Latest MCSE 70-411 Real Exam Download 31-40

Ensurepass


QUESTION 31

You have a DNS server named Server1. Server1 has a primary zone named contoso.com. Zone Aging/ Scavenging is configured for the contoso.com zone.

One month ago, an Administrator removed a server named Server2 from the network. You discover that a static resource record for Server2 is present in contoso.com.

Resource records for decommissioned client computers are removed automatically from contoso.com. You need to ensure that the static resource records for all of the servers are removed automatically from contoso.com.

What should you modify?

A. The Security settings of the static resource records

B. The Expires after value of contoso.com

C. The Record time stamp value of the static resource records

D. The time-to-live (TTL) value of the static resource records

Answer: C


QUESTION 32

Your network contains two Active Directory domains named contoso.com and adatum.com. The network contains a server named Server1 that runs Windows Server 2012.

Server1 has the DNS Server server role installed. Server1 has a copy of the contoso.com DNS zone. You need to configure Server1 to resolve names in the adatum.com domain.

The solution must meet the following requirements:

· Prevent the need to change the configuration of the current name servers that host zones for adatum. com.

· Minimize Administrative effort.

Which type of zone should you create?
A. Primary

B. Secondary

C. Reverse lookup

D. Stub

Answer: D


QUESTION 33

Your network contains two servers named Server1 and Server2. Both servers run Windows Server 2012 and have the DNS Server server role installed.

On Server1, you create a standard primary zone named contoso.com.

You need to ensure that Server2 can host a secondary zone for contoso.com.

What should you do from Server1?
A. Add Server2 as a name server.

B. Convert contoso.com to an Active Directory-integrated zone.

C. Create a zone delegation that points to Server2.
D. Create a trust anchor named Server2.

Answer: A


QUESTION 34

Your network contains an Active Directory domain named contoso.com. The domain contains more than

100 Group Policy objects (GPOs).

Currently, there are no enforced GPOs. The domain contains a GPO named GPO1. GPO1 contains several Group Policy preferences.

You need to view all of the preferences configured in GPO1.

What should you use?
A. dcgpofix

B. Get-GPOReport

C. Gpfixup

D. Gpresult

E. Gptedit.msc
F. Import-GPO

G. Restore-GPO

H. Set-GPInheritance

I. Set-GPLink

J. Set-GPPermission

K. Gpupdate

L. Add-ADGroupMember

Answer: B


QUESTION 35

Your network contains an Active Directory domain named contoso.com. The domain contains more than

100 Group Policy objects (GPOs).

Currently, there are no enforced GPOs. You need to prevent all of the GPOs at the site level and at the domain level from being applied to users and computers

in an organizational unit (OU) named OU1.

You want to achieve this goal by using the minimum amount of Administrative effort.

What should you use?
A. dcgpofix

B. Get-GPOReport

C. Gpfixup

D. Gpresult

E. Gptedit.msc
F. Import-GPO

G. Import-GPO
H. Restore-GPO

I. Set-GPInheritance

J. Set-GPLink

K. Set-GPPermission

L. Gpupdate

M. Add-ADGroupMember

Answer: I


QUESTION 36

Your network contains an Active Directory domain named contoso.com. The domain contains more than

100 Group Policy objects (GPOs).

Currently, there are no enforced GPOs. You have two GPOs linked to an organizational unit (OU) named

OU1.

You need to change the precedence order of the GPOs.

What should you use?
A. dcgpofix

B. Get-GPOReport

C. Gpfixup

D. Gpresult

E. Gptedit.msc
F. Import-GPO

G. Restore-GPO

H. Set-GPInheritance

I. Set-GPLink

J. Set-GPPermission

K. Gpupdate

L. Add-ADGroupMember

Answer: I


QUESTION 37

Your network contains an Active Directory domain named contoso.com. The domain contains more than

100 Group Policy objects (GPOs).

Currently, there are no enforced GPOs. You need to provide an Administrator named Admin1 with the ability to create GPOs in the domain.

The solution must not provide Admin1 with the ability to link GPOs.

What should you use?

A. dcgpofix

B. Get-GPOReport

C. Gpfixup

D. Gpresult

E. Gptedit.msc
F. Import-GPO G. Restore-GPO

H. Set-GPInheritance

I. Set-GPLink

J. Set-GPPermission

K. Gpupdate

L. Add-ADGroupMember

Answer: J


QUESTION 38

You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access server role installed.

On Server1, you create a network policy named Policy1.

You need to configure Policy1 to apply only to VPN connections that use the L2TP protocol.

What should you configure in Policy1?
A. The Tunnel Type

B. The Service Type

C. The NAS Port Type

D. The Framed Protocol

Answer: A


QUESTION 39

Your network contains an Active Directory domain named contoso.com. All servers run Windows Server

2012. The domain contains two servers.

The servers are configured as shown in the following table.

clip_image001

All client computers run Windows 8 Enterprise. You plan to deploy Network Access Protection (NAP) by using IPSec enforcement. A Group Policy object (GPO) named GPO1 is configured to deploy a trusted server group to all of the client computers.

You need to ensure that the client computers can discover HRA servers automatically.

Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

A. On DC1, create a service location (SRV) record.

B. On Server2, configure the EnableDiscovery registry key.

C. On all of the client computers, configure the EnableDiscovery registry key.

D. In a GPO, modify the Request Policy setting for the NAP Client Configuration.
E. On Dc1, create an alias (CNAME) record.

Answer: ACD


QUESTION 40

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012.

Server1 has the Network Policy Server role service installed.

You plan to configure Server1 as a Network Access Protection (NAP) health policy server for VPN

enforcement by using the Configure NAP wizard.

You need to ensure that you can configure the VPN enforcement method on Server1 successfully.

What should you install on Server1 before you run the Configure NAP wizard?
A. The Host Credential Authorization Protocol (HCAP)

B. A system health validator (SHV)

C. The Remote Access server role

D. A Computer certificate

Answer: D

 

Download Latest 70-411 Real Free Tests , help you to pass exam 100%.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.