We provide real examcollection 70 411 exam questions and answers braindumps in two formats. Download PDF & Practice Tests. Pass Microsoft 70 411 exam dumps Exam quickly & easily. The mcp 70 411 PDF type is available for reading and printing. You can print more and practice many times. With the help of our Microsoft exam 70 411 dumps pdf and vce product and material, you can easily pass the 70 411 exam dumps pdf exam.

Q17. HOTSPOT 

Your company has four offices. The offices are located in Montreal, Seattle, Sydney, and New York. 

The network contains an Active Directory domain named contoso.com. The domain contains a server named Server2 that runs Windows Server 2012 R2. Server2 has the DHCP Server server role installed. 

All client computers obtain their IPv4 and IPv6 addresses from DHCP. 

You need to ensure that Network Access Protection (NAP) enforcement for DHCP applies to all of the client computers except for the client computers in the New York office. 

Which two nodes should you configure? To answer, select the appropriate two nodes in the answer area.

 

Answer: 


Q18. Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2. 

All sales users have laptop computers that run Windows 8. The sales computers are joined to the domain. All user accounts for the sales department are in an organizational unit (OU) named Sales_OU. 

A Group Policy object (GPO) named GPO1 is linked to Sales_OU. 

You need to configure a dial-up connection for all of the sales users. 

What should you configure from User Configuration in GPO1? 

A. Policies/Administrative Templates/Network/Windows Connect Now 

B. Preferences/Control Panel Settings/Network Options 

C. Policies/Administrative Templates/Windows Components/Windows Mobility Center 

D. Policies/Administrative Templates/Network/Network Connections 

Answer:

Explanation: 

The Network Options extension allows you to centrally create, modify, and delete dial-up networking and virtual private network (VPN) connections. Before you create a network option preference item, you should review the behavior of each type of action possible with the extension. 

To create a new Dial-Up Connection preference item 

Open the Group Policy Management Console. Right-click the Group Policy object (GPO) that should contain the new preference item, and then click Edit. 

In the console tree under Computer Configuration or User Configuration, expand the Preferences folder, and then expand the Control Panel Settings folder. 

Right-click the Network Options node, point to New, and select Dial-Up Connection. 

References: 

http: //technet. microsoft. com/en-us/library/cc772107. aspx 

http: //technet. microsoft. com/en-us/library/cc772107. aspx 

http: //technet. microsoft. com/en-us/library/cc772449. aspx 


Q19. Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. 

The domain contains a top-level organizational unit (OU) for each department. A group 

named Group1 contains members from each department. 

You have a GPO named GPO1 that is linked to the domain. 

You need to configure GPO1 to apply settings to Group1 only. 

What should you use? 

A. Dcgpofix 

B. Get-GPOReport 

C. Gpfixup 

D. Gpresult 

E. Gpedit. msc 

F. Import-GPO 

G. Restore-GPO 

H. Set-GPInheritance 

I. Set-GPLink 

J. Set-GPPermission 

K. Gpupdate 

L. Add-ADGroupMember 

Answer:

Explanation: 

Set-GPPermission grants a level of permissions to a security principal (user, security group, or computer) for one GPO or all the GPOs in a domain. You use the TargetName and TargetType parameters to specify a user, security group, or computer for which to set the permission level. 

-Replace <SwitchParameter> Specifies that the existing permission level for the group or user is removed before the new permission level is set. If a security principal is already granted a permission level that is higher than the specified permission level and you do not use the Replace parameter, no change is made. 

Reference: http: //technet. microsoft. com/en-us/library/ee461038. aspx 


Q20. Your network contains an Active Directory domain named contoso.com. The functional level of the forest is Windows Server 2008 R2. 

Computer accounts for the marketing department are in an organizational unit (OU) named Departments\Marketing\Computers. User accounts for the marketing department are in an OU named Departments\Marketing\Users. 

All of the marketing user accounts are members of a global security group named MarketingUsers. All of the marketing computer accounts are members of a global security group named MarketingComputers. 

In the domain, you have Group Policy objects (GPOs) as shown in the exhibit. (Click the Exhibit button.) 

You create two Password Settings objects named PSO1 and PSO2. PSO1 is applied to MarketingUsers. PSO2 is applied to MarketingComputers. 

The minimum password length is defined for each policy as shown in the following table. 

You need to identify the minimum password length required for each marketing user. 

What should you identify? 

A. 5 

B. 6 

C. 7 

D. 10 

E. 12 

Answer:


Q21. Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2. 

An organizational unit (OU) named OU1 contains 200 client computers that run Windows 8 Enterprise. A Group Policy object (GPO) named GPO1 is linked to OU1. 

You make a change to GPO1. 

You need to force all of the computers in OU1 to refresh their Group Policy settings immediately. The solution must minimize administrative effort. 

Which tool should you use? 

A. The Secedit command 

B. Group Policy Management Console (GPMC) 

C. Server Manager 

D. The Gpupdate command 

Answer:

Explanation: 

In the previous versions of Windows, this was accomplished by having the user run GPUpdate.exe on their computer. 

Starting with Windows Server. 2012 and Windows. 8, you can now remotely refresh Group Policy settings for all computers in an OU from one central location through the Group Policy Management Console (GPMC). Or you can use the Invoke-GPUpdatecmdlet to refresh Group Policy for a set of computers, not limited to the OU structure, for example, if the computers are located in the default computers container. 

http: //technet. microsoft. com/en-us//library/jj134201. aspx 

http: //blogs. technet. com/b/grouppolicy/archive/2012/11/27/group-policy-in-windows-server-2012-using-remote-gpupdate. aspx 


Q22. HOTSPOT 

You have a server named Server1 that has the Network Policy and Access Services server role installed. 

You plan to configure Network Policy Server (NPS) on Server1 to use certificate-based authentication for VPN connections. 

You obtain a certificate for NPS. 

You need to ensure that NPS can perform certificate-based authentication. 

To which store should you import the certificate? 

To answer, select the appropriate store in the answer area. 

Answer: 


Q23. Your network contains an Active Directory domain named adatum.com. 

You have a standard primary zone named adatum.com. 

You need to provide a user named User1 the ability to modify records in the zone. Other users must be prevented from modifying records in the zone. 

What should you do first? 

A. Run the Zone Signing Wizard for the zone. 

B. From the properties of the zone, modify the start of authority (SOA) record. 

C. From the properties of the zone, change the zone type. 

D. Run the New Delegation Wizard for the zone. 

Answer:

Explanation: 

The Zone would need to be changed to a AD integrated zone When you use directory-integrated zones, you can use access control list (ACL) editing to secure a dnsZone object container in the directory tree. This feature provides detailed access to either the zone or a specified resource record in the zone. For example, an ACL for a zone resource record can be restricted so that dynamic updates are allowed only for a specified client computer or a secure group, such as a domain administrators group. This security feature is not available with standard primary zones. 

DNS update security is available only for zones that are integrated into Active Directory. After you integrate a zone, you can use the access control list (ACL) editing features that are available in the DNS snap-in to add or to remove users or groups from the ACL for a specific zone or for a resource record. 

Standard (not an Active Directory integrated zone) has no Security settings: 

You need to firstly change the "Standard Primary Zone" to AD Integrated Zone: 

Now there's Security tab: 

References: http: //technet. microsoft. com/en-us/library/cc753014. aspx 

http: //technet. microsoft. com/en-us/library/cc726034. aspx 

http: //support. microsoft. com/kb/816101 


Q24. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 P.2. Server1 has the Network Policy and Access Services server role installed. 

Your company's security policy requires that certificate-based authentication must be used by some network services. 

You need to identify which Network Policy Server (NPS) authentication methods comply with the security policy. 

Which two authentication methods should you identify? (Each correct answer presents part of the solution. Choose two.) 

A. MS-CHAP 

B. PEAP-MS-CHAP v2 

C. Chap 

D. EAP-TLS 

E. MS-CHAP v2 

Answer: B,D 

Explanation: 

PEAP is similar in design to EAP-TTLS, requiring only a server-side PKI certificate to create a secure TLS tunnel to protect user authentication, and uses server-side public key certificates to authenticate the server. When you use EAP with a strong EAP type, such as TLS with smart cards or TLS with certificates, both the client and the server use certificates to verify their identities to each other.