Certification Exam Prep Questions For Administering Windows Server 2012 (70-411)


QuickStart is now offering assessment questions for Administering Windows Server 2012 (70-411) . Whether you are deciding which exam to sign up for, or simply want to practice the materials necessary to complete certification for this course, we have provided a practice assessment to better aid in certification. 100% of the questions are real questions; from a recent version of the test you will take for Administering Windows Server 2012 (70-411)


Arrow
 

1

Your network is configured as an Active Directory Domain Services (AD DS) domain. All domain controllers run Windows Server 2012 R2. Your network configuration includes a perimeter network. You have a computer running Windows Server 2012 R2 deployed in the perimeter network. The computer is configured to act as a virtual private network (VPN) endpoint and to support the Network Access Protection (NAP) role. You are configuring policies to control computer access to the network that are based on Windows System Health Validator (WSHV) policies. You have already created a Network Policy that grants access to all NAP-capable computers. You need to ensure that a computer that is not NAP-capable is not granted any access to the network until it is reconfigured to be NAP-capable. What should you do?

2

Your network is configured as an Active Directory Domain Services (AD DS) domain. All domain controllers run Windows Server 2012 R2. You use a computer running the Network Access Protection (NAP) role to determine what level of access to allow clients requesting an IP address through DHCP. You need to make sure that clients that are not compliant are blocked from accessing network resource servers and, if possible, are brought into compliance as quickly as possible. You want to keep the administrative effort necessary to a minimum. What should you do? (Each correct answer presents part of the solution. Choose two.)

3

Your network is configured as a single Active Directory Domain Services (AD DS) domain. All domain controllers run Windows Server 2012 or Windows Server 2012 R2. You install the Network Policy Server (NPS) role configured as a Network Access Policy (NAP) server on a member server that is running Windows Server 2012 R2. You want to enforce health policies on all local 802.1x wireless clients. All wireless client computers are located in the Wireless OU. Client computers run Windows 8 or Windows 8.1. You want to keep the administrative effort needed to a minimum. What should you do? (Each correct answer presents part of the solution. Choose two.)

4

Your network includes a domain member server running Microsoft Windows Server 2012 R2. The computer is configured as a Windows Server Update Services (WSUS) server. The client computers are configured through a Group Policy object (GPO). The GPO is currently configured as Enabled. The client computers are located in 50 branch offices and the WSUS server is located in the main office. Each branch office has its own Internet connection. You need to reconfigure the WSUS settings for optimal usage of existing connections while still maintaining control of the updates to be approved. Bandwidth requirements across links to branch offices should be kept to a minimum. What should you do?

5

You are the administrator for an Active Directory Domain Services (AD DS) domain named corp.net. The domain has two domain controllers (DCs) named DC1 and DC2 that run Microsoft Windows Server 2012 R2. You need to back up SYSVOL and the AD database before performing maintenance on DC1. You want to back up to a network shared folder. The backup file needs to be as small as possible. What should you do? (More than one answer choice may be correct. Choose the BEST answer.)

6

Your network is configured as a single Active Directory Domain Services (AD DS) domain. All domain controllers run Windows Server 2012 or Windows Server 2012 R2. Your network includes a Microsoft Windows Deployment Services (WDS) server installed on one of the domain controllers. You added a custom image named CustomWin8.wim to the WDS server. After creating and adding the custom image to the WDS server, you realize that you need to add the Telnet Client feature to the image. You mount the image to the cAmount folder. What should you do next?

7

You are an administrator for an Active Directory Domain Services (AD DS) domain. FS1 is a member server running Microsoft Windows Server 2012 R2. You install the File Server Resource Manager (FSRM) role on the server. You need to set quotas on several shared folders on FS1. The folders will have different quota parameters. What should you use?

A. Fsutil.
Incorrect.
B. File Explorer.
Incorrect.
C. Dirquota.
Correct!
D. Computer Manager
Incorrect.
8

You suspect that the Trusted Platform Module (TPM) owner password (owner authorization) on a computer running Windows 2012 R2 has been compromised. You need to prevent any unauthorized person from making administrative changes to the TPM. The computer's system and data drives are protected by BitLocker Data Encryption (BDE). You want to avoiding invalidating existing keys or losing any data on the computer. What should you do? (Each correct answer presents a complete solution. Choose two.)

9

You create the file screen shown below on a computer running Microsoft Windows Server 2012 R2. The file screen is an active file screen based on the Block Image Files template. You need to be able to store .jpg files in the C:\Review\RawPics folder. That is the only type of image file that should be allowed in the RawPics folder. You want to keep changes to folder configurations to a minimum. What should you do?

10

You have a single Active Directory Domain Services (AD DS) domain. All domain controllers are running Windows Server 2012 R2. Your network includes member servers running Microsoft Windows Server 2012 and client computers running a mix of Windows 8.1, Windows 8, Windows 7, and Windows XP. You create a new Group Policy object (GPO) and link it to the domain. The GPO is configured as shown in the exhibit. The GPO is designed to configure a mapped drive on each client computer. By inspection, you discover that not all client computers are configured with the mapped drive. You need to correct the situation as quickly as possible. Your solution should not risk compromising AD security. What should you do?

11

Your network is configured as a single Active Directory Domain Services (AD DS) domain. All domain controllers run Windows Server 2012 or Windows Server 2012 R2. The domain function level is Windows Server 2008. The network includes a member server running Windows Server 2012 R2 that has the Network Policy and Access Services role installed. You create a network policy that limits non-compliant client computers to a restricted network until all issues have been resolved. You need to identify the remediation servers available for this purpose.

12

Your network is an Ethernet local area network (LAN). Client computers run Microsoft Windows 7 and Windows 8.1. Computers connect to the network using an 802.1x authenticating switch. You need to ensure that client computers can only access two servers if they are not running anti-virus software. You deploy a new server running Windows Server 2012 R2 to support this. What should you do? (Each correct answer presents part of the solution. Choose two.)

13

You deploy a custom DNS lookup service on three servers on your network that are running Windows Server 2012 R2. You want to have service hosts returned to DNS clients in a random order to keep the load somewhat balanced. You want to minimize the amount of work that is required to do this. What should you do?

14

Your network is configured as a single Active Directory Domain Services (AD DS) domain. All domain controllers run Windows Server 2012 or Windows Server 2012 R2. You deploy a Network Policy Server (NIPS) configured as a RADIUS server and RADIUS proxy. Visitors from a partner organization sometimes connect to the partner organization's network from your local network. You want to have domain members authenticated locally, but visitors should be authenticated by a RADIUS server in their home network. What should you do?

15

You are the administrator for an Active Directory Domain Services (AD DS) domain. All domain controllers and member servers run Windows Server 2012 or Windows Server 2012 R2. A system state backup is run on each domain controller nightly and a full backup run once a week. All client computers run Windows 7 or Windows 8.1. Earlier in the week you made a number of changes to computer policies through the Default Domain group policy changes. Since then, you have encountered various problems with the client computers. You need to return the Default Domain group policy back to its baseline configuration settings as quickly as possible. What should you do?

16

You manage an Active Directory Domain Services (AD DS) domain. Each domain controller runs either Windows Server 2012 or Windows Server 2012 R2. Your network includes a member server running Windows Server 2012 R2 configured as a Network Policy Server (N PS) RADIUS server. Your network is configured with a private Public Key Infrastructure (PKI). Remote clients connect through a VPN server deployed in your perimeter network. You use EAP-TLS to authenticate remote clients. You have set up automatic certificate enrollment for client computers that are domain members. The NPS server is able to authenticate remote clients configured as domain members, but cannot authenticate non-domain members. You need to ensure that users who connect with computers that are not domain members can be authenticated. What should you do? (Each correct answer presents a complete solution. Choose two.)

17

Your network is configured as a single Active Directory Domain Services (AD DS) domain. All domain controllers run Windows Server 2008 R2 or Windows Server 2012. You have four folders, all with quotas configured as shown in the exhibit. Some users are complaining that they are blocked from saving critical files. You need to enable them to save files in all folders using this quota template as soon as possible. You also need to ensure that any files saved in excess of the quota are logged. What should you do? (More than one answer choice may be correct. Choose the BEST answer.)

18

You are an administrator for an Active Directory Domain Services (AD DS) domain. All domain controllers run Microsoft Windows Server 2012 or Windows Server 2012 R2. Your main office is in New York City with branch offices in various geographic locations around the world. Each office location is configured as a different AD site. You install and configure Windows Update Services (WSUS) on a computer running Windows Server 2012 R2 in each office. Updates will be downloaded from the Microsoft Updates site to the WSUS server in the New York office only. The remaining WSUS servers are deployed in a hub-and-spoke configuration. You want to ensure that updates are applied only after hours based on the local time in each office. What should you do? (Each correct answer presents a complete solution. Choose two.)

19

You are the administrator for a small network that is configured as an Active Directory Domain Services (AD DS) domain named corp.net. Member servers run Microsoft Windows Server 2012 R2 and domain clients run Windows 8 or Windows 8.1. All member computers are configured to use the Encrypting File System (EFS). You have been assigned the role of EFS Recovery Agent. A domain user is having difficulties accessing an EFS-encrypted file on his computer. You investigate the problem and conclude that the user's EFS settings are causing the problem. You log on to the user's computer with your EFS Recovery Agent account and try to remove the EFS encryption from the file, but you receive an error message. You need to remove the EFS encryption from the file. What should you do first?

20

Your company has an Active Directory Domain Services (AD DS) domain. You have two domain controllers running Windows Server 2012 R2. Your internal network infrastructure meets the deployment requirements for DirectAccess. You have 20 remote users who need access to the internal network. Remote clients run Windows 7 or Windows 8.1. You deploy a server running Windows Server 2012 R2 and configure the server to support Advanced Remote Access (DirectAccess). What else should you do? (Each correct answer presents part of the solution. Choose two.)

21

You administer an Active Directory Domain Services (AD DS) domain. All domain controllers Windows Server 2012 or Windows Server 2012 R2. Client computers run either Windows 7 or Windows 8. You want to configure the client computers to use microsoft.com as their default home page. You configure a Group Policy object (GPO) with the Preferences settings shown in the exhibit. You link the GPO to the OU containing the client computers. The settings are not taking effect on the client computers. You need to activate the settings in Preferences. What should you do?

A. Press F8.
Incorrect.
B. Press F11
Incorrect.
C. Press F6
Correct!
D. Press F7
Incorrect.
22

Your network is configured as a single Active Directory Domain Services (AD DS) domain. All domain controllers run Windows Server 2012 R2. Your network includes a main office and several branch offices. You set up DFS replication in a hub and spoke configuration with the hub in the main office. All servers used with DFS replication run Windows Server 2012 R2. All replication group members support read/write DFS databases. You review the log entries for DFS and discover that replication is being interrupted because the staging folder has become a bottleneck. You need to increase the quota size on the staging folder. What should you do? (Each correct answer presents a complete solution. Choose two.)

23

A medical services network is configure as an Active Directory Domain Services (AD DS) domain. All domain servers run Windows Server 2008 R2 or Windows Server 2012 R2. Sensitive records are kept on a secure file server named Serverl that is running Windows Server 2012 R2. Each folder on the file server is encrypted using Encrypting File Service (EFS). You need to know every time there is a failed attempt to access a shared folder on Serverl. You need to keep the log size to a minimum. You want to minimize the administrative effort needed to implement this. What should you do? (More than one answer choice may be correct. Choose the BEST answer.)

24

Your network is configured as an Active Directory Domain Services (AD DS) domain. Domain controllers (DCs) include computers that are running Windows Server 2003, Windows Server 2008, and Windows Server 2012 R2. You need to ensure that you can quickly restore deleted AD objects, including all linked and non-linked attributes, without having to take any domain controller into Directory Services Restore Mode (DSRM). You need to keep the changes to the AD DS infrastructure to a minimum. What should you do first?

25

Your network is configured as a single Active Directory Domain Services (AD DS) domain. All domain controllers run Windows Server 2012 or Windows Server 2012 R2. Your network includes a Microsoft Windows Deployment Services (WDS) server installed on a domain member server running Windows Server 2012 R2. The network and all client computers support Preboot Execution Environment (PXE) boot. When attempting to deploy an image to a new computer, the boot process stops and displays the message shown in the exhibit. You need to have the boot process continue. Which command should you run on the WDS server?

A. wdsutil /enable
Correct!
B. wdsutil /start
Incorrect.
C. wdsutil /approve
Incorrect.
D. wdsutil /initialize
Incorrect.
26

Your company's network consists of a single Active Directory domain. You install Microsoft Windows Server 2012 R2 on all servers on the network. All client computers on the network run Windows 8.1. Some users in the marketing department want to access the company's network while traveling. You install a Network Policy Server (NPS) and enable the Routing and Remote Access role service on the server to provide virtual private network (VPN) connectivity to remote users. You want to ensure that only authorized remote users are allowed to access the corporate network only between 9 A.M. to 6 P.M. Authorized remote users are all part of a security group containing only authorized remote users. What should you do?

27

You network is configured as an Active Directory Domain Services (AD DS) domain. You recently upgraded all domain controllers to Windows Server 2012. The domain functional level is Windows 2008. Network client computers were recently upgraded to Windows 8.1. Basic audit policies configured to Audit logon events were previously configured through a Group Policy object (GPO) linked at the domain. You configure Advanced Audit policies to audit when domain users are validated with their account credentials. The GPO settings are shown in the exhibit. No events are being logged for credential validation. What should you do?

28

Your network is configured as an Active Directory Domain Services (AD DS) domain. All domain controllers run Windows Server 2012 R2. Domain clients are a mix of computers running with Windows XP SP2, Windows 7, Windows 8, or Windows 8.1. Client computer objects are stored in the departmental OU in which they are used. You want to ensure that laptop computers running Windows XP go into hibernation when the computer lid is closed. This is the only change that you want to make. You want this policy to apply to laptop computers only. You want to keep the administrative effort needed to accomplish this to a minimum. What should you do?

29

Your network is configured as a single Active Directory Domain Services (AD DS) domain. All domain controllers run Windows Server 2012 R2. A member server named RFSO4 runs Windows Server 2012 R2 and is a member of multiple DFS replication groups. Each DFS replication database is maintained on a different volume. One of the DFS databases has become corrupted on the server after an unexpected power loss. You want to recover the database as quickly as possible. What should you do first? (More than one answer choice may be correct. Choose the BEST answer.)

PDP Url

Sample Question - Administering Windows Server 2012 (70-411)


Self-Paced

Learning Style

Beginner

Difficulty

1 Hour

Course Duration

Certificate

See Sample

Buy Individually
About Individual Course:
  • Individual course plan gives you access to this course
$109.00
$109.00
/ Each

Outline

More Information

More Information
Lab Access No
Learning Style Self-Paced Learning
Difficulty Beginner
Course Duration 1 Hour
Language English

Reviews

Write Your Own Review
Only registered users can write reviews. Please Sign in or create an account

Contact A Learning Consultant


click here