web analytics

(New Updated) Grasping New Microsoft 70-417 Exam Questions And Never Fail The Real Exam (16-30)

PassLeader now suppling the latest and 100 percent pass 70-417 exam questions, we ensure the 70-417 exam questions are the newest, and you can pass 70-417 exam without difficults. Visit the site passleader.com and get the free exam vce and pdf dumps and FREE VCE PLAYER to acquire high score in real test.

NEW QUESTION 16
Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All servers runs Windows Server 2012 R2.The domain contains two domain controllers named DC1 and DC2. Both domain controllers are virtual machines on a Hyper-V host. You plan to create a cloned domain controller named DC3 from an image of DC1. You need to ensure that you can clone DC1. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

A.    Add the computer account of DC1 to the Cloneable Domain Controllers group.
B.    Create a DCCIoneConfig.xml file on DC1.
C.    Add the computer account of DC3 to the Cloneable Domain Controllers group.
D.    Run the Enable-AdOptionalFeaturecmdlet.
E.    Modify the contents of the DefaultDCCIoneAllowList.xml file on DC1.

Answer: AB
Explanation:
* Cloneable Domain Controllers Group (located in the Users container). Membership in this group dictates whether a DC can or cannot be cloned. This group has some permissions set on the domain head that should not be removed. Removing these permissions will cause cloning to fail. Also, as a best practice, DCs shouldn’t be added to the group until you plan to clone and DCs should be removed from the group once cloning is complete. Cloned DCs will also end up in the Cloneable Domain Controllers group.
* DCCloneConfig.xml is an XML configuration file that contains all of the settings the cloned DC will take when it boots. This includes network settings, DNS, WINS, AD site name, new DC name and more.

NEW QUESTION 17
Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2008 R2. One of the domain controllers is named DC1. The network contains a member server named Server1 that runs Windows Server 2012 R2. You need to promote Server1 to a domain controller by using install from media (IFM). What should you do first?

A.    Run the Active Directory Domain Services Installation Wizard on DC1.
B.    Upgrade DC1 to Windows Server 2012 R2.
C.    Run the Active Directory Domain Services Configuration Wizard on Server1.
D.    Create a system state backup of DC1.
E.    Create IFM media on DC1.

Answer: B
Explanation:
This is the only valid option. You could install ADDS role on Server 1 and run ADDS configuration wizard and add DC to existing domain.

NEW QUESTION 18
Your network contains an Active Directory domain named contoso.com. The Active Directory Recycle bin is enabled for contoso.com. A support technician accidentally deletes a user account named User1. You need to restore the User1 account. Which tool should you use?

A.    Ldp
B.    Esentutl
C.    Active Directory Administrative Center
D.    Ntdsutil

Answer: C

Explanation:
http://technet.microsoft.com/nl-nl/library/dd379509(v=ws.10).aspx#BKMK_2
http://technet.microsoft.com/en-us/magazine/2007.09.tombstones.aspx
http://technet.microsoft.com/en-us/library/hh875546.aspx
http://technet.microsoft.com/en-us/library/dd560651(v=ws.10).aspx

NEW QUESTION 19
Your network contains an Active Directory domain named adatum.com. All domain controllers run Windows Server 2012 R2. The domain contains a virtual machine named DC2. On DC2, you run Get-ADDCCloningExcludcdApplicationList and receive the output shown in the following table.
191_thumb[2]
You need to ensure that you can clone DC2. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)
192_thumb[1]

A.    Option A
B.    Option B
C.    Option C
D.    Option D
E.    Option E

Answer: AE

NEW QUESTION 20
You have a server named Server1 that runs Windows Server 2012 R2. On Server1, you configure a custom Data Collector Set (DCS) named DCS1. DCS1 is configured to store performance log data in C:\Logs. You need to ensure that the contents of C:\Logs are deleted automatically when the folder reaches 100 MB in size. What should you configure?

A.    A File Server Resource Manager (FSRM) file screen on the C:\Logs folder
B.    The Data Manager settings of DCS1
C.    A schedule for DCS1
D.    A File Server Resource Manager (FSRM) quota on the C:\Logs folder

Answer: B
Explanation:
To configure data management for a Data Collector Set
1. In Windows Performance Monitor, expand Data Collector Sets and click User Defined.
2. In the console pane, right-click the name of the Data Collector Set that you want to configure and click Data Manager.
3. On the Data Manager tab, you can accept the default values or make changes according to your data retention policy. See the table below for details on each option. When Minimum free disk or Maximum folders is selected, previous data will be deleted according to the Resource policy you choose (Delete largest or Delete oldest) when the limit is reached. When Apply policy before the data collector set starts is selected, previous data will be deleted according to your selections before the data collector set creates its next log file. When Maximum root path size is selected, previous data will be deleted according to your selections when the root log folder size limit is reached.
4. Click the Actions tab. You can accept the default values or make changes. See the table below for details on each option.
5. When you have finished making your changes, click OK.

NEW QUESTION 21
Hotspot Question
Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server1. Server1 runs Windows Server 2012 R2. You enable the EventLog-Application event trace session. You need to set the maximum size of the log file used by the trace session to 10 MB. From which tab should you perform the configuration? To answer, select the appropriate tab in the answer area.
211_thumb[2]

Answer:
212_thumb[1]

NEW QUESTION 22
Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server 1. All servers run Windows Server 2012 R2. You need to collect the error events from all of the servers on Server1. The solution must ensure that when new servers are added to the domain, their error events are collected automatically on Server1. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

A.    On Server1, create a collector initiated subscription.
B.    On Server1, create a source computer initiated subscription.
C.    From a Group Policy object (GPO), configure the Configure target Subscription Manager setting.
D.    From a Group Policy object (GPO), configure the Configure forwarder resource usage setting.

Answer: BC
Explanation:
To set up a Source-Initiated Subscription with Windows Server 2003/2008 so that events of interest from the Security event log of several domain controllers can be forwarded to an administrative workstation
* Group Policy
The forwarding computer needs to be configured with the address of the server to which the events are forwarded. This can be done with the following group policy setting:
Computer configuration-Administrative templates-Windows components-Event forwarding- Configure the server address, refresh interval, and issue certificate authority of a target subscription manager.
* Edit the GPO and browse to Computer Configuration | Policies | Administrative Templates | Windows Components | Event Forwarding – Configure the server address, refresh interval, and issuer certificate authority of a target Subscription Manager


http://www.passleader.com/70-417.html

NEW QUESTION 23
Hotspot Question
Your network contains a RADIUS server named Admin1. You install a new server named Server2 that runs Windows Server 2012 R2 and has Network Policy Server (NPS) installed. You need to ensure that all accounting requests for Server2 are forwarded to Admin1. On Server2, you create a new remote RADIUS server group named Group1 that contains Admin1. What should you configure next on Server2? To answer, select the appropriate node in the answer area.
231_thumb[3]

Answer:
232_thumb[3]

NEW QUESTION 24
Your network contains an Active Directory domain named adatum.com. A network administrator creates a Group Policy central store. After the central store is created, you discover that when you create new Group Policy objects (GPOs), the GPOs do not contain any Administrative Templates. You need to ensure that the Administrative Templates appear in new GPOs. What should you do?

A.    Add your user account to the Group Policy Creator Owners group.
B.    Configure all domain controllers as global catalog servers.
C.    Copy files from %Windir%\Policydefinitions to the central store.
D.    Modify the Delegation settings of the new GPOs.

Answer: C
Explanation:
To take advantage of the benefits of .admx files, you must create a Central Store in the SYSVOL folder on a domain controller. The Central Store is a file location that is checked by the Group Policy tools. The Group Policy tools use any .admx files that are in the Central Store. The files that are in the Central Store are later replicated to all domain controllers in the domain.

NEW QUESTION 25
Hotspot Question
You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the Remote Access server role installed. You need to configure the ports on Server1 to ensure that client computers can establish VPN connections to Server1 by using TCP port 443. What should you modify? To answer, select the appropriate object in the answer area.
251_thumb[2]

Answer:
252_thumb[2]

NEW QUESTION 26
Your network contains an Active Directory domain named contoso.com. The domain contains three servers. The servers are configured as shown in the following table.
261_thumb[2]
You need to ensure that end-to-end encryption is used between clients and Server2 when the clients connect to the network by using DirectAccess. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

A.    From the Remote Access Management Console, reload the configuration.
B.    Add Server2 to a security group in Active Directory.
C.    Restart the IPSec Policy Agent service on Server2.
D.    From the Remote Access Management Console, modify the Infrastructure Servers settings.
E.    From the Remote Access Management Console, modify the Application Servers settings.

Answer: BE

NEW QUESTION 27
You have a DNS server named DNS1 that runs Windows Server 2012 R2. On DNS1, you create a standard primary DNS zone named adatum.com. You need to change the frequency that secondary name servers will replicate the zone from DNS1. Which type of DNS record should you modify?

A.    Name server (NS)
B.    Start of authority (SOA)
C.    Host information (HINFO)
D.    Service location (SRV)

Answer: B
Explanation:
The time to live is specified in the Start of Authority (SOA) record.
Note: TTL (time to live) – The number of seconds a domain name is cached locally before expiration and return to authoritative nameservers for updated information.

NEW QUESTION 28
Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server 1. Server1 has the IP Address Management (IPAM) Server feature installed. A technician performs maintenance on Server1. After the maintenance is complete, you discover that you cannot connect to the IPAM server on Server1. You open the Services console as shown in the exhibit. (Click the Exhibit button.)
281_thumb[2]
You need to ensure that you can connect to the IPAM server. Which service should you start?

A.    Windows Process Activation Service
B.    Windows Event Collector
C.    Windows Internal Database
D.    Windows Store Service (WSService)

Answer: C

NEW QUESTION 29
You have a server named Server1 that runs Windows Server 2012 R2. Server1 is located in the perimeter network and has the DNS Server server role installed. Server1 has a zone named contoso.com. You apply a security template to Server1. After you apply the template, users report that they can no longer resolve names from contoso.com. On Server1, you open DNS Manager as shown in the DNS exhibit. (Click the Exhibit button.)
291_thumb[2]
On Server1, you open Windows Firewall with Advanced Security as shown in the Firewall exhibit. (Click the Exhibit button.)
292_thumb[1]
You need to ensure that users can resolve contoso.com names. What should you do?

A.    From Windows Firewall with Advanced Security, disable the DNS (TCP, Incoming) rule and the DNS (UDP, Incoming) rule.
B.    From DNS Manager, modify the Zone Transfers settings of the contoso.com zone.
C.    From DNS Manager, unsign the contoso.com zone.
D.    From DNS Manager, modify the Start of Authority (SOA) of the contoso.com zone.
E.    From Windows Firewall with Advanced Security, modify the profiles of the DNS (TCP, Incoming) rule and the DNS (UDP, Incoming) rule.

Answer: E

NEW QUESTION 30
Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012 R2. DC1 has the DNS Server server role installed. The network contains client computers that run either Linux, Windows 7, or Windows 8. You have a zone named adatum.com as shown in the exhibit. (Click the Exhibit button.)
301_thumb[2]
You plan to configure Name Protection on all of the DHCP servers. You need to configure the adatum.com zone to support Name Protection. What should you do?

A.    Change the zone type.
B.    Sign the zone.
C.    Add a DNSKEY record.
D.    Configure Dynamic updates.

Answer: D
Explanation:
http://technet.microsoft.com/en-us/library/ee941152(v=ws.10).aspx


We PassLeader provide the best 70-417 training materials for certification exams. We offer the latest 70-417 exam VCE dumps with free vaild VCE player to ensure that you 100 percent pass exam, and what’s more, we will offer you the new updated exam questions for free.

http://www.passleader.com/70-417.html

Welcome To Visit PassLeader