrastructure
Explanation
Explanation/Reference:
Notes:
For each network policy at least one configured condition is required. The Network Policy Server Network Policy Server (NPS) provides many condition
groups that allow you to precisely define the characteristics that must have received from NPS connection request to comply with the Directive. The
following sets of conditions are available:
Groups
HCAP
Day and Time Restrictions
Network Access Protection
Connection Properties
RADIUS client properties
Gateway
The RADIUS client properties Client IPv4 address is the IPv4 address of the RADIUS client to that forwarded the connection request to the NPS server.
The RADIUS client properties MS-RAS manufacturer specifies the manufacturer’s identification number of the network access server that is requesting
authentication. The manufacturer identification number ^ $ 311 featuring a Microsoft Routing and Remote Access Server.
QUESTION 48
Your network contains an Active Directory domain named contoso.com.
The domain controllers in the domain are configured as shown in the following table.
following sets of conditions are available:
Groups
HCAP
Day and Time Restrictions
Network Access Protection
Connection Properties
RADIUS client properties
Gateway
The RADIUS client properties Client IPv4 address is the IPv4 address of the RADIUS client to that forwarded the connection request to the NPS server.
The RADIUS client properties MS-RAS manufacturer specifies the manufacturer’s identification number of the network access server that is requesting
authentication. The manufacturer identification number ^ $ 311 featuring a Microsoft Routing and Remote Access Server.
QUESTION 48
Your network contains an Active Directory domain named contoso.com.
The domain controllers in the domain are configured as shown in the following table.
![NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE](http://www.hotitexam.com/wp-content/uploads/2016/08/image-257.png)
You deploy a new domain controller named DC3 that runs Windows Server 2012.
You discover that you cannot create Password Settings objects (PSOs) by using Active Directory Administrative Center.
You need to ensure that you can create PSOs from Active Directory Administrative Center.
What should you do?
A. Raise the functional level of the domain.
B. Upgrade DC1.
C. Transfer the infrastructure master operations master role.
D. Transfer the PDC emulator operations master role.
You discover that you cannot create Password Settings objects (PSOs) by using Active Directory Administrative Center.
You need to ensure that you can create PSOs from Active Directory Administrative Center.
What should you do?
A. Raise the functional level of the domain.
B. Upgrade DC1.
C. Transfer the infrastructure master operations master role.
D. Transfer the PDC emulator operations master role.
Correct Answer: A
Section: 5. Configure and manage Active Directory
Explanation
Explanation/Reference:
Notes:. Among the new features of Windows Server 2012 and Windows Server 2012 R2 include the possibility PSOs create directly in Active Directory
Administrative Center to manage and apply to users or groups prerequisite for using matched password policy is that the domain functional level to
Windows Server 2008 or set up.
QUESTION 49
You need to create Active directory application partition.
Which tool should you use?
A. dsmod
B. dsamain
C. dsmgmt
D. nesth
Correct Answer: C
Section: 5. Configure and manage Active Directory
Explanation
Explanation/Reference:
QUESTION 50
You are the administrator of an Active Directory Domain Services (AD DS) domain named contoso.com.
The domain has a Microsoft Windows Server 2012 R2 server named Contoso-SR05 that hosts the File and Storage Services server role. Contoso-SR05
hosts a shared folder named userData.
You want to receive an email alert when a multimedia file is saved to the userData folder.
Which tool should you use?
A. You should use File Management Tasks in File Server Resource Manager.
B. You should use File Screen Management in File Server Resource Manager.
C. You should use Quota Management in File Server Resource Manager.
Section: 5. Configure and manage Active Directory
Explanation
Explanation/Reference:
Notes:. Among the new features of Windows Server 2012 and Windows Server 2012 R2 include the possibility PSOs create directly in Active Directory
Administrative Center to manage and apply to users or groups prerequisite for using matched password policy is that the domain functional level to
Windows Server 2008 or set up.
QUESTION 49
You need to create Active directory application partition.
Which tool should you use?
A. dsmod
B. dsamain
C. dsmgmt
D. nesth
Correct Answer: C
Section: 5. Configure and manage Active Directory
Explanation
Explanation/Reference:
QUESTION 50
You are the administrator of an Active Directory Domain Services (AD DS) domain named contoso.com.
The domain has a Microsoft Windows Server 2012 R2 server named Contoso-SR05 that hosts the File and Storage Services server role. Contoso-SR05
hosts a shared folder named userData.
You want to receive an email alert when a multimedia file is saved to the userData folder.
Which tool should you use?
A. You should use File Management Tasks in File Server Resource Manager.
B. You should use File Screen Management in File Server Resource Manager.
C. You should use Quota Management in File Server Resource Manager.
D. You should use File Management Tasks in File Server Resource Manager.
E. You should use Storage Reports in File Server Resource Manager.
Correct Answer: B
Section: 2. Configure file and print services
Explanation
Explanation/Reference:
QUESTION 51
You have two servers, Server 1 and server 2.
You create a custom data collector set DCS1 on Server 1.
You need to export DCS1 from Server 1 to Server2.
What should you do?
A. Right click on DCS1 and click on Export list
B. Right click on DCS1 and click on Save template
C. Right click on DCS1 and click on Data Manager
D. Right click on DCS1 and click on Export manager
Correct Answer: B
Section: 1. Deploy and manage server images
Explanation
Explanation/Reference:
Notes:
The function Save Template … lets you export the definition of a data collector set in an XML file. Subsequently, the Data Collector Set can be imported
on Server2.
E. You should use Storage Reports in File Server Resource Manager.
Correct Answer: B
Section: 2. Configure file and print services
Explanation
Explanation/Reference:
QUESTION 51
You have two servers, Server 1 and server 2.
You create a custom data collector set DCS1 on Server 1.
You need to export DCS1 from Server 1 to Server2.
What should you do?
A. Right click on DCS1 and click on Export list
B. Right click on DCS1 and click on Save template
C. Right click on DCS1 and click on Data Manager
D. Right click on DCS1 and click on Export manager
Correct Answer: B
Section: 1. Deploy and manage server images
Explanation
Explanation/Reference:
Notes:
The function Save Template … lets you export the definition of a data collector set in an XML file. Subsequently, the Data Collector Set can be imported
on Server2.
![NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE](http://www.hotitexam.com/wp-content/uploads/2016/08/image-259.png)
QUESTION 52
Your network contains an Active Directory domain named contoso.com.
Your network contains an Active Directory domain named contoso.com.
All domain controllers run Windows Server 2012. The domain contains two servers.
The servers are configured as shown in the following table.
The servers are configured as shown in the following table.
![NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE](http://www.hotitexam.com/wp-content/uploads/2016/08/image-261.png)
Server1 and Server2 host a load-balanced website named Web1. Web1 runs by using an application pool named WebApp1. WebApp1 uses a group
Managed Service Account named gMSA1 as its identity.
Domain users connect to Web1 by using either the name Web1.contoso.com or the alias myweb.contoso.com.
You discover the following:
When the users access Web1 by using Web1.contoso.com, they authenticate by using Kerberos.
When the users access Web1 by using myweb.contoso.com, they authenticate by using NTLM.
You need to ensure that the users can authenticate by using Kerberos when they connect by using myweb.contoso.com.
What should you do?
A. Run the Set-ADServiceAccount cmdlet.
B. Run the New-ADServiceAccount cmdlet.
C. Modify the properties of the WebApp1 application pool.
D. Modify the properties of the Web1 website.
Correct Answer: A
Section: 5. Configure and manage Active Directory
Explanation
Explanation/Reference:
Managed Service Account named gMSA1 as its identity.
Domain users connect to Web1 by using either the name Web1.contoso.com or the alias myweb.contoso.com.
You discover the following:
When the users access Web1 by using Web1.contoso.com, they authenticate by using Kerberos.
When the users access Web1 by using myweb.contoso.com, they authenticate by using NTLM.
You need to ensure that the users can authenticate by using Kerberos when they connect by using myweb.contoso.com.
What should you do?
A. Run the Set-ADServiceAccount cmdlet.
B. Run the New-ADServiceAccount cmdlet.
C. Modify the properties of the WebApp1 application pool.
D. Modify the properties of the Web1 website.
Correct Answer: A
Section: 5. Configure and manage Active Directory
Explanation
Explanation/Reference:
Notes:
Independent managed service accounts that were introduced in Windows Server 2008 R2 and Windows 7 are managed domain accounts that provide
an automatic password management and simplified management of SPN (Service Principal Names SPNs) – including delegation of management to
other administrators.
The Group managed service account provides the same functions within the domain, but this also is expanding to multiple servers. When connecting
with a service that is hosted in a server farm (for example, a Network Load Balancing), the authentication protocols require with mutual authentication,
that all instances of services use the same principal. If group managed service accounts can be used as a service principals, the password for the
account from the Windows operating system is managed, rather than leaving the password keeper the Administrator.
The Microsoft Key Distribution Service (“kdssvc.dll”) provides the mechanism for secure retrieval of current key or a certain key ready for an Active
Directory account with a key ID. This service is new in Windows Server 2012 and can not run on older versions of the Windows Server operating
system. From the key distribution service secret information to create keys for the account are provided. These keys are changed regularly. In one group
managed service account to the Windows Server 2012 domain controller calculates the password for the key specified by the Key Distribution Service –
just like any other attributes of the group managed service account. Current and older password values can be 8-member hosts accessed by contacting
a Windows Server 2012 domain controller of Windows Server 2012- and Windows.
Group Managed Service Accounts provide a single identity solution for services that are running on a server farm or on systems behind a Network Load
Balancing. By providing a solution for group managed service accounts (groups-MSA solution) services for the new group MSA principal can be
configured, while the password manager of Windows is handled. When using a group managed service account must be managed by services or
service administrators no password synchronization between service instances become. The group managed service account supported hosts that are
offline for an extended period, as well as the managing member of hosts for all instances of a service.
So you can deploy a server farm that supports a single identity, with respect to the can authenticate existing client computer without knowing with which
instance of the service a connection is established. It is most likely that the service account gMSA1 only the name web1.contoso contains .de as
registered SPN. To ensure that Kerberos authentication works even when use of the name myweb.certbase.de, must match the service account name
myweb.certbase.de be added as additional SPN. This is possible by editing the account Properties or by using theSet-ADServiceAccount.
QUESTION 53
Your network contains a server named Server1 that has the Network Policy and Access Services server role installed. All of the network access server’s
forward connection requests to Server1.
You create a new network policy on Server1.
You need to ensure that the new policy applies only to connection requests from the 192.168.0.0/24 subnet.
What should you do?
A. Set the Called Station ID constraint to 192.168.0.
B. Set the Client IP4 Address condition to 192.168.0.0/24.
C. Set the Client IP4 Address condition to 192.168.0.
D. Set the Called Station ID constraint to 192.168.0.0/24.
Independent managed service accounts that were introduced in Windows Server 2008 R2 and Windows 7 are managed domain accounts that provide
an automatic password management and simplified management of SPN (Service Principal Names SPNs) – including delegation of management to
other administrators.
The Group managed service account provides the same functions within the domain, but this also is expanding to multiple servers. When connecting
with a service that is hosted in a server farm (for example, a Network Load Balancing), the authentication protocols require with mutual authentication,
that all instances of services use the same principal. If group managed service accounts can be used as a service principals, the password for the
account from the Windows operating system is managed, rather than leaving the password keeper the Administrator.
The Microsoft Key Distribution Service (“kdssvc.dll”) provides the mechanism for secure retrieval of current key or a certain key ready for an Active
Directory account with a key ID. This service is new in Windows Server 2012 and can not run on older versions of the Windows Server operating
system. From the key distribution service secret information to create keys for the account are provided. These keys are changed regularly. In one group
managed service account to the Windows Server 2012 domain controller calculates the password for the key specified by the Key Distribution Service –
just like any other attributes of the group managed service account. Current and older password values can be 8-member hosts accessed by contacting
a Windows Server 2012 domain controller of Windows Server 2012- and Windows.
Group Managed Service Accounts provide a single identity solution for services that are running on a server farm or on systems behind a Network Load
Balancing. By providing a solution for group managed service accounts (groups-MSA solution) services for the new group MSA principal can be
configured, while the password manager of Windows is handled. When using a group managed service account must be managed by services or
service administrators no password synchronization between service instances become. The group managed service account supported hosts that are
offline for an extended period, as well as the managing member of hosts for all instances of a service.
So you can deploy a server farm that supports a single identity, with respect to the can authenticate existing client computer without knowing with which
instance of the service a connection is established. It is most likely that the service account gMSA1 only the name web1.contoso contains .de as
registered SPN. To ensure that Kerberos authentication works even when use of the name myweb.certbase.de, must match the service account name
myweb.certbase.de be added as additional SPN. This is possible by editing the account Properties or by using theSet-ADServiceAccount.
QUESTION 53
Your network contains a server named Server1 that has the Network Policy and Access Services server role installed. All of the network access server’s
forward connection requests to Server1.
You create a new network policy on Server1.
You need to ensure that the new policy applies only to connection requests from the 192.168.0.0/24 subnet.
What should you do?
A. Set the Called Station ID constraint to 192.168.0.
B. Set the Client IP4 Address condition to 192.168.0.0/24.
C. Set the Client IP4 Address condition to 192.168.0.
D. Set the Called Station ID constraint to 192.168.0.0/24.
Correct Answer: C
Section: 4. Configure a Network Policy Server infrastructure
Explanation
Explanation/Reference:
Notes:
For each network policy at least one configured condition is required. The Network Policy Server Network Policy Server (NPS) provides many condition
groups that allow you to precisely define the characteristics that must have received from NPS connection request to comply with the Directive. The
following sets of conditions are available:
Groups
HCAP
Day and Time Restrictions
Network Access Protection
Connection Properties
RADIUS client properties
Gateway
The RADIUS client properties Client IPv4 Address Specifies the IPv4 address of the RADIUS client that forwarded the connection request to the NPS
server.
QUESTION 54
Your network contains two servers named W5U51 and WSUS_REPL that run Windows Server 2012.
WSUS1 and WSUS_REPL have the Windows Server Update Services server role installed.
All client computers run Windows 7.
WSUS1 synchronizes from Microsoft Update. WSUS_REPL is a Windows Server Update Services (WSUS) replica of WSUS1.
You need to configure replica downstream servers to send WSUS_REPL summary information about the computer update status.
What should you do?
A. From WSUS1, configure Reporting Rollup.
B. From WSUS_REPL, configure Reporting Rollup.
C. From WSUS1, configure Email Notifications.
D. From WSUS_REPL, configure Email Notifications.
Section: 4. Configure a Network Policy Server infrastructure
Explanation
Explanation/Reference:
Notes:
For each network policy at least one configured condition is required. The Network Policy Server Network Policy Server (NPS) provides many condition
groups that allow you to precisely define the characteristics that must have received from NPS connection request to comply with the Directive. The
following sets of conditions are available:
Groups
HCAP
Day and Time Restrictions
Network Access Protection
Connection Properties
RADIUS client properties
Gateway
The RADIUS client properties Client IPv4 Address Specifies the IPv4 address of the RADIUS client that forwarded the connection request to the NPS
server.
QUESTION 54
Your network contains two servers named W5U51 and WSUS_REPL that run Windows Server 2012.
WSUS1 and WSUS_REPL have the Windows Server Update Services server role installed.
All client computers run Windows 7.
WSUS1 synchronizes from Microsoft Update. WSUS_REPL is a Windows Server Update Services (WSUS) replica of WSUS1.
You need to configure replica downstream servers to send WSUS_REPL summary information about the computer update status.
What should you do?
A. From WSUS1, configure Reporting Rollup.
B. From WSUS_REPL, configure Reporting Rollup.
C. From WSUS1, configure Email Notifications.
D. From WSUS_REPL, configure Email Notifications.
Correct Answer: A
Section: 1. Deploy and manage server images
Explanation
Explanation/Reference:
Section: 1. Deploy and manage server images
Explanation
Explanation/Reference:
![NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE NEW! 70-411 EXAM] MICROSOFT.BRAINDUMPS.BY.SACRIESTORY_AIKONFX.383Q EXAM C PART3 (41-60) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE](http://www.hotitexam.com/wp-content/uploads/2016/08/image-263.png)
QUESTION 55
Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2. Both servers run
Windows Server 2012.
For Server2, you are configuring constrained delegation to a third-party service named Service1 on Server1.
When you attempt to add Service1 from Server1 to the delegation setting of Server2, you discover that Service1 is not listed in the Available services
list.
You need to ensure that you can add Service1 for constrained delegation.
What should you do first?
A. From the Services console, modify the properties of Service1.
B. From ADSI Edit, create a serviceConnectionPoint (SCP) object.
C. From a command prompt, run the setspn.exe command.
D. From Active Directory Users and Computers, enable the Advanced Features option.
Correct Answer: A
Section: 5. Configure and manage Active Directory
Explanation
Explanation/Reference:
Notes:
An SPN (SPN) is a unique identifier for a service in a network with Kerberos authentication. SPNs are made up of a service class, a host name and a
port. In a network with Kerberos authentication an SPN must be registered for the server under an integrated computer account such as Network
Service or Local System or a user account.
SPNs are automatically registered for built-in accounts. If you run a service under a domain user account, you must register the SPN manually for the
account that you want to use.
In order to make the service Service1, which runs on Server1, on other computers of the domain “visible”, has a service account be established, which
can be used over the range of the local computer addition (domain user account).
QUESTION 56
Your network contains an Active Directory domain named contoso.com.
All domain controllers run either Windows Server 2008 or Windows Server 2008 R2.
You deploy a new domain controller named DC1 that runs Windows Server 2012 R2. You log on to DC1 by using an account that is a member of the
Domain Admins group.
Windows Server 2012.
For Server2, you are configuring constrained delegation to a third-party service named Service1 on Server1.
When you attempt to add Service1 from Server1 to the delegation setting of Server2, you discover that Service1 is not listed in the Available services
list.
You need to ensure that you can add Service1 for constrained delegation.
What should you do first?
A. From the Services console, modify the properties of Service1.
B. From ADSI Edit, create a serviceConnectionPoint (SCP) object.
C. From a command prompt, run the setspn.exe command.
D. From Active Directory Users and Computers, enable the Advanced Features option.
Correct Answer: A
Section: 5. Configure and manage Active Directory
Explanation
Explanation/Reference:
Notes:
An SPN (SPN) is a unique identifier for a service in a network with Kerberos authentication. SPNs are made up of a service class, a host name and a
port. In a network with Kerberos authentication an SPN must be registered for the server under an integrated computer account such as Network
Service or Local System or a user account.
SPNs are automatically registered for built-in accounts. If you run a service under a domain user account, you must register the SPN manually for the
account that you want to use.
In order to make the service Service1, which runs on Server1, on other computers of the domain “visible”, has a service account be established, which
can be used over the range of the local computer addition (domain user account).
QUESTION 56
Your network contains an Active Directory domain named contoso.com.
All domain controllers run either Windows Server 2008 or Windows Server 2008 R2.
You deploy a new domain controller named DC1 that runs Windows Server 2012 R2. You log on to DC1 by using an account that is a member of the
Domain Admins group.
You discover that you cannot create Password Settings objects (PSOs) by using Active Directory Administrative Center.
You need to ensure that you can create PSOs from Active Directory Administrative Center.
What should you do?
A. Modify the membership of the Group Policy Creator Owners group.
B. Transfer the PDC emulator operations master role to DC1.
C. Upgrade all of the domain controllers that run Window Server 2008.
D. Raise the functional level of the domain.
Correct Answer: D
Section: 5. Configure and manage Active Directory
Explanation
Explanation/Reference:
QUESTION 57
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012
P.2.
Server1 has the Network Policy and Access Services server role installed.
Your company’s security policy requires that certificate-based authentication must be used by some network services.
You need to identify which Network Policy Server (NPS) authentication methods comply with the security policy.
Which two authentication methods should you identify?
(Each correct answer presents part of the solution. Choose two.)
A. MS-CHAP
B. PEAP-MS-CHAP v2
C. Chap
D. EAP-TLS
E. MS-CHAP v2
Correct Answer: BD
Section: 4. Configure a Network Policy Server infrastructure
You need to ensure that you can create PSOs from Active Directory Administrative Center.
What should you do?
A. Modify the membership of the Group Policy Creator Owners group.
B. Transfer the PDC emulator operations master role to DC1.
C. Upgrade all of the domain controllers that run Window Server 2008.
D. Raise the functional level of the domain.
Correct Answer: D
Section: 5. Configure and manage Active Directory
Explanation
Explanation/Reference:
QUESTION 57
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012
P.2.
Server1 has the Network Policy and Access Services server role installed.
Your company’s security policy requires that certificate-based authentication must be used by some network services.
You need to identify which Network Policy Server (NPS) authentication methods comply with the security policy.
Which two authentication methods should you identify?
(Each correct answer presents part of the solution. Choose two.)
A. MS-CHAP
B. PEAP-MS-CHAP v2
C. Chap
D. EAP-TLS
E. MS-CHAP v2
Correct Answer: BD
Section: 4. Configure a Network Policy Server infrastructure
Explanation
Explanation/Reference:
QUESTION 58
You administrate an Active Directory domain named EnsurePass.com.
The domain has a Microsoft Windows Server 2012 R2 server named EP-SR01 that hosts the File Server Resource Manager role service.
You are configuring quota threshold and want to receive an email alert when 80% of the quota has been reached.
Where would you enable the email alert?
A. You should consider creating a Data Collector Set (DCS).
B. You should use Windows Resource Monitor.
C. You should use the File Server Resource Manager.
D. You should use Disk Quota Tools.
E. You should use Performance Logs and Alerts.
Correct Answer: C
Section: 1. Deploy and manage server images
Explanation
Explanation/Reference:
Explanation:
To make use of email alerts, you need to configure the SMTP Server address details in the File Server Resource Manager options.
QUESTION 59
You deploy a windows Server Update (WSUS) server named Server01.
You need to ensure that you can view update reports and computer reports on server01.
Which two components should you install? Each correct answer presents part of the solution.
A. Microsoft Report Viewer 2008 Redistributable Package
B. Microsoft .Net Framework 2.0
C. Microsoft SQL Server 2008 R2 Builder 3.0
D. Microsoft XPS Viewer
E. Microsoft SQL Server 2012 reporting Services (SSRS)
Explanation/Reference:
QUESTION 58
You administrate an Active Directory domain named EnsurePass.com.
The domain has a Microsoft Windows Server 2012 R2 server named EP-SR01 that hosts the File Server Resource Manager role service.
You are configuring quota threshold and want to receive an email alert when 80% of the quota has been reached.
Where would you enable the email alert?
A. You should consider creating a Data Collector Set (DCS).
B. You should use Windows Resource Monitor.
C. You should use the File Server Resource Manager.
D. You should use Disk Quota Tools.
E. You should use Performance Logs and Alerts.
Correct Answer: C
Section: 1. Deploy and manage server images
Explanation
Explanation/Reference:
Explanation:
To make use of email alerts, you need to configure the SMTP Server address details in the File Server Resource Manager options.
QUESTION 59
You deploy a windows Server Update (WSUS) server named Server01.
You need to ensure that you can view update reports and computer reports on server01.
Which two components should you install? Each correct answer presents part of the solution.
A. Microsoft Report Viewer 2008 Redistributable Package
B. Microsoft .Net Framework 2.0
C. Microsoft SQL Server 2008 R2 Builder 3.0
D. Microsoft XPS Viewer
E. Microsoft SQL Server 2012 reporting Services (SSRS)
Correct Answer: AB
Section: 1. Deploy and manage server images
Explanation
Explanation/Reference:
Notes:
The Microsoft Report Viewer 2008 Redistributable Package includes Windows Forms and ASP.NET Web server controls for viewing reports that have
been created for the Microsoft reporting technology.
The Windows Server Update Services (WSUS) require the .Net Framework 2.0 and this extension to display the reports. To distribute updates of the
extension is not needed. In the later installation of a subsequent restart of the management console is required.
QUESTION 60
You deploy a windows Server Update (WSUS) server named Server01.
You need to prevent the WSUS service on Server01 from being updated automatically.
What should you do from the update service console?
A. From the Product and Classification options, modify the Products setting.
B. From the Automatic Approvals options, modify the Advanced settings.
C. From the Product and Classification options, modify the Classifications setting.
D. From the Automatic Approvals options, modify the Default Automatic Approval rule.
Correct Answer: B
Section: 1. Deploy and manage server images
Explanation
Explanation/Reference:
Section: 1. Deploy and manage server images
Explanation
Explanation/Reference:
Notes:
The Microsoft Report Viewer 2008 Redistributable Package includes Windows Forms and ASP.NET Web server controls for viewing reports that have
been created for the Microsoft reporting technology.
The Windows Server Update Services (WSUS) require the .Net Framework 2.0 and this extension to display the reports. To distribute updates of the
extension is not needed. In the later installation of a subsequent restart of the management console is required.
QUESTION 60
You deploy a windows Server Update (WSUS) server named Server01.
You need to prevent the WSUS service on Server01 from being updated automatically.
What should you do from the update service console?
A. From the Product and Classification options, modify the Products setting.
B. From the Automatic Approvals options, modify the Advanced settings.
C. From the Product and Classification options, modify the Classifications setting.
D. From the Automatic Approvals options, modify the Default Automatic Approval rule.
Correct Answer: B
Section: 1. Deploy and manage server images
Explanation
Explanation/Reference:
Latest online browsing the 70-411 exam!
70-411 PDF dumps & 70-411 VCE dumps: http://examsavior.com/70-411
100% Pass:http://examsavior.com/
No comments:
Post a Comment