PrepAway - Latest Free Exam Questions & Answers

You need to configure updates and compliance reporting for new devices

You administer a group of servers that run Windows Server 2012 R2.
You must install all updates. You must report on compliance with the update policy on a monthly
basis.
You need to configure updates and compliance reporting for new devices.
What should you do?

PrepAway - Latest Free Exam Questions & Answers

A.
Deploy the Microsoft Baseline Security Analyzer. Scan the servers and specify the /apply switch.

B.
In Configuration Manager, deploy a new Desired Configuration Management baseline that
includes all required updates.

C.
Configure a new group policy to install updates monthly. Deploy the group policy to all servers.

D.
In Operations Manager, create an override that enables the software updates management pack.
Apply the new override to the servers.

13 Comments on “You need to configure updates and compliance reporting for new devices

  1. exam123 says:

    Instead of C and D options below are new options. please confirm the answer for the below 2 options.

    Configure windows server update service(WSUS) to automatically approve all updates. Configure the servers to use the WSUS server for updates

    In the service manager console, add all updates and servers to a new change request. Approve the Change request




    0



    0
  2. OSA says:

    My issue with the given answer is that it mentions nothing about wsus configuration/approval. This configuration is implied in (B) when it mentions “includes all required updates”

    DCR in sccm (with update point role installed) can report on and remediate noncompliant devices. New devices can also be identified in SCCM.

    I would go for B as the answer.




    0



    0
      1. puck says:

        C looks like the usual Microsoft Red Herring though, because they ask us to report on compliance with the update policy on a monthly basis. They don’t tell use we need to install updates monthly.




        0



        0
  3. BluAlien says:

    C can’t be, with group policy you cant choose to install update monthly you can choose only week day and timo to perform notification, download, updates ecc.

    The same is for WSUS, automatic update using WSUS are implemented via group policy, and also there is no mention that WSUS is installed on some server, “Configure Windows Update Service WSUS to automatically ….” means that it’s already installed on at least one server. No mention about this.

    Finally Configuration Manager is the only one that can check the compliance on a wider scheduler for example each 30 day, and generate compliance report.

    The correct answer is B.




    0



    0

Leave a Reply