(New Version) First Try Passleader Free Microsoft 70-413 Dumps and First Pass The 70-413 Certification Exam (81-100)
Info For 100% 70-413 Exam Pass: PassLeader have been updated the 70-413 exam dumps and added the new exam questions, in the latest version of VCE and PDF braindumps, you will get all the new changed 70-413 exam questions, which will help you 100% passing exam, and you will get the free version of VCE Player together with your 70-413 practice tests. QUESTION 81 Your network contains an Active Directory forest named contoso.com. The forest functional level is Windows Server 2012. The forest contains an Active Directory domain. The domain contains a global security group named GPO_Admins that is responsible for managing Group Policies in the forest. A second forest named fabrikam.com contains three domains. The forest functional level is Windows Server 2003. You need to design a trust infrastructure to ensure that the GPO_Admins group can create, edit, and link Group Policies in every domain of the fabrikam.com forest. What should you include in the design? More than one answer choice may achieve the goal. Select the BEST answer. A. A two-way forest trust B. A one-way forest trust C. Three external trusts D. Three shortcut trusts Answer: B QUESTION 82 Your network contains an Active Directory domain named contoso.com. Client computers run either Windows 7 or Windows 8. You plan to implement several Group Policy settings that will apply only to laptop computers. You need to recommend a Group Policy strategy for the planned deployment. What should you include in the recommendation? More than one answer choice may achieve the goal. Select the BEST answer. A. Loopback processing B. WMI filtering C. Security filtering D. Block inheritance Answer: B Explanation: http://www.discoposse.com/index.php/2012/04/05/group-policy-wmi-filter-laptop-or-desktop-hardware/ Another method to detect hardware as laptop only is to look for the presence of a battery based on the BatteryStatus property of the Win32_Battery class. By using the Win32_Battery class, we can search to see if there is a battery present. If the battery status is not equal to zero ( BatteryStatus <> 0 ) then you know that it is a laptop. QUESTION 83 Your network contains an Active Directory domain named contoso.com. The domain contains an organizational unit (OU) named OU1. You have a Group Policy object (GPO) named GPO1 that is linked to contoso.com. GPO1 contains custom security settings. You need to design a Group Policy strategy to meet the following requirements: - The security settings in GPO1 must be applied to all client computers. - Only GPO1 and other GPOs that are linked to OU1 must be applied to the client computers in OU1. What should you include in the design? More than one answer choice may achieve the goal. Select the BEST answer. A. Enable the Block Inheritance option at the domain level. Enable the Enforced option on GPO1. B. Enable the Block Inheritance option on OU1. Link GPO1 to OU1. C. Enable the Block Inheritance option on OU1. Enable the Enforced option on GPO1. D. Enable the Block Inheritance option on OU1. Enable the Enforced option on all of the GPOs linked to OU1. Answer: C QUESTION 84 A new company registers the domain name of contoso.com. The company has a web presence on the Internet. All Internet resources have names that use a DNS suffix of contoso.com. A third-party hosts the Internet resources and is responsible for managing the contoso.com DNS zone on the Internet. The zone contains several hundred records. The company plans to deploy an Active Directory forest. You need to recommend an Active Directory forest infrastructure to meet the following requirements: - Ensure that users on the internal network can resolve the names of the company's Internet resources. - Minimize the amount of administrative effort associated with the addition of new Internet servers. What should you recommend? A. A forest that contains a root domain named contoso.com and another domain named ad.contoso.com B. A forest that contains a root domain named contoso.com and another domain named contoso.local C. A forest that contains a single domain named contoso.local D. A forest that contains a single domain named contoso.com Answer: C QUESTION 85 Your network contains an Active Directory domain named contoso.com. The domain contains four computers that are configured as shown in the following table.
You plan to use domain controller cloning. You need to identify on which computers you can clone domain controllers that run Windows Server 2012. Which computers should you identify? (Each correct answer presents part of the solution. Choose all that apply.) A. Server1 B. Server2 C. Server3 D. Client1 Answer: AD Explanation: DC cloning can be done from either Hyper-V on Server 2012 and Hyper-V on Windows 8 QUESTION 86 Your network contains an Active Directory domain named contoso.com. The domain contains multiple sites. You plan to deploy DirectAccess. The network security policy states that when client computers connect to the corporate network from the Internet, all of the traffic destined for the Internet must be routed through the corporate network. You need to recommend a solution for the planned DirectAccess deployment that meets the security policy requirement. What should you include in the recommendation? A. Set the ISATAP State to state enabled. B. Enable split tunneling. C. Set the ISATAP State to state disabled. D. Enable force tunneling. Answer: D Explanation: http://blogs.technet.com/b/csstwplatform/archive/2009/12/15/directaccess-how-toconfigure-forcetunneling-forda-so-that-client-are-forced-to-use-ip-https.aspx You can configure DirectAccess clients to send all of their traffic through the tunnels to the DirectAccess server with force tunneling. When force tunneling is configured, DirectAccess clients that detect that they are on the Internet modify their IPv4 default route so that default route IPv4 traffic is not sent. With the exception of local subnet traffic, all traffic sent by the DirectAccess client is IPv6 traffic that goes through tunnels to the DirectAccess server. QUESTION 87 Your company has two divisions named Division1 and Division2. The network contains an Active Directory domain named contoso.com. The domain contains two child domains named division1.contoso.com and division2.contoso.com. The company sells division1 to another company. You need to prevent administrators in contoso.com and division2.contoso.com from gaining administrative access to the resources in division1.contoso.com. What should you recommend? A. Create a new tree in the forest named contoso.secure. Migrate the resources and the accounts in division1.contoso.com to contoso.secure. B. On the domain controller accounts in division1.contoso.com, deny the Enterprise Admins group the Allowed to Authenticate permission. C. Create a new forest and migrate the resources and the accounts in division1.contoso.com to the new forest. D. In division1.contoso.com, remove the Enterprise Admins group from the Domain Admins group and remove the Enterprise Admins group from the access control list (ACL) on the division1.contoso.com domain object. Answer: C QUESTION 88 Your network contains an Active Directory domain named contoso.com. On several organizational units (OUs), an administrator named Admin1 plans to delegate control of custom tasks. You need to ensure that Admin1 can delegate a custom task named Task1 by using the Delegation of Control Wizard. What should you do? A. Add a new class to the Active Directory schema. B. Configure a custom MMC console. C. Modify the Delegwiz.inf file. D. Configure a new authorization store by using Authorization Manager. Answer: C Explanation: http://support.microsoft.com/kb/308404 QUESTION 89 Your network contains 50 servers that run Windows Server 2003 and 50 servers that run Windows Server 2008. You plan to implement Windows Server 2012. You need to create a report that includes the following information: - The servers that run applications and services that can be moved to Windows Server 2012 - The servers that have hardware that can run Windows Server 2012 - The servers that are suitable to be converted to virtual machines hosted on Hyper-V hosts that run Windows Server 2012 What should you do? A. From an existing server, run the Microsoft Application Compatibility Toolkit (ACT). B. Install Windows Server 2012 on a new server, and then run the Windows Server Migration Tools. C. Install Windows Server 2012 on a new server, and then run Microsoft Deployment Toolkit (MDT) 2012. D. From an existing server, run the Microsoft Assessment and Planning (MAP) Toolkit. Answer: D QUESTION 90 Your network contains a server named Server1 that runs Windows Server 2012. Server1 has the DHCP Server server role installed. All of the client computers that are in a subnet named Subnet1 receive their IP address configurations from Server1. You plan to add another DHCP server named Server2 to Subnet1. You need to recommend changes to the DHCP infrastructure to ensure that the client computers continue to receive IP addressing information if a single DHCP server fails. What should you do? More than one answer choice may achieve the goal. Select the BEST answer. A. Create a Network Load Balancing (NLB) cluster. B. Configure Failover for the scope. C. Create a DHCP failover cluster. D. Create a split scope. Answer: B Explanation: http://blogs.technet.com/b/keithmayer/archive/2012/10/28/step-by-step-scoping-out-thenew-dhcpfailover-inwindows-server-2012-31-days-of-favorite-features-part-28-of-31.aspx#.UQhW-b-jbK0 http://www.passleader.com/70-413.html QUESTION 91 Your network contains an Active Directory forest named contoso.com. The forest contains one domain. Your company plans to open a new division named Division1. A group named Division1Admins will administer users and groups for Division1. You identify the following requirements for Division1: - All Division1 users must have a complex password that is 14 characters. - Division1Admins must be able to manage the user accounts for Division1. - Division1Admins must be able to create groups, and then delete the groups that they create. - Division1Admins must be able to reset user passwords and force a password change at the next logon for all Division1 users. You need to recommend changes to the forest to support the Division1 requirements. What should you recommend? More than one answer choice may achieve the goal. Select the BEST answer. A. Create a new child domain named divisionl.contoso.com. Move all of the Division1 user accounts to the new domain. Add the Division1Admin members to the Domain Admins group. Configure the password policy in a Group Policy object (GPO). B. In the forest, create a new organizational unit (OU) named Division1 and add Division1Admins to the Managed By attribute of the new OU. Move the Division1 user objects to the new OU. Create a fine-grained password policy for the Division1 users. C. Create a new forest. Migrate all of the Division1 user objects to the new forest and add the Division1Admins members to the Enterprise Admins group. Configure the password policy in a Group Policy object (GPO). D. In the forest, create a new organizational unit (OU) named Division1 and delegate permissions for the OU to the Division1Admins group. Move all of the Division1 user accounts to the new OU. Create a fine-grained password policy for the Division1 users. Answer: D QUESTION 92 Your company has a main office and four branch offices. The main office is located in London. The network contains an Active Directory domain named contoso.com. The network is configured as shown in the exhibit. (Click the Exhibit button.) Each office contains several servers that run Windows Server 2012. In each branch office, you plan to deploy an additional 20 servers that will run Windows Server 2012. Some of the servers will have a Server Core Installation of Windows Server 2012. You identify the following requirements for the deployment of the new servers: - Operating system images must be administered centrally. - The operating system images must be deployed by using PXE. - The WAN traffic caused by the deployment of each operating system must be minimized. You need to recommend a solution for the deployment of the new servers. What should you recommend?
A. Deploy Windows Deployment Services (WDS) in each office. Replicate the images by using Distributed File System (DFS) Replication. B. Deploy Windows Deployment Services (WDS) in each office. Copy the images by using BranchCache. C. Deploy Windows Deployment Services (WDS) in the main office only. Copy the images by using BranchCache. D. Deploy Windows Deployment Services (WDS) in the main office only. Replicate the images by using Distributed File System (DFS) Replication. Answer: A QUESTION 93 Your network contains an Active Directory domain named contoso.com. The domain contains a Microsoft System Center 2012 infrastructure. The domain contains two sites named Site1 and Site2. The sites connect to each other by using a 1-Mbps WAN link. The sites contain four servers. The servers are configured as shown in the following table.
In Site2, you plan to deploy 50 Hyper-V hosts. You need to recommend a solution to deploy the Hyper-V hosts by using VMM. The solution must minimize the amount of traffic between Site1 and Site2 during deployment. What should you recommend? A. On Server4, install VMM. From the Virtual Machine Manager console, add Server1 as a PXE server and add Server4 as a library server. B. On Server4/ install VMM. From the Virtual Machine Manager console, add Server1 as a PXE server and a library server. C. On Server4, install WDS. From the Virtual Machine Manager console, add Server4 as a PXE server and a library server. D. On Server4, install WDS. From the Virtual Machine Manager console, add Server4 as a PXE server and add Server1 as a library server. Answer: C QUESTION 94 Your network contains an Active Directory forest named contoso.com. You plan to add a new domain named child.contoso.com to the forest. On the DNS servers in child.contoso.com, you plan to create conditional forwarders that point to the DNS servers in contoso.com. You need to ensure that the DNS servers in contoso.com can resolve names for the servers in child. contoso.com. What should you create on the DNS servers in contoso.com? A. A root hint B. A zone delegation C. A conditional forwarder D. A trust point Answer: B QUESTION 95 Your network contains a server named Server1 that runs Windows Server 2012. Server1 has the DHCP Server server role installed. The network contains a Virtual Desktop Infrastructure (VDI). All virtual machines run Windows 8. You identify the following requirements for allocating IPv4 addresses to client computers: - All virtual desktops must have static IP addresses. - All laptop computers must receive dynamic IP addresses. - All virtual desktops must be prevented from obtaining dynamic address. You need to recommend a DHCP solution that meets the requirements for allocating IPv4 addresses. The solution must use the least amount of administrative effort. What should you recommend? More than one answer choice may achieve the goal. Select the BEST answer. A. Create two physical subnets. Configure 802.1x authentication for each subnet. B. Create two physical subnets. Connect the laptop computers to the subnet that contains Server1. C. Configure DHCP filtering. D. Configure DHCP policies. Answer: C Explanation: Policies would work too but filtering is less effort QUESTION 96 Your network contains an Active Directory forest that has two domains named contoso.com and europe. contoso.com. The forest contains five servers. The servers are configured as shown in the following table.
You plan to manage the DHCP settings and the DNS settings centrally by using IP Address Management (IPAM). You need to ensure that you can use IPAM to manage the DHCP and DNS settings in both domains. The solution must use the minimum amount of administrative effort. What should you do? A. Upgrade DCE1 and DCE2 to Windows Server 2012, and then install the IP Address Management (IPAM) Server feature. Run the Invoke-IpamGpoProvisioning cmdlet for each domain. B. Upgrade DCE1 and DCE2 to Windows Server 2012, and then install the IP Address Management (IPAM) Server feature. Run the Set-IpamConfiguration cmdlet for each domain. C. Upgrade DC1 and DC2 to Windows Server 2012, and then install the IP Address Management (IPAM) Server feature. Run the Set-IpamConfiguration cmdlet for each domain. D. Upgrade DC1 and DC2 to Windows Server 2012, and then install the IP Address Management (IPAM) Server feature. Run the Invoke-IpamGpoProvisioning cmdlet for each domain. Answer: A Explanation: Invoke-IpamGpoProvisioning Creates and links group policies in the specified domain for provisioning required access settings on the servers managed by the computer running the IP Address Management (IPAM) server. http://technet.microsoft.com/en-us/library/jj553805.aspx Set-IpamConfiguration Sets the configuration for the computer running the IP Address Management (IPAM) server, including the TCP port number over which the computer running the IPAM Remote Server Administration Tools (RSAT) client connects with the computer running the IPAM server. http://technet.microsoft.com/en-us/library/jj590816.aspx QUESTION 97 Your company is a hosting provider that provides cloud-based services to multiple customers. Each customer has its own Active Directory forest located in your company's datacenter. You plan to provide VPN access to each customer. The VPN solution will use RADIUS for authentication services and accounting services. You need to recommend a solution to forward authentication and accounting messages from the perimeter network to the Active Directory forest of each customer. What should you recommend? More than one answer choice may achieve the goal. Select the BEST answer. A. A RADIUS server for each customer and one RADIUS proxy B. A RADIUS server for each customer and a RADIUS proxy for each customer C. One RADIUS proxy and one Active Directory Lightweight Directory Services (AD LDS) instance for each customer D. One RADIUS proxy for each customer and Active Directory Federation Services (AD FS) Answer: A QUESTION 98 Your network contains an Active Directory domain named contoso.com. The domain contains two domain controllers named DC1 and DC2 that run Windows Server 2008 R2. You plan to replace the domain controllers with new servers that run Windows Server 2012. The new servers will be named DC3 and DC4. You need to recommend a strategy to replace DC1 and DC2 with DC3 and DC4. The solution must minimize the amount of disruption to the users. Which three actions should you recommend? To answer, move the appropriate three actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
QUESTION 99 Your network contains an Active Directory forest. The forest contains two domains named contoso.com and fabrikam.com. You plan to decommission the fabrikam.com domain. You need to perform the following migration tasks: - Copy user accounts from the fabrikam.com domain to the contoso.com domain. - Move the client computers from fabrikam.com to contoso.com. The solution must ensure that all of the user profiles are associated to the migrated user accounts. Which tool should you use to perform each task? To answer, drag the appropriate tool to the correct migration task in the answer area. Each tool may be used once, more than once, or not at all. Additionally, you may need to drag the split bar between panes or scroll to view content.
Answer:
QUESTION 100 Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2008 R2. Server1 is a file server. You deploy a new member server named Server2 that runs Windows Server 2012. You plan to migrate file shares from Server1 to Server2. File share and NTFS permissions are assigned only to domain local groups. You need to identify which actions are required to perform the migration. Which five actions should you identify? To answer, move the five appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
http://www.passleader.com/70-413.html
|