Point Checklist: examcollection 70 410

Master the 70 410 exam dumps Installing and Configuring Windows Server 2012 content and be ready for exam day success quickly with this Pass4sure exam collections 70 410 brain dumps. We guarantee it!We make it a reality and give you real microsoft 70 410 exam questions in our Microsoft exam 70 410 pdf braindumps.Latest 100% VALID Microsoft 70 410 pdf Exam Questions Dumps at below page. You can use our Microsoft microsoft 70 410 braindumps and pass your exam.

2017 NEW RECOMMEND

Free VCE & PDF File for Microsoft 70-410 Real Exam
(Full Version!)

Pass on Your First TRY 100% Money Back Guarantee Realistic Practice Exam Questions

Free Instant Download NEW 70-410 Exam Dumps (PDF & VCE):
Available on:
http://www.certleader.com/70-410-dumps.html

Q251. – (Topic 3) 

What should you do for server core so it can be managed from another server 2012 R2? 

A. 1 

B. 2 

C. 3 

D. 4 

E. 5 

F. 6 

G. 7 

H. 8 

I. 9 

J. 10 

K. 11 

L. 12 

M. 13 

N. 14 

O. 15 

Answer:

Explanation: 

You should join the server to the domain first. You can add workgroup servers to Server Manager on a domain joined server, however, you must first add the workgroup computer to the Trusted Hosts list using "Set-Item wsman:\\localhost\\Client\\TrustedHostsWorkgroupServerName -Concatenate -Force" 

Q252. – (Topic 3) 

Your network contains an Active Directory domain named contoso.com. The domain contains servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 has the Active Directory Federation Services server role installed.Server2 is a file server. 

Your company introduces a Bring Your Own Device (BYOD) policy. 

You need to ensure that users can use a personal device to access domain resources by using Single Sign-On (SSO) while they are connected to the internal network. 

Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.) 

A. Enable the Device Registration Service in Active Directory. 

B. Publish the Device Registration Service by using a Web Application Proxy. 

C. Configure Active Directory Federation Services (AD FS) for the Device Registration Service. 

D. Install the Work Folders role service on Server2. 

E. Create and configure a sync share on Server2. 

Answer: A,C 

Explanation: 

*Prepare your Active Directory forest to support devices. This is a one-time operation that you must run to prepare your Active Directory forest to support devices. To prepare the Active Directory forest On your federation server, open a Windows PowerShell command window and type: Initialize-ADDeviceRegistration *Enable Device Registration Service on a federation server farm node. To enable Device Registration Service: 

1. On your federation server, open a Windows PowerShell command window and type: Enable-AdfsDeviceRegistration. 

2.  Repeat this step on each federation farm node in your AD FS farm. 

Q253. HOTSPOT – (Topic 1) 

Your network contains an Active Directory forest. The forest contains a single domain named contoso.com. 

AppLocker policies are enforced on all member servers. 

You view the AppLocker policy applied to the member servers as shown in the exhibit. (Click the Exhibit button.) 

To answer, complete each statement according to the information presented in the exhibit. Each correct selection is worth one point. 

Answer: 

Q254. – (Topic 3) 

Your network contains an Active Directory domain named contoso.com. All user accounts in the sales department reside in an organizational unit (OU) named OU1. 

You have a Group Policy object (GPO) named GPO1. GPO1 is used to deploy a logon script to all of the users in the sales department. 

You discover that the logon script does not run when the sales users log on to their computers. You open Group Policy Management as shown in the exhibit. 

You need to ensure that the logon script in GPO1 is applied to the sales users. What should you do? 

A. Enforce GPO1. 

B. Modify the link order of GPO1. 

C. Modify the Delegation settings of GPO1. 

D. Enable the link of GPO1. 

Answer:

Q255. HOTSPOT – (Topic 3) 

You have a Group Policy object (GPO) named Server Audit Policy. The settings of the GPO are shown in the Settings exhibit. (Click the Exhibit button.) 

The scope of the GPO is shown in the Scope exhibit. (Click the Exhibit button.) 

The domain contains a group named Group1. The membership of Group1 is shown in the Group1 exhibit. (Click the Exhibit button.) 

Select Yes if the statement can be shown to be true based on the available information; otherwise select No. Each correct selection is worth one point. 

Answer: 

Q256. – (Topic 3) 

You work as an administrator at Contoso.com. The Contoso.com network consists of a single domain named Contoso.com. All servers in the Contoso.com domain, including domain controllers, have Windows Server 2012 R2 installed. 

You have configured a server, named ENSUREPASS-SR07, as a VPN server. You are required to configure new firewall rules for workstation connections. 

You want to achieve this using the least amount of administrative effort. 

Which of the following actions should you take? 

A. You should consider making use of the Enable-NetFirewallRule cmdlet. 

B. You should consider making use of the New-NetFirewallRule cmdlet. 

C. You should consider making use of dism.exe from the command prompt. 

D. You should consider making use of dsadd.exe from the command prompt. 

Answer:

Explanation: 

New-NetFirewallRule – Creates a new inbound or outbound firewall rule and adds the rule to the target computer. You can’t Enable what doesn’t exist yet… you must use New-NetFirewallRule 

Q257. – (Topic 3) 

Your network contains an Active Directory forest that contains three domains. A group named Group1 is configured as a domain local distribution group in the forest root domain. You plan to grant Group1 read-only access to a shared folder named Share1. Share1 is located in a child domain. 

You need to ensure that the members of Group1 can access Share1. 

What should you do first? 

A. Convert Group1 to a global distribution group. 

B. Convert Group1 to a universal security group. 

C. Convert Group1 to a universal distribution group. 

D. Convert Group1 to a domain local security group 

Answer:

Q258. – (Topic 3) 

You have a file server named Server1 that runs Windows Server 2012 R2. Server1 has following hardware configurations: 

-16GB of RAM 

-A single quad-core CPU 

-Three network teams that have two network adapters each 

You add additional CPUs and RAM to Server 1. 

You repurpose Server1 as a virtualization host. You install the Hyper-V server role on Server1. You need to create four external virtual switches in Hyper-V. Which cmdlet should you run first? 

A. Set-NetAdapter. 

B. Add-Net1.bfoTeamNic 

C. Add-VMNetworkAdapter 

D. Remove-NetLbfoTeam 

Answer:

Q259. – (Topic 3) 

You install Windows Server 2012 R2 on a standalone server named Server1. You configure Server1 as a VPN server. 

You need to ensure that client computers can establish PPTP connections to Server1. 

Which two firewall rules should you create? (Each correct answer presents part of the solution. Choose two.) 

A. An inbound rule for protocol 47 

B. An outbound rule for protocol 47 

C. An inbound rule for TCP port 1723 

D. An inbound rule for TCP port 1701 

E. An outbound rule for TCP port 1723 

F. An outbound rule for TCP port 1701 

Answer: A,C 

Explanation: 

The following is a list of firewall ports which need to be opened for the various VPN tunnel 

protocols: 

For PPTP: 

IP Protocol=TCP, TCP Port number=1723 <- Used by PPTP control path 

IP Protocol=GRE (value 47) <- Used by PPTP data path 

For L2TP: 

IP Protocol Type=UDP, UDP Port Number=500 <- Used by IKEv1 (IPSec control path) 

IP Protocol Type=UDP, UDP Port Number=4500 <- Used by IKEv1 (IPSec control path) 

IP Protocol Type=ESP (value 50) <- Used by IPSec data path 

For SSTP: 

IP Protocol=TCP, TCP Port number=443 <- Used by SSTP control and data path 

For IKEv2: 

IP Protocol Type=UDP, UDP Port Number=500 <- Used by IKEv2 (IPSec control path) 

IP Protocol Type=UDP, UDP Port Number=4500 <- Used by IKEv2 (IPSec control path) 

IP Protocol Type=ESP (value 50) <- Used by IPSec data path 

Q260. – (Topic 3) 

Your network contains an Active Directory forest named contoso.com. The forest contains a child domain named europe.contoso.com. The europe.contoso.com child domain 

contains a server named Server1 that runs Windows Server 2012 R2. You install the DHCP Server server role on Server1. You have access to the administrative accounts shown in the following table. 

A. Admin1 

B. Admin2 

C. Admin3 

D. Admin4 

Answer:

Explanation: 

A. Local account can’t be used 

B. Authorization needs to happen in contoso.com and must be an Ent Admin 

C. Authorization needs to happen in contoso.com and must be an Ent Admin 

D. Correct domain and is a member of Ent Admin’s 

Certleader Dumps
Certleader is a company specialized on providing high quality IT exam materials and fully committed to assist our respected clients crack any IT certification tests on their 1st efforts.