PrepAway - Latest Free Exam Questions & Answers

Category: 70-411 (v.1)

Exam 70-411: Administering Windows Server 2012 (update March 20th, 2014)

You need to prevent all of the GPOs at the site level and at the domain level from being applied to users and

Your network contains an Active Directory domain named contoso.com. The domain contains more than 100
Group Policy objects (GPOs). Currently, there are no enforced GPOs. You need to prevent all of the GPOs at
the site level and at the domain level from being applied to users and computers in an organizational unit (OU)
named OU1. You want to achieve this goal by using the minimum amount of Administrative effort. What should
you use?

You need to provide an Administrator named Admin1 with the ability to create GPOs in thedomain

Your network contains an Active Directory domain named contoso.com. The domain contains more than 100
Group Policy objects (GPOs). Currently, there are no enforced GPOs. You need to provide an Administrator
named Admin1 with the ability to create GPOs in thedomain. The solution must not provide Admin1 with the
ability to link GPOs. What should you use?

Which three actions should you perform?

Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012.
The domain contains two servers. The servers are configured as shown in the following table.

All client computers run Windows 8 Enterprise. You plan to deploy Network Access Protection (NAP) by using
IPSec enforcement. A Group Policy object (GPO) named GPO1 is configured to deploy a trusted server group
to all of the client computers. You need to ensure that the client computers can discover HRA servers
automatically. Which three actions should you perform? (Each correct answer presents part of the solution.
Choose three.)

What should you install on Server1 before you run the Configure NAP wizard?

Your network contains an Active Directory domain named contoso.com. The domain contains a server named
Server1 that runs Windows Server 2012. Server1 has the Network Policy Server role service installed. You
plan to configure Server1 as a Network Access Protection (NAP) health policy server for VPN enforcement by
using the Configure NAP wizard. You need to ensure that you can configure the VPN enforcement method on
Server1 successfully. What should you install on Server1 before you run the Configure NAP wizard?

Which settings should you manually configure on Server2?

You deploy two servers named Server1 and Server2. You install Network Policy Server (NPS) on both servers.
On Server1, you configure the following NPS settings:
RADIUS Clients
Network Policies
Connection Request Policies
SQL Server Logging Properties
You export the NPS configurations to a file and import the file to Server2. You need to ensure that the NPS
configurations on Server2 are the same as the NPS configurations on Server1. Which settings should you
manually configure on Server2?

You need to recreate the Default Domain Policy GPO

Your network contains an Active Directory domain named contoso.com. The domain contains more than 100
Group Policy objects (GPOs). Currently, there are no enforced GPOs. A network Administrator accidentally
deletes the Default Domain Policy GPO. You do not have a backup of any of the GPOs. You need to recreate
the Default Domain Policy GPO. What should you use?

You need to ensure that the existing GPOs are applied to users and computers

Your network contains an Active Directory domain named contoso.com. The domain contains more than 100
Group Policy objects (GPOs). Currently, there are no enforced GPOs. The domain is renamed to adatum.com.
Group Policies no longer function correctly. You need to ensure that the existing GPOs are applied to users
and computers. You want to achieve this goal by using the minimum amount of Administrative effort. What
should you use?

You need to configure GPO1 to apply settings to Group1 only

Your network contains an Active Directory domain named contoso.com. The domain contains more than 100
Group Policy objects (GPOs). Currently, there are no enforced GPOs. The domain contains a top-level
organizational unit (OU) for each department. A group named Group1 contains members from each
department. You have a GPO named GPO1 that is linked to the domain. You need to configure GPO1 to apply
settings to Group1 only. What should you use?

Which two actions should you perform?

Your network contains an Active Directory domain named contoso.com. The domain does not contain a
certification authority (CA). All servers run Windows Server 2012. All client computers run Windows 8.You
need to add a data recovery agent for the Encrypting File System (EFS) to the domain. Which two actions
should you perform? (Each correct answer presents part of the solution. Choose two.)


Page 5 of 8« First...34567...Last »