Latest Real 70-411 Tests Dumps and VCE Exam 221-230

Ensurepass

QUESTION 221

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012. You mount an Active Directory snapshot on DC1. You need to expose the snapshot as an LDAP server. Which tool should you use?

 

A.      ADSI Edit

B.      Ntdsutil

C.      Dsamain

D.      Ldp

 

Correct Answer: C

 

 

QUESTION 222

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012. Server1 has a drive named E that is encrypted by using BitLocker Drive Encryption (BitLocker). A recovery key is stored on drive C. Drive E becomes locked. When you attempt to use the recovery key, you receive the following error message.

clip_image001

 

You need to access the data stored on drive E. What should you run first?

 

A.      manage-bde -protectors get e:

B.      manage-bde -unlock e: -recoverykey c:

C.      disable-bitlocker -mountpoint e:

D.      unlock-bitlocker -mountpoint e: -recoverykeypath c:

 

Correct Answer: B

 

 

QUESTION 223

Your network contains an Active Directory domain named contoso.com. All user accounts reside in an organizational unit (OU) named OU1. You create a Group Policy object (GPO) named GPO1. You link GPO1 to OU1. You configure the Group Policy preference of GPO1 to add a shortcut named Link1 to the desktop of each user. You discover that when a user deletes Link1, the shortcut is removed permanently from the desktop. You need to ensure that if a user deletes Link1, the shortcut is added to the desktop again. What should you do?

 

A.      Modify the Link1 shortcut preference of GPO1.

B.      Enable loopback processing in GPO1.

C.      Enforce GPO1.

D.      Modify the Security Filtering settings of GPO1.

 

Correct Answer: A

 

 

QUESTION 224

Your network contains an Active Directory forest named contoso.com. The forest contains two sites named Main and Branch. The Main site contains 400 desktop computers and the Branch site contains 150 desktop computers. All of the desktop computers run Windows 8. In Main, the network contains a member server named Server1 that runs Windows Server 2012. You install the Windows Server Update Services server role on Server1. You need to ensure that Windows updates obtained from Windows Server Update Services (WSUS) are the same for the computers in each site. You want to achieve this goal by using the minimum amount of administrative effort. What should you do?

 

A.      From the Update Services console, create computer groups.

B.      From the Update Services console, configure the Computers options.

C.      From the Group Policy Management console, configure the Windows Update settings.

D.      From the Group Policy Management console, configure the Windows Anytime Upgrade settings.

E.       From the Update Services console, configure the Synchronization Schedule options.

 

Correct Answer: A

 

 

QUESTION 225

Your network contains an Active Directory forest named contoso.com. The domain contains three servers. The servers are configured as shown in the following table.

 

clip_image003

 

You plan to implement the BitLocker Drive Encryption (BitLocker) Network Unlock feature. You need to identify which server role must be deployed to the network to support the planned implementation. Which role should you identify?

 

A.      Network Policy and Access Services

B.      Volume Activation Services

C.      Active Directory Rights Management Services

D.      Windows Deployment Services

 

Correct Answer: D

 

 

QUESTION 226

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1. You need to create an Active Directory snapshot on DC1. Which four commands should you run?

 

To answer, move the four appropriate commands from the list of commands to the answer area and arrange them in the correct order.

 

Select and Place:

clip_image005

 

Correct Answer:

clip_image007

 

 

QUESTION 227

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Print1. Your company implements DirectAccess. A user named User1 frequently works at a customer’s office. The customer’s office contains a print server named Print1. While working at the customer’s office, User1 attempts to connect to Print1. User1 connects to the Print1 server in contoso.com instead of the Print1 server at the customer’s office. You need to provide User1 with the ability to connect to the Print1 server in the customer’s office. Which Group Policy option should you configure?

 

To answer, select the appropriate option in the answer area.

 

Hot Area:

clip_image009

 

Correct Answer:

clip_image011

 

 

QUESTION 228

Your network contains an Active Directory domain named contoso.com. You need to create a certificate template for the BitLocker Drive Encryption (BitLocker) Network Unlock feature. Which Cryptography setting of the certificate template should you modify?

 

To answer, select the appropriate setting in the answer area.

 

Solution:

Cryptographic provider that supports RSA (Microsoft Software Key Storage Provider)

 

A.      True

B.      False

 

Correct Answer: A

 

 

QUESTION 229

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All domain controllers run Windows Server 2012. The domain contains two domain controllers. The domain controllers are configured as shown in the following table.

 

clip_image013

 

You discover that a support technician accidentally removed 100 users from an Active Directory group named Group1 an hour ago. You need to restore the membership of Group1. What should you do?

 

A.      Apply a virtual machine snapshot to VM1.

B.      Perform an authoritative restore.

C.      Perform a non-authoritative restore.

D.      Perform tombstone reanimation.

 

Correct Answer: B

 

 

QUESTION 230

Your network contains an Active Directory domain named contoso.com. The domain contains a read-only domain controller (RODC) named RODC1. You create a global group named RODC_Admins. You need to provide the members of RODC_Admins with the ability to manage the hardware and the software on RODC1. The solution must not provide RODC_Admins with the ability to manage Active Directory objects. What should you do?

 

A.      From Active Directory Site and Services, configure the Security settings of the RODC1 server object.

B.      From Active Directory Sites and Services, run the Delegation of Control Wizard.

C.      From Windows PowerShell, run the Set-ADAccountControl cmdlet.

D.      From Active Directory Users and Computers, configure the Managed By settings of the RODC1 account.

 

Correct Answer: D

 

 

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.