getcertified4sure.com

Jun 2021 updated: microsoft 70 413




It is impossible to pass Microsoft microsoft 70 413 exam without any help in the short term. Come to Actualtests soon and find the most advanced, correct and guaranteed Microsoft 70 413 exam practice questions. You will get a surprising result by our Updated Designing and Implementing a Server Infrastructure practice guides.

Q71. - (Topic 8) 

You plan to deploy serverl.child.contoso.com as a read-only domain controller (RODC). 

You run the adprep.exe /rodcprep command on DC3 and receive the following error message: 

You need to identify what prevents you from successfully running Adprep /rodcprep on DC3. 

What should you identify? 

A. The domain functional level of child.contoso.com isset to the wrong level. 

B. DC3 cannot connect to the domain naming master on DC1. 

C. The forest functional level is set to the wrong level. 

D. DC3 cannot connect to the infrastructure master onDC2. 

Answer:

Explanation: Adprep could not contact a replica… 

This problem occurs when the Adprep /rodcprep command tries to contact the 

infrastructure master for each application partition in the forest. 

Reference: Error message when you run the "Adprep /rodcprep" command in Windows 

Server 2008: "Adprep could not contact a replica for partition 

DC=DomainDnsZones,DC=Contoso,DC=com" 


Q72. DRAG DROP - (Topic 8) 

Your network contains an Active Directory domain named contoso.com. The domain contains an IP Address Management (IPAM) server. 

You plan to delegate the administration of IPAM as shown in the following table. 

You need to recommend which IPAM security group must be used for each department. The solution must minimize the number of permissions assigned to each group. 

What should you recommend? 

To answer, drag the appropriate group to the correct department in the answer area. Each group may be used once, more than once, or not at all. Additionally, you may need to drag the split bar between panes or scroll to view content. 

Answer: 


Q73. - (Topic 5) 

You need to plan the expansion of the Los Angeles office. 

What should you do? 

A. Install a read-only domain controller in Los Angeles. 

B. Install a domain controller in Los Angeles. 

C. Create and apply a filtered attribute set to the Los Angeles site. 

D. Create and apply a Group Policy object to the Los Angeles site. 

Answer:


Q74. - (Topic 6) 

You need To configure the Group Policy for salespeople. 

Solution: You move all shared desktops to a separate organizational unit (OU). You create one Group Policy object (GPO) that has an AppLocker policy rule and enable loopback policy processing within the GPO. You link the GPO to the new OU. 

Does this meet the goal? 

A. Yes 

B. No 

Answer:


Q75. - (Topic 8) 

Your network contains multiple servers that run Windows Server 2012. All client computers run Windows 8. 

You need to recommend a centralized solution to download the latest antivirus definitions for Windows Defender. 

What should you include in the recommendation? 

A. Microsoft System Center 2012 Endpoint Protection 

B. Network Access Protection (NAP) 

C. Microsoft System Center Essentials 

D. Windows Server Update Services (WSUS) 

Answer:

Explanation: 

To use WSUS to deploy Windows Defender definition updates to client computers, follow these steps: 

1. Open the WSUS Administrator console, and then click Options at the top of the console. 

2. Click Synchronization Options. 

3. Under Products and Classifications, click Change under Products. 

4. Verify that the Windows Defender check box is selected, and then click OK. 

5. Under Products and Classifications, click Change under Update Classifications. 

6. Verify that the Definition Updates check box is selected, and then click OK. 

7. Optional Update the automatic approval rule. To do this, follow these steps: 

a. At the top of the console, click Options. 

b. Click Automatic Approval Options. 

c. Make sure that the Automatically approve updates for installation by using the following rule check box is selected. 

d. Under Approve for Installation, click Add/Remove Classification. 

e. Verify that the Definition Updates check box is selected, and then click OK. 

8. At the top of the console, click Options. 

9. Click Synchronization Options. 

10. On the taskbar on the left, click Synchronize now. 

11. At the top of the console, click Updates. 

12. Approve any Windows Defender updates that WSUS should deploy. 

Reference: How to use Windows Server Update Services (WSUS) to deploy definition updates to computers that are running Windows Defender 


Q76. - (Topic 3) 

You need to recommend a solution that meets the security requirements. 

Which schema attribute properties should you recommend modifying? 

A. isIndexed 

B. searchFlags 

C. isCriticalSystemObject 

D. schemaFlagsEx 

Answer:

Explanation: 

* Scenario: ). Confidential attributes must not be replicated to the Chicago office. 

* Applies To: Windows Server 2008, Windows Server 2012 This topic includes procedures for adding an attribute to the filtered attribute set (FAS) for a readonly domain controller (RODC) and marking the attribute as confidential data. You can perform these procedures to exclude specific data from replicating to RODCs in the forest. Because the data is not replicated to any RODCs, you can be assured that the data will not be revealed to an attacker who manages to successfully compromise an RODC. In most cases, adding an attribute to the RODC FAS is completed by the developer of the application that added the attribute to the schema. 

. Determine and then modify the current searchFlags value of an attribute 

. Verify that an attribute is added to the RODC FAS -Determine and then modify the current searchFlags value of an attribute To add an attribute to an RODC FAS, you must first determine the current searchFlags value of the attribute that you want to add, and then set the following values for searchflags: 

. To add the attribute to the RODC FAS, set the 10th bit to 0x200. 

. To mark the attribute as confidential, set the 7th bit to 0x080. 

Reference: Adding Attributes to the RODC Filtered Attribute Set 

http://technet.microsoft.com/en-us/library/cc754794(v=ws.10).aspx 


Q77. - (Topic 8) 

Your network contains an Active Directory forest named contoso.com. 

You plan to automate the deployment of servers that run Windows Server 2012. 

You identify the following requirements for the deployment: 

Update the custom images that will be used for the deployment. 

Add custom drivers to the images that will be used for the deployment. 

Add software packages to the images that will be used for the deployment. 

Perform a zero touch bare-metal installation that uses Wake On LAN. 

A network consultant recommends using Windows Deployment Services (WDS) and the Windows Assessment and Deployment Kit (Windows ADK) to deploy the servers. 

You need to identify which requirements are achieved by using the consultant's recommendations. 

Which requirements should you identify? (Each correct answer presents part of the solution. Choose all that apply.) 

A. Update the custom images used for the deployment. 

B. Add software packages to the images used for the deployment. 

C. Perform a zero touch bare-metal installation that uses Wake On LAN. 

D. Add custom drivers to the images used for the deployment. 

Answer: A,D 

Explanation: Microsoft Deployment Toolkit 2010 

MDT 2010 requires Windows AIK for Windows. 

Manage your images, from adding/removing drivers to easily swapping out the operating 

system you would like to deploy. 

Incorrect: 

Not C: System Center Configuration Manager (ConfigMgr) 

ConfigMgr allows you to push an OSD to the computers of your choice at the time of your 

choosing due to its built in Wake on LAN (WOL) feature. 


Q78. - (Topic 1) 

You are planning the implementation of two new servers that will be configured as RADIUS servers. 

You need to recommend which configuration must be performed on the VPN servers. The solution must meet the technical requirements. 

What should you do on each VPN server? 

A. Add a RADIUS client. 

B. Install the Health Registration Authority role service. 

C. Enable DirectAccess. 

D. Modify the authentication provider. 

Answer:

Explanation: 

* Implement RADIUS authentication for VPN connections. 

* The new sales.contoso.com domain will contain a web application that will access data from a Microsoft SQL Server located in the contoso.com domain. The web application must use integrated Windows authentication. Users' credentials must be passed from the web applications to the SQL Server. 


Q79. - (Topic 8) 

Your network contains an Active Directory domain named contoso.com. The Active Directory site topology is configured as shown in the exhibit. (Click the Exhibit button.) 

DC1 and DC2 run Windows Server 2003 R2. All FSMO roles are located on DC2. 

You plan to deploy a read-only domain controller (RODC) to Site3. 

You need to recommend changes to the network to support the planned RODC 

implementation. 

What should you recommend? 

More than one answer choice may achieve the goal. Select the BEST answer. 

A. To Site1, add an RODC that runs Windows Server 2012. 

B. Replace DC2 with a domain controller that runs Windows Server 2012. 

C. To Site2, add an RODC that runs Windows Server 2012. 

D. Replace DC1 with a domain controller that runs Windows Server 2012. 

Answer:

Explanation: Each RODC requires a writable domain controller running Windows Server 

2012 for the same domain from which the RODC can directly replicate. 

Typically, this requires that a writable domain controller running Windows Server 2012 be 

placed in the nearest site in the topology. 

Reference: Active Directory Replication Considerations 


Q80. - (Topic 3) 

You need to recommend a server deployment strategy for the main office that meets the server deployment requirements. 

What should you recommend installing in the main office? 

A. Windows Deployment Services (WDS) 

B. The Windows Automated Installation Kit (Windows AIK) 

C. The Express Deployment Tool (EDT) 

D. The Windows Assessment and Deployment Kit (Windows ADK) 

Answer:

Explanation: WDS is a server role that enables you to remotely deploy Windows operating systems. You can use it to set up new computers by using a network-based installation. 

This means that you do not have to install each operating system directly from a CD, USB drive, or DVD. 

Reference: What's New in Windows Deployment Services in Windows Server