[2016-NEW!] PassLeader Premium 70-411 Exam Questions For Free Reading (Question 91 – Question 120)

      Comments Off on [2016-NEW!] PassLeader Premium 70-411 Exam Questions For Free Reading (Question 91 – Question 120)

Where to download the valid 70-411 exam dumps? PassLeader now is offering the newest and valid 447q 70-411 exam questions for preparing for 70-411 exam, we ensure our new version 447q 70-411 PDF dumps and VCE dumps are 100% valid for passing 70-411 exam, because PassLeader 70-411 PDF dumps and VCE dumps have been updated with the newest 70-411 questions and PassLeader 70-411 practice tests have been corrected with right questions and answers. Now visit passleader.com to get the newest 447q 70-411 practice tests with free VCE simulator!

keywords: 70-411 exam,447q 70-411 exam dumps,447q 70-411 exam questions,70-411 pdf dumps,70-411 vce dumps,70-411 study guide,70-411 practice test,Administering Windows Server 2012 R2 Exam

P.S. Download Free 70-411 PDF Dumps and Preview PassLeader 70-411 VCE Dumps At The End Of This Post!!! (Ctrl+End)

QUESTION 91
Hotspot Question
Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All domain controllers run Windows Server 2012 R2 and are configured as DNS servers. All DNS zones are Active Directory-integrated. Active Directory Recycle Bin is enabled. You need to modify the amount of time deleted objects are retained in the Active Directory Recycle Bin. Which naming context should you use? To answer, select the appropriate naming context in the answer area.

Answer:

QUESTION 92
Your network contains an Active Directory domain named contoso.com. The domain contains six domain controllers. The domain controllers are configured as shown in the following table.

The network contains a server named Server1 that has the Hyper-V server role installed. DC6 is a virtual machine that is hosted on Server1. You need to ensure that you can clone DC6. What should you do?

A.    Transfer the schema master to DC6.
B.    Transfer the schema master to DC4.
C.    Transfer the PDC emulator to DC2.
D.    Transfer the PDC emulator to DC5.

Answer: C

QUESTION 93
Hotspot Question
Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2. You need to audit successful and failed attempts to read data from USB drives on the servers. Which two objects should you configure? To answer, select the appropriate two objects in the answer area.

Answer:

QUESTION 94
Hotspot Question
You have a server named Server4 that runs Windows Server 2012 R2. Server4 has the Windows Deployment Services server role installed. Server4 is configured as shown in the exhibit. (Click the Exhibit button.)

To answer, complete each statement according to the information presented in the exhibit. Each correct selection is worth one point.

Answer:

QUESTION 95
You manage a server that runs Windows Server 2012 R2. The server has the Windows Deployment Services server role installed. You have a desktop computer that has the following configuration:
– Computer name: Computer1
– Operating system: Windows 8
– MAC address: 20-CF-30-65-D0-87
– GUID: 979708BF-C04B-4525-9FE0-C4150BB6C618
You need to configure a pre-staged device for Computer1 in the Windows Deployment Services console. Which two values should you assign to the device ID? (Each correct answer presents a complete solution. Choose two.)

A.    20CF3065D08700000000000000000000
B.    979708BFC04B45259FE0C4150BB6C618
C.    979708BF-C04B-452S-9FE0-C4150BB6C618
D.    0000000000000000000020CF306SD087
E.    00000000-0000-0000-0000-C41S0BB6C618

Answer: CD

QUESTION 96
Hotspot Question
Your company has four offices. The offices are located in Montreal, Seattle, Sydney, and New York. The network contains an Active Directory domain named contoso.com. The domain contains a server named Server2 that runs Windows Server 2012 R2. Server2 has the DHCP Server server role installed. All client computers obtain their IPv4 and IPv6 addresses from DHCP. You need to ensure that Network Access Protection (NAP) enforcement for DHCP applies to all of the client computers except for the client computers in the New York office. Which two nodes should you configure? To answer, select the appropriate two nodes in the answer area.

Answer:

QUESTION 97
Your network contains an Active Directory domain named adatum.com. A network administrator creates a Group Policy central store. After the central store is created, you discover that when you create new Group Policy objects (GPOs), the GPOs do not contain any Administrative Templates. You need to ensure that the Administrative Templates appear in new GPOs. What should you do?

A.    Add your user account to the Group Policy Creator Owners group.
B.    Configure all domain controllers as global catalog servers.
C.    Copy files from %Windir%\Policydefimtions to the central store.
D.    Modify the Delegation settings of the new GPOs.

Answer: C

QUESTION 98
Your network contains two Active Directory forests named contoso.com and dev.contoso.com. The contoso.com forest contains a domain controller named DC1. The dev.contoso.com forest contains a domain controller named DC2. Each domain contains an organizational unit (OU) named OU1. Dev.contoso.com has a Group Policy object (GPO) named GPO1. GPO1 contains 200 settings, including several settings that have network paths. GPO1 is linked to OU1. You need to copy GPO1 from dev.contoso.com to contoso.com. What should you do first on DC2?

A.    From the Group Policy Management console, right-click GPO1 and select Copy.
B.    Run the mtedit.exe command and specify the /Domaintcontoso.com /DC:DC 1 parameter.
C.    Run the Save-NetGpocmdlet.
D.    Run the Backup-Gpocmdlet.

Answer: D

QUESTION 99
Your network contains four Network Policy Server (NPS) servers named Server1, Server2, Server 3, and Server4. Server1 is configured as a RADIUS proxy that forwards connection requests to a remote RADIUS server group named Group1. You need to ensure that Server2 and Server3 receive connection requests. Server4 must only receive connection requests if both Server2 and Server3 are unavailable. How should you configure Group1?

A.    Change the Weight of Server4 to 10.
B.    Change the Weight of Server2 and Server3 to 10.
C.    Change the Priority of Server2 and Server3 to 10.
D.    Change the Priority of Server4 to 10.

Answer: D

QUESTION 100
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the DHCP Server server role installed. The network contains 400 client computers that run Windows 8. All of the client computers are joined to the domain and are configured DHCP clients. You install a new server named Server2 that runs Windows Server 2012 R2. On Server2, you install the Network Policy Server role service and you configure Network Access Protection (NAP) to use the DHCP enforcement method. You need to ensure that Server1 only provides a valid default gateway to computers that pass the system health validation. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

A.    From the DHCP console, configure the 016 Swap Server option.
B.    From the DHCP console, create a new policy.
C.    From the NAP Client Configuration console, enable the DHCP Quarantine Enforcement Client.
D.    From the DHCP console, enable NAP on all scopes.
E.    From Server Manager, install the Network Policy Server role service.

Answer: DE

QUESTION 101
Your network is configured as shown in the exhibit. (Click the Exhibit button.)

Server1 regularly accesses Server2. You discover that all of the connections from Server1 to Server2 are routed through Router1. You need to optimize the connection path from Server1 to Server2. Which route command should you run on Server1?

A.    Route add -p 10.10.10.0 MASK 255.255.255.0 10.10.10.1 METRIC 50
B.    Route add -p 10.10.10.0 MASK 255.255.255.0 172.23.16.2 METRIC 100
C.    Route add -p 10.10.10.12 MASK 255.255.255.0 10.10.10.1 METRIC 100
D.    Route add -p 10.10.10.12 MASK 255.255.255.0 10.10.10.0 METRIC 50

Answer: B

QUESTION 102
Your network contains an Active Directory domain named adatum.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 is configured as a Network Policy Server (NPS) server and as a DHCP server. You need to ensure that only computers that send a statement of health are checked for Network Access Protection (NAP) health requirements. Which two settings should you configure? (Each correct answer presents part of the solution. Choose two.)

A.    The Called Station ID constraints
B.    The MS-Service Class conditions
C.    The Health Policies conditions
D.    The NAS Port Type constraints
E.    The NAP-Capable Computers conditions

Answer: CE

QUESTION 103
Your network contains two Active Directory forests named adatum.com and contoso.com. The network contains three servers. The servers are configured as shown in the following table.

You need to ensure that connection requests from adatum.com users are forwarded to Server2 and connection requests from contoso.com users are forwarded to Server3. Which two should you configure in the connection request policies on Server1? (Each correct answer presents part of the solution. Choose two.)

A.    The Authentication settings
B.    The User Name condition
C.    The Standard RADIUS Attributes settings
D.    The Identity Type condition
E.    The Location Groups condition

Answer: AB

QUESTION 104
Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2. The domain contains a server named Server1 that has the Network Policy Server server role and the Remote Access server role installed. The domain contains a server named Server2 that is configured as a RADIUS server. Server1 provides VPN access to external users. You need to ensure that all of the VPN connections to Server1 are logged to the RADIUS server on Server2. What should you run?

A.    Add-RemoteAccessRadius -ServerNameServer1 -AccountingOnOffMsg Enabled – SharedSecret “Secret” -Purpose Accounting
B.    Set-RemoteAccessAccounting -AccountingOnOffMsg Enabled -AccountingOnOffMsg Enabled
C.    Add-RemoteAccessRadius -ServerName Server2 -AccountingOnOffMsg Enabled – SharedSecret “Secret” -Purpose Accounting
D.    Set-RemoteAccessAccounting -EnableAccountingType Inbox -AccountingOnOffMsg Enabled

Answer: C

QUESTION 105
Hotspot Question
Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2. Server1 has the Network Policy Server server role installed. Server2 has the DHCP Server server role installed. Both servers run Windows Server 2012 R2. You are configuring Network Access Protection (NAP) to use DHCP enforcement. You configure a DHCP scope as shown in the exhibit. (Click the Exhibit button.)

You need to ensure that non-compliant NAP clients receive different DHCP options than compliant NAP clients. What should you configure on each server? To answer, select the appropriate options for each server in the answer area.

Answer:

QUESTION 106
Your network contains a Network Policy Server (NPS) server named Server1. The network contains a server named SQL1 that has Microsoft SQL Server 2008 R2 installed. All servers run Windows Server 2012 R2. You configure NPS on Server1 to log c. You need to ensure that the accounting data is captured if SQL1 fails. The solution must minimize cost. What should you do?

A.    Implement Failover Clustering.
B.    Implement database mirroring.
C.    Run the Accounting Configuration Wizard.
D.    Modify the SQL Server Logging properties.

Answer: C

QUESTION 107
Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2. The domain contains two servers. The servers are configured as shown in the following table.

All client computers run Windows 8 Enterprise. You plan to deploy Network Access Protection (NAP) by using IPSec enforcement. A Group Policy object (GPO) named GPO1 is configured to deploy a trusted server group to all of the client computers. You need to ensure that the client computers can discover HRA servers automatically. Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

A.    On DC1, create a service location (SRV) record.
B.    On Server2, configure the EnableDiscovery registry key.
C.    On all of the client computers, configure the EnableDiscovery registry key.
D.    In a GPO, modify the Request Policy setting for the NAP Client Configuration.
E.    On DC1, create an alias (CNAME) record.

Answer: ACD

QUESTION 108
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Network Policy Server role service installed. You plan to configure Server1 as a Network Access Protection (NAP) health policy server for VPN enforcement by using the Configure NAP wizard. You need to ensure that you can configure the VPN enforcement method on Server1 successfully. What should you install on Server1 before you run the Configure NAP wizard?

A.    The Host Credential Authorization Protocol (HCAP)
B.    A system health validator (SHV)
C.    The Remote Access server role
D.    A Computer certificate

Answer: D

QUESTION 109
You deploy two servers named Server1 and Server2. You install Network Policy Server (NPS) on both servers. On Server1, you configure the following NPS settings:
– RADIUS Clients
– Network Policies
– Connection Request Policies
– SQL Server Logging Properties
You export the NPS configurations to a file and import the file to Server2. You need to ensure that the NPS configurations on Server2 are the same as the NPS configurations on Server1. Which settings should you manually configure on Server2?

A.    SQL Server Logging Properties
B.    Connection Request Policies
C.    RADIUS Clients
D.    Network Policies

Answer: A

QUESTION 110
You have a server named Server1 that has the Network Policy and Access Services server role installed. You plan to configure Network Policy Server (NPS) on Server1 to use certificate-based authentication for VPN connections. You obtain a certificate for NPS. You need to ensure that NPS can perform certificate-based authentication. To which store should you import the certificate? To answer, select the appropriate store in the answer area.

Answer:

QUESTION 111
Your network contains a RADIUS server named Server1. You install a new server named Server2 that runs Windows Server 2012 R2 and has Network Policy Server (NPS) installed. You need to ensure that all accounting requests for Server2 are forwarded to Server1. On Server2, you create a new remote RADIUS server group named Group1 that contains Server1. What should you configure next on Server2? To answer, select the appropriate node in the answer area.

Answer:

QUESTION 112
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1. Server1 has the DHCP Server server role and the Network Policy Server role service installed. Server1 contains three non-overlapping scopes named Scope1, Scope2, and Scope3. Server1 currently provides the same Network Access Protection (NAP) settings to the three scopes. You modify the settings of Scope1 as shown in the exhibit. (Click the Exhibit button.) You need to configure Server1 to provide unique NAP enforcement settings to the NAP non- compliant DHCP clients from Scope1. What should you create?

A.    A network policy that has the MS-Service Class condition
B.    A network policy that has the Identity Type condition
C.    A connection request policy that has the Identity Type condition
D.    A connection request policy that has the Service Type condition

Answer: A

QUESTION 113
You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the Remote Access server role installed. You have a client named Client1 that is configured as an 802.1X supplicant. You need to configure Server1 to handle authentication requests from Client1. The solution must minimize the number of authentication methods enabled on Server1. Which authentication method should you enable? To answer, select the appropriate authentication method in the answer area.

Answer:

QUESTION 114
Your network contains an Active Directory domain named contoso.com. The domain contains a RADIUS server named Server1 that runs Windows Server 2012 R2. You add a VPN server named Server2 to the network. On Server1, you create several network policies. You need to configure Server1 to accept authentication requests from Server2. Which tool should you use on Server1?

A.    Connection Manager Administration Kit (CMAK)
B.    Routing and Remote Access
C.    Network Policy Server (NPS)
D.    Set-RemoteAccessRadius

Answer: C

QUESTION 115
Hotspot Question
Your network contains an Active Directory domain named contoso.com. The domain contains the users shown in the following table.

You have a Network Policy Server (NPS) server that has the network policies shown in the following table.

User1, User2, and User3 plan to connect to the network by using a VPN. You need to identify which network policy will apply to each user. What should you identify? To answer, select the appropriate policy for each user in the answer area.

Answer:

QUESTION 116
Drag and Drop Question
Your network contains an Active Directory forest named contoso.com. The forest contains a Network Policy Server (NPS) server named NPS1 and a VPN server named VPN1. VPN1 forwards all authentication requests to NPS1. A partner company has an Active Directory forest named adatum.com. The adatum.com forest contains an NPS server named NPS2. You plan to grant users from adatum.com VPN access to your network. You need to authenticate the users from adatum.com on VPN1. What should you create on each NPS server? To answer, drag the appropriate objects to the correct NPS servers. Each object may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

Answer:

QUESTION 117
Hotspot Question
You have a server named LON-SVR1 that runs Windows Server 2012 R2. LON-SVR1 has the Remote Access server role installed. LON-SVRl is located in the perimeter network. The IPv4 routing table on LON-SVR1 is configured as shown in the following exhibit. (Click the Exhibit button.) Your company purchases an additional router named Router1. Router1 has an interface that connects to the perimeter network and an interface that connects to the Internet. The IP address of the interface that connects to the perimeter network is 172.16.0.2. You need to ensure that LON-SVR1 will route traffic to the Internet by using Router1 if the current default gateway is unavailable. How should you configure the static route on LON-SVR1? To answer, select the appropriate static route in the answer area.

Answer:

QUESTION 118
Your network contains an Active Directory domain named contoso.com. The domain contains client computers that run either Windows XP, Windows 7, or Windows 8. Network Policy Server (NPS) is deployed to the domain. You plan to create a system health validator (SHV). You need to identify which policy settings can be Applied to all of the Windows XP computers. Which three policy settings should you identify? (Each correct answer presents part of the solution. Choose three.)

A.    A firewall is enabled for all network connections.
B.    An antispyware application is on.
C.    Automatic updating is enabled.
D.    Antivirus is up to date.
E.    Antispyware is up to date.

Answer: ACD

QUESTION 119
Your network contains an Active Directory domain named adatum.com. You have a Group Policy object (GPO) that configures the Windows Update settings. Currently, client computers are configured to download updates from Microsoft Update servers. Users choose when the updates are installed. You need to configure all client computers to install Windows updates automatically. Which setting should you configure in the GPO? To answer, select the appropriate setting in the answer area.

Answer:

QUESTION 120
Your network contains an Active Directory domain named contoso.com. Network Access Protection (NAP) is deployed to the domain. You need to create NAP event trace log files on a client computer. What should you run?

A.    Logman
B.    Tracert
C.    Register-EngineEvent
D.    Register-ObjectEvent

Answer: A

Download Free 70-411 PDF Dumps From Google Drive: https://drive.google.com/open?id=0B-ob6L_QjGLpfnVfbXEwbmlUa1paemdDc19zQ1JWdVpqU1poRlB2TnktaWlBUFhfQXNJZVU (Explanation For Every Question Is Available!)

PassLeader 70-411 VCE Dumps Screenshots:

Download New 70-411 VCE Dumps From PassLeader: http://www.passleader.com/70-411.html (New Questions Are 100% Available and Wrong Answers Have Been Corrected!!!)