New Updated Microsoft MCSA 70-410 Real Exam Questions and Answers Download 281-290

Ensurepass

QUESTION 281

Your network contains an Active Directory domain named contoso.com. Your company hires 500 temporary employees for the summer. The human resources department gives you a Microsoft Excel document that contains a list of the temporary employees. You need to automate the creation of user accounts for the 500 temporary employees. Which tool or tools should you use?

 

A.

The Set-ADUsercmdlet and the Add-Member cmdlet

B.

The Import-CSV cmdlet and the New-ADUsercmdlet

C.

ADSI Edit

D.

Active Directory Users and Computers

 

Correct Answer: B

Explanation:

http://technet.microsoft.com/en-us/library/ee176874.aspx

The CSVDE is a command-line utility that can create new AD DS objects by importing information from a comma-separated value (.csv) file. This would be the least amount of administrative effort in this case especially considering that these would be temporary employees.

 

 

QUESTION 282

Hotspot Question

You deploy a Server with a GUI installation of Windows Server 2012 R2 Datacenter. From Windows PowerShell, you run the following command: Remove-WindowsFeature ServerGui-Shell. In the table below, identify which tools are available on Server1 and which tools are unavailable on Server1. Make only one selection in each row. Each correct selection is worth one point.

 

70-410-demo-307

Correct Answer:

 

 

70-410-demo-308

 

 

QUESTION 283

Drag and Drop Question

Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2. Server1 and Server2 run a Server with a GUI installation of Windows Server 2012 R2. You remove the Graphical Management Tools and Infrastructure feature on Server2. You need to restart Server2. What should you do? (To answer, drag the appropriate tools to the correct statements. Each tool may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.)

 

70-410-demo-309

 

Correct Answer:

 

70-410-demo-310

 

 

QUESTION 284

Drag and Drop Question

You have a server that runs Windows Server 2012 R2. You need to create a volume that will remain online if two disks in the volume fail. The solution must minimize the number of disks used to create the volume.

Which three actions should you perform in sequence? (To answer, move the appropriate three actions from the list of actions to the answer area and arrange them in the correct order.)

 

70-410-demo-311

 

Correct Answer:

 

70-410-demo-312

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

QUESTION 285

Hotspot Question

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server that runs Windows Server 2012 R2. You perform a Server Core Installation of Windows Server 2012 R2 on a new server. You need to ensure that you can add the new server to Server Manager on Server1. What should you configure on the new server?

To answer, select the appropriate setting in the answer area.

 

70-410-demo-313

 

Correct Answer:

 

 

70-410-demo-314

 

 

QUESTION 286

You work as an administrator at ENSUREPASS.com. The ENSUREPASS.com network consists of a single domain named ENSUREPASS.com. All servers in the ENSUREPASS.com domain, including domain controllers, have Windows Server 2012 installed.

You have been instructed to modify the name of the local Administrator account on all ENSUREPASS.com workstations. You want to achieve this using as little administrative effort as possible.

Which of the following actions should you take?

You should consider configuring the Security Options settings via the Group Policy

 

A.

You should consider configuring the Security Options settings via the Group Policy Management

Console (GPMC).

B.

You should consider navigating to Local Users and Groups via Computer

C.

You should consider configuring the replication settings.

D.

You should consider navigating to Local Users and Groups via Computer Management on each workstation.

 

Correct Answer: A

Explanation:

Rename administrator account policy setting determines whether a different account name is associated with the security identifier (SID) for the Administrator account.

Because the Administrator account exists on all Windows server versions, renaming the account makes it slightly more difficult for attackers to guess this user name and password combination. By default, the built-in Administrator account cannot be locked out no matter how many times a malicious user might use a bad password. This makes the Administrator account a popular target for brute-force password-guessing attacks. The value of this countermeasure is lessened because this account has a well-known SID and there are non-Microsoft tools that allow you to initiate a brute-force attack over the network by specifying the SID rather than the account name. This means that even if you have renamed the Administrator account, a malicious user could start a brute-force attack by using the SID.

Rename the Administrator account by specifying a value for the Accounts: Rename administrator account policy setting.

Location: GPO_nameComputer ConfigurationWindows SettingsSecurity SettingsLocal

PoliciesSecurity Options

http://technet.microsoft.com/en-us/library/jj852273%28v=ws.10%29.aspx http://windowsitpro.com/group-policy/securing-administrator-account

 

 

QUESTION 287

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1. Server1 runs Windows Server 2012 R2. An administrator creates a security template named Template1. You need to App1y Template1 to Server1. Which snap-in should you use?

A.

Security Templates

B.

Authorization Manager

C.

Security Configuration and Analysis

D.

Resultant Set of Policy

 

Correct Answer: C

 

 

QUESTION 288

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The domain contains two domain controllers named DC1 and DC2 that run Windows Server 2012 R2. The domain contains a user named User1 and three global security groups named Group1, Group2 and, Group3. You need to add User1 to Group1, Group2, and Group3. Which cmdlet should you run?

 

A.

Add-AdPrincipalGroupMembership

B.

Install- AddsDomainController

C.

Install- WindowsFeature

D.

Install-AddsDomain

E.

Rename-AdObject

F.

Set-AdAccountControl

G.

Set-AdGroup

H.

Set-User

 

Correct Answer: A

Explanation:

http://technet.microsoft.com/en-us/library/ee617203.aspx

The Add-ADPrincipalGroupMembership cmdlet adds a user, group, service account, or computer as a new member to one or more Active Directory groups.

 

 

 

QUESTION 289

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The domain contains two domain controllers named DC1 and DC2 that run Windows Server 2012 R2. The domain contains a user named User1 and a global security group named Group1. You need to ensure that User1 can manage the group membership of Group1. The solution must minimize the number of permissions assigned to User1. Which cmdlet should you run?

 

A.

Add-AdPrincipalGroupMembership

B.

Install- AddsDomainController

C.

Install- WindowsFeature

D.

Install-AddsDomain

E.

Rename-AdObject

F.

Set-AdAccountControl

G.

Set-AdGroup

H.

Set-User

 

Correct Answer: G

Explanation:

http://technet.microsoft.com/en-us/library/ee617199.aspx

The Set-ADGroup cmdlet modifies the properties of an Active Directory group. You can modify commonly used property values by using the cmdlet parameters.

 

 

QUESTION 290

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The domain contains two domain controllers named DC1 and DC2 that run Windows Server 2012 R2. The domain contains a user named User1 and a global security group named Group1. You need to prevent User1 from changing his password. The solution must minimize administrative effort. Which cmdlet should you run?

 

A.

Add-AdPrincipalGroupMembership

B.

Install- AddsDomainController

C.

Install- WindowsFeature

D.

Install-AddsDomain

E.

Rename-AdObject

F.

Set-AdAccountControl

G.

Set-AdGroup

H.

Set-User

 

Correct Answer: F

Explanation:

http://technet.microsoft.com/en-us/library/ee617249.aspx

Set-ADAccountControl

The Set-ADAccountControl cmdlet modifies the user account control (UAC) values for an Active Directory user or computer account. UAC values are represented by cmdlet parameters.

CannotChangePassword

Modifies the ability of an account to change its password. To disallow password change by the account set this to $true.. This parameter changes the Boolean value of the CannotChangePassword property of an account.

The following example shows how to specify the PasswordCannotChange parameter.

-CannotChangePassword $false

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-410 Real Exam

Try Microsoft MCSA 70-410 Free Demo