PrepAway - Latest Free Exam Questions & Answers

What should you create on each NPS server?

DRAG DROP
Your network contains an Active Directory forest named contoso.com. The forest contains a Network Policy
Server (NPS) server named NPS1 and a VPN server named VPN1. VPN1 forwards all authentication requests to NPS1.
A partner company has an Active Directory forest named adatum.com. The adatum.com forest contains an
NPS server named NPS2.
You plan to grant users from adatum.com VPN access to your network.
You need to authenticate the users from adatum.com on VPN1.
What should you create on each NPS server?
To answer, drag the appropriate objects to the correct NPS servers. Each object may be used once, more than
once, or not at all. You may need to drag the split bar between panes or scroll to view content.

PrepAway - Latest Free Exam Questions & Answers

Answer:

17 Comments on “What should you create on each NPS server?

  1. NervousTestTaker says:

    Hi everyone. Do you all agree with the supplied answer? I am actually in tow minds thinking NPS1 has connection policy and RADIUS server group as mentioned but NPS2 a Network Policy. Thanks




    0



    0
  2. den says:

    dudes, try to think or even try for yourself in a test environment before stating stuff as stupid…
    @NervousTestTaker: how should this work using a network policy on NPS2?? makes no sense as NPS1 gets the requests from VPN1 and has to forward to NPS2.
    @Marcin: NPS1 already has a a network policy that will work for all users, and your forwarding strategy is vice-versa and just makes no sense

    check this:
    I think provided answer is correct:
    – adatum.com clients pass by using VPN1
    – VPN1 forwards to NPS1
    – to get adatum.com users authenticated you have to forward their requests (using an appropriate filter) from NPS1 to NPS2 by setting up a Connection Request Policy on NPS1 (right answer point 1)
    – to configure a Connection Request Policy to forward requests you HAVE to choose a remote RADIUS server group, even if it’s a single server, then this group has only one member. therefore create this group on NPS1 that has NPS2 as member (right answer point 2)
    – because NPS1 is forwarding requests to NPS2 it is mandatory to have NPS1 configured as a RADIUS client in NPS2 (right answer point 3)

    and why not using network policy? because nps1 already has a network policy (for contoso.com users) that will be processed also for the adatum.com users right after the forwarded authentication requests are succsessfully handeled…and network policy will be handeled by NPS1, not by NPS2! NPS2 only does processing the authentication request, as soon as this is done NPS1 will continue processing network policy…




    0



    0
    1. Siyamand says:

      I think you mixed between NPS1 and NPS2
      forward their requests (using an appropriate filter) from NPS1 to NPS2 by setting up a Connection Request Policy on NPS1 (right answer point 1)

      you should say forward their requests (using an appropriate filter) from NPS2 to NPS1 by setting up a Connection Request Policy on NPS1 (right answer point 1)




      0



      0

Leave a Reply