[Free] Download New Latest (November) Microsoft 70-417 Actual Tests 281-290

Ensurepass

QUESTION 281

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2.

 

DirectAccess is deployed to the network.

 

Remote users connect to the DirectAccess server by using a variety of network speeds.

 

The remote users report that sometimes their connection is very slow.

 

You need to minimize Group Policy processing across all wireless wide area network (WWAN) connections.

 

Which Group Policy setting should you configure?

 

A.

Configure Direct Access connections as a fast network connection.

B.

Change Group Policy processing to run asynchronously when a slow network connection is detected.

C.

Configure Group Policy slow link detection.

D.

Configure wireless policy processing.

 

Correct Answer: C

 

 

 

 

 

 

QUESTION 282

HOTSPOT

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All domain controllers run Windows Server 2012 R2 and are configured as DNS servers. All DNS zones are Active Directory-integrated. Active Directory Recycle Bin is enabled.

 

You need to modify the amount of time deleted objects are retained in the Active Directory Recycle Bin.

 

Which naming context should you use?

 

To answer, select the appropriate naming context in the answer area.

 

clip_image001

 

Correct Answer:

clip_image002

 

 

QUESTION 283

Your company deploys a new Active Directory forest named contoso.com. The first domain controller in the forest runs Windows Server 2012 R2. The forest contains a domain controller named DC10.

 

On DC10, the disk that contains the SYSVOL folder fails.

 

You replace the failed disk. You stop the Distributed File System (DFS) Replication service.

 

You restore the SYSVOL folder.

 

You need to perform a non-authoritative synchronization of SYSVOL on DC10.

 

Which tool should you use before you start the DFS Replication service on DC10?

 

A.

Active Directory Sites and Services

B.

Dfsmgmt.msc

C.

Ldp

D.

Frsutil

 

Correct Answer: B

 

 

 

 

 

 

 

 

 

 

 

QUESTION 284

Your network contains an Active Directory forest named contoso.com. The forest contains two sites named Main and Branch. The Main site contains 400 desktop computers and the Branch site contains 150 desktop computers. All of the desktop computers run Windows 8.

 

In Main, the network contains a member server named Server1 that runs Windows Server 2012.

 

You install the Windows Server Update Services server role on Server1.

 

You need to ensure that Windows updates obtained from Windows Server Update Services (WSUS) are the same for the computers in each site.

 

You want to achieve this goal by using the minimum amount of administrative effort.

 

What should you do?

 

A.

From the Update Services console, create computer groups

B.

From the Update Services console, configure the Computers options

C.

From the Group Policy Management console, configure the Windows Update settings

D.

From the Group Policy Management console, configure the Windows Anytime Upgrade settings

E.

From the Update Services console, configure the Synchronization Schedule options

 

Correct Answer: C

 

 

QUESTION 285

DRAG DROP

Your network contains an Active Directory domain named adatum.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 is configured as a Network Policy Server (NPS) server and as a DHCP server.

 

You need to log all DHCP clients that have Windows Firewall disabled.

 

Which three actions should you perform in sequence?

 

To answer, move the three appropriate actions from the list of actions to the answer area and arrange them in the correct order.

 

clip_image004

 

Correct Answer:

clip_image006

 

 

QUESTION 286

Your network contains an Active Directory domain named contoso.com. The domain contains domain controllers that run Windows Server 2008, Windows Server 2008 R2 Windows Server 2012, and Windows Server 2012 R2.

 

A domain controller named DC1 runs Windows Server 2012 R2. DC1 is backed up daily.

 

During routine maintenance, you delete a group named Group1.

 

You need to recover Group1 and identify the names of the users who were members of Group1 prior to its deletion. You want to achieve this goal by using the minimum amount of administrative effort.

 

What should you do first?

 

A.

Perform an authoritative restore of Group1.

B.

Mount the most recent Active Directory backup.

C.

Use the Recycle Bin to restore Group1.

D.

Reactivate the tombstone of Group1.

 

Correct Answer: A

Explanation:

The Active Directory Recycle Bin does not have the ability to track simple changes to objects. If the object itself is not deleted, no element is moved to the Recycle Bin for possible recovery in the future. In other words, there is no rollback capacity for changes to object properties, or, in other words, to the values of these properties. There is another approach you should be aware of. Tombstone reanimation (which has nothing to do with zombies) provides the only way to recover deleted objects without taking a DC offline, and it’s the only way to recover a deleted object’s identity information, such as its objectGUID and objectSid attributes. It neatly solves the problem of recreating a deleted user or group and having to fix up all the old access control list (ACL) references, which contain the objectSid of the deleted object.

Restores domain controllers to a specific point in time, and marks objects in Active Directory as being authoritative with respect to their replication partners.

 

 

 

 

 

 

 

 

 

 

QUESTION 287

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All servers runs Windows Server 2012 R2.The domain contains two domain controllers named DC1 and DC2. Both domain controllers are virtual machines on a Hyper-V host.

 

You plan to create a cloned domain controller named DC3 from an image of DC1.

 

You need to ensure that you can clone DC1.

 

Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

 

A.

Add the computer account of DC1 to the Cloneable Domain Controllers group.

B.

Create a DCCIoneConfig.xml file on DC1.

C.

Add the computer account of DC3 to the Cloneable Domain Controllers group.

D.

Run the Enable-AdOptionalFeaturecmdlet.

E.

Modify the contents of the DefaultDCCIoneAllowList.xml file on DC1.

 

Correct Answer: AB

Explanation:

* Cloneable Domain Controllers Group (located in the Users container).

Membership in this group dictates whether a DC can or cannot be cloned. This group has some permissions set on the domain head that should not be removed. Removing these permissions will cause cloning to fail. Also, as a best practice, DCs shouldn’t be added to the group until you plan to clone and DCs should be removed from the group once cloning is complete. Cloned DCs will also end up in the Cloneable Domain Controllers group.

* DCCloneConfig.xml is an XML configuration file that contains all of the settings the cloned DC will take when it boots. This includes network settings, DNS, WINS, AD site name, new DC name and more.

 

 

QUESTION 288

HOTSPOT

You have a server that runs Windows Server 2012 R2 and has the iSCSI Target Server role service installed.

 

You run the New-IscsiVirtualDisk cmdlet as shown in the New-IscsiVirtualDisk exhibit. (Click the Exhibit button.)

 

clip_image008

 

To answer, complete each statement according to the information presented in the exhibits. Each correct selection is worth one point.

 

clip_image010

 

Correct Answer:

clip_image012

 

 

QUESTION 289

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access server role installed.

 

You log on to Server1 by using a user account named User2.

 

From the Remote Access Management Console, you run the Getting Started Wizard and you receive a warning message as shown in the exhibit. (Click the Exhibit button.)

 

clip_image014

 

You need to ensure that you can configure DirectAccess successfully. The solution must minimize the number of permissions assigned to User2.

 

To which group should you add User2?

 

A.

Account Operators

B.

Enterprise Admins

C.

Domain Admins

D.

Server Operators

 

Correct Answer: C

Explanation:

http://technet.microsoft.com/en-us/library/hh918408.aspx#feedback

QUESTION 290

HOTSPOT

You have a server named Server1 that has the Network Policy and Access Services server role installed.

 

You plan to configure Network Policy Server (NPS) on Server1 to use certificate-based authentication for VPN connections.

 

You obtain a certificate for NPS.

 

You need to ensure that NPS can perform certificate-based authentication.

 

To which store should you import the certificate?

 

To answer, select the appropriate store in the answer area.

 

clip_image016

 

Correct Answer:

clip_image018

 

Free VCE & PDF File for Microsoft 70-417 Actual Tests

Instant Access to Free VCE Files: MCSE|MCSA|MCITP…
Instant Access to Free PDF Files: MCSE|MCSA|MCITP…