You need to configure updates and compliance reporting for new devices
You administer a group of servers that run Windows Server 2012 R2.
You must install all updates. You must report on compliance with the update policy on a monthly
basis.
You need to configure updates and compliance reporting for new devices.
What should you do?
Contoso employees authenticate to the VPN by using a user certificate issued by the C
You are an Active Directory administrator for Contoso, Ltd. You have a properly configured
certification authority (CA) in the contoso.com Active Directory Domain Services (AD DS) domain.
Contoso employees authenticate to the VPN by using a user certificate issued by the CA.
Contoso acquires a company named Litware, Inc., and establishes a forest trust between
contoso.com and litwareinc.com. No CA currently exists in the litwareinc.com AD DS domain. Litware
employees do not have user accounts in contoso.com and will continue to use their litwareinc.com
user accounts.
Litware employees must be able to access Contoso’s VPN and must authenticate by using a user
certificate that is issued by Contoso’s CA.
You need to configure cross-forest certificate enrollment for Litware users.
Which two actions should you perform? Each correct answer presents part of the solution.
You need to configure the environment
A company has data centers in Seattle and New York. A high-speed link connects the data centers.
Each data center runs a virtualization infrastructure that uses Hyper-V Server 2012 and Hyper-V
Server 2012 R2. Administrative users from the Seattle and New York offices are members of Active
Directory Domain Services groups named SeattleAdmins and NewYorkAdmins, respectively.
You deploy one System Center Virtual Machine Manager (SCVMM) in the Seattle data center. You
create two private clouds named SeattleCloud and NewYorkCloud in the Seattle and New York data
centers, respectively.
You have the following requirements:
Administrators from each data center must be able to manage the virtual machines and services
from their location by using a web portal.
Administrators must not apply new resource quotas or change resource quotas.
You must manage public clouds by using the existing SCVMM server.
You must use the minimum permissions required to perform the administrative tasks.
You need to configure the environment.
What should you do?
Which two actions should you perform?
You administer an Active Directory Domain Services forest that includes an Active Directory
Federation Services (AD FS) server and Azure Active Directory. The fully qualified domain name of
the AD FS server is adfs.contoso.com.
Your must implement single sign-on (SSO) for a cloud application that is hosted in Azure. All domain
users must be able to use SSO to access the application.
You need to configure SSO for the application.
Which two actions should you perform? Each correct answer presents part of the solution.
Solution: You set the memory-weight threshold value to High for each business-critical VM, Does this meet the
You manage a Hyper-V 2012 cluster by using System Center Virtual Machine Manager 2012 SP1. You
need to ensure high availability for business-critical virtual machines (VMs) that host business-critical
SQL Server databases.
Solution: You set the memory-weight threshold value to High for each business-critical VM, Does this
meet the goal?
Does this meet the goal?
NOTE: Once you answer this question, you will NOT be able to return to it. You manage a Hyper-V
2012 cluster by using System Center Virtual Machine Manager 2012 SP1. You need to ensure high
availability for business-critical virtual machines (VMs) that host business-critical SQL Server
databases.
Solution: You configure preferred and possible owners for each business-critical VM.
Does this meet the goal?
Does this meet the goal?
You plan to allow users to run internal applications from outside the company’s network. You have a
Windows Server 2012 R2 that has the Active Directory Federation Services (AD FS) role installed. You
must secure on-premises resources by using multi-factor authentication (MFA). You need to design a
solution to enforce different access levels for users with personal Windows 8.1 or iOS 8 devices.
Solution: You migrate the AD FS server to Microsoft Azure and connect it to the internal Active
Directory instance on the network. Then, you use the Workplace Join process to configure access for
personal devices to the on-premises resources.
Does this meet the goal?
Does this meet the goal?
You plan to allow users to run internal applications from outside the company s network. You have a
Windows Server 2012 R2 that has the Active Directory Federation Services (AD FS) role installed. You
must secure on-premises resources by using multi-factor authentication (MFA). You need to design a
solution to enforce different access levels for users with personal Windows 8.1 or iOS 8 devices.
Solution: You install a local instance of the MFA Server. You connect the instance to the Microsoft
Azure MFA provider and then you use Microsoft Intune to manage personal devices.
Does this meet the goal?
Does this meet the goal?
Your network contains an Active Directory domain named contoso.com. The domain contains a
Microsoft System Center 2012 infrastructure.
You deploy a service named Service1 by using a service template. Service1 contains two virtual
machines. The virtual machines are configured as shown in the following table.
You need to recommend a monitoring solution to ensure that an administrator can review the
availability information of Service1.
Solution: From Configuration Manager, you create a Collection and a Desired Configuration
Management baseline.
Does this meet the goal?
Does this meet the goal?
Your network contains an Active Directory domain named contoso.com. The domain contains a
Microsoft System Center 2012 infrastructure.
You deploy a service named Service1 by using a service template. Service1 contains two virtual
machines. The virtual machines are configured as shown in the following table.
You need to recommend a monitoring solution to ensure that an administrator can review the
availability information of Service1.
Solution: From Operations Manager, you create a Distributed Application and a Monitor Override.
Does this meet the goal?