QUESTION 61

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012 R2.

 

All client computers run Windows 8 Enterprise.

 

DC1 contains a Group Policy object (GPO) named GPO1.

 

You need to deploy a VPN connection to all users.

 

What should you configure from User Configuration in GPO1?

 

A.

Policies/Administrative Templates/Network/Windows Connect Now

B.

Policies/Administrative Templates/Network/Network Connections

C.

Policies/Administrative Templates/Windows Components/Windows Mobility Center

D.

Preferences/Control Panel Settings/Network Options

 

Correct Answer: D

Explanation:

1. Open the Group Policy Management Console. Right-click the Group Policy object (GPO) that should contain the new preference item, and then click Edit.

2. In the console tree under Computer Configuration or User Configuration, expand the Preferences folder, and then expand the Control Panel Settings folder.

3. Right-click the Network Options node, point to New, and select VPN Connection.

 

The Network Options extension allows you to centrally create, modify, and delete dial-up networking and virtual private network (VPN) connections. Before you create a network option preference item, you should review the behavior of each type of action possible with the extension.

http://technet.microsoft.com/en-us/library/cc772449.aspx

 

clip_image002

QUESTION 62

Your network contains an Active Directory domain named contoso.com. All client computers run Windows 8.1.

 

The network contains a shared folder named FinancialData that contains five files.

 

You need to ensure that the FinancialData folder and its contents are copied to all of the client computers.

 

Which two Group Policy preferences should you configure? (Each correct answer presents part of the solution. Choose two.)

 

A.

Shortcuts

B.

Network Shares

C.

Environment

D.

Folders

E.

Files

 

Correct Answer: DE

Explanation:

Folder preference
items allow you to create, update, replace, and delete folders and their contents. (To configure individual files rather than folders, see Files Extension.) Before you create a Folder preference item, you should review the behavior of each type of action possible with this extension.

File preference items allow you to copy, modify the attributes of, replace, and delete files. (To configure folders rather than individual files, see Folders Extension.) Before you create a File preference item, you should review the behavior of each type of action possible with this extension.

 

 

QUESTION 63

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2.

 

You have a Group Policy object (GPO) named GPO1 that contains hundreds of settings. GPO1 is linked to an organizational unit (OU) named OU1. OU1 contains 200 client computers.

 

You plan to unlink GPO1 from OU1.

 

You need to identify which GPO settings will be removed from the computers after GPO1 is unlinked from OU1.

 

Which two GPO settings should you identify? (Each correct answer presents part of the solution. Choose two.)

 

A.

The managed Administrative Template settings

B.

The unmanaged Administrative Template settings

C.

The System Services security settings

D.

The Event Log security settings

E.

The Restricted Groups security settings

 

Correct Answer: AD

Explanation:

http://technet.microsoft.com/en-us/library/cc778402(v=ws.10).aspx

http://technet.microsoft.com/en-us/library/bb964258.aspx

There are two kinds of Administrative Template policy settings: Managed and Unmanaged . The Group Policy service governs Managed policy settings and removes a policy setting when it is no longer within scope of the user or computer

 

 

QUESTION 64

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2. The domain contains 500 client computers that run Windows 8.1 Enterprise and Microsoft Office 2013.

 

You implement a Group Policy central store.

 

You need to modify the default Microsoft Office 2013 Save As location for all client computers. The solution must minimize administrative effort.

 

What should you configure in a Group Policy object (GPO)?

 

A.

The Group Policy preferences

B.

An application control policy

C.

The Administrative Templates

D.

The Software Installation settings

 

Correct Answer: A

Explanation:

Group Policy preferences provide the means to simplify deployment and standardize configurations. They add to Group Policy a centralized system for deploying preferences (that is, settings that users can change later). You can also use Group Policy preferences to configure applications that are not Group Policy-aware. By using Group Policy preferences, you can change or delete almost any registry setting, file or folder, shortcut, and more. You are not limited by the contents of Administrative Template files.

http://technet.microsoft.com/en-us/library/dn581922.aspx

 

 

QUESTION 65

HOTSPOT

Your network contains an Active Directory domain named contoso.com.

 

You have several Windows PowerShell scripts that execute when users log on to their client computer.

 

You need to ensure that all of the scripts execute completely before the users can access their desktop.

 

Which setting should you configure?

 

To answer, select the appropriate setting in the answer area.

 

clip_image004

 

Correct Answer:

clip_image006

< span lang="EN-US" style="font-family: ; mso-font-kerning: 0pt; mso-no-proof: yes"> 

 

QUESTION 66

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2.

 

The domain contains 200 Group Policy objects (GPOs).

 

An administrator named Admin1 must be able to add new WMI filters from the Group Policy Management Console (GPMC).

 

You need to delegate the required permissions to Admin1. The solution must minimize the number of permissions assigned to Admin1.

 

What should you do?

 

A.

From Active Directory Users and Computers, add Admin1 to the WinRMRemoteWMIUsers_group.

B.

From Group Policy Management, assign Creator Owner to Admin1 for the WMI Filters container.

C.

From Active Directory Users and Computers, add Admin1 to the Domain Admins group.

D.

From Group Policy Management, assign Full control to Admin1 for the WMI Filters container.

 

Correct Answer: D

Explanation:

Users with Full control permissions can create and control all WMI filters in the domain, including WMI filters created by others.

Users with Creator owner permissions can create WMI filters, but can only control WMI filters that they create.

http://technet.microsoft.com/en-us/library/cc757429(v=ws.10).aspx

 

 

QUESTION 67

HOTSPOT

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the Remote Access server role installed.

 

You have a client named Client1 that is configured as an 802. IX supplicant.

 

You need to configure Server1 to handle authentication requests from Client1. The solution must minimize the number of authentication methods enabled on Server1.

 

Which authentication method should you enable? To answer, select the appropriate authentication method in the answer area.

&
nbsp;

clip_image008

 

Correct Answer:

clip_image010

 

 

QUESTION 68

HOTSPOT

Your network contains an Active Directory domain named contoso.com.

 

All DNS servers host a DNS zone named adatum.com. The adatum.com zone is not Active Directory-integrated.

 

An administrator modifies the start of authority (SOA) record for the adatum.com zone.

 

After the modification, you discover that when you add or modify DNS records in the adatum.com zone, the changes are not transferred to the DNS servers that host secondary copies of the adatum.com zone.

 

You need to ensure that the records are transferred to all the copies of the adatum.com zone.

 

What should you modify in the SOA record for the adatum.com zone?

 

To answer, select the appropriate setting in the answer area.

 

clip_image012

 

Correct Answer:

clip_image014

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

QUESTION 69

HOTSPOT

Your network contains an Active Directory domain named contoso.com.

 

You implement DirectAccess.

 

You need to view the properties of the DirectAccess connection.

 

Which connection properties should you view?

 

To answer, select the appropriate connection properties in the answer area.

 

clip_image016

 

Correct Answer:

clip_image018

 

QUESTION 70

Your network contains two DNS servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 hosts a primary zone for contoso.com. Server2 hosts a secondary zone for contoso.com.

 

You need to ensure that Server2 replicates changes to the contoso.com zone every five minutes.

 

Which setting should you modify in the start of authority (SOA) record?

 

A.

Retry interval

B.

Expires after

C.

Minimum (default) TTL

D.

Refresh interval

 

Correct Answer: D

Explanation:

By default, the refresh interval for each zone is set to 15 minutes. The refresh interval is used to determine how often other DNS servers that load and host the zone must attempt to renew the zone.

 

clip_image020

 

 

Free VCE & PDF File for Microsoft 70-411 Real Exam

Instant Access to Free VCE Files: MCSE|MCSA|MCITP…
Instant Access to Free PDF Files: MCSE|MCSA|MCITP…