We provide real mcsa 70 410 pdf exam questions and answers braindumps in two formats. Download PDF & Practice Tests. Pass Microsoft 70 410 dumps pdf Exam quickly & easily. The 70 410 exam dumps PDF type is available for reading and printing. You can print more and practice many times. With the help of our Microsoft mcsa 70 410 dumps pdf and vce product and material, you can easily pass the 70 410 vce exam.

Q151. - (Topic 1) 

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has three physical network adapters named NIC1, NIC2, and NIC3. 

On Server1, you create a NIC team named Team1 by using NIC1 and NIC2. You configure Team1 to accept network traffic on VLAN 10. 

You need to ensure that Server1 can accept network traffic on VLAN 10 and VLAN 11. The solution must ensure that the network traffic can be received on both VLANs if a network adapter fails. 

What should you do? 

A. From Server Manager, change the load balancing mode of Team1. 

B. Run the New-NetLbfoTeam cmdlet. 

C. From Server Manager, add an interface to Team1. 

D. Run the Add-NetLbfoTeamMember cmdlet. 

Answer:


Q152. - (Topic 3) 

You work as an administrator at Contoso.com. The Contoso.com network consists of two Active Directory forests, named Contoso.com and test.com. There is no trust relationship configured between the forests. 

A backup of Group Policy object (GPO) from the test.com domain is stored on a domain controller in the Contoso.com domain. 

You are informed that a GPO must be created in the Contoso.com domain, and must be based on the settings of the GPO in the test.com domain. 

You start by creating the new GPO using the New-GPO Windows PowerShell cmdlet. You want to complete the task via a Windows PowerShell cmdlet. 

Which of the following actions should you take? 

A. You should consider making use of the Invoke-GPUpdate Windows PowerShell cmdlet. 

B. You should consider making use of the Copy-GPO Windows PowerShell cmdlet. 

C. You should consider making use of the New-GPLink Windows PowerShell cmdlet. 

D. You should consider making use of the Import-GPO Windows PowerShell cmdlet. 

Answer:

Explanation: 

Import-GPO -Imports the Group Policy settings from a backed-up GPO into a specified GPO. 


Q153. - (Topic 3) 

Your network contains an Active Directory domain named adatum.com. The domain contains the servers shown in the following table. 

You need to ensure that you can use Server Manager on DC1 to manage DC2. 

Which two tasks should you perform? (Each correct answer presents part of the solution. Choose two.) 

A. Install Microsoft .NET Framework 4 on DC2. 

B. Install Remote Server Administration Tools on DC1. 

C. Install the Windows PowerShell 2.0 engine on DC1. 

D. Install Remote Server Administration Tools on DC2. 

E. Install Windows Management Framework 3.0 on DC2. 

Answer: A,E 

Explanation: 

In Windows Server 2012 R2, you can use Server Manager to perform management tasks on remote servers. Remote management is enabled by default on servers that are running Windows Server 2012 R2. To manage a server remotely by using Server Manager, you add the server to the Server Manager server pool. You can use Server Manager to manage remote servers that are running Windows Server 2008 and Windows Server 2008 R2, but the following updates are required to fully manage these older operating systems. Windows Management Framework 3.0. To use this release of Server Manager to access and manage remote servers that are running Windows Server 2008 or Windows Server 2008 R2, you must first install .NET Framework 4.0, and then install Windows Management Framework 3.0 on those servers. 

Reference: 

Training Guide: Installing and Configuring Windows Server 2012 R2, Chapter 2: Deploying servers, p. 80 


Q154. - (Topic 2) 

Your network contains a Hyper-V host named Server1 that runs Windows Server 2012 R2. 

Server1 hosts a virtual machine named VM1 that runs Windows Server 2012 R2. 

You create a checkpoint of VM1, and then you install an application on VM1. You verify 

that the application runs properly. 

You need to ensure that the current state of VM1 is contained in a single virtual hard disk 

file. 

The solution must minimize the amount of downtime on VM1. 

What should you do? 

A. From a command prompt, run dism.exe and specify the /delete-image parameter. 

B. From a command prompt, run dism.exe and specify the /commit-image parameter. 

C. From Hyper-V Manager, delete the checkpoint. 

D. From Hyper-V Manager, inspect the virtual hard disk. 

Answer:


Q155. - (Topic 2) 

Your network contains a server named Server1 that runs Windows Server 2012 R2.Server1 has the Hyper-V server role installed. Server1 hosts four virtual machines named VM1, VM2, VM3, and VM4.Server1 is configured as shown in the following table. 

VM3 is used to test applications. 

You need to prevent VM3 from synchronizing its clock to Server1. 

What should you configure? 

A. NUMA topology 

B. Resource control 

C. Resource metering 

D. Virtual Machine Chimney 

E. The VLAN ID 

F. Processor Compatibility 

G. The startup order 

H. Automatic Start Action 

I. Integration Services 

J. Port mirroring 

K. Single-root I/O visualization 

Answer:

Explanation: 

Integration Services settings on virtual machines includes services such as operating system shutdown, time synchronization, data exchange, Heart beat, and Backup (volume snapshot services. Thus you should disable the time synchronization using Integration Services. 

References: http://blogs.technet.com/b/virtualization/archive/2008/08/29/backing-up-hyper-v-virtual-machines.aspx Exam Ref 70-410, Installing and Configuring Windows Server 2012 R2, Chapter 3: Configure Hyper-V, Objective 3.1: Create and Configure virtual machine settings, p. 144 


Q156. - (Topic 1) 

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The domain contains two domain controllers named DC1 and DC2 that run Windows Server 2012 R2. 

The domain contains a user named User1 and a global security group named Group1. 

You reconfigure DC2 as a member server in the domain. 

You need to add DC2 as the first domain controller in a new domain in the forest. 

Which cmdlet should you run? 

A. Add-AdPrincipalGroupMembership 

B. Install-AddsDomainController 

C. Install WindowsFeature 

D. Install AddsDomain 

E. Rename-AdObject 

F. Set AdAccountControl 

G. Set-AdGroup 

H. Set-User 

Answer:

Explanation: 

Since a member server does not have Active Directory Domain Services installed, you must install this role before you can configure the new Domain Controller (which would require you to run Install-ADDSForest). 

Topic 2, Volume B 


Q157. - (Topic 3) 

Your network contains an Active Directory domain named contoso.com. 

All servers run Windows Server 2012 R2. 

An application named Appl.exe is installed on all client computers. Multiple versions of Appl.exe are installed on different client computers. Appl.exe is digitally signed. 

You need to ensure that only the latest version of Appl.exe can run on the client computers. 

What should you create? 

A. An application control policy packaged app rule 

B. A software restriction policy certificate rule 

C. An application control policy Windows Installer rule 

D. An application control policy executable rule 

Answer:

Explanation: 

A. A publisher rule for a Packaged app is based on publisher, name and version B. You can create a certificate rule that identifies software and then allows or does not allow the software torun, depending on the security level. 

C. For .msi or .msp 

D. Executable Rules, for .exe and can be based on Publisher, Product name, filename and version. Use Certificate Rules on Windows Executables for Software Restriction Policies This security setting determines if digital certificates are processed when a user or process attempts to run software with an .exe file name extension. This security settings is used to enable or disable certificate rules, a type of software restriction policies rule. With software restriction policies, you can create a certificate rule that will allow or disallow software that is signed by Authenticode to run, based on the digital certificate that is associated with the software. In order for certificate rules to take effect, you must enable this security setting. When certificate rules are enabled, software restriction policies will check a certificate revocation list (CRL) to make sure the software’s certificate and signature are valid. This may decrease performance when start signed programs. You can disable this feature. On Trusted Publishers Properties, clear the Publisher and Timestampcheck boxes. 


Q158. - (Topic 3) 

Your network contains an Active Directory domain named contoso.com. All user accounts are in an organizational unit (OU) named Employees. 

You create a Group Policy object (GPO) named GP1. You link GP1 to the Employees OU. 

You need to ensure that GP1 does not apply to the members of a group named Managers. 

What should you configure? 

A. The Security settings of Employees 

B. The WMI filter for GP1 

C. The Block Inheritance option for Employees 

D. The Security settings of GP1 

Answer:

Explanation: 

A. Wrong Group 

B. Windows Management Instrumentation (WMI) filters allow you to dynamically determine 

the scope of Group Policy objects (GPOs) based on attributes of the target computer. 

C. Blocking inheritance prevents Group Policy objects (GPOs) that are linked to higher 

sites, domains, or organizational units from being automatically inherited by the child-level. 

D. Set Managers to – Members of this security group are exempt from this Group Policy 

object. 

Security settings. 

You use the Security Settings extension to set security options for computers and users 

within the scope of a Group Policy object. You can define local computer, domain, and network security settings. Figure below shows an example of the security settings that allow everyone to be affected by this GPO except the members of the Management group, who were explicitly denied permission to the GPO by setting the Apply Group Policy ACE to Deny. Note that if a member of the Management group were also a member of a group that had an explicit Allow setting for the Apply Group Policy ACE, the Deny would take precedence and the GPO would not affect the user. 


Q159. - (Topic 1) 

You have a server named Server1 that runs Windows Server 2012 R2.Server1 has six network adapters. Two of the network adapters are connected to a network named LAN1, two of the network adapters are connected to a network named LAN2, and two of the network adapters are connected to a network named LAN3. 

You create a network adapter team named Team1 from the two adapters connected to LAN1. You create a network adapter team named Team2 from the two adapters connected to LAN2. 

A company policy states that all server IP addresses must be assigned by using a reserved address in DHCP. 

You need to identify how many DHCP reservations you must create for Server1. 

How many reservations should you identify? 

A. 3 

B. 4 

C. 6 

D. 8 

Answer:

Explanation: 

1 for each NIC Team (2 total) and 1 for each non-teamed NIC (2 total) -> 4 total IP addresses are required. 


Q160. - (Topic 1) 

Your network contains an Active Directory domain named contoso.com. The domain contains 100 user accounts that reside in an organizational unit (OU) named OU1. 

You need to ensure that a user named User1 can link and unlink Group Policy objects (GPOs) to OU1. The solution must minimize the number of permissions assigned to User1. 

What should you do? 

A. Run the Delegation of Control Wizard on OU1. 

B. Add User1 to the Group Policy Creator Owners group. 

C. Modify the permission on the \\Contoso.com\SYSVOL\Contoso.com\Policies folder. 

D. Modify the permissions on the User1 account. 

Answer:

Explanation: 

The Delegation of Control Wizard allows you to delegate tasks, active Directory Object types and to set permissions.