70-411 - MCSA: Administering Windows Server 2012 - Exam 1

Description

This exam measures your ability to accomplish the technical tasks listed below: Deploy, Manage, and Maintain Servers Configure File and Print Services Configure Network Services and Access Configure a Network Policy Server Infrastructure Configure and Manage Active Directory Configure and Manage Group Policy
Mike M
Quiz by Mike M, updated more than 1 year ago More Less
Mike M
Created by Mike M about 6 years ago
Mike M
Copied by Mike M about 6 years ago
108
1

Resource summary

Question 1

Question
Your network contains an Active Directory domain named contoso.com. The functional level of the forest is Server 2008 R2. Computer accounts for the marketing department are in an organizational unit (OU) named Departments\Marketing\Computers. User accounts for the marketing department are in an OU named Departments\Marketing\Users. All of the marketing user accounts are members of a global security group named MarketingUsers. All of the marketing computeraccounts are members of a global security group named MarketingComputers. In the domain, you have Group Policy objects (GPOs) as shown in the exhibit. You create two Password Settings objects named PSO1 and PSO2. PSO1 is applied to MarketingUsers. PSO2 is applied to MarketingComputers. The minimum password length is defined for each policy as shown in the following table: You need to identify the minimum password length required for each marketing user. What should you identify?
Answer
  • 5
  • 6
  • 7
  • 10
  • 12

Question 2

Question
Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012. You have a Group Policy object (GPO) named GPO1 that contains several custom Administrative templates. You need to filter the GPO to display only settings that will be removed from the registry when the GPO falls out of scope. The solution must only display settings that are either enabled or disabled and that have a comment. How should you configure the filter? Select three.
Answer
  • Set Managed to: Any
  • Set Managed to: No
  • Set Managed to: Yes
  • Set Configured to: Any
  • Set Configured to: No
  • Set Configured to: Yes
  • Set Commented to: Any
  • Set Commented to: No
  • Set Commented to: Yes

Question 3

Question
Your network contains an Active Directory domain named contoso.com. You have several Windows PowerShell scripts that execute when users log on to their client computer. You need to ensure that all of the scripts execute completely before users can access their desktop. Which setting should you configure?
Answer
  • Allow logon scripts when NETBIOS or WINS is disabled.
  • Specify maximum time for Group Policy scripts.
  • Run Windows PowerShell scripts first at computer startup, s...
  • Run logon scripts synchronously
  • Display instructions in shutdown scripts as they run
  • Run startup scripts asynchronously
  • Display instructions in startup scripts as they run
  • Run Windows PowerShell scripts first at user logon, logoff

Question 4

Question
Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named dc1.contoso.com. You discover that the Default Domain Policy Group Policy Objects (GPOs) and the Default Domain Controllers Policy GPOs were deleted. You need to recover the Default Domain Policy and the Default Domain Controllers Policy GPOs. What should you run?
Answer
  • dcgpofix.exe /target:domain
  • gpfixup.exe /dc:dc1.contoso.com
  • dcgpofix.exe /target:both
  • gpfixup.exe /oldnb:contoso /newnb:dc1

Question 5

Question
Your network contains an Active Directory domain named contoso.com. Domain controllers run either Windows Server 2008, Windows Server 2008 R2, or Windows Server 2012. You have a Password Settings object (PSOs) named PSO1. You need to view the settings of PSO1. Which tool should you use?
Answer
  • Group Policy Management
  • Server Manager
  • Get-ADAccountResultantPasswordReplicationPolicy
  • Active Directory Administrative Center

Question 6

Question
Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy Objects (GPOs). Currently, there are no enforced GPOs. You need to prevent all of the GPOs at the site level and at the domain level from being applied to users and computers in an Organizational Unit (OU) named OU1. You want to achieve this goal by using the minimum amount of Administrative effort. What should you use?
Answer
  • Get-GPOReport
  • Gpfixup
  • Gpresult
  • Gpedit.msc
  • Import-GPO
  • Restore-GPO
  • Set-GPInheritance
  • Set-GPLink
  • Set-GPPermission
  • Gpupdate

Question 7

Question
Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy Objects (GPOs). Currently, there are no enforced GPOs. You need to change the preference order of the GPOs. What should you use?
Answer
  • dcgpofix
  • Gpupdate
  • Gpfixup
  • Gpresult
  • GPedit.msc
  • Import-GPO
  • Restore-GPO
  • Set-GPInheritance
  • Set-GPLink
  • Set-GPPermissioon

Question 8

Question
Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy Objects (GPOs). Currently, there are no enforced GPOs. You need to provide an Administrator named Admin1 with the ability to create GPOs in the domain. The solution must not provide Admin1 with the ability to link GPOs. What should you use?
Answer
  • dcgpofix
  • Get-GPOReport
  • Gpfixup
  • Gpresult
  • GPedit.msc
  • Import-GPO
  • Restore-GPO
  • Set-GPInheritance
  • Set-GPLink
  • Set-GPPermission

Question 9

Question
Your network contains an Active Directory domain named contoso.com. The domain contains a Group Policy object (GPO) named GPO1. GPO1 contains several Group Policy preferences. You need to view all of the preferences configured in GPO1. What should you use?
Answer
  • dcgpofix
  • Get-GPOReport
  • Gpfixup
  • Gpresult
  • GPedit.msc
  • Import-GPO
  • Restore-GPO
  • Set-GPInheritance
  • Set-GPLink
  • Set-GPPermissioon

Question 10

Question
Your network contains a Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs), Currently, there are no enforced GPOs. A network administrator accidentally deletes the Default Domain Policy GPO. You do not have a backup of any of the GPOs. You need to recreate the Default Domain Policy GPO. What should you use?
Answer
  • dcgpofix
  • Get-GPOReport
  • Gpfixup
  • Gpresult
  • GPedit.msc
  • Import-GPO
  • Restore-GPO
  • Set-GPInheritance
  • Set-GPLink
  • Set-GPPermissioon

Question 11

Question
Your network contains a Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs), Currently, there are no enforced GPOs. The domain is renamed to adatum.com. Group Policies no longer function correctly. You need to ensure the existing GPOs are applied to users and computers. You want to achieve this goal by using the minimum amount of Administrative effort. What should you use?
Answer
  • dcgpofix
  • Gpupdate
  • Gpfixup
  • Gpresult
  • GPedit.msc
  • Import-GPO
  • Restore-GPO
  • Set-GPInheritance
  • Set-GPLink
  • Set-GPPermissioon

Question 12

Question
Your network contains a Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs), Currently, there are no enforced GPOs. The domain contains a top-level organizational unit (OU) for each department. A group named Group1 contains members from each department. You have a GPO named GPO1 that is linked to the domain. You need to configure GPO1 to apply settings to Group1 only. What should you use?
Answer
  • dcgpofix
  • Get-GPOReport
  • Gpfixup
  • Gpresult
  • GPedit.msc
  • Import-GPO
  • Restore-GPO
  • Set-GPInheritance
  • Set-GPLink
  • Set-GPPermission

Question 13

Question
Your network contains an Active Directory domain named contoso.com. A user named User1 creates a central store and opens the Group Policy Management Editor. You need to ensure that the default Administrative Templates appear in GPO1. What should you do?
Answer
  • Link a WMI filter to GPO1
  • Add User1 to the Group Policy Creator Owners group
  • Configure Security Filtering in GPO1.
  • Copy files from %Windir%\PolicyDefinitions to the central store.

Question 14

Question
Your network contains a single Active Directory domain named contoso.com. The domain contains an Active Directory site named Site and an Organizational Unit (OU) named OU1. The domain contains a client computer named Client1 that is located in OU1 and Site1. You create five Group Policy Objects (GPOs). The GPOs are configured as shown in the following table: You need to identify in which order the GPOs will be applied to Client1. In which order should you arrange the listed GPOs?
Answer
  • GPO1, GPO2, GPO3, GPO4, GPO5
  • GPO3, GPO4, GPO5, GPO1, GPO2,
  • GPO1, GPO4, GPO5, GPO2, GPO3
  • GPO4, GPO5, GPO2, GPO3, GPO1
  • GPO5, GPO4, GPO2, GPO3, GPO1
  • GPO2, GPO3, GPO4, GPO5, GPO1
  • GPO3, GPO1, GPO2, GPO4, GPO5
  • GPO4, GPO5, GPO1, GPO2, GPO3

Question 15

Question
Your network contains an Active Directory domain named contoso.com. Domain controllers run either Windows Server 2008 , Windows Server 2008 R2, or Windows Server 2012. You have a Password Settings object (PSOs) named PSO1. You need to view the settings of PSO1. What tool should you use?
Answer
  • Get-ADFineGrainedPasswordPolicy
  • Get-ADAccountResultantPasswordReplicationPolicy
  • Get-ADDomainControllerPasswordReplicationPolicy
  • Get-ADDefaultDomainPasswordPolicy

Question 16

Question
Your network contains a production Active Directory forest named contoso.com and a test Active Directory forest named test.contoso.com. There is no network connectivity between contoso.com and test.contoso.com. The test.contoso.com domain contains a Group Policy object (GPO) named GPO1. You need to apply the settings in GPO1 to the contoso.com domain. Which four actions should you perform?
Answer
  • Run the Copy-GPO cmdlet in test.contoso.com.
  • Run the Restore-GPO cmdlet in contoso.com.
  • Use removable media to transfer the contents of the test.contoso.com to contoso.com
  • Run the Copy-GPO cmdlet in contoso.com.
  • Run the Backup-GPO cmdlet in test.contoso.com
  • Run the New-GPO cmdlet in contoso.com
  • Run the Import-GPO cmdlet in contoso.com.

Question 17

Question
Your network contains a single Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2. The domain contains 400 desktop computers that run Windows 8 and 10 desktop computers that run Windows XP Service Pack 3 (SP3). All new desktop computers that are added to the domain run Windows 8. All of the desktop computers are located in an Organizational Unit (OU) named OU1. You create a Group Policy object (GPO) named GPO1. GPO1 contains startup script settings. You link GPO1 to OU1. You need to ensure that GPO1 is applied only to computers that run Windows XP SP3. What should you do?
Answer
  • Modify the Security Settings of OU1
  • Run the Set-GPLink cmdlet and specify the -target parameter
  • Create and link a WMI filter to GPO1
  • Run the Set-GPInheritance cmdlet and specify the -target parameter

Question 18

Question
Your network contains an Active Directory domain named contoso.com. All user accounts reside in an Organizational Unit (OU) named OU1. All of the users in the marketing department are members of a group named Marketing. All of the users in the human resources department are members of a group named HR. You create a Group Policy object (GPO) named GPO1. You link GPO1 to OU1. You configure the Group Policy preferences of GPO1 to add two shortcuts named Link1 and Link2 to the desktop of each user. You need to ensure that Link1 only appears on the desktop of users in Marketing and that Link2 only appears on the desktop of the users in HR. What should you configure?
Answer
  • Item-level targeting
  • Group Policy Inheritance
  • Security Filtering
  • WMI Filtering

Question 19

Question
Your network contains an Active Directory domain named contoso.com. The domain contains 30 user accounts that are used for network administration. The user accounts are members of a domain global group named Group1. You identify the security requirements for the 30 user accounts as shown in the following table. You need to identify which settings must be implemented by using a Password Settings object (PSO) and which settings must be implemented by modifying the properties of the user accounts. What should you identify? Choose 4:
Answer
  • PSO: Minimum password length
  • User account properties: Minimum password length
  • PSO: Account is sensitive and cannot be delegated
  • User account properties: Account is sensitive and cannot be delegated
  • PSO: User cannot change password
  • User account properties: User cannot change password
  • PSO: Enforce password history
  • User account properties: Enforce password history

Question 20

Question
Computer1 is located in an OU, and the GPO1, User1 is another OU, and as GPO2, to ensure you can apply GPO1 to User1, should be how to do?
Answer
  • Security Filtering
  • Inheritance
  • GPUpdate
  • GPO4

Question 21

Question
Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. You have a GPO named GPO1 that contains hundreds of settings. GPO1 is linked to an OU named OU1. OU1 contains 200 client computers. You plan to unlink GPO1 from OU1. You need to identify which GPO settings will be removed from the computers after GPO1 is unlinked from OU1. Which two GPO settings should you identify?
Answer
  • The managed Administrative Template Settings
  • The Unmanaged Administrative Template Settings
  • The System Services security settings
  • The Event Log security settings
  • The Restricted Groups security settings

Question 22

Question
Your network contains an Active Directory domain named contoso.com. The domain contains an organizational unit (OU) named IT and an OU named Sales. All of the help desk user accounts are located in the IT OU. All of the sales user accounts are located in the Sales OU. The Sales OU contains a global security group named G_Sales. The IT OU contains a global security group named G_HelpDesk. You need to ensure that members of the G_HelpDesk can both reset the passwords of the sales users and force the sales users to change their password at their next logon. What should you do?
Answer
  • Run the Set-ADFineGrainedPasswordPolicy cmdlet and specify the -Identity parameter
  • Right-click the IT OU and select Delegate Control
  • Right-click the Sales OU and select Delegate Control
  • Run the Set-ADAccountPassword cmdlet and specify the -identity parameter

Question 23

Question
Your network contains an Active Directory domain named contoso.com. The domain contains 30 organizational units, (OUs). You need to ensure that a user named User1 can link Group Policy Objects (GPOS) in the domain. What should you do?
Answer
  • From the Active Directory User and Computers, add User1 to the Network Configuration Operators group.
  • From the Group Policies Management, click the contoso.com node and modify the Delegation settings.
  • From the Group Policies Management, click the Group Policy Objects node and modify the Delegation settings
  • From the Active Directory Users and Computers, add user1 to the Group Policy Creator Owners group.

Question 24

Question
Your network contains an Active Directory domain named contoso.com. All client computers run Windows 7. Group Policy objects (GPOs) are linked to the domain as shown in the exhibit. GPO2 contains user configurations only, and GPO3 contains Computer configurations only. You need to configure the GPOs to meet he following requirements: -Ensure that GPO2 only applies to the user accounts in OU2 that are members of a Global Group named Group2. -Ensure that GPO3 only applies to the computer accounts in OU3 that have more than 100GB free disk space. What should you do?
Answer
  • Configure Security Filtering on GPO2 and WMI Filtering on GPO3
  • Configure Security Filtering on GPO2 and Security Filtering on GPO3
  • Configure Enforced Settings on GPO2 and WMI Filtering on GPO3
  • Configure WMI Filtering on GPO2 and WMI Filtering on GPO3
  • Configure WMI Filtering on GPO2 and Enforced Settings on GPO3

Question 25

Question
Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. The domain contains 500 client computers that run Windows 8 Enterprise. You implement a Group Policy Central Store. You have an application named App1. App1 requires that a custom registry setting be deployed to all users. You need to deploy the custom registry setting. The solution must minimize administrative effort. What should you configure in a Group Policy object (GPOs)?
Answer
  • Administrative Templates
  • An application control policy
  • The Group Policy preferences
  • The Software Installation settings

Question 26

Question
Your network contains two Active Directory forests named contoso.com and adatum.com. All domain controllers run Windows Server 2012. The adatum.com domain contains a Group Policy object (GPO) named GPO1. An administrator from adatum.com backs up GPO1 to a USB flash drive. You have a domain controller named DC1.contoso.com. You insert the USB flash drive in DC1.contoso.com. You need to identify the domain-specific reference in GPO1. What should you do?
Answer
  • From Group Policy Management, run Group Policy Results Wizard.
  • From the Migration Table Editor, click Populate from GPO
  • From Group Policy Management, run the Group Policy Modeling Wizard
  • From the Migration Table Editor, click Populate from Backup.

Question 27

Question
Your network contains an Active Directory domain named contoso.com All client computers run Windows Vista Service pack 2 (SP2). All client computers are in an organizational unit (OU) named OU1. All user accounts are in an OU named OU2. All users log on to their client computer by using standard user accounts. A Group Policy object (GPO) named GPO1 is linked to OU1. A GPO named GPO2 is linked to OU2. You need to apply advanced audit policy settings to all of the client computers. What should you do?
Answer
  • In GPO1, configure a startup script that runs auditpol.exe
  • In GPO2, configure a logon script that runs auditpol.exe.
  • In GPO1, configure the Advanced Audit Policy Configuration settings.
  • In GPO2, configure the Advanced Audit Policy Configuration settings.

Question 28

Question
Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. An organizational unit (OU) named OU1 contains 200 client computers that run Windows 8 Enterprise. A Group Policy object (GPO) named GPO1 is linked to OU1. You make a change to GPO1. You need to force all of the computers in OU1 to refresh their Group Policy settings immediately. The solution must minimize administrative effort. Which tool should you use?
Answer
  • Group Policy Object Editor
  • The secedit command
  • Group Policy Management Console (GPMC)
  • Active Directory Users and Computers

Question 29

Question
Your network contains an Active Directory domain named contoso.com. The domain contains a Web server named www.contoso.com. The Web server is available on the Internet. You implement DirectAccess by using the default configuration. You need to ensure that users never attempt to connect to www.contoso.com by using DirectAccess. The solution must not prevent the users from using DirectAccess to access other resources in contoso.com. Which settings should you configure in a Group Policy object (GPO)?
Answer
  • Name Resolution Policy
  • DNS Clients
  • Network Connections
  • DirectAccess Client Experience Settings

Question 30

Question
You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access server role installed. You need to configure the ports on Server1 to ensure that client computers can establish VPN connection to Server1 by using TCP port 443. What should you modify?
Answer
  • Wan Miniport (IKEv2)
  • Wan Miniport (PPPOE)
  • Wan Miniport (L2TP)
  • Wan Miniport (PPTP)
  • Wan Miniport (SSTP)

Question 31

Question
You have a DNS server named Server1. Server1 has a primary zone named contoso.com. Zone Aging/Scavenging is configured for the contoso.com zone. One month ago, an Administrator removed a server named Server2 from the network. You discovered that a static resource record for Server2 is present in contoso.com. Resource records for decommissioned client computers are removed automatically from contoso.com. You need to ensure that the static resource records for all of the servers are removed automatically from contoso.com What should you modify?
Answer
  • The security settings of the static resource records.
  • The Expires after value of contoso.com
  • The Record time stamp value of the static resource records.
  • The time-to-live (TTL) value of the static resource records.

Question 32

Question
Your network contains two Active Directory domains named contoso.com and adatum.com. The network contains a server named Server1 that runs Windows Server 2012. Server1 has the DNS server role installed. Server1 has a copy of the contoso.com DNS zone. You need to configure Server1 to resolve names in the adatum.com domain. The solution must meet the following requirements: Prevent the need to change the configuration of the name servers that host zones for adatum.com and minimize administrative effort. Which type of zone should you create?
Answer
  • Primary
  • Secondary
  • Reverse Lookup
  • Stub

Question 33

Question
Your network contains two servers named Server1 and Server2. Both servers run Windows Server 2012 and have the DNS Server server role installed. On Server1, you create a standard primary zone named contoso.com. You need to ensure that Server2 can host a secondary zone for contosos.com. What should you do from Server1?
Answer
  • Add Server2 as a name server
  • Convert contoso.com to an Active Directory-integrated zone
  • Create a zone delegation that points to Server2
  • Create a trust anchor named Server2

Question 34

Question
You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access server role installed. On Server1, you create a network policy named Policy1. You need to configure Policy1 to apply only to VPN connections that use the L2TP protocol. What should you configure in Policy1?
Answer
  • The Tunnel Type
  • The Service Type
  • The NAS Port Type
  • The Framed Protocol

Question 35

Question
Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012. All sales users have laptop computers that run Windows 8. The sales computers are joined to the domain. All user accounts for the sales department are in an organizational unit (OU) named Sales_OU. A Group Policy object (GPO) named GPO1 is linked to the Sales_OU. You need to configure a dial-up connection for all of the sales users. What should you configure from User Configuration in GPO1?
Answer
  • Policies /Administrative Templates/Network/Windows Connect Now
  • Policies/Administrative Templates/Windows Components/Windows Mobility Center
  • Preferences/Control Panel Settings/Network Options
  • Policies /Administrative Templates/Network/Network Connections

Question 36

Question
Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All domain controllers run Windows Server 2012 and are configured as DNS servers. All DNS zones are Active Directory integrated. Active Directory recycle bin is enabled. You need to modify the amount of time deleted objects are retained in the Active Directory Recycle Bin. Which naming context should you use in ADSI edit?
Answer
  • RootDSE
  • Schema
  • ForestDNSZones
  • DomainDNSZones
  • Configuration
  • Default naming context

Question 37

Question
Your network contains an Active Directory domain named contoso.com. You have a standard primary zone named contoso.com You need to ensure that only users who are members of a group named Group1 can create DNS records in the contoso.com zone. All other users must be prevented from creating, modifying, or deleting DNS records in the zone. What should you do first?
Answer
  • Run the Zone Signing Wizard for the zone
  • From the properties of the zone, change the zone type.
  • Run the new Delegation Wizard for the zone
  • From the properties of the zone, modify the Start Of Authority (SOA) record.

Question 38

Question
Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1. DC1 is a DNS server for contoso.com. The network contains a server named Server1 that is part of a workgroup named Workgroup. You need to ensure that Server1 dynamically registers a host (A) record in the contoso.com zone. What should you configure?
Answer
  • The Dynamic updates settings of the contoso.com zone
  • The workgroup name of Server1
  • The primary DNS suffix of Server1
  • The Security settings of the contsoo.com zone

Question 39

Question
Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. One of the domain controllers is named DC1. The DNS zone for the contoso.com zone is Active Directory-integrated and has the default settings. A server named Server1 is a DNS server that runs a UNIX-based operating system. You plan to use Server1 as a secondary DNS server for the contoso.com zone. You need to ensure that Server1 can host a secondary copy of the contoso.com zone. What should you do?
Answer
  • From a Windows PowerShell, run the Set-DNSServerSetting cmdlet and specify DC1 as a target.
  • From DNS Manager, modify the Zone Transfers settings of the contoso.com zone.
  • From DNS Manager, modify the replication scope of the contoso.com zone.
  • From DNS manager, modify the Security settings of the contoso.com zone.

Question 40

Question
You have a server named Server1 that has the Web Server (IIS) server role installed. You obtain a Web Server certificate. You need to configure a website on Server1 to use Secure Socket Layer (SSL). To which store should you import the certificate?
Answer
  • Certificate (Local Computer) > Personal
  • Certificate (Local Computer) > Trusted Root Certification Authorities
  • Certificate (Local Computer) > Enterprise Trust
  • Certificate (Local Computer) > Intermediate Certificate Authorities
  • Certificate (Local Computer) > Trusted Publishers
  • Certificate (Local Computer) > Untrusted Certificates
  • Certificate (Local Computer) > Third-Party Root Certificate Authorities
  • Certificate (Local Computer) > Trusted People
  • Certificate (Local Computer) > Client Authentication Issueres
  • Certificate (Local Computer) > Web Hosting
Show full summary Hide full summary

Similar

CCNA Security 210-260 IINS - Exam 3
Mike M
The Internet
Gee_0599
SQL Quiz
R M
Application of technology in learning
Jeff Wall
The SAT Math test essentials list
lizcortland
Innovative Uses of Technology
John Marttila
How to improve your SAT math score
Brad Hegarty
Ch1 - The nature of IT Projects
mauricio5509
CCNA Answers – CCNA Exam
Abdul Demir
Translations and transformations of functions
Christine Laurich
Professional, Legal, and Ethical Issues in Information Security
mfundo.falteni