Download New Updated (Spring 2015) Microsoft 70-413 Actual Tests 45-60

Ensurepass

 

QUESTION 45

Your network contains an Active Directory domain named contoso.com. The domain contains an

organizational unit (OU) named OU1. You have a Group Policy object (GPO) named GPO1 that is

linked to contoso.com. GPO1 contains custom security settings. You need to design a Group

Policy strategy to meet the following requirements:

 

Ÿ   The security settings in GPO1 must be applied to all client computers.

Ÿ   Only GPO1 and other GPOs that are linked to OU1 must be applied to the client computers

in OU1.

 

What should you include in the design? (More than one answer choice may achieve the goal.

Select the BEST answer.)

 

A.      Enable the Block Inheritance option at the domain level. Enable the Enforced option on

GPO1.

B.      Enable the Block Inheritance option on OU1. Link GPO1 to OU1.

C.      Enable the Block Inheritance option on OU1. Enable the Enforced option on GPO1.

D.      Enable the Block Inheritance option on OU1. Enable the Enforced option on all of the GPOs

linked to OU1.

 

Correct Answer: C

 

 

 

 

 

QUESTION 46

A new company registers the domain name of contoso.com. The company has a web presence on

the Internet. All Internet resources have names that use a DNS suffix of contoso.com. A

third-party hosts the Internet resources and is responsible for managing the contoso.com DNS

zone on the Internet. The zone contains several hundred records. The company plans to deploy

an Active Directory forest. You need to recommend an Active Directory forest infrastructure to

meet the following requirements:

 

Ÿ   Ensure that users on the internal network can resolve the names of the company’s Internet

resources.

Ÿ   Minimize the amount of administrative effort associated with the addition of new Internet

servers.

 

What should you recommend?

 

A.      A forest that contains a root domain named contoso.com and another domain named

ad.contoso.com.

B.      A forest that contains a root domain named contoso.com and another domain named

contoso.local.

C.      A forest that contains a single domain named contoso.local.

D.      A forest that contains a single domain named contoso.com.

 

Correct Answer: C

 

 

QUESTION 47

Your network contains an Active Directory forest named contoso.com. The forest contains one

domain. Your company plans to open a new division named Division1. A group named

Division1Admins will administer users and groups for Division1. You identify the following

requirements for Division1:

 

Ÿ   All Division1 users must have a complex password that is 14 characters.

Ÿ   Division1Admins must be able to manage the user accounts for Division1.

Ÿ   Division1Admins must be able to create groups, and then delete the groups that they create.

Ÿ   Division1Admins must be able to reset user passwords and force a password change at the

next logon for all Division1 users.

 

You need to recommend changes to the forest to support the Division1 requirements. What

should you recommend? (More than one answer choice may achieve the goal. Select the BEST

answer.)

 

A.      Create a new child domain named divisionl.contoso.com. Move all of the Division1 user

accounts to the new domain. Add the Division1Admin members to the Domain Admins

group. Configure the password policy in a Group Policy object (GPO).

B.      In the forest, create a new organizational unit (OU) named Division1 and add

Division1Admins to the Managed By attribute of the new OU. Move the Division1 user

objects to the new OU. Create a fine-grained password policy for the Division1 users.

C.      Create a new forest. Migrate all of the Division1 user objects to the new forest and add the

Division1Admins members to the Enterprise Admins group. Configure the password policy in

a Group Policy object (GPO).

D.      In the forest, create a new organizational unit (OU) named Division1 and delegate

permissions for the OU to the Division1Admins group. Move all of the Division1 user

accounts to the new OU. Create a fine-grained password policy for the Division1 users.

 

Correct Answer: A

 

 

QUESTION 48

Your network contains an internal network and a perimeter network. The internal network

contains an Active Directory forest named contoso.com. The forest contains a Microsoft Exchange

Server 2010 organization. All of the domain controllers in contoso.com run Windows Server 2012.

The perimeter network contains an Active Directory forest named litware.com. You deploy

Microsoft Forefront Unified Access Gateway (UAG) to litware.com. All of the domain controllers

in litware.com run Windows Server 2012. Some users connect from outside the network to use

Outlook Web App. You need to ensure that external users can authenticate by using client

certificates. What should you do? (More than one answer choice may achieve the goal. Select the

BEST answer.)

 

A.      Enable Kerberos constrained delegation in litware.com.

B.      To the perimeter network, add an Exchange server that has the Client Access server role

installed.

C.      Enable Kerberos delegation in litware.com.

D.      Deploy UAG to contoso.com.

 

Correct Answer: A

 

 

QUESTION 49

Your company has a main office and 20 branch offices. All of the offices connect to each other by

using a WAN link. The network contains an Active Directory forest named contoso.com. The

forest contains a domain for each office. The forest root domain contains all of the server

resources. Each branch office contains two domain controllers for the branch office domain and

one domain controller for the contoso.com domain. Each branch office has a support technician

who is responsible for managing the accounts of their respective office only. You recently

updated all of the WAN links to high-speed WAN links. You need to recommend changes to the

Active Directory infrastructure to meet the following requirements:

 

Ÿ   Reduce the administrative overhead of moving user accounts between the offices.

Ÿ   Ensure that the support technician in each office can manage the user accounts of their

respective office.

 

What should you include in the recommendation?

 

More than one answer choice may achieve the goal. Select the BEST answer.

 

A.      Create shortcut trusts between each child domain.

In the main office, add a domain controller to each branch office domain.

B.      Create a new child domain named corp.contoso.com.

Create a shortcut trust between each child domain and corp.contoso.com.

C.      Move all of the user accounts of all the branch offices to the forest root domain.

Decommission all of the child domains.

D.      Create a new forest root domain named contoso.local.

Move all of the user accounts of all the branch offices to the new forest root domain.

Decommission all of the child domains.

 

Correct Answer: C

 

 

QUESTION 50

Your company, which is named Contoso, Ltd., has a main office and two branch offices. The main

office is located in North America. The branch offices are located in Asia and Europe. You plan to

design an Active Directory forest and domain infrastructure. You need to recommend an Active

Directory design to meet the following requirements:

 

Ÿ   The contact information of all the users in the Europe office must not be visible to the users

in the other offices.

Ÿ   The administrators in each office must be able to control the user settings and the computer

settings of the users in their respective office.

 

The solution must use the least amount of administrative effort. What should you include in the

recommendation?

 

A.      One forest that contains three domains

B.      One forest that contains one domain

C.      Three forests that each contain one domain

D.      Two forests that each contain one domain

 

Correct Answer: B

 

 

 

 

QUESTION 51

Your network contains an Active Directory forest named contoso.com. You plan to deploy 200

Hyper-V hosts by using Microsoft System Center 2012 Virtual Machine Manager (VMM) Service

Pack 1 (SP1). You add a PXE server to the fabric. You need to identify which objects must be

added to the VMM library for the planned deployment. What should you identify? (Each correct

answer presents part of the solution. Choose all that apply.)

 

A.      A host profile

B.      A capability profile

C.      A hardware profile

D.      A generalized image

E.       A service template

 

Correct Answer: AD

 

 

QUESTION 52

You plan to deploy multiple servers in a test environment by using Windows Deployment Services

(WDS). You need to identify which network services must be available in the test environment to

deploy the servers. Which network services should you identify? (Each correct answer presents

part of the solution. Choose all that apply.)

 

A.      DHCP

B.      Active Directory Domain Services (AD DS)

C.      DNS

D.      Active Directory Lightweight Directory Services (AD LDS)

E.       WINS

F.       Network Policy Server (NPS)

 

Correct Answer: AC

 

 

QUESTION 53

Your network contains an Active Directory forest named contoso.com. The forest is managed by

using Microsoft System Center 2012. Web developers must be able to use a self-service portal to

request the deployment of virtual machines based on predefined templates. The requests must

be approved by an administrator before the virtual machines are deployed. You need to

recommend a solution to deploy the virtual machines. What should you include in the

recommendation? (More than one answer choice may achieve the goal. Select the BEST answer.)

 

A.      A Virtual Machine Manager (VMM) service template, a Service Manager service offering, and

an Orchestrator runbook

B.      A Virtual Machine Manager (VMM) service template, an Operations Manager dashboard,

and an Orchestrator runbook

C.      A Service Manager service offering, an Orchestrator runbook, and Configuration Manager

packages

D.      A Service Manager service offering, an Orchestrator runbook, and an Operations Manager

dashboard

 

Correct Answer: A

 

 

QUESTION 54

Your company has a main office and four branch offices. The main office is located in London. The

network contains an Active Directory domain named contoso.com. The network is configured as

shown in the exhibit.

 

clip_image001

 

Each office contains several servers that run Windows Server 2012. In each branch office, you

plan to deploy an additional 20 servers that will run Windows Server 2012. Some of the servers

will have a Server Core Installation of Windows Server 2012.

 

You identify the following requirements for the deployment of the new servers:

 

Ÿ   Operating system images must be administered centrally.

Ÿ   The operating system images must be deployed by using PXE.

Ÿ   The WAN traffic caused by the deployment of each operating system must be minimized.

 

You need to recommend a solution for the deployment of the new servers. What should you

recommend?

 

A.      Deploy Windows Deployment Services (WDS) in each office.

Replicate the images by using Distributed File System (DFS) Replication.

B.      Deploy Windows Deployment Services (WDS) in each office.

Copy the images by using BranchCache.

C.      Deploy Windows Deployment Services (WDS) in the main office only.

Copy the images by using BranchCache.

D.      Deploy Windows Deployment Services (WDS) in the main office only.

Replicate the images by using Distributed File System (DFS) Replication.

 

Correct Answer: A

 

 

QUESTION 55

Your network contains an Active Directory domain named contoso.com. The domain contains a

Microsoft System Center 2012 infrastructure. The domain contains two sites named Site1 and

Site2. The sites connect to each other by using a 1-Mbps WAN link. The sites contain four servers.

The servers are configured as shown in the following table.

 

clip_image002

 

In Site2, you plan to deploy 50 Hyper-V hosts. You need to recommend a solution to deploy the

Hyper-V hosts by using VMM. The solution must minimize the amount of traffic between Site1

and Site2 during deployment. What should you recommend?

 

A.      On Server4, install VMM. From the Virtual Machine Manager console, add Server1 as a PXE

server and add Server4 as a library server.

B.      On Server4/ install VMM. From the Virtual Machine Manager console, add Server1 as a PXE

server and a library server.

C.      On Server4, install WDS. From the Virtual Machine Manager console, add Server4 as a PXE

server and a library server.

D.      On Server4, install WDS. From the Virtual Machine Manager console, add Server4 as a PXE

server and add Server1 as a library server.

 

Correct Answer: C

 

QUESTION 56

Your network contains an Active Directory forest named contoso.com. You plan to add a new

domain named child.contoso.com to the forest. On the DNS servers in child.contoso.com, you

plan to create conditional forwarders that point to the DNS servers in contoso.com. You need to

ensure that the DNS servers in contoso.com can resolve names for the servers in

child.contoso.com. What should you create on the DNS servers in contoso.com?

 

A.      A root hint

B.      A zone delegation

C.      A conditional forwarder

D.      A trust point

 

Correct Answer: B

 

 

QUESTION 57

Your network contains a server named Server1 that runs Windows Server 2012. Server1 has the

DHCP Server role installed. The network contains a Virtual Desktop Infrastructure (VDI). All virtual

machines run Windows 8. You identify the following requirements for allocating IPv4 addresses

to client computers:

 

Ÿ   All virtual desktops must have static IP addresses.

Ÿ   All laptop computers must receive dynamic IP addresses.

Ÿ   All virtual desktops must be prevented from obtaining dynamic address.

 

You need to recommend a DHCP solution that meets the requirements for allocating IPv4

addresses. The solution must use the least amount of administrative effort. What should you

recommend? (More than one answer choice may achieve the goal. Select the BEST answer.)

 

A.      Create two physical subnets. Configure 802.1x authentication for each subnet.

B.      Create two physical subnets. Connect the laptop computers to the subnet that contains

Server1.

C.      Configure DHCP filtering.

D.      Configure DHCP policies.

 

Correct Answer: C

 

 

QUESTION 58

You have a server named Server1 that runs Windows Server 2012. Server1 has the DNS Server

role installed. You need to recommend changes to the DNS infrastructure to protect the cache

from cache poisoning attacks. What should you configure on Server1?

 

A.      DNS devolution

B.      DNS Security Extensions (DNSSEC)

C.      DNS cache locking

D.      The global query block list

 

Correct Answer: C

 

 

QUESTION 59

Your network contains an Active Directory forest that has two domains named contoso.com and

europe.contoso.com. The forest contains five servers. The servers are configured as shown in the

following table.

 

clip_image004

 

You plan to manage the DHCP settings and the DNS settings centrally by using IP Address

Management (IPAM). You need to ensure that you can use IPAM to manage the DHCP and DNS

settings in both domains. The solution must use the minimum amount of administrative effort.

What should you do?

 

A.      Upgrade DCE1 and DCE2 to Windows Server 2012, and then install the IP Address

Management (IPAM) Server feature. Run the Invoke-IpamGpoProvisioning cmdlet for each

domain.

B.      Upgrade DCE1 and DCE2 to Windows Server 2012, and then install the IP Address

Management (IPAM) Server feature. Run the Set-IpamConfiguration cmdlet for each domain.

C.      Upgrade DC1 and DC2 to Windows Server 2012, and then install the IP Address Management

(IPAM) Server feature. Run the Set-IpamConfiguration cmdlet for each domain.

D.      Upgrade DC1 and DC2 to Windows Server 2012, and then install the IP Address Management

(IPAM) Server feature. Run the Invoke-IpamGpoProvisioning cmdlet for each domain.

 

Correct Answer: A

 

 

 

QUESTION 60

Your company is a hosting provider that provides cloud-based services to multiple customers.

Each customer has its own Active Directory forest located in your company’s datacenter. You plan

to provide VPN access to each customer. The VPN solution will use RADIUS for authentication

services and accounting services. You need to recommend a solution to forward authentication

and accounting messages from the perimeter network to the Active Directory forest of each

customer. What should you recommend? (More than one answer choice may achieve the goal.

Select the BEST answer.)

 

A.      A RADIUS server for each customer and one RADIUS proxy

B.      A RADIUS server for each customer and a RADIUS proxy for each customer

C.      One RADIUS proxy and one Active Directory Lightweight Directory Services (AD LDS) instance

for each customer

D.      One RADIUS proxy for each customer and Active Directory Federation Services (AD FS)

 

Correct Answer: A

 

Free VCE & PDF File for Microsoft 70-413 Real Exam

Instant Access to Free VCE Files: MCSE|MCSA|MCITP…
Instant Access to Free PDF Files: MCSE|MCSA|MCITP…