PrepAway - Latest Free Exam Questions & Answers

Which of the following options would you choose to deploy a patch management strategy that deploys updates on

You are an Enterprise administrator for contoso.com. The corporate network of the company consists of a single Active Directory domain. All the servers in the domain run Windows Server 2008 and all client computers run Windows Vista.

Several servers on the corporate network of the company run Windows Server Update Services (WSUS) and distribute updates to all computers on the internal network.

The company has many remote users that connect the internal network from their personal computers using a split-tunnel VPN connection.

Which of the following options would you choose to deploy a patch management strategy that deploys updates on the remote user’s computers? While deploying the solution, you need to ensure that the bandwidth use over the VPN connections is minimized and the required updates are approved on the WSUS servers before they are installed on the client computers?

PrepAway - Latest Free Exam Questions & Answers

A.
Perform client-side targeting using a GPO.

B.
Create and configure a computer group for the remote users computers to allow them to use the internal WSUS server.

C.
Deploy an additional WSUS server for the remote users computers. Configure the additional WSUS server to leave the updates on the Microsoft Update Web site.

D.
Use Connection Manager Administration Kit (CMAK) to create a custom connection and then deploy the custom connection to all of the remote users computers.

E.
None of the above

Explanation:

To deploy a patch management strategy that deploys updates on the remote user’s computers, you need to deploy an additional WSUS server. Configure the remote users computers to use the additional WSUS server. Configure the additional WSUS server to leave the updates on the Microsoft Update Web site.

Microsoft Windows Server Update Services (WSUS) is the Microsoft provided solution for enterprise patch management. Using WSUS, network administrators can manage and deploy software updates for all of the Microsoft products in a network Using autonomous mode, the upstream server transmits update files to the downstream servers, but nothing else. This means that individual computer groups and update approvals must be configured for each particular downstream server. In this deployment type, you get the benefit of optimized bandwidth usage with the flexibility of allowing individual site administrators to manage computer groups and update approvals themselves.
In a typical WAN scenario the bandwidth is a restriction. It is common that remote network locations will have a high speed connection to the internet but a rather low speed link back to the main office, such as through a VPN. In these cases, an upstream server can manage update approvals, but those remote downstream servers can be configured to download the approved updates directly from the Internet as opposed to the upstream server. Therefore you need to cconfigure the additional WSUS server to leave the updates on the Microsoft Update Web site
Reference: Deploying Microsoft Windows Server Update Services

http://www.windowsnetworking.com/articles_tutorials/Deploying-Microsoft-Windows-Server-Update-Services.html


Leave a Reply