PrepAway - Latest Free Exam Questions & Answers

Category: 70-411 (v.9)

Exam 70-411: Administering Windows Server 2012 (update June 27th, 2017)

Which domain controller should you identify?

Your network contains an Active Directory forest named contoso.com. The forest contains two domains named contoso.com and childl.contoso.com. All domain
controllers run Windows Server 2012. The domain contains four domain controllers. The domain controllers are configured as shown in the following table.

You open Active Directory Users and Computers on a client computer and connect to DC1. You display the members of a group named Group1 as shown in the
Group1 Members exhibit.

When you view the properties of a user named User102, you receive the error message shown in the Error exhibit.

The error message does not display for any other members of Group1. You need to identify which domain controller causes the issue shown in the error message.
Which domain controller should you identify?

You need to restore the membership of Group1

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All domain controllers run Windows Server 2012. The
domain contains two domain controllers. The domain controllers are configured as shown in the following table.

You discover that a support technician accidentally removed 100 users from an Active Directory group named Group1 an hour ago. You need to restore the
membership of Group1. What should you do?

Which Cryptography setting of the certificate template …

Your network contains an Active Directory domain named contoso.com. You need to create a

certificate template for the BitLocker Drive Encryption (BitLocker) Network Unlock feature. Which Cryptography setting of the certificate template should you
modify? To answer, select the appropriate setting in the answer area.
Solution:
Cryptographic provider that supports RSA (Microsoft Software Key Storage Provider)

Which Group Policy option should you configure?

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Print1. Your company implements DirectAccess. A
user named User1 frequently works at a customer’s office. The customer’s office contains a print server named Print1. While working at the customer’s office,
User1 attempts to connect to Print1. User1 connects to the Print1 server in contoso.com instead of the Print1 server at the customer’s office. You need to provide
User1 with the ability to connect to the Print1 server in the customer’s office. Which Group Policy option should you configure?
To answer, select the appropriate option in the answer area.
Hot Area:

Which criteria should you specify when you create the D…

You are a network administrator of an Active Directory domain named contoso.com. You have a server named Server1 that runs Windows Server 2012. Server1
has the DHCP Server server role and the Network Policy Server role service installed. You enable Network Access Protection (NAP) on all of the DHCP scopes on

Server1. You need to create a DHCP policy that will apply to all of the NAP non-compliant DHCP clients. Which criteria should you specify when you create the
DHCP policy?

Which two actions should you perform on Server1?

Your network contains two Active Directory domains named contoso.com and adatum.com. The contoso.com domain contains a server named
Server1.contoso.com. The adatum.com domain contains a server named server2.adatum.com. Server1 and Server2 run Windows Server 2012 and have the
DirectAccess and VPN (RRAS) role service installed. Server1 has the default network policies and the default connection request policies. You need to configure
Server1 to perform authentication and authorization of VPN connection requests to Server2. Only users who are members of Adatum\\Group1 must be allowed to
connect. Which two actions should you perform on Server1? (Each correct answer presents part of the solution. Choose two.)

Which two actions should you perform on Server1?

Your network contains two Active Directory domains named contoso.com and adatum.com. The contoso.com domain contains a server named
Server1.contoso.com. The adatum.com domain contains a server named server2.adatum.com. Server1 and Server2 run Windows Server 2012 and have the
DirectAccess and VPN (RRAS) role service installed. Server1 has the default network policies and the default connection request policies. You need to configure
Server1 to perform authentication and authorization of VPN connection requests to Server2. Only users who are members of Adatum\\Group1 must be allowed to
connect. Which two actions should you perform on Server1? (Each correct answer presents part of the solution. Choose two.)

Which two actions should you perform on Server1?

Your network contains two Active Directory domains named contoso.com and adatum.com. The contoso.com domain contains a server named
Server1.contoso.com. The adatum.com domain contains a server named server2.adatum.com. Server1 and Server2 run Windows Server 2012 and have the
DirectAccess and VPN (RRAS) role service installed. Server1 has the default network policies and the default connection request policies. You need to configure
Server1 to perform authentication and authorization of VPN connection requests to Server2. Only users who are members of Adatum\\Group1 must be allowed to
connect. Which two actions should you perform on Server1? (Each correct answer presents part of the solution. Choose two.)

You need to ensure that Server1 can host a secondary co…

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. One of the domain controllers is named
DC1. The DNS zone for the contoso.com zone is Active Directory-integrated and has the default settings. A server named Server1 is a DNS server that runs a
UNIX-based operating system. You plan to use Server1 as a secondary DNS server for the contoso.com zone. You need to ensure that Server1 can host a
secondary copy of the contoso.com zone. What should you do?

What should you modify?

Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Admin1 and Server2. Both servers run Windows
Server 2012. Both servers have the File and Storage Services server role, the DFS Namespaces role service, and the DFS Replication role service installed.
Admin1 and Server2 are part of a Distributed File System (DFS) Replication group named Group1. Admin1 and Server2 are separated by a low-speed WAN
connection. You need to limit the amount of bandwidth that DFS can use to replicate between Admin1 and Server2. What should you modify?


Page 3 of 2412345...1020...Last »