Your success in exam 70 417 is our sole target and we develop all our 70 417 exam in a way that facilitates the attainment of this target. Not only is our 70 417 vce material the best you can find, it is also the most detailed and the most updated. 70 417 dumps for Microsoft 70-417 are written to the highest standards of technical accuracy.

Online Microsoft 70-417 free dumps demo Below:

NEW QUESTION 1
Your network contains an Active Directory domain named contoso.com. The domain contains client computers that run Either Windows XP, Windows 7, or Windows 8.
Network Policy Server (NPS) is deployed to the domain. You plan to create a system health validator (SHV).
You need to identify which policy settings can be applied to all of the computers.
Which three policy settings should you identify? (Each correct answer presents part of the
solution. Choose three.)

  • A. Automatic updating is enabled.
  • B. A firewall is enabled for all network connections.
  • C. An antispyware application is on.
  • D. Antispyware is up to date.
  • E. Antivirus is up to date.

Answer: ABE

Explanation: http://technet.microsoft.com/en-us/library/cc731260.aspx
* System health agent (SHA) is a NAP component.
* System health agent (SHA)
A component that checks the state of the client computer to determine whether the settings monitored by the SHA are up-to-date and configured correctly. For example, the Windows Security Health Agent (WSHA) can monitor Windows Firewall, whether antivirus software is installed, enabled, and updated, whether antispyware software is installed, enabled, and updated, and whether Microsoft Update Services is enabled and the computer has the most recent security updates from Microsoft Update Services. There might also be SHAs (and corresponding system health validators) available from other companies that provide different functionality.
 

NEW QUESTION 2
Which terminology is being described below?
These trusts are sometimes necessary when users need access to resources that are located in a Windows NT 4.0 domain or in a domain that is in a separate Active Directory Domain Services (AD DS) forest that is not joined by a forest trust.

  • A. Shortcut Trusts
  • B. Realm Trusts
  • C. Forest Trusts
  • D. External Trust

Answer: D

Explanation: You can create an external trust to form a one-way or two-way, nontransitive trust with domains that are outside your forest http://technet.microsoft.com/enus/library/cc775736%28v=ws.10%29.aspx Trust types
70-417 dumps exhibit
http://technet.microsoft.com/en-us/library/cc731297.aspx
Understanding When to Create a Realm Trust When to create a realm trust You can establish a realm trust between any non-Windows Kerberos version 5 (V5) realm and an Active Directory domain. This trust relationship allows cross-platform interoperability with security services that are based on other versions of the Kerberos V5 protocol, for example, UNIX and MIT implementations. Realm trusts can switch from non transitive to transitive and back. Realm trusts can also be either one-way or two way.
 

NEW QUESTION 3
Your network contains an Active Directory forest named contoso.com. All domain controllers currently run Windows Server 2008 R2.
You plan to install a new domain controller named DC4 that runs Windows Server 2012 R2.
The new domain controller will have the following configurations:
✑ Schema master
✑ Global catalog server
✑ DNS Server server role
✑ Active Directory Certificate Services server role
You need to identify which configurations cannot be fulfilled by using the Active Directory Domain Services Configuration Wizard.
Which two configurations should you identify? (Each correct answer presents part of the solution. Choose two.)

  • A. Enable the global catalog server.
  • B. Transfer the schema master.
  • C. Install the Active Directory Certificate Services role.
  • D. Install the DNS Server role.

Answer: BC

Explanation: AD Installation Wizard will automatically install DNS and allows for the option to set it as a global catalog server. ADCS and schema must be done separately.
70-417 dumps exhibit
 

NEW QUESTION 4
You have a server named Server1 that runs Windows Server 2012 R2.
You plan to enable Hyper-V Network Virtualization on Server1.
You need to install the Windows Network Virtualization Filter Driver on Server1. Which Windows PowerShell cmdlet should you run?

  • A. Set-NetVirtualizationGlobal
  • B. Enable-NetAdapterBinding
  • C. Add - WindowsFeature
  • D. Set-NetAdapterVmq

Answer: B

Explanation: Hyper-V Network Virtrtualization runs multiple virtual networks on a physical network. And each virtual network operates as if it is running as a physical network. The The Set-NetAdaptercmdlet sets the basic properties of a network adapter such as virtual LAN (VLAN) identifier (ID) and MAC address. Thus if you add the binding parameter to the command then you will be able to install the Windows Network Virtualization Filter Driver. Step one:Enable Windows Network Virtualization (WNV). This is a binding that is applied to the NIC that you External Virtual Switch is bound to. This can be a physical NIC, it can be an LBFO NIC team. Either way, it is the network adapter that your External Virtual Switch uses to exit the server.This also means that if you have multiple virtual networks or multiple interfaces that you can pick and choose and it is not some global setting.If you have one External Virtual Switch this is fairly easy:
$vSwitch = Get-VMSwitch -SwitchType External# Check if Network Virtualization is bound# This could be done by checking for the binding and seeing if it is enabledForEach-Object - InputObject $vSwitch {if ((Get-NetAdapterBinding -ComponentID "ms_netwnv" - InterfaceDescription $_.NetAdapterInterfaceDescription).Enabled -eq $false){ # Lets enable itEnable-NetAdapterBinding -InterfaceDescription $_.NetAdapterInterfaceDescription - ComponentID "ms_netwnv"}}
 

NEW QUESTION 5
HOTSPOT
Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server 2012 R2. The servers have the Hyper-V server role installed.
A certification authority (CA) is available on the network.
A virtual machine named vml.contoso.com is replicated from Server1 to Server2. A virtual machine named vm2.contoso.com is replicated from Server2 to Server1.
You need to configure Hyper-V to encrypt the replication of the virtual machines. Which common name should you use for the certificates on each server?
To answer, configure the appropriate common name for the certificate on each server in the answer area.
70-417 dumps exhibit

    Answer:

    Explanation: 70-417 dumps exhibit
     

    NEW QUESTION 6
    DRAG DROP
    Your network contains an Active Directory domain named contoso.com. All client computers run Windows 8.
    Group Policy objects (GPOs) are linked to the domain as shown in the exhibit. (Click the Exhibit button.)
    70-417 dumps exhibit
    GPO2 contains computer configurations only and GPO3 contains user configurations only. You need to configure the GPOs to meet the following requirements:
    ✑ Ensure that GPO2 only applies to the computer accounts in OU2 that have more than one processor.
    ✑ Ensure that GPO3 only applies to the user accounts in OU3 that are members of a
    security group named SecureUsers.
    Which setting should you configure in each GPO?
    To answer, drag the appropriate setting to the correct GPO. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
    70-417 dumps exhibit

      Answer:

      Explanation: 70-417 dumps exhibit
       

      NEW QUESTION 7
      Which of the following features is available when Windows Server 2012 R2 is installed using the GUI option but without the desktop experience feature installed?

      • A. Metro-style Start screen
      • B. Built-in help system
      • C. All of these
      • D. Windows Media Player

      Answer: AB

      Explanation: Here is description of Desktop Experience: http://technet.microsoft.com/en-us/library/cc772567.aspx
      70-417 dumps exhibit
       

      NEW QUESTION 8
      You have a server named Server1 that runs Windows Server 2012 R2. From Server Manager, you install the Active Directory Certificate Services server role on Server1.
      A domain administrator named Admin1 logs on to Server1. When Admin1 runs the Certification Authority console, Admin1 receive the following error message.
      70-417 dumps exhibit
      You need to ensure that when Admin1 opens the Certification Authority console on Server1, the error message does not appear.
      What should you do?

      • A. Install the Active Directory Certificate Services (AD CS) tools
      • B. Configure the Active Directory Certificate Services server role from Server Manager
      • C. Run the regsvr32.exe command
      • D. Modify the PATH system variable

      Answer: B

      Explanation:  

      NEW QUESTION 9
      A network technician installs Windows Server 2012 R2 Standard on a server named Server1.
      A corporate policy states that all servers must run Windows Server 2012 R2 Enterprise. You need to ensure that Server1 complies with the corporate policy.
      You want to achieve this goal by using the minimum amount of administrative effort. What should you perform?

      • A. a clean installation of Windows Server 2012 R2
      • B. an upgrade installation of Windows Server 2012 R2
      • C. online servicing by using Dism
      • D. offline servicing by using Dism

      Answer: C

      Explanation: A. Not least effort
      B. Not least effort
      C. dism /online /set-edition
      D. offline would be less ideal and more workex: DISM /online /Set- Edition:ServerEnterprise/ProductKey:489J6-VHDMP-X63PK-3K798-CPX3YWindows Server 2008 R2/2012 contains a command-line utility called DISM (Deployment Image Servicing and Management tool). This tool has many features, but one of those features is the ability to upgrade the edition of Windows in use. Note that this process is for upgrades only and is irreversible. You cannot set a Windows image to a lower edition. The lowest edition will not appear when you run the /Get- TargetEditions option.
      If the server is running an evaluation version of Windows Server 2012 R2 Standard or Windows Server 2012 R2 Datacenter, you can convert it to a retail version as follows:
      If the server is a domain controller, you cannot convert it to a retail version. In this case, install an additional domain controller on a server that runs a retail version and remove AD DS from the domain controller that runs on the evaluation version. From an elevated command prompt, determine the current edition name with the command DISM /online
      /Get-CurrentEdition. Make note of the edition ID, an abbreviated form of the edition name. Then run DISM /online /Set-Edition:<edition ID> /ProductKey:XXXXXXXXXX-XXXXX- XXXXXXXXXX/AcceptEula, providing the edition ID and a retail product key.
      The server will restart twice.
       

      NEW QUESTION 10
      Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012. The domain contains a server named Server1.
      You open Review Options in the Active Directory Domain Services Configuration Wizard, and then you click View script.
      You need to ensure that you can use the script to promote Server1 to a domain controller. Which file extension should you use to save the script?

      • A. .bat
      • B. .ps1
      • C. .xml
      • D. .cmd

      Answer: B

      Explanation: The View Script button is used to view the corresponding PowerShell script The PowerShell script extension is .ps1, The Answer could logically be either a .cmd file or a .bat file.
      According to http://www.fileinfo.com/:
      PAL Settings file created by Corel Painter or Palette of colors used by Dr. Halo bitmap images BAT DOS batch file used to execute commands with the Windows Command Prompt (cmd.exe); contains aseries of line commands that typically might be entered at the DOS command prompt; most commonly used tostart programs and run maintenance utilities within Windows. XML XML (Extensible Markup Language) data file that uses tags to define objects and object attributes;formatted much like an .HTML document, but uses custom tags to define objects and the data within eachobject; can be thought of as a text- based database.
      CMD Batch file that contains a series of commands executed in order; introduced with Windows NT, but canbe run by DOS or Windows NT systems; similar to a .BAT file, but is run by CMD.EXE instead of COMMAND.COM.
       

      NEW QUESTION 11
      Your network contains a Hyper-V host named Server1 that runs Windows Server 2012 R2. Server1 hosts a virtual machine named VM1 that runs Windows Server 2012 R2.
      You create a checkpoint of VM1, and then you install an application on VM1. You verify that the application runs properly.
      You need to ensure that the current state of VM1 is contained in a single virtual hard disk file.
      The solution must minimize the amount of downtime on VM1. What should you do?

      • A. From a command prompt run dism.exe and specify the /commit-image parameter.
      • B. From a command prompt, run dism.exe and specify the /delete-image parameter.
      • C. From Hyper-V Manager, delete the checkpoint.
      • D. From Hyper-V Manager, inspect the virtual hard disk.

      Answer: C

      Explanation:  

      NEW QUESTION 12
      Your network contains an Active Directory domain named contoso.com. The domain contains an organizational unit (OU) named AHServers.OU.
      You create and link a Group Policy object (GPO) named GP01 to AllServer.OU. GPO1 is configured as shown in the exhibit. (Click the Exhibit button.)
      70-417 dumps exhibit
      You need to ensure that GPO1 only applies to servers that have Remote Desktop Services (RDS) installed.
      What should you configure?

      • A. Item-level targeting
      • B. WMI Filtering
      • C. Security Filtering
      • D. Block Inheritance

      Answer: B

      Explanation: Windows Management Instrumentation (WMI) filters allow you to dynamically determine the scope of Group Policy objects (GPOs) based on attributes of the target computer. When a GPO that is linked to a WMI filter is applied on the target computer, the filter is
      evaluated on the target computer. If the WMI filter evaluates to false, the GPO is not applied. If the WMI filter evaluates to true, the GPO is applied.
       

      NEW QUESTION 13
      HOTSPOT
      Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The forest contains two Active Directory sites named Site1 and Site2.
      You plan to deploy a read-only domain controller (RODC) named DC10 to Site2. You pre- create the DC10 domain controller account by using Active Directory Users and Computers.
      You need to identify which domain controller will be used for initial replication during the promotion of the RODC.
      Which tab should you use to identify the domain controller? To answer, select the appropriate tab in the answer area.
      70-417 dumps exhibit

        Answer:

        Explanation: 70-417 dumps exhibit
         

        NEW QUESTION 14
        HOTSPOT
        You have a server named Server1 that has the Web Server (IIS) server role installed. You obtain a Web Server certificate.
        You need to configure a website on Server1 to use Secure Sockets Layer (SSL). To which store
        should you import the certificate?
        To answer, select the appropriate store in the answer area.
        70-417 dumps exhibit

          Answer:

          Explanation: When organizations deploy their own public key infrastructure (PKI) and install a private trusted root CA, their CA automatically sends its certificate to all domain member computers in the organization. The domain member client and server computers store the CA certificate in the Trusted Root Certification Authorities certificate store. After this occurs, the domain member computers trust certificates that are issued by the organization trusted root CA.
          For example, if you install AD CS, the CA sends its certificate to the domain member computers in your organization and they store the CA certificate in the Trusted Root Certification Authorities certificate store on the local computer. If you also configure and autoenroll a server certificate for your NPS servers and then deploy PEAP-MS-CHAP v2 for wireless connections, all domain member wireless client computers can successfully authenticate your NPS servers using the NPS server certificate because they trust the CA
          that issued the NPS server certificate.
          On computers that are running the Windows operating system, certificates that are installed on the computer are kept in a storage area called the certificate store. The certificate store is accessible using the Certificates Microsoft Management Console (MMC) snap-in.
          This store contains multiple folders, where certificates of different types are stored. For example, the certificate store contains a Trusted Root Certification Authorities folder where the certificates from all trusted root CAs are kept.
          When your organization deploys a PKI and installs a private trusted root CA using AD CS, the CA automatically sends its certificate to all domain member computers in the organization. The domain member client and server computers store the CA certificate in the Trusted Root Certification Authorities folder in the Current User and the Local Computer certificate stores. After this occurs, the domain member computers trust certificates that are issued by the trusted root CA.
          Similarly, when you autoenroll computer certificates to domain member client computers, the certificate is kept in the Personal certificate store for the Local Computer. When you autoenroll certificates to users, the user certificate is kept in the Personal certificate store for the Current User.
          http: //technet. microsoft. com/en-us/library/cc730811. aspx http: //technet. microsoft. com/en-us/library/cc730811. aspx
          http: //technet. microsoft. com/en-us/library/cc772401%28v=ws. 10%29. aspx http: //technet. microsoft. com/en-us/library/ee407543%28v=ws. 10%29. aspx
           

          NEW QUESTION 15
          You have a server named Server1 that runs a Server Core Installation of Windows Server 2012 R2 Datacenter.
          You have a WIM file that contains the four images of Windows Server 2012 R2 as shown in the Images exhibit. (Click the Exhibit button.)
          70-417 dumps exhibit
          You review the installed features on Server1 as shown in the Features exhibit. (Click the Exhibit button.)
          70-417 dumps exhibit
          You need to install the Server Graphical Shell feature on Server1.
          Which two possible sources can you use to achieve this goal? (Each correct answer presents a complete solution. Choose two.)

          • A. Index 1
          • B. Index 2
          • C. Index 3
          • D. Index 4

          Answer: BD

          Explanation:  

          NEW QUESTION 16
          Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2.
          You enable and configure Routing and Remote Access (RRAS) on Server1. You create a user account named User1.
          You need to ensure that User1 can establish VPN connections to Server1. What should you do?

          • A. Modify the members of the Remote Management Users group
          • B. Add a RADIUS client
          • C. Modify the Dial-in setting of User1
          • D. Create a connection request policy

          Answer: C

          Explanation:  

          NEW QUESTION 17
          Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC4 that runs Windows Server 2012 R2.
          You create a DCCIoneConfig.xml file. You need to clone DC4. Where should you place DCCIoneConfig.xml on DC4?

          • A. %Systemroot%SYSVOL
          • B. %Systemdrive%
          • C. %Systemroot%NTDS
          • D. %Programdata%Microsoft

          Answer: C

          Explanation: http://technet.microsoft.com/de-de/library/hh831734.aspx
          70-417 dumps exhibit
           

          NEW QUESTION 18
          Your network contains an Active Directory domain named adatum.com. The domain contains a server named Server1 that runs WindowsServer 2012 R2. Server1 is configured as a Network Policy Server (NPS) server and as a DHCP server.
          You need to ensure that only computers that send a statement of health are checked for
          Network Access Protection (NAP) health requirements.
          Which two settings should you configure? (Each correct answer presents part of the solution. Choose two.)

          • A. The NAS Port Type constraints
          • B. The MS-Service Class conditions
          • C. The Health Policies conditions
          • D. The NAP-Capable Computers conditions
          • E. The Called Station ID constraints

          Answer: CD

          Explanation:
          The NAP-Capable ensures that the machine is able to send a statement of health, and the Health Policy tells it which policy to evaluate against.
           

          P.S. prep-labs.com now are offering 100% pass ensure 70-417 dumps! All 70-417 exam questions have been updated with correct answers: https://www.prep-labs.com/dumps/70-417/ (453 New Questions)