Want to know Actualtests exam ref 70 411 administering windows server 2012 r2 pdf Exam practice test features? Want to lear more about Microsoft Administering Windows Server 2012 certification experience? Study Highest Quality Microsoft 70 411 exam questions answers to Avant-garde 70 411 exam questions questions at Actualtests. Gat a success with an absolute guarantee to pass Microsoft 70 411 vce (Administering Windows Server 2012) test on your first attempt.


♥♥ 2021 NEW RECOMMEND ♥♥

Free VCE & PDF File for Microsoft 70-411 Real Exam (Full Version!)

★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions

Free Instant Download NEW 70-411 Exam Dumps (PDF & VCE):
Available on: http://www.surepassexam.com/70-411-exam-dumps.html

Q51. Your company has a main office and two branch offices. The main office is located in New York. The branch offices are located in Seattle and Chicago. 

The network contains an Active Directory domain named contoso.com. An Active Directory site exists for each office. Active Directory site links exist between the main office and the branch offices. All servers run Windows Server 2012 R2. 

The domain contains three file servers. The file servers are configured as shown in the following table. 

You implement a Distributed File System (DFS) replication group named ReplGroup. 

ReplGroup is used to replicate a folder on each file server. ReplGroup uses a hub and spoke topology. NYC-SVR1 is configured as the hub server. 

You need to ensure that replication can occur if NYC-SVR1 fails. 

What should you do? 

A. Create an Active Directory site link bridge. 

B. Create an Active Directory site link. 

C. Modify the properties of Rep1Group. 

D. Create a connection in Rep1Group. 

Answer:

Explanation: 

Unsure about this answer. 

D: 

A: 

The Bridge all site links option in Active Directory must be enabled. (This option is available in the Active Directory Sites and Services snap-in.) Turning off Bridge all site links can affect the ability of DFS to refer client computers to target computers that have the least expensive connection cost. An Intersite Topology Generator that is running Windows Server 2003 relies on the Bridge all site links option being enabled to generate the intersite cost matrix that DFS requires for its site-costing functionality. If you turn off this option, you must create site links between the Active Directory sites for which you want DFS to calculate accurate site costs. Any sites that are not connected by site links will have the maximum possible cost. For more information about site link bridging, see “Active Directory Replication Topology Technical Reference.” 

Reference: 

http: //faultbucket. ca/2012/08/fixing-a-dfsr-connection-problem/ 

http: //faultbucket. ca/2012/08/fixing-a-dfsr-connection-problem/ 

http: //technet. microsoft. com/en-us/library/cc771941. aspx 


Q52. DRAG DROP 

Your network contains an Active Directory forest named contoso.com. All domain controllers run Windows Server 2008 R2. 

The schema is upgraded to Windows Server 2012 R2. 

Contoso.com contains two servers. The servers are configured as shown in the following table. 

Server1 and Server2 host a load-balanced application pool named AppPool1. 

You need to ensure that AppPool1 uses a group Managed Service Account as its identity. 

Which three actions should you perform? 

To answer, move the three appropriate actions from the list of actions to the answer area and arrange them in the correct order. 

Answer: 


Q53. Your network contains an Active Directory domain named adatum.com. The domain contains five servers. The servers are configured as shown in the following table. 

All desktop computers in adatum.com run Windows 8 and are configured to use BitLocker Drive Encryption (BitLocker) on all local disk drives. 

You need to deploy the Network Unlock feature. The solution must minimize the number of features and server roles installed on the network. 

To which server should you deploy the feature? 

A. Server3 

B. Server1 

C. DC2 

D. Server2 

E. DC1 

Answer:

Explanation: 

The BitLocker-NetworkUnlock feature must be installed on a Windows Deployment Server (which does not have to be configured--the WDSServer service just needs to be running). 


Q54. Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that runs Windows Server 2012 R2. 

Server1 has the Windows Server updates Services server role installed and is configured to download updates from the Microsoft Update servers. 

You need to ensure that Server1 downloads express installation files from the Microsoft Update servers. 

What should you do from the Update Services console? 

A. From the Update Files and Languages options, configure the Update Files settings. 

B. From the Automatic Approvals options, configure the Update Rules settings. 

C. From the Products and Classifications options, configure the Products settings. 

D. From the Products and Classifications options, configure the Classifications settings. 

Answer:

Explanation: 

To specify whether express installation files are downloaded during synchronization 

In the left pane of the WSUS Administration console, click Options. 

In Update Files and Languages, click the Update Files tab. 

If you want to download express installation files, select the Download express installation files check box. If you do not want to download express installation files, clear the check box. 

Reference: http: //technet. microsoft. com/en-us/library/cc708431. aspx 

http: //technet. microsoft. com/en-us/library/cc708431. aspx 


Q55. Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012 R2. DC1 is backed up daily. 

The domain has the Active Directory Recycle Bin enabled. 

During routine maintenance, you delete 500 inactive user accounts and 100 inactive groups. One of the deleted groups is named Group1. Some of the deleted user accounts are members of some of the deleted groups. 

For documentation purposes, you must provide a list of the members of Group1 before the group was deleted. 

You need to identify the names of the users who were members of Group1 prior to its deletion. 

You want to achieve this goal by using the minimum amount of administrative effort. 

What should you do first? 

A. Mount the most recent Active Directory backup. 

B. Reactivate the tombstone of Group1. 

C. Perform an authoritative restore of Group1. 

D. Use the Recycle Bin to restore Group1. 

Answer:

Explanation: 

The Active Directory Recycle Bin does not have the ability to track simple changes to objects. 

If the object itself is not deleted, no element is moved to the Recycle Bin for possible recovery in the future. In other words, there is no rollback capacity for changes to object properties, or, in other words, to the values of these properties. 


Q56. Your network contains an Active Directory domain named contoso.com. Domain controllers run either Windows Server 2008, Windows Server 2008 R2, or Windows Server 2012 R2. 

You have a Password Settings object (PSOs) named PSO1. 

You need to view the settings of PSO1. 

Which tool should you use? 

A. Get-ADDefaultDomainPasswordPolicy 

B. Active Directory Administrative Center 

C. Local Security Policy 

D. Get-ADAccountResultantPasswordReplicationPolicy 

Answer:

Explanation: 

In Windows Server 2012, fine-grained password policy management is made much easier than Windows Server 2008/2008 R2. Windows Administrators not have to use ADSI Edit and configure complicated settings to create the Password Settings Object (PSO) in the Password Settings Container. Instead we can configure fine-grained password policy directly in Active Directory Administrative Center (ADAC). 


Q57. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. The domain contains 30 user accounts that are used for network administration. The user accounts are members of a domain global group named Group1. 

You identify the security requirements for the 30 user accounts as shown in the following table. 

You need to identify which settings must be implemented by using a Password Settings object (PSO) and which settings must be implemented by modifying the properties of the user accounts. 

What should you identify? To answer, configure the appropriate settings in the dialog box in the answer area. 

Answer: 


Q58. Your network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computers run Windows 8.1. 

The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2. 

You need to identify whether deleted objects can be recovered from the Active Directory Recycle Bin. 

Which cmdlet should you use? 

A. Get-ADGroupMember 

B. Get-ADDomainControllerPasswordReplicationPolicy 

C. Get-ADDomainControllerPasswordReplicationPolicyUsage 

D. Get-ADDomain 

E. Get-ADOptionalFeature 

F. Get-ADAccountAuthorizationGroup 

Answer:

Explanation: The Get-ADOptionalFeature cmdlet gets an optional feature or performs a search to retrieve multiple optional features from an Active Directory. 

Example: Get-ADOptionalFeature 'Recycle Bin Feature' 

Get the optional feature with the name 'Recycle Bin Feature'. 

Reference: Get-ADOptionalFeature 

https://technet.microsoft.com/en-us/library/ee617218.aspx 


Q59. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that has the Remote Access server role installed. 

DirectAccess is implemented on Server1 by using the default configuration. 

You discover that DirectAccess clients do not use DirectAccess when accessing websites on the Internet. 

You need to ensure that DirectAccess clients access all Internet websites by using their DirectAccess connection. 

What should you do? 

A. Configure a DNS suffix search list on the DirectAccess clients. 

B. Configure DirectAccess to enable force tunneling. 

C. Disable the DirectAccess Passive Mode policy setting in the DirectAccess Client Settings Group Policy object (GPO). 

D. Enable the Route all traffic through the internal network policy setting in the DirectAccess Server Settings Group Policy object (GPO). 

Answer:

Explanation: 

With IPv6 and the Name Resolution Policy Table (NRPT), by default, DirectAccess clients separate their intranet and Internet traffic as follows: 

. DNS name queries for intranet fully qualified domain names (FQDNs) and all intranet traffic is exchanged over the tunnels that are created with the DirectAccess server or directly with intranet servers. Intranet traffic from DirectAccess clients is IPv6 traffic. 

. DNS name queries for FQDNs that correspond to exemption rules or do not match the intranet namespace, and all traffic to Internet servers, is exchanged over the physical interface that is connected to the Internet. Internet traffic from DirectAccess clients is typically IPv4 traffic. 

In contrast, by default, some remote access virtual private network (VPN) implementations, including the VPN client, send all intranet and Internet traffic over the remote access VPN connection. Internet-bound traffic is routed by the VPN server to intranet IPv4 web proxy servers for access to IPv4 Internet resources. It is possible to separate the intranet and Internet traffic for remote access VPN clients by using split tunneling. This involves configuring the Internet Protocol (IP) routing table on VPN clients so that traffic to intranet locations is sent over the VPN connection, and traffic to all other locations is sent by using the physical interface that is connected to the Internet. 

You can configure DirectAccess clients to send all of their traffic through the tunnels to the DirectAccess server with force tunneling. When force tunneling is configured, DirectAccess clients detect that they are on the Internet, and they remove their IPv4 default route. With the exception of local subnet traffic, all traffic sent by the DirectAccess client is IPv6 traffic that goes through tunnels to the DirectAccess server. 


Q60. Your network contains an Active Directory domain named contoso.com. The network contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Network Policy and Access Services server role installed. 

You plan to deploy additional servers that have the Network Policy and Access Services server role installed. You must standardize as many settings on the new servers as possible. 

You need to identify which settings can be standardized by using Network Policy Server (NPS) templates. 

Which three settings should you identify? (Each correct answer presents part of the solution. Choose three.) 

A. IP filters 

B. shared secrets 

C. health policies 

D. network policies 

E. connection request policies 

Answer: A,B,C