Achieve New Updated (September) Microsoft 70-410 Examination Questions 351-360

Ensurepass

 

 

QUESTION 351

You work as an administrator at ENSUREPASS.com. The ENSUREPASS.com network consists of a single domain named ENSUREPASS.com. All servers in the ENSUREPASS.com domain, including domain controllers, have Windows Server 2012 installed.

You have been instructed to modify an Active Directory computer object.

Which of the following actions should you take?

 

A.

You should consider making use of the Get-ADComputer Windows PowerShell cmdlet.

B.

You should consider making use of the Set-ADComputer Windows PowerShell cmdlet

C.

You should consider making use of the New-ADComputer Windows PowerShell cmdlet

D.

You should consider making use of the Get-ADComputerServiceAccount Windows PowerShell cmdlet

 

Correct Answer: B

Explanation:

Set-ADComputer – Modifies an Active Directory computer object.

http://technet.microsoft.com/en-us/library/ee617263.aspx

 

 

QUESTION 352

You work as an administrator at ENSUREPASS.com. The ENSUREPASS.com network consists of an Active Directory forest that contains a root domain, named ENSUREPASS.com, and two child domains, named us.ENSUREPASS.com and uk.ENSUREPASS.com. All servers on the ENSUREPASS.com network have Windows Server 2012 R2 installed.

The root domain hosts a domain local distribution group, named ENSUREPASSGroup. You are preparing to issue ENSUREPASSGroup read-only access to a shared folder hosted by the us.ENSUREPASS.com domain.

You want to make sure that ENSUREPASSGroup is able to access the shared folder in the us.ENSUREPASS.com domain.

Which of the following actions should you take?

 

A.

You should consider re-configuring ENSUREPASSGroup as a universal Admins group.

B.

You should consider re-configuring ENSUREPASSGroup as a universal security group.

C.

You should consider re-configuring ENSUREPASSGroup as a global administrators group.

D.

You should consider re-configuring ENSUREPASSGroup as a local administrators group.

 

Correct Answer: B

Explanation:

Group scope Universal can be assigned permissions in any domain or forest.

 

clip_image001

 

http://technet.microsoft.com/en-us/library/cc781446(v=ws.10).aspx http://technet.microsoft.com/en-us/library/cc755692(v=ws.10).aspx

 

 

QUESTION 353

You work as an administrator at ENSUREPASS.com. The ENSUREPASS.com network consists of a single domain named ENSUREPASS.com.

ENSUREPASS.com has a domain controller, named ENSUREPASS-DC01, which has Windows Server 2012 R2 installed. Another ENSUREPASS.com domain controller, named ENSUREPASS-DC02, has Windows Server 2008 R2 installed.

You have deployed a server, named ENSUREPASS-SR15, on ENSUREPASS.com’s perimeter network. ENSUREPASSSR15 is running a Server Core Installation of Windows Server 2012 R2.

You have been instructed to make sure that ENSUREPASS-SR15 is part of the ENSUREPASS.com domain.

 

Which of the following actions should you take?

 

A.

You should consider making use of Set-Computer Windows PowerShell cmdlet on ENSUREPASS-SR15.

B.

You should consider making use of Get-Computer Windows PowerShell cmdlet on ENSUREPASS-SR15.

C.

You should consider making use of Test-Computer Windows PowerShell cmdlet on ENSUREPASS-SR15.

D.

You should consider making use of Add-Computer Windows PowerShell cmdlet on ENSUREPASS-SR15.

 

Correct Answer: D

Explanation:

Add-Computer – Add the local computer to a domain or workgroup.

http://technet.microsoft.com/en-us/library/hh849798.aspx

 

 

QUESTION 354

You work as an administrator at ENSUREPASS.com. The ENSUREPASS.com network consists of two Active Directory forests, named ENSUREPASS.com and test.com. There is no trust relationship configured between the forests.

A backup of Group Policy object (GPO) from the test.com domain is stored on a domain controller in the ENSUREPASS.com domain. You are informed that a GPO must
be created in the ENSUREPASS.com domain, and must be based on the settings of the GPO in the test.com domain.

You start by creating the new GPO using the New-GPO Windows PowerShell cmdlet. You want to complete the task via a Windows PowerShell cmdlet.

Which of the following actions should you take?

 

A.

You should consider making use of the Invoke-GPUpdate Windows PowerShell cmdlet.

B.

You should consider making use of the Copy-GPO Windows PowerShell cmdlet.

C.

You should consider making use of the New-GPLink Windows PowerShell cmdlet.

D.

You should consider making use of the Import-GPO Windows PowerShell cmdlet.

 

Correct Answer: D

Explanation:

Import-GPO -Imports the Group Policy settings from a backed-up GPO into a specified GPO.

http://technet.microsoft.com/en-us/library/ee461044.aspx

 

 

 

 

 

 

 

 

QUESTION 355

You work as an administrator at ENSUREPASS.com. The ENSUREPASS.com network consists of a single domain named ENSUREPASS.com. All servers in the ENSUREPASS.com domain, including domain controllers, have Windows Server 2012 R2 installed.

ENSUREPASS.com has a server, named ENSUREPASS-SR15, which is configured as a file server. You have received instructions to make sure that a user, named Mia Hamm, has the ability to generate a complete backup of ENSUREPASS-SR15 via Windows Server Backup.

Which of the following actions should you take?

 

A.

You should consider making use of Computer Management to configure the local groups.

B.

You should consider making use of Computer Management to configure the domain local groups.

C.

You should consider making use of Computer Management to configure the global groups.

D.

You should consider making use of Computer Management to configure the administrator groups.

 

Correct Answer: A

Explanation:

To perform backups or recoveries by using Windows Server Backup, you must be a member of the Administrators or Backup Operators groups.

http://technet.microsoft.com/en-us/library/ee849849%28v=ws.10%29.aspx

Notes

You can only use Backup locally; you cannot backup a remote computer.

You can only back up and restore System State data on a local computer. You cannot back up and restore System State data on a remote computer even if you are an administrator on the remote computer.

http://technet.microsoft.com/en-us/library/cc776822%28v=ws.10%29.aspx

 

 

QUESTION 356

You work as a senior administrator at ENSUREPASS.com. The ENSUREPASS.com network consists of a single domain named ENSUREPASS.com. All servers on the ENSUREPASS.com network have Windows Server 2012 R2 installed.

You are running a training exercise for junior administrators. You are currently discussing the Windows Firewall with Advanced Security feature.

Which of the following is TRUE with regards to Windows Firewall with Advanced Security? (Choose all that apply.)

 

A.

It provides host-based, two-way network traffic filtering for a computer.

B.

It provides host-based, one-way network traffic filtering for a computer.

C.

It blocks unauthorized network traffic flowing into or out of the local computer.

D.

It only blocks unauthorized network traffic flowing into the local computer.

E.

It only blocks unauthorized network traffic flowing out of the local computer.

 

Correct Answer: AC

Explanation:

Windows Firewall with Advanced Security is an important part of a layered security model.

By providing host-based, two-way network traffic filtering for a computer, Windows Firewall with Advanced Security blocks unauthorized network traffic flowing into or out of the local computer. Windows Firewall with Advanced Security also works with Network Awareness so that it can apply security settings appropriate to the types of networks to which the computer is connected. Windows Firewall and Internet Protocol Security (IPsec) configuration settings are integrated into a single Microsoft Management Console (MMC) named portant part of your network’s

Windows Firewall with Advanced Security, so Windows Firewall is also an im isolation strategy.

http://technet.microsoft.com/en-us/library/hh831365.aspx

 

QUESTION 357

You work as a senior administrator at ENSUREPASS.com. The ENSUREPASS.com network consists of a single domain named ENSUREPASS.com. All servers on the ENSUREPASS.com network have Windows Server 2012 R2 installed.

You are running a training exercise for junior administrators. You are currently discussing connection security rules.

Which of the following is TRUE with regards to connection security rules? (Choose all that apply.)

 

A.

Connection security rules allows for traffic to be secured via IPsec.

B.

Connection security rules do not allow the traffic through the firewall.

C.

Connection security rules are applied to programs or services.

D.

Connection security rules are applied between two computers.

 

Correct Answer: ABD

Explanation:

Connection security involves the authentication of two computers before they begin communications and the securing of information sent between two computers. Windows Firewall with Advanced Security uses Internet Protocol security (IPsec) to achieve connection security by using key exchange, authentication, data integrity, and, optionally, data encryption.

How firewall rules and connection security rules are related

Firewall rules allow traffic through the firewall, but do not secure that traffic. To secure traffic with IPsec, you can create Computer Connection Security rules. However, the creation of a connection securityrule does not allow the traffic through the firewall. You must create a firewall rule to do this, if the traffic is not allowed by the default behavior of the firewall. Connection security rules are not applied toprograms or services; they are applied between the computers that make up the two endpoints.

http://technet.microsoft.com/en-us/library/cc772017.aspx

http://technet.microsoft.com/en-us/library/cc772017%28v=ws.10%29.aspx

 

 

QUESTION 358

You work as an administrator at ENSUREPASS.com. The ENSUREPASS.com network consists of a single domain named ENSUREPASS.com. All servers in the ENSUREPASS.com domain, including domain controllers, have Windows Server 2012 R2 installed.

You have been instructed to make sure that ENSUREPASS.com users are not able to install a Windows Store application. You then create a rule for packaged apps.

Which of the following is the rule based on? (Choose all that apply.)

 

A.

The publisher of the package.

B.

The publisher of the application.

C.

The name of the package

D.

The name of the application

E.

The package version.

F.

The application version.

 

Correct Answer: ACE

Explanation:

Packaged apps (also known as Windows 8 apps) are new to Windows Server 2012 R2 and Windows 8.

They are based on the new app model that ensures that all the files within an app package share the same identity. Therefore, it is possible to control the entire application using a single AppLocker rule as opposed to the non-packaged apps where each file within the app could have a unique identity. Windows does not support unsigned packaged apps which implies all packaged apps must be signed.

AppLocker supports only publisher rules for Packaged apps.

A publisher rule for a Packaged app is based on the following information:

Publisher of the package

Package name

Package version

All the files within a package as well as the package installer share these attributes. Therefore, an AppLocker rule for a Packaged app controls both the installation as well as the running of the app. Otherwise, the publisher rules for Packaged apps are no different than the rest of the rule collections; they support exceptions, can be increased or decreased in scope, and can be assigned to users and groups.

http://technet.microsoft.com/en-us/library/hh994588.aspx

 

 

QUESTION 359

You work as a senior administrator at ENSUREPASS.com. The ENSUREPASS.com network consists of a single domain named ENSUREPASS.com. All servers on the ENSUREPASS.com network have Windows Server 2012 R2 installed.

You are running a training exercise for junior administrators. You are currently discussing Group Policy preference.

Which of the following is TRUE with regards to Group Policy preference?

 

A.

It supports applications and operating system features that are not compatible with Group Policy

B.

It does not support item-level targeting.

C.

It is the same as Group Policy filtering.

D.

It does not cause the application or operating system feature to disable the user interface for the settings

they configure.

 

Correct Answer: AD

 

 

QUESTION 360

You work as an administrator at ABC.com. The ABC.com network consists of a single domain named ABC.com. All servers in the ABC.com domain, including domain controllers, have Windows Server 2012 R2 installed.

ABC.com has a domain controller, named ABC-DC01, which contains the ABC.com domain’s primary DNS zone. ABC.com’s workstations refer to ABC-DC01 as their primary DNS server.

You have been instructed to make sure that any DNS requests that are not for the ABC.com domain, is resolved by ABC-DC01 querying the DNS server of ABC.com’s Internet Service Provider (ISP).

Which of the following actions should you take?

 

A.

You should consider configuring a reverse lookup zone.

B.

You should consider configuring forward lookup zone.

C.

You should consider configuring Forwarders.

D.

You should consider configuring 019 IP Layer Forwarding.

 

Correct Answer: C

Explanation:

A forwarder is a Domain Name System (DNS) server on a network that forwards DNS queries for external DNS names to DNS servers outside that network. You can also forward queries according to specific domain names using conditional forwarders.

You designate a DNS server on a network as a forwarder by configuring the other DNS servers in the network to forward the queries that they cannot resolve locally to that DNS server. By using a forwarder, you can manage name resolution for names outside your network, such as names on the Internet, and improve the efficiency of name resolution for the computers in your network.

http://technet.microsoft.com/en-us/library/cc754931.aspx

http://technet.microsoft.com/en-us/library/cc730756.aspx

Free VCE & PDF File for Microsoft 70-410 Real Exam

Instant Access to Free VCE Files: MCSE|MCSA|MCITP…
Instant Access to Free PDF Files: MCSE|MCSA|MCITP…