Server test exam 1

Description

Some exam questions for Microsoft Exam 70-411
Dondee
Quiz by Dondee, updated more than 1 year ago
Dondee
Created by Dondee over 8 years ago
270
0

Resource summary

Question 1

Question
Your network contains an Active Directory domain named contoso.com. The functional level of the forest is Windows Server 2008 R2. Computer accounts for the marketing department are in an organizational unit (OU) named Departments \Marketing\Computers. User accounts for the marketing department are in an OU named Departments\Marketing\Users. All of the marketing user accounts are members of a global security group named MarketingUsers. All of the marketing computer accounts are members of a global security group named MarketingComputers. In the domain, you have Group Policy objects (GPOs) as shown in the exhibit. (Click the Exhibit button.) You create two Password Settings objects named PSO1 and PSO2. PSO1 is applied to MarketingUsers. PSO2 is applied to MarketingComputers. The minimum password length is defined for each policy as shown in the following table. You need to identify the minimum password length required for each marketing user. What should you identify?
Answer
  • 5
  • 6
  • 7
  • 10
  • 12

Question 2

Question
Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012. You have a Group Policy object (GPO) named GPO1 that contains several custom Administrative templates. You need to filter the GPO to display only settings that will be removed from the registry when the GPO falls out of scope. The solution must only display settings that are either enabled or disabled and that have a comment. How should you configure the filter? To answer, select the appropriate options below. Select three.
Answer
  • Set to Managed: Yes
  • Set to Managed: No
  • Set to Managed: Any
  • Set to Configured: Yes
  • Set to Configured: No
  • Set to Configured: Any
  • Set to Commented: Yes
  • Set to Commented: No
  • Set to Commented: Any

Question 3

Question
Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named dc1.contoso.com. You discover that the Default Domain Policy Group Policy objects (GPOs) and the Default Domain Controllers Policy GPOs were deleted. You need to recover the Default Domain Policy and the Default Domain Controllers Policy GPOs. What should you run?
Answer
  • dcgpofix.exe /target:domain
  • gpfixup.exe /dc:dc1.contoso.com
  • dcgpofix.exe /target:both
  • gptixup.exe /oldnb:contoso /newnb:dc1

Question 4

Question
Your network contains an Active Directory domain named contoso.com. Domain controllers run either Windows Server 2008, Windows Server 2008 R2, or Windows Server 2012. You have a Password Settings object (PSOs) named PSO1. You need to view the settings of PSO1. Which tool should you use?
Answer
  • Group Policy Management
  • Server Manager
  • Get-ADAccountResultantPasswordReplicationPolicy
  • Active Directory Administrative Center

Question 5

Question
Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. You need to prevent all of the GPOs at the site level and at the domain level from being applied to users and computers in an organizational unit (OU) named OU1. You want to achieve this goal by using the minimum amount of Administrative effort. What should you use?
Answer
  • Add-ADGroupMember
  • Get-GPOReport
  • Gpfixup
  • Set-GPPermission
  • Gptedit.msc
  • dcgpofix
  • Import-GPO
  • Restore-GPO
  • Set-GPInheritance
  • Set-GPLink

Question 6

Question
Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. You have two GPOs linked to an organizational unit (OU) named OU1. You need to change the precedence order of the GPOs. What should you use?
Answer
  • dcgpofix
  • Get-GPOReport
  • Gpfixup
  • Gpresult
  • Gptedit.msc
  • Import-GPO
  • Restore-GPO
  • Set-GPInheritance
  • Set-GPLink
  • Set-GPPermission

Question 7

Question
Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. You need to provide an Administrator named Admin1 with the ability to create GPOs in the domain. The solution must not provide Admin1 with the ability to link GPOs. What should you use?
Answer
  • Gpfixup
  • Gpresult
  • Gptedit.msc
  • Import-GPO
  • Restore-GPO
  • Set-GPInheritance
  • Set-GPLink
  • Set-GPPermission
  • Gpupdate
  • Add-ADGroupMember

Question 8

Question
Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. The domain contains a GPO named GPO1. GPO1 contains several Group Policy preferences. You need to view all of the preferences configured in GPO1. What should you use?
Answer
  • dcgpofix
  • Get-GPOReport
  • Gpfixup
  • Gpresult
  • Gptedit.msc
  • Import-GPO
  • Restore-GPO
  • Set-GPInheritance
  • Set-GPLink
  • Set-GPPermission

Question 9

Question
Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. A network Administrator accidentally deletes the Default Domain Policy GPO. You do not have a backup of any of the GPOs. You need to recreate the Default Domain Policy GPO. What should you use?
Answer
  • dcgpofix
  • Get-GPOReport
  • Gpfixup
  • Gptedit.msc
  • mport-GPO
  • Restore-GPO
  • Set-GPInheritance
  • Set-GPLink
  • Set-GPPermission
  • Gpupdate

Question 10

Question
Your network contains an Active Directory domain named contoso.com. A user named User1 creates a central store and opens the Group Policy Management Editor as shown in the exhibit. (Click the Exhibit button.) You need to ensure that the default Administrative Templates appear in GPO1. What should you do?
Answer
  • Link a WMI filter to GPO1.
  • Add User1 to the Group Policy Creator Owners group.
  • Configure Security Filtering in GPO1.
  • Copy files from %Windir%\PolicyDefinitions to the central store.

Question 11

Question
Your network contains an Active Directory domain named contoso.com. Domain controllers run either Windows Server 2008, Windows Server 2008 R2, or Windows Server 2012. You have a Password Settings object (PSOs) named PSO1. You need to view the settings of PSO1. Which tool should you use?
Answer
  • Get-ADFineGrainedPasswordPolicy
  • Get-ADAccountResultantPasswordReplicationPolicy
  • Get-ADDomainControllerPasswordReplicationPolicy
  • Get-ADDefaultDomainPasswordPolicy

Question 12

Question
Your network contains an Active Directory domain named contoso.com. All user accounts reside in an organizational unit (OU) named OU1. All of the users in the marketing department are members of a group named Marketing. All of the users in the human resources department are members of a group named HR. You create a Group Policy object (GPO) named GPO1. You link GPO1 to OU1. You configure the Group Policy preferences of GPO1 to add two shortcuts named Link1 and Link2 to the desktop of each user. You need to ensure that Link1 only appears on the desktop of the users in Marketing and that Link2 only appears on the desktop of the users in HR. What should you configure?
Answer
  • Item-level targeting
  • Group Policy Inheritance
  • Security Filtering
  • WMI Filtering

Question 13

Question
Your network contains a single Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. The domain contains 400 desktop computers that run Windows 8 and 10 desktop computers that run Windows XP Service Pack 3 (SP3). All new desktop computers that are added to the domain run Windows 8. All of the desktop computers are located in an organizational unit (OU) named OU1. You create a Group Policy object (GPO) named GPO1. GPO1 contains startup script settings. You link GPO1 to OU1. You need to ensure that GPO1 is applied only to computers that run Windows XP SP3. What should you do?
Answer
  • Modify the Security settings of OU1.
  • Run the Set-GPLink cmdlet and specify the -target parameter.
  • Create and link a WMI filter to GPO1.
  • Run the Set-GPInheritance cmdlet and specify the -target parameter.

Question 14

Question
Computer1 is located in an OU, and the GPO1, User1 is another OU, and as GPO2, to ensure you can apply GPO1 to User1 should be how to do?
Answer
  • Security filtering
  • Inheritance
  • Gpupdate
  • GPO

Question 15

Question
Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. You have a Group Policy object (GPO) named GPO1 that contains hundreds of settings. GPO1 is linked to an organizational unit (OU) named OU1. OU1 contains 200 client computers. You plan to unlink GPO1 from OU1. You need to identify which GPO settings will be removed from the computers after GPO1 is unlinked from OU1. Which two GPO settings should you identify? (Each correct answer presents part of the solution. Choose two.)
Answer
  • The managed Administrative Template settings
  • The unmanaged Administrative Template settings
  • The System Services security settings
  • The Event Log security settings
  • The Restricted Groups security settings

Question 16

Question
Your network contains an Active Directory domain named contoso.com. The domain contains an organizational unit (OU) named IT and a OU named Sales. All of the help desk user accounts are located in the IT OU. All of the sales user accounts are located in the Sales OU. The Sales OU contains a global security group named G_Sales. The IT OU contains a global security group named G_HelpDesk. You need to ensure that members of G_HelpDesk can perform the following tasks: · Reset the passwords of the sales users. · Force the sales users to change their password at their next logon. What should you do?
Answer
  • Run the Set-ADFinecrainedPasswordPolicy cmdlet and specify the -identity parameter.
  • Right-click the IT OU and select Delegate Control.
  • Right-click the Sales OU and select Delegate Control.
  • Run the Set-ADAccountPassword cmdlet and specify the -identity parameter.

Question 17

Question
Your network contains an Active Directory domain named contoso.com. The domain contains 30 organizational units (OUs). You need to ensure that a user named User1 can link Group Policy Objects (GPOs) in the domain. What should you do?
Answer
  • From the Active Directory Users and Computers, add User1 to the Network Configuration Operators group.
  • From the Group Policies Management, click the contoso.com node and modify the Delegation settings.
  • From the Group Policies Management, click the Group policy Objects node and modify the Delegation settings.
  • From the Active Directory Users and Computers, add User1 to the Group Policy Creator Owners group.

Question 18

Question
Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. The domain contains 500 client computers that run Windows 8 Enterprise. You implement a Group Policy central store. You have an application named Appl. Appl requires that a custom registry setting be deployed to all of the computers. You need to deploy the custom registry setting. The solution must minimize administrator effort. What should you configure in a Group Policy object (GPO)?
Answer
  • The Administrative Templates
  • An application control policy
  • The Group Policy preferences
  • The Software Installation settings

Question 19

Question
Your network contains two Active Directory forests named contoso.com and adatum.com. All domain controllers run Windows Server 2012. The adatum.com domain contains a Group Policy object (GPO) named GPO1. An administrator from adatum.com backs up GPO1 to a USB flash drive. You have a domain controller named dcl.contoso.com. You insert the USB flash drive in dcl.contoso.com. You need to identify the domain-specific reference in GPO1. What should you do?
Answer
  • From Group Policy Management, run the Group Policy Results Wizard.
  • From the Migration Table Editor, click Populate from GPO.
  • From Group Policy Management, run the Group Policy Modeling Wizard.
  • From the Migration Table Editor, click Populate from Backup.

Question 20

Question
Your network contains two servers named Server1 and Server2. Both servers run Windows Server 2012 and have the DNS Server server role installed. On Server1, you create a standard primary zone named contoso.com. You need to ensure that Server2 can host a secondary zone for contoso.com. What should you do from Server1?
Answer
  • Add Server2 as a name server.
  • Convert contoso.com to an Active Directory-integrated zone.
  • Create a zone delegation that points to Server2.
  • Create a trust anchor named Server2.

Question 21

Question
You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access server role installed. On Server1, you create a network policy named Policy1. You need to configure Policy1 to apply only to VPN connections that use the L2TP protocol. What should you configure in Policy1?
Answer
  • The Tunnel Type
  • The Service Type
  • The NAS Port Type
  • The Framed Protocol

Question 22

Question
Your network contains an Active Directory domain named contoso.com. You have a standard primary zone names contoso.com. You need to ensure that only users who are members of a group named Group1 can create DNS records in the contoso.com zone. All other users must be prevented from creating, modifying, or deleting DNS records in the zone. What should you do first?
Answer
  • Run the Zone Signing Wizard for the zone.
  • From the properties of the zone, change the zone type.
  • Run the new Delegation Wizard for the zone.
  • From the properties of the zone, modify the Start Of Authority (SOA) record.

Question 23

Question
Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1. DC1 is a DNS server for contoso.com. The properties of the contoso.com zone are configured as shown in the exhibit. (See Exhibit) The domain contains a server named Server1 that is part of a workgroup named Workgroup. Server1 is configured to use DC1 as a DNS server. You need to ensure that Server1 dynamically registers a host (A) record in the contoso.com zone. What should you configure?
Answer
  • The Dynamic updates setting of the contoso.com zone
  • The workgroup name of Server1
  • The primary DNS suffix of Server1
  • The Security settings of the contoso.com zone

Question 24

Question
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012. You enable and configure Routing and Remote Access (RRAS) on Server1. You create a user account named User1. You need to ensure that User1 can establish VPN connections to Server1. What should you do?
Answer
  • Create a network policy.
  • Modify the members of the Remote Management Users group.
  • Create a connection request policy.
  • Add a RADIUS client.

Question 25

Question
Server1 as a DNS server hosts a Primary zone,Server2 is the secondary zone contoso.com domain, you need to determine how long Server2 Server1 to renew regional, how to configure
Answer
  • Refresh interval
  • Restart DNS
  • Forwarders
  • Stub zone

Question 26

Question
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and fabrikam.com. All of the DNS servers in both of the domains run Windows Server 2012. The network contains two servers named Server1 and Server2. Server1 hosts an Active Directory-integrated zone for contoso.com. Server2 hosts an Active Directoryintegrated zone for fabrikam.com. Server1 and Server2 connect to each other by using a WAN link. Client computers that connect to Server1 for name resolution cannot resolve names in fabrikam.com. You need to configure Server1 to support the resolution of names in fabrikam.com. The solution must ensure that users in contoso.com can resolve names in fabrikam.com if the WAN link fails. What should you do on Server1?
Answer
  • Add a forwarder.
  • Create a conditional forwarder.
  • Create a secondary zone.
  • Create a stub zone

Question 27

Question
Your network contains an Active Directory domain named contoso.com. The domain functional level in Windows Server 2008. All domain controllers run Windows Server 2008 R2. The domain contains a file server named Server1 that runs Windows Server 2012. Server1 has a BitLocker Drive Encryption (BitLocker)-encrypted drive. Server1 uses a trusted Platform Module (TPM) chip. You enable the Turn on TPM backup to Active Directory Domain Services policy setting by using a Group Policy object (GPO). You need to ensure that you can back up the BitLocker recovery information to Active Directory. What should you do?
Answer
  • Upgrade a domain controller to Windows 2012.
  • Enable the Store BitLocker recovery information in the Active Directory Services (Windows Server2008 and Windows Vista) policy settings.
  • Raise the forest functional level to Windows 2008 R2.
  • Add a BitLocker data recovery agent

Question 28

Question
Your company has a main office and a branch office. The main office is located in Seattle. The branch office is located in Montreal. Each office is configured as an Active Directory site. The network contains an Active Directory domain named adatum.com. The Seattle office contains a file server named Server1. The Montreal office contains a file server named Server2. The servers run Windows Server 2012 and have the File and Storage Services server role, the DFS Namespaces role service, and the DFS Replication role service installed. Server1 and Server2 each have a share named Share1 that is replicated by using DFS Replication. You need to ensure that users connect to the replicated folder in their respective office when they connect to \\contoso.com\Share1. Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)
Answer
  • Share and publish the replicated folder.
  • Modify the Referrals settings.
  • Create a new topology.
  • Create a namespace.
  • Create a replication connection.

Question 29

Question
Your network contains an Active Directory domain named adatum.com. The domain contains five servers. The servers are configured as shown in the following table. All desktop computers in adatum.com run Windows 8 and are configured to use BitLocker Drive Encryption (BitLocker) on all local disk drives. You need to deploy the Network Unlock feature. The solution must minimize the number of features and server roles installed on the network. To which server should you deploy the feature?
Answer
  • Server3
  • Server1
  • DC2
  • Server2
  • DC1

Question 30

Question
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012. Server1 has the File Server Resource Manager role service installed. You configure a quota threshold as shown in the exhibit. (Click the Exhibit button.) You need to ensure that a user named User1 receives an email notification when the threshold is exceeded. What should you do?
Answer
  • Configure the File Server Resource Manager Options.
  • Modify the members of the Performance Log Users group.
  • Create a performance counter alert.
  • Create a classification rule.
Show full summary Hide full summary

Similar

The SAT Math test essentials list
lizcortland
How to improve your SAT math score
Brad Hegarty
What is a Computer?
cscutt
Server test exam 2
Dondee
Server Test Exam 3
Dondee
70-411 - MCSA: Administering Windows Server 2012 - Exam 4
Mike M
70-411 - MCSA: Administering Windows Server 2012 - Exam 3
Mike M
70-411 - MCSA: Administering Windows Server 2012 - Exam 5
Mike M
70-411 - MCSA: Administering Windows Server 2012 - Exam 6
Mike M
RE Keywords - Paper 1 - Religion and life
Kerris Linney
Quick tips to improve your Exam Preparation
James Timpson