Download New Updated (Spring 2015) Microsoft 70-687 Actual Tests 41-50

Ensurepass

 

QUESTION 41

DRAG DROP

A desktop computer runs Windows 8.1. The computer is joined to an Active Directory Domain Services (AD DS) domain named contoso.com.

 

You have two domain user accounts:

 

A primary account named User1 that does not have domain administrative privileges.

An account named Admin1 that has administrative privileges in the domain.

 

You are currently logged in as User1. You need to run an application named appl.exe.

 

You have the following requirements:

 

Start the application by using your administrative credentials.

Minimize the application load time.

 

You need to complete the command to meet the requirements.

Which command segments should you use to complete the command? (To answer, drag the appropriate command segments to the correct locations in the answer area. Command segments may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.)

 

clip_image001

 

Answer:

clip_image002

 

 

QUESTION 42

DRAG DROP

A company has 50 client computers that run Windows 8.1. Forty client computers are connected to a secure internal network, and 10 client computers are located in public kiosks.

 

A new company security policy includes the following requirements:

 

Visitors can access only kiosk computers.

Employees can access and shut down only internal computers.

Only administrators can access all computers remotely.

Only administrators can shut down kiosk computers.

 

You need to assign security groups to local security policies to meet the requirements.

 

What should you do? (To answer, drag the appropriate security group or groups to the correct location or locations in the answer area. Security groups may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.)

clip_image004

 

Answer:

clip_image006

 

 

QUESTION 43

A company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows Vista and are members of the domain. A Group Policy object (GPO) configuring a software restriction policy is implemented in the domain to block a specific application.

 

You upgrade a computer to Windows 8.1 and implement a GPO that configures an AppLocker rule in the domain. The blocked application runs on the Windows 8.1 computer but not on the Windows Vista computers.

You need to ensure that the application is blocked from running on all computers and the AppLocker rule is applied to the computers in the domain.

 

What should you do?

 

A.

Add the blocked application as an additional AppLocker rule to the GPO that configures AppLocker.

B.

Run the Get-AppLockerPolicy Windows PowerShell cmdlet.

C.

Run the Set-ExecutionPolicy Windows PowerShell cmdlet.

D.

Configure the software restriction policy as a local policy on the Windows 8.1 computer.

E.

Add the blocked application as a software restriction policy to the GPO that configures AppLocker.

 

Answer: A

Explanation:

http://technet.microsoft.com/library/hh994614

Use AppLocker and Software Restriction Policies in the Same Domain

 

AppLocker is supported on systems running Windows 7 and above. Software Restriction Policies (SRP) is supported on systems running Windows Vista or earlier. You can continue to use SRP for application control on your pre-Windows 7 computers, but use AppLocker for computers running Windows Server 2008 R2, Windows 7 and later. It is recommended that you author AppLocker and SRP rules in separate GPOs and target the GPO with SRP policies to systems running Windows Vista or earlier. When both SRP and AppLocker policies are applied to computers running Windows Server 2008 R2, Windows 7 and later, the SRP policies are ignored.

 

http://technet.microsoft.com/en-us/library/ee791851%28v=ws.10%29.aspx

Both SRP and AppLocker use Group Policy for domain management. However, when SRP policies and AppLocker policies exist in the same domain and applied through Group Policy, AppLocker policies will take precedence over SRP policies on computers running Windows Server 2012, Windows Server 2008 R2, Windows 8 or Windows 7.

 

As an example of how both types of policy would affect the bank’s “Teller software” application, consider the following scenario where the application is deployed on different Windows desktop operating systems and managed by the Tellers GPO.

 

clip_image008

 

Further Information:

http://technet.microsoft.com/en-us/library/hh847214.aspx

Get-AppLockerPolicy

The Get-AppLockerPolicy cmdlet retrieves the AppLocker policy from the local Group Policy Object (GPO), a specified Group Policy Object (GPO), or the effective policy on the computer.

By default, the output is an AppLockerPolicy object. If the XML parameter is used, then the output will be the AppLocker policy as an XML-formatted string.

 

http://technet.microsoft.com/en-us/library/hh849812.aspx

Set-ExecutionPolicy

The Set-ExecutionPolicy cmdlet changes the user preference for the Windows PowerShell execution policy.

The execution policy is part of the security strategy of Windows PowerShell. It determines whether you can load configuration files (including your Windows PowerShell profile) and run scripts, and it determines which scripts, if any, must be digitally signed before they will run.

 

 

QUESTION 44

A company has client computers that run Windows 8.1. Users store data on company- issued USB flash drives.

 

You establish that users are able to store data on personally owned USB flash drives.

 

You need to ensure that users can save data on company flash drives but not on personal flash drives.

 

What should you do?

 

A.

Disable driver signature enforcement.

B.

Run Device Manager as an administrator.

C.

In the local Group Policy, modify the device installation restrictions.

D.

In the system properties for hardware, modify the device installation settings.

 

Answer: C

Explanation:

You could prevent installation of mass storage devices but use the “Allow administrators to override” setting to ensure an administrator could get the flash drive installed.

 

clip_image010

 

Further information:

http://msdn.microsoft.com/en-us/library/bb530324.aspx

Step-By-Step Guide to Controlling Device Installation Using Group Policy

 

Group Policy Settings for Device Installation

To enable control over device installation, Windows Vista and Windows Server 2008 introduce several policy settings. You can configure these policy settings individually on a single computer, or you can apply them to a large number of computers through the use of Group Policy in an Active Directory domain.

 

Whether you want to apply the settings to a stand-alone computer or to many computers in an Active Directory domain, you use the Group Policy Object Editor to configure and apply the policy settings.

 

The following is a brief description of the DMI policy settings that are used in this guide. Prevent installation of devices not described by other policy settings. This policy setting controls the installation of devices that are not specifically described by any other policy setting. If you enable this policy setting, users cannot install or update the driver for devices unless they are described by either the Allow installation of devices that match these device IDs policy setting or the Allow installation of devices for these device classes policy setting. If you disable or do not configure this policy setting, users can install and update the driver for any device that is not described by the Prevent installation of devices that match these device IDs policy setting, the Prevent installation of devices for these device classes policy setting, or the Prevent installation of removable devices policy setting.

 

Allow installation of devices that match any of these device IDs. This policy setting specifies a list of Plug and Play hardware IDs and compatible IDs that describe devices

 

that users can install. This setting is intended to be used only when the Prevent installation of devices not described by other policy settings policy setting is enabled and does not take precedence over any policy setting that would prevent users from installing a device. If you enable this policy setting, users can install and update any device with a hardware ID or compatible ID that matches an ID in this list if that installation has not been specifically prevented by the Prevent installation of devices that match these device IDs policy setting, the Prevent installation of devices for these device classes policy setting, or the Prevent installation of removable devices policy setting. If another policy setting prevents users from installing a device, users cannot install it even if the device is also described by a value in this policy setting. If you disable or do not configure this policy setting and no other policy describes the device, the Prevent installation of devices not described by other policy settings policy setting determines whether users can install the device.

 

 

QUESTION 45

You manage computers that run Windows 8.1.

 

You plan to install a desktop app named MarketingApp on one of the client computers.

 

You need to display a progress bar to the user while installing the app.

 

Which command should you run?

 

A.

msiexec /i marketingapp.msi Jqn

B.

msiexec /i marketingapp.msi /qb

C.

msiexec /x marketingapp.msi /qb

D.

msiexec /x marketingapp.msi /qn

 

Answer: B

Explanation:

http://technet.microsoft.com/en-us/library/cc759262(v=ws.10).aspx

 

/i installs or configures a product

/qb displays a basic user interface

/qn Displays no user interface.

/x Uninstalls a product.

 

 

QUESTION 46

A company has 10 client computers that run Windows 8.1. You are responsible for technical support. You purchase a support tool from the Windows Store while logged in with your Microsoft account.

 

You install the support tool on several client computers.

 

Three months later, you attempt to install the support tool on another client computer. The installation fails.

 

You need to ensure that you can install the support tool on the client computer.

 

What should you do?

 

A.

Log in with your Microsoft account and remove a computer from the Windows Store device list.

B.

On the computer on which you want to install the tool, synchronize the Windows Store application licenses.

C.

Disassociate your Microsoft account from the computer on which you want to install the tool. Then reassociate your Microsoft account with the computer.

D.

Reset your Microsoft account password.

 

Answer: A

Explanation:

You could prevent installation of mass storage devices but use the “Allow administrators to override” setting to ensure an administrator could get the flash drive installed.

 

clip_image012

 

http://windows.microsoft.com/en-us/windows-8/windows-store-install-apps-multiple-pcs

You can remove a PC from your account when you’re signed in to the Store on any PC. After you’ve removed a PC from your account, you won’t be able to use the apps that were installed from the Store on that PC.

 

Further information:

http://windows.microsoft.com/en-us/windows-8/what-troubleshoot-problems-app Troubleshoot problems with an app

 

Sync app licenses

If a license for an app is out of sync with the license installed on your PC, the app might stop working.

 

 

QUESTION 47

You update the video card driver on a computer that runs Windows 8.1.

 

You can no longer configure the display settings to extend the display to a projector.

 

You need to restore the display options as quickly as possible and retain all user data.

 

What should you do?

 

A.

Roll back the video card driver to the previous version.

B.

Run the DisplaySwitch/extend command.

C.

Run the sic /scannow command.

D.

Start the computer from the Windows 8.1 installation media and perform a system image recovery.

 

Answer: A

Explanation:

Rolling back the driver is the simplest and fastest solution.

 

Example:

 

clip_image013

clip_image014

 

Further Information:

The DisplaySwitch /extend command might not work is the driver is broken. The sfc /scannow command checks system files for consistency. And a system image recovery will affect the user data.

 

 

 

 

 

QUESTION 48

A company has an Active Directory Domain Services (AD DS) domain with one physical domain controller. All client computers run Windows 8.1.

 

A client computer hosts a Windows 8.1 virtual machine (VM) test environment. The VMs are connected to a private virtual switch that is configured as shown in the Virtual Switch Manager exhibit. (Click the Exhibit button.)

 

clip_image016

 

The VMS are unable to connect to the domain controller. You have the following requirements:

 

Configure the test environment to allow VMs to communicate with the domain controller.

Ensure that the VMs can communicate with other VMS fl the test environment when the domain controller is unavailable.

 

You need to meet the requirements.

 

What should you do first?

 

A.

Create a new virtual switch with an Internal Network connection type.

B.

Create a new virtual switch with a Private Network connection type.

C.

Create a new virtual switch with an External Network connection type.

D.

Change the connection type of the private virtual switch to Internal only.

 

Answer: C

Explanation:

http://john.bryntze.net/jbkb-v2/certification-exam-70-687-configuring-windows-8-part-2-configure-hardware-and-applications-16/

 

Virtual switches/ Hyper-V VLAN – you can create 3 different types of virtual switches depending the needs of your virtual machines and one single machine can use multiple virtual NICs that is member of different Virtual Switches.

External – This virtual switch binds to the physical network adapter and create a new adapter you can see in Control PanelNetwork and InternetNetwork Connections so if a virtual machine needs contact outside the host machine this one is a must.

Internal – This virtual switch can be used to connect all virtual machines and the host machine but cannot go outside that.

Private – This virtual switch can only be used by the virtual host

 

Further information:

http://technet.microsoft.com/en-us/library/cc816585%28v=ws.10%29.aspx

Configuring Virtual Networks

 

clip_image018

 

Private will not allow communication with the host machine. External will allow communication with the host machine but also allow access to other machines on the host machine’s network.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

QUESTION 49

A company has an Active Directory Domain Services domain. All client computers run Windows 8.1 and are joined to the domain.

 

You run the ipconfiq command on a client computer. The following output depicts the results.

 

Ethernet adapter Local Area Connection 3:

 

clip_image019

 

You need to ensure that you can establish a DirectAccess connection from the client computer to the network.

 

What should you do?

 

A.

Create a new VPN connection.

B.

Remove the computer from the domain.

C.

Enable IPv6 on the network adapter.

D.

Configure a static IPv4 address.

 

Answer: C

Explanation:

http://technet.microsoft.com/en-us/library/dd637767%28v=ws.10%29.aspx

DirectAccess Connections

 

DirectAccess overcomes the limitations of VPNs by automatically establishing a bi- directional connection from client computers to the corporate network. DirectAccess is built on a foundation of proven, standards-based technologies: Internet Protocol security (IPsec) and Internet Protocol version 6 (IPv6).

 

Further Information:

http://john.bryntze.net/jbkb-v2/certification-exam-70-687-configuring-windows-8-part-3-configure-network-connectivity-15/

 

A few Windows 8 functions only work with IPv6 such as DirectAccess and HomeGroup.

 

 

 

 

 

 

 

 

QUESTION 50

DRAG DROP 

A computer currently runs a 64-bit version of Windows 7 Enterprise.

 

You need to deploy a 64-bit version of Windows 8.1 Pro to the computer. The new deployment must not affect the Windows 7 installation on the computer.

 

Which three actions should you perform in sequence? (To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.)

 

clip_image020

 

Answer:

clip_image021

 

Free VCE & PDF File for Microsoft 70-687 Real Exam

Instant Access to Free VCE Files: MCSE|MCSA|MCITP…
Instant Access to Free PDF Files: MCSE|MCSA|MCITP…