getcertified4sure.com

Foolproof exam ref 70 411 tips




Master the 70 411 dumps Administering Windows Server 2012 content and be ready for exam day success quickly with this Ucertify 70 411 administering windows server 2012 r2 pdf rapidshare. We guarantee it!We make it a reality and give you real 70 411 exam questions questions in our Microsoft microsoft 70 411 braindumps.Latest 100% VALID Microsoft 70 411 dumps Exam Questions Dumps at below page. You can use our Microsoft mcp 70 411 braindumps and pass your exam.

Q121. You are a network administrator of an Active Directory domain named contoso.com. 

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the DHCP Server server role and the Network Policy Server role service installed. 

You enable Network Access Protection (NAP) on all of the DHCP scopes on Server1. 

You need to create a DHCP policy that will apply to all of the NAP non-compliant DHCP clients. 

Which criteria should you specify when you create the DHCP policy? 

A. The client identifier 

B. The user class 

C. The vendor class 

D. The relay agent information 

Answer:

Explanation: 

To configure a NAP-enabled DHCP server 

On the DHCP server, click Start, click Run, in Open, type dhcpmgmt. smc, and then press ENTER. 

In the DHCP console, open <servername>\IPv4. 

Right-click the name of the DHCP scope that you will use for NAP client computers, and then click Properties. 

On the Network Access Protection tab, under Network Access Protection Settings, choose Enable for this scope, verify that Use default Network Access Protection profile is selected, and then click OK. 

In the DHCP console tree, under the DHCP scope that you have selected, right-click Scope Options, and then click Configure Options. 

On the Advanced tab, verify that Default User Class is selected next to User class. 

Select the 003 Router check box, and in IP Address, under Data entry, type the IP address for the default gateway used by compliant NAP client computers, and then click Add. Select the 006 DNS Servers check box, and in IP Address, under Data entry, type the IP address for each router to be used by compliant NAP client computers, and then click Add. Select the 015 DNS Domain Name check box, and in String value, under Data entry, type your organization's domain name (for example, woodgrovebank. local), and then click Apply. This domain is a full-access network assigned to compliant NAP clients. On the Advanced tab, next to User class, choose Default Network Access Protection Class. Select the 003 Router check box, and in IP Address, under Data entry, type the IP address for the default gateway used by noncompliant NAP client computers, and then click Add. This can be the same default gateway that is used by compliant NAP clients. Select the 006 DNS Servers check box, and in IP Address, under Data entry, type the IP address for each DNS server to be used by noncompliant NAP client computers, and then click Add. These can be the same DNS servers used by compliant NAP clients. Select the 015 DNS Domain Name check box, and in String value, under Data entry, type a name to identify the restricted domain (for example, restricted. Woodgrovebank. local), and then click OK. This domain is a restricted-access network assigned to noncompliant NAP clients. Click OK to close the Scope Options dialog box. Close the DHCP console. 

Reference: http: //technet.microsoft.com/en-us/library/dd296905%28v=ws.10%29.aspx 


Q122. You have a group Managed Service Account named Service01. Three servers named Server01, Server02, and Server03 currently use the Service01 service account. 

You plan to decommission Server01. 

You need to remove the cached password of the Service01 service account from Server01. The solution must ensure that Server02 and Server 03 continue to use Service01. 

Which cmdlet should you run? 

A. Set-ADServiceAccount 

B. Remove-ADServiceAccount 

C. Uninstall-ADServiceAccount 

D. Reset-ADServiceAccountPassword 

Answer:

Explanation: The Remove-ADServiceAccount cmdlet removes an Active Directory service account. This cmdlet does not make changes to any computers that use the service account. After this operation, the service account is no longer hosted on the target computer but still exists in the directory. 

Incorrect: 

Not C: The Uninstall-ADServiceAccount cmdlet removes an Active Directory service 

account on the computer on which the cmdlet is run. The specified service account must be installed on the computer. 

Reference: Remove-ADServiceAccount 

https://technet.microsoft.com/en-us/library/ee617190.aspx 


Q123. Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server1. Server1 runs Windows Server 2012 R2 and has the Hyper-V server role installed. 

Server1 hosts 10 virtual machines. A virtual machine named VM1 runs Windows Server 2012 R2 and hosts a processor-intensive application named App1. 

Users report that App1 responds more slowly than expected. 

You need to monitor the processor usage on VM1 to identify whether changes must be made to the hardware settings of VM1. 

Which performance object should you monitor on Server1? 

A. Processor 

B. Hyper-V Hypervisor Virtual Processor 

C. Hyper-V Hypervisor Logical Processor 

D. Hyper-V Hypervisor Root Virtual Processor 

E. Process 

Answer:

Explanation: 

In the simplest way of thinking the virtual processor time is cycled across the available logical processors in a round-robin type of fashion. Thus all the processing power gets used over time, and technically nothing ever sits idle. To accurately measure the processor utilization of a guest operating system, use the “\Hyper-V Hypervisor Logical Processor (Total)\% Total Run Time” performance monitor counter on the Hyper-V host operating system. 


Q124. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2. 

You need to audit successful and failed attempts to read data from USB drives on the servers. 

Which two objects should you configure? To answer, select the appropriate two objects in the answer area. 

Answer: 


Q125. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 P.2. Server1 has the Network Policy and Access Services server role installed. 

Your company's security policy requires that certificate-based authentication must be used by some network services. 

You need to identify which Network Policy Server (NPS) authentication methods comply with the security policy. 

Which two authentication methods should you identify? (Each correct answer presents part of the solution. Choose two.) 

A. MS-CHAP 

B. PEAP-MS-CHAP v2 

C. Chap 

D. EAP-TLS 

E. MS-CHAP v2 

Answer: B,D 

Explanation: 

PEAP is similar in design to EAP-TTLS, requiring only a server-side PKI certificate to create a secure TLS tunnel to protect user authentication, and uses server-side public key certificates to authenticate the server. When you use EAP with a strong EAP type, such as TLS with smart cards or TLS with certificates, both the client and the server use certificates to verify their identities to each other. 


Q126. Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2. 

All sales users have laptop computers that run Windows 8. The sales computers are joined to the domain. All user accounts for the sales department are in an organizational unit (OU) named Sales_OU. 

A Group Policy object (GPO) named GPO1 is linked to Sales_OU. 

You need to configure a dial-up connection for all of the sales users. 

What should you configure from User Configuration in GPO1? 

A. Policies/Administrative Templates/Network/Windows Connect Now 

B. Preferences/Control Panel Settings/Network Options 

C. Policies/Administrative Templates/Windows Components/Windows Mobility Center 

D. Policies/Administrative Templates/Network/Network Connections 

Answer:

Explanation: 

The Network Options extension allows you to centrally create, modify, and delete dial-up networking and virtual private network (VPN) connections. Before you create a network option preference item, you should review the behavior of each type of action possible with the extension. 

To create a new Dial-Up Connection preference item 

Open the Group Policy Management Console. Right-click the Group Policy object (GPO) that should contain the new preference item, and then click Edit. 

In the console tree under Computer Configuration or User Configuration, expand the Preferences folder, and then expand the Control Panel Settings folder. 

Right-click the Network Options node, point to New, and select Dial-Up Connection. 

References: 

http: //technet. microsoft. com/en-us/library/cc772107. aspx 

http: //technet. microsoft. com/en-us/library/cc772107. aspx 

http: //technet. microsoft. com/en-us/library/cc772449. aspx 


Q127. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. The domain contains servers named Server1 and Server2. Both servers have the DFS Replication role service installed. 

You need to configure the DFS Replication environment to meet the following requirements: 

. Increase the quota limit of the staging folder. 

. Configure the staging folder cleanup process to provide the highest amount of free space possible. 

Which cmdlets should you use to meet each requirement? To answer, select the appropriate options in the answer area. 

Answer: 


Q128. Your network contains an Active Directory domain named contoso.com. All domain 

controllers run Windows Server 2012 R2. 

DirectAccess is deployed to the network. 

Remote users connect to the DirectAccess server by using a variety of network speeds. 

The remote users report that sometimes their connection is very slow. 

You need to minimize Group Policy processing across all wireless wide area network 

(WWAN) connections. 

Which Group Policy setting should you configure? 

A. Configure Group Policy slow link detection. 

B. Configure Direct Access connections as a fast network connection. 

C. Configure wireless policy processing. 

D. Change Group Policy processing to run asynchronously when a slow network connection is detected. 

Answer:


Q129. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Remote Desktop Session Host role service installed. The computer account of Server1 resides in an organizational unit (OU) named OU1. 

You create and link a Group Policy object (GPO) named GPO1 to OU1. 

You need to prevent GPO1 from applying to your user account when you log on to Server1. GPO1 must apply to every other user who logs on to Server1. 

What should you configure? 

A. Security Filtering. 

B. WMI Filtering. 

C. Block Inheritance. 

D. Item-level targeting. 

Answer:

Explanation: 

You can use item-level targeting to change the scope of individual preference items, so they apply only to selected users or computers. Within a single Group Policy object (GPO), you can include multiple preference items, each customized for selected users or computers and each targeted to apply settings only to the relevant users or computers. 

Reference: https://technet.microsoft.com/en-us/library/cc733022.aspx 


Q130. HOTSPOT 

You have a server named Servers that runs Windows Server 2012 R2. Servers has the Windows Deployment Services server role installed. 

Server5 contains several custom images of Windows 8. 

You need to ensure that when 32-bit client computers start by using PXE, the computers automatically install an image named Image 1. 

What should you configure? 

To answer, select the appropriate tab in the answer area. 

Answer: