[Free] New Updated (October) Microsoft 70-980 Real Exam 51-60

Ensurepass

 

QUESTION 51

Your network contains an Active Directory domain named contoso.com. The domain contains three VLANs. The VLANs are configured as shown in the following table.

 

clip_image002

 

All client computers run either Windows 7 or Windows 8.

 

The corporate security policy states that all of the client computers must have the latest security updates installed.

 

You need to implement a solution to ensure that only the client computers that have all of the required security updates installed can connect to VLAN 1. The solution must ensure that all other client computers connect to VLAN 3.

 

Solution: You implement the IPsec enforcement method.

 

Does this meet the goal?

A.

Yes

B.

No

 

Correct Answer: B

 

 

QUESTION 52

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain and two sites named Montreal and Vancouver.

 

Montreal contains an IP Address Management (IPAM) server named Server1 that is used to manage all of the DHCP servers and the DNS servers in the site.

 

Vancouver contains several DHCP servers and several DNS servers.

 

In Vancouver, you install the IP Address Management (IPAM) Server feature on a server named Server2.

 

You need to recommend which configurations must be performed to ensure that the DHCP servers and the DNS servers in Vancouver are managed by Server2.

 

What should you recommend?

 

A.

Replicate the IPAM database from Server1 to Server2. On Server2, change the manageability status of the DNS servers and the DHCP servers in Vancouver.

B.

Replicate the IPAM database from Server1 to Server2. On Server1, change the manageability status of the DNS servers and the DHCP servers in Vancouver.

C.

From Server2, run the Invoke-IpamGpoProvisioningcmdlet On Server2, change the manageability status of the DNS servers and the DHCP servers in Vancouver.

D.

From Server1, run the Invoke-IpamGpoProvisioningcmdlet. On Server1, change the manageability status of the DNS servers and the DHCP servers in Vancouver.

 

Correct Answer: C

 

 

QUESTION 53

Your company is a hosting provider that provides cloud-based services to multiple customers.

 

Each customer has its own Active Directory forest located in your company’s datacenter.

 

You plan to provide VPN access to each customer. The VPN solution will use RADIUS for authentication services and accounting services.

 

You need to recommend a solution to forward authentication and accounting messages from the perimeter network to the Active Directo

ry forest of each customer.

 

What should you recommend?

 

More than one answer choice may achieve the goal. Select the BEST answer.

 

A.

One RADIUS proxy for each customer and Active Directory Federation Services (AD FS)

B.

A RADIUS server for each customer and one RADIUS proxy

C.

One RADIUS proxy and one Active Directory Lightweight Directory Services (AD LDS) instance for each customer

D.

A RADIUS server for each customer and a RADIUS proxy for each customer

 

Correct Answer: B

 

 

QUESTION 54

Your network contains an Active Directory forest named contoso.com. The forest contains one domain.

 

Your company plans to open a new division named Division1. A group named Division1Admins will administer users and groups for Division1.

 

You identify the following requirements for Division1:

 

clip_image004All Division1 users must have a complex password that is 14 characters.

clip_image004[1]Division1Admins must be able to manage the user accounts for Division1.

clip_image004[2]Division1Admins must be able to create groups, and then delete the groups that they create.

clip_image004[3]Division1Admins must be able to reset user passwords and force a password change at the next logon for all Division1 users.

 

You need to recommend changes to the forest to support the Division1 requirements.

 

What should you recommend?

 

More than one answer choice may achieve the goal. Select the BEST answer.

 

A.

In the forest create a new organizational unit (OU) named Division1 and delegate permissions for the OU to the Division1Admins group. Move all of the Division1 user accounts to the new OU. Create a fine-grained password policy for the Division1 users.

B.

Create a new child domain named divisionl.contoso.com. Move all of the Division1 user accounts to the new domain. Add the Division1Admin members to the Domain Admins group. Configure the password policy in a Group Policy object (GPO).

C.

Create a new forest. Migrate all of the Division1 user objects to the new forest and add the Division1Admins members to the Enterprise Admins group. Configure the password policy in a Group Policy object (GPO).

D.

In the forest create a new organizational unit (OU) named Division1 and add Division1Admins to the Managed By attribute of the new OU. Move the Division1 user objects to the new OU. Create a fine-grained password policy for the Division1 users.

 

Correct Answer: A

 

 

QUESTION 55

Your network contains an Active Directory domain named contoso.com. The domain contains multiple sites.

 

You plan to deploy DirectAccess.

 

The network security policy states that when client computers connect to the corporate network from the Internet, all of the traffic destined for the Internet must be routed through the corporate network.

 

You need to recommend a solution for the planned DirectAccess deployment that meets the security policy requirement.

Solution: You enable split tunneling.

 

Does this meet the goal?

 

A.

Yes

B.

No

 

Correct Answer: B

 

 

QUESTION 56

Your network contains an Active Directory forest named contoso.com. The forest contains five domains. You need to ensure that the CountryCode attribute is replicated to the global catalog. What should you do?

 

A.

Modify the schema partition.

B.

Create and modify an application partition.

C.

Modify the configuration partition.

D.

Modify the domain partitions.

 

Correct Answer: A

 

 

QUESTION 57

Your network contains an Active Directory domain named contoso.com. The domain contains four computers that are configured as shown in the following table.

 

You plan to use domain controller cloning.

 

You need to identify on which computers you can clone domain controllers that run Windows Server 2012.

 

Which computers should you identify? (Each correct answer presents part of the solution. Choose all that apply.)

 

A.

Server1

B.

Server2

C.

Server3

D.

Client1

 

Correct Answer: AD

Explanation:

DC cloning can be done from either Hyper-V on Server 2012 and Hyper-V on Windows 8.

 

 

 

 

 

 

 

 

 

 

 

QUESTION 58

Your network contains an Active Directory domain named contoso.com. All servers run either Windows Server 2008 R2 or Windows Server 2012.

 

Your company uses IP Address Management (IPAM) to manage multiple DHCP servers.

 

A user named User1 is a member of the IPAM Users group and is a member of the local

 

Administrators group on each DHCP server.

 

When User1 edits a DHCP scope by using IPAM, the user receives the error message shown in the exhibit. (Click the Exhibit button.)

 

clip_image006

 

You need to prevent User1 from receiving the error message when editing DHCP scopes by using IPAM.

 

What should you do?

 

A.

Add User1 to the DHCP Administrators group on each DHCP server.

B.

Add User1 to the IPAM Administrators group.

C.

Run the Set-IpamServerConfig cmdlet.

D.

Run the Invoke-IpamGpoProvisioning cmdlet.

 

Correct Answer: B

Explanation:

http://technet.microsoft.com/en-us/library/hh831622.aspx

IPAM Administrators: IPAM Administrators have the privileges to view all IPAM data and perform all IPAM tasks.

 

 

 

QUESTION 59

You have a System Center 2012 R2 Virtual Machine Manager (VMM) infrastructure that manages five Hyper-V hosts. The Hyper-V hosts are not clustered.

 

You have a virtual machine template that deploys a base image of Windows Server 2012 R2. No role services or features are enabled in the base image.

 

You need to deploy a virtual machine named VM1 that is based on the virtual machine template.

 

VM1 will be deployed as part of a service. VM1 must have the Web Server (IIS) server role installed. The solution must not require modifications to the virtual machine template or the base image.

 

What are two possible profile types that achieve the goal? Each correct answer presents a complete solution.

 

A.

Capability

B.

Application

C.

Guest OS

D.

Hardware

E.

Physical Computer

 

Correct Answer: AC

 

 

QUESTION 60

Your network contains an Active Directory domain named contoso.com.

 

You deploy several servers that have the Remote Desktop Session Host role service installed.

 

You have two organizational units (OUs). The OUs are configured as shown in the following table.

 

clip_image008

 

GPO1 contains the Folder Redirection settings for all of the users.

 

You need to recommend a solution to prevent the sales users’ folders from being redirected when the users log on to a Remote Desktop session.

 

What should you include in the recommendation?

 

A.

FromGPO2, set the loopback processing mode.

B.

From GPO1, set the loopback processing mode.

C.

Configure security filtering for GPO1.

D.

Apply a WMI filter to GPO2.

 

Correct Answer: A

Explanation:

http://support.microsoft.com/kb/231287

Free VCE & PDF File for Microsoft 70-980 Real Exam

Instant Access to Free VCE Files: MCSE|MCSA|MCITP…
Instant Access to Free PDF Files: MCSE|MCSA|MCITP…