web analytics

You need to reduce the amount of disk space used to store the Active Directory database on a domain controller. Which tool should you use?

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in

You need to ensure that the users can access the protected content. What should you do?

You have an Active Directory Rights Management Services (AD RMS) server named RMS1. Multiple documents are protected by using RMS1. RMS1 fails and cannot be recovered. You install the AD

Solution: From Windows PowerShell on a domain controller, you run the Set-KdsConfiguration cmdlet. Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals.

You need to resolve the issue without diminishing the security of the smart card logons. What should you do?

Your network contains an Active Directory domain named contoso.com. Domain users use smart cards to sign in to their client computer. Some users report that it takes a long time

You need to configure the domain computers to validate DNS responses for adatum.com records. What should you configure in Group Policy?

You network contains one Active Directory domain named adatum.com. The domain contains a DNS server named Server1 that runs Windows Server 2016. All domain computers use Server1 for DNS. You

You need to ensure that your DNS servers can resolve partners.adatum.com to the correct IP address immediately. What should you do?

Your network contains an Active Directory forest named contoso.com. Users frequently access the website of an external partner company. The URL of the website is http://partners.adatum.com. The partner company informs

You need to ensure that clients will check at least every 30 minutes as to whether a certificate has been revoked. Which of the following should you configure to accomplish this goal?

You need to ensure that clients will check at least every 30 minutes as to whether a certificate has been revoked. Which of the following should you configure to accomplish

Which of the following CA types would you deploy if you wanted to deploy a CA at the top of a hierarchy that could issue signing certificates to other CAs and which would be taken offline if not issuing, renewing, or revoking signing certificates?

Which of the following CA types would you deploy if you wanted to deploy a CA at the top of a hierarchy that could issue signing certificates to other CAs

You are configuring AD FS. Which server should you deploy on your organization’s perimeter network?

You are configuring AD FS. Which server should you deploy on your organization’s perimeter network? A. Web application proxy B. Relying-party server C. Federation server D. Claims-provider server Answer: A

You are configuring AD FS. Which server should you deploy on your organization's perimeter network?

You are configuring AD FS. Which server should you deploy on your organization’s perimeter network? A. Web application proxy B. Relying-party server C. Federation server D. Claims-provider server Answer: A

You need to ensure that all users can autoenroll for certificated based on the UserAutoEnroll template. Which setting should you configure from the properties on the UserAutoEnroll certificate template?

You have an enterprise certification authority (CA) named CA1. You have a certificate template named UserAutoEnroll that is based on the User certificate template. Domain users are configured to autoenroll

You need to provide access for a group named Research in fabrikam.com to resources in contoso.com. The solution must use the principle of least privilege. What should you do?

Your network contains an Active Directory forest named contoso.com. A partner company has a forest named fabrikam.com. Each forest contains one domain. You need to provide access for a group

Prevent the users from signing in to a client computer if the computer is disconnected from the domain. What should you do?

Your network contains an Active Directory domain named contoso.com. The domain functional level is Windows Server 2012 R2. You need to secure several high-privilege user accounts to meet the following

You need to configure LON-DC02 as a global catalog server. What should you do?

Your network contains an Active Directory forest. The forest contains two domains named litwarenc.com and contoso.com. The contoso.com domain contains two domains controllers named LON-DC01 and LON-DC02. The domain controllers

You need to prevent the new users from accessing any of the resources in the domain after 90 days. What should you do?

Your network contains an Active Directory forest named contoso.com Your company plans to hire 500 temporary employees for a project that will last 90 days. You create a new user

Which server role or role service should you install on Server1?

You have a server named Server1 that runs Windows Server 2016. You need to configure Server1 as a Web Application Proxy. Which server role or role service should you install

You need to enable certificate authentication from the Internet on Server1. Which two inbound TCP ports should you open on the firewall? Each correct answer presents part of the solution.

Your network contains an Active Directory forest named contoso.com. The forest contains a member server named Server1 that runs Windows Server 2016. Server1 is located in the perimeter network. You

You need to ensure that you can use role separation to manage the farm. Which cmdlet should you run?

Your network contains an Active Directory forest named contoso.com. You have an Active Directory Federation Services (AD FS) farm. The farm contains a server named Server1 that runs Windows Server

You need to force users to change their account password at least every 30 days. What should you do?

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in

You need to configure the Documents folder of every user to be stored on a server named FileServer1. What should you do?

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in

You need to use the application control policy settings to prevent several applications from running on the network. What should you do?

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in

You need to ensure that any user who signs in to a computer that runs Windows 10 in OU1 receives the new printer. All of the computers in OU1 must continue to apply the corporate desktop restrictions from GPO1. What should you configure?

Your network contains an Active Directory domain named contoso.com. You have a Group Policy object (GPO) named GPO1. GPO1 is linked to an organizational unit (OU) named OU1. GPO1 contains

You need to publish App1 to OU1 by using Group Policy. What should you do?

Your network contains an Active Directory domain named contoso.com. You have an organizational unit (OU) named OU1 that contains the computer accounts of two servers and the user account of

You need to restore the Default Domain Policy to the default settings from when the domain was first installed. What should you do?

Your company recently deployed a new child domain to an Active Directory forest. You discover that a user modified the Default Domain Policy to configure several Windows components in the

You need to enable a technician named Tech1 to create Group Policy objects (GPOs) and to link the GPOs to TestOU. The solution must use the principle of least privilege. Which two actions should you perform? Each correct answer presents part of the solution.

Your network contains an Active Directory domain named contoso.com. You have an organizational unit (OU) named TestOU that contains test computers. You need to enable a technician named Tech1 to

You need to run the script once weekly only on the laptops. What should you do?

You network contains an Active Directory domain named contoso.com. The domain contains 1,000 desktop computers and 500 laptops. An organizational unit (OU) named OU1 contains the computer accounts for the

You need to ensure that the issued certificates are valid for two years and support autoenrollment. What should you do first?

You deploy a new enterprise certification authority (CA) named CA1. You plan to issue certificates based on the User certificate template. You need to ensure that the issued certificates are

You need to ensure that new certificates based on Secure_Computer are valid for three years. What should you do?

Your network contains an enterprise root certification authority (CA) named CA1. Multiple computers on the network successfully enroll for certificates that will expire in one year. The certificates are based

You need to ensure that Admin01 can configure Server1 as an enterprise CA. The solution must use the principle of least privilege. To which group should you add Admin01?

Your network contains an Active Directory forest named contoso.com. The forest contains several domains. An administrator named Admin01 installs Windows Server 2016 on a server named Server1 and then joins

You need to identify to which group Admin01 must be a member to configure Server1 as a standalone CA. The solution must use the principle of least privilege. To which group should you add Admin01?

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The domain contains a server named Server1. An administrator named Admin01 plans to configure Server1

For the web server, you need to request a certificate that does not contain the revocation information of CA1. What should you do first?

You network contains an Active Directory domain named contoso.com. The domain contains an enterprise certification authority (CA) named CA1. You have a test environment that is isolated physically from the

You need to ensure that the warning message is not generated when the users attempt to access the web applications from the Internet. What should you do?

You have users that access web applications by using HTTPS. The web applications are located on the servers in your perimeter network. The servers use certificates obtained from an enterprise

You need to ensure that a domain administrator can recover a deleted Active Directory object quickly. Which tool should you use?

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in

You need to limit the number of Active Directory Domain Services (AD DS) objects that a user can create in the domain. Which tool should you use?

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in

You need to make the Active Directory data in the backup accessible by using Lightweight Directory Access Protocol (LDAP). Which tool should you use?

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals.

Solution: From the Computer Configuration node of GPO1, you configure the Account Policies settings. Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals.

Solution: From the Computer Configuration node of GPO1, you configure the Local Users and Groups preference. Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals.

Solution: From a domain controller, you run the Set-AdComputer cmdlet. Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals.

Solution: You raise the domain functional level to Windows Server 2012 R2. Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals.

Solution: You upgrade a domain controller to Windows Server 2016. Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals.

Solution: You run adprep.exe from the Windows Server 2016 installation media. Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals.

Solution: From AD RMS in contoso.com, you configure fabrikam.com as a trusted user domain. Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals.

Solution: From AD RMS in contoso.com, you configure fabrikam.com as a trusted publisher domain. Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals.

Solution: From AD RMS in fabrikam.com, you configure contoso.com as a trusted publisher domain. Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals.