[Free] Download New Latest (November) Microsoft 70-417 Actual Tests 341-350

Ensurepass

QUESTION 341

HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Active Directory Certificate Services server role installed and configured.

 

For all users, you are deploying smart cards for logon. You are using an enrollment agent to enroll the smart card certificates for the users.

 

You need to configure the Contoso Smartcard Logon certificate template to support the use of the enrollment agent.

 

Which setting should you modify?

 

To answer, select the appropriate setting in the answer area.

 

clip_image002

Correct Answer:

clip_image004

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

QUESTION 342

Your network contains an Active Directory domain named contoso.com. The domain contains a file server named Server1. The File Server Resource Manager role service is installed on Server1. All servers run Windows Server 2012 R2.

 

A Group Policy object (GPO) named GPO1 is linked to the organizational unit (OU) that contains Server1. The following graphic shows the configured settings in GPO1.

 

clip_image006

 

Server1 contains a folder named Folder1. Folder1 is shared as Share1.

 

You attempt to configure access-denied assistance on Server1, but the Enable access- denied assistance option cannot be selected from File Server Resource Manager.

 

You need to ensure that you can configure access-denied assistance on Server1 manually by using File Server Resource Manager.

 

What should you do?

 

A.

Set the Customize message for Access Denied errors policy setting to Enabled for GPO1.

B.

Set the Enable access-denied assistance on client for all file types policy setting to Disabled for GPO1.

C.

Set the Enable access-denied assistance on client for all file types policy setting to Enabled for GPO1.

D.

Set the Customize message for Access Denied errors policy setting to Not Configured for GPO1.

 

Correct Answer: D

Explanation:

Ensure that you can configure access-denied assistance

http://technet.microsoft.com/en-us/library/hh831402.aspx#BKMK_1

 

 

 

 

 

 

 

 

 

 

 

QUESTION 343

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012 R2. DC1 has the DNS Server server role installed.

 

The network contains client computers that run either Linux, Windows 7, or Windows 8.

 

You have a zone named adatum.com as shown in the exhibit. (Click the Exhibit button.)

 

clip_image008

 

You plan to configure Name Protection on all of the DHCP servers.

 

You need to configure the adatum.com zone to support Name Protection.

 

What should you do?

 

A.

Change the zone type.

B.

Sign the zone.

C.

Add a DNSKEY record.

D.

Configure Dynamic updates.

 

Correct Answer: D

 

QUESTION 344

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2.

 

You enable and configure Routing and Remote Access (RRAS) on Server1.

 

You create a user account named User1.

 

You need to ensure that User1 can establish VPN connections to Server1.

 

What should you do?

 

A.

Modify the members of the Remote Management Users group

B.

Add a RADIUS client

C.

Modify the Dial-in setting of User1

D.

Create a connection request policy

 

Correct Answer: C

 

 

QUESTION 345

HOTSPOT

Your network contains two Hyper-V hosts that are configured as shown in the following table.

 

clip_image010

 

You create a virtual machine on Server1 named VM1.

 

You plan to export VM1 from Server1 and import VM1 to Server2.

 

You need to ensure that you can start the imported copy of VM1 from snapshots.

 

What should you configure on VM1?

 

To answer, select the appropriate node in the answer area.

 

clip_image012

 

Correct Answer:

clip_image014

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

QUESTION 346

DRAG DROP

Your network contains an Active Directory domain named contoso.com. All file servers in the domain run Windows Server 2012 R2.

 

The computer accounts of the file servers are in an organizational unit (OU) named OU1. A Group Policy object (GPO) named GPO1 is linked to OU1.

 

You plan to modify the NTFS permissions for many folders on the file servers by using central access policies.

 

You need to identify any users who will be denied access to resources that they can currently access once the new permissions are implemented.

 

In which order should you perform the five actions?

 

To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.

 

clip_image016

 

Correct Answer:

clip_image018

 

 

 

 

 

QUESTION 347

You have a VHD that contains an image of Windows Server 2012 R2. You plan to Apply updates to the image.

 

You need to ensure that only updates that can install without requiring a restart are installed.

 

Which DISM option should you use?

 

A.

/Apply-Unattend

B.

/Add-ProvisionedAppxPackage

C.

/PreventPending

D.

/Cleanup-Image

 

Correct Answer: C

Explanation:

http://technet.microsoft.com/en-us/library/hh825265.aspx

 

 

QUESTION 348

Your network contains three servers named Server1, Server2, and Server3. All servers run Windows Server 2012 R2. You need to ensure that Server1 can provide iSCSI storage for Server2 and Server3. What should you do on Server1?

 

A.

Install the iSCSI Target Server role service and configure iSCSI targets

B.

Start the Microsoft iSCSI Initiator Service and configure the iSCSI Initiator Properties

C.

Install the iSNS Server service feature and create a Discovery Domain

D.

Install the Multipath I/O (MPIO) feature and configure the MPIO Properties

 

Correct Answer: A

 

 

QUESTION 349

Your network contains three Active Directory forests. Each forest contains an Active Directory Rights Management Services (AD RMS) root cluster.

 

All of the users in all of the forests must be able to access protected content from any of the forests.

 

You need to identify the minimum number of AD RMS trusts required.

 

How many trusts should you identify?

 

A.

2

B.

3

C.

4

D.

6

 

Correct Answer: D

Explanation:

http://technet.microsoft.com/en-us/library/dd772648%28v=ws.10%29.aspx

 

AD RMS Multi-forest Considerations

clip_image020

 

 

QUESTION 350

You have a server named LON-DC1 that runs Windows Server 2012 R2. An iSCSI virtual disk named VirtualiSCSI1.vhd exists on LON-DC1 as shown in the exhibit. (Click the Exhibit button.)

 

clip_image022

 

You create a new iSCSI virtual disk named VirtualiSCSI2.vhd by using the existing itgt iSCSI target.

 

VirtualiSCSIl.vhd is removed from LON-DC1.

 

You need to assign VirtualiSCSI2.vhd a logical unit value of 0.

 

What should you do?

 

A.

Modify the properties of the itgt ISCSI target.

B.

Modify the properties of the VirtualiSCSI2.vhd iSCSI virtual disk

C.

Run the Set-VirtualDisk cmdlet and specify the -Uniqueld parameter

D.

Run the iscsicli command and specify the reportluns parameter

 

Correct Answer: B

 

Free VCE & PDF File for Microsoft 70-417 Actual Tests

Instant Access to Free VCE Files: MCSE|MCSA|MCITP…
Instant Access to Free PDF Files: MCSE|MCSA|MCITP…