70-413 New Exam Question Thread (Plz all new Questions Post here ) !!!Important

Discussion in '70-413' started by mecbeau, Nov 22, 2015.

  1. mc

    mcpchat Member
    Member

    Joined:
    Dec 16, 2015
    Messages:
    6
    Likes Received:
    0
    Contoso. Ltd. Case Study question

    You need to configure the Group Policy for salespeople.
    SOlution: You create one Group Policy Object (GPO) that uses applocker and link the GPO to the root of the domain. You modify GPO security filtering to allow only the sales department computers to read and apply the GPO. You also create a WMI filter that applies only to laptop computers and associate the filter with the GPO.

    Does this meet the goal.

    A. Yes
    B. No

    Please give the answer for this.
     
  2. mc

    mcpchat Member
    Member

    Joined:
    Dec 16, 2015
    Messages:
    6
    Likes Received:
    0
    Your network contains two server named DHCP1 and DHCP2 that run Windows Server 2012 and have the DHCP Server server role installed. You need to design a highly available DHCP deployment to meet the following requirements.

    . Deploy stateless DHCPv6
    . Provide Ipv6 options to clients on multiple subnets.
    . Allow for clients to renew existing IPV6 address leases if a single server is unavailable.
    . Minimize administrative effort.

    What should you include in the design?

    A. Configure both servers to provide identical option configuration.
    B. Add DHCP1 and DHCP2 to a failover cluster. Configure the DHCP for high availability.
    C. From DHCP1, configure DHCP Failover in Hot Standby Mode
    D. From DHCP1, configure DHCP Failover in Load Balance Mode.
     
  3. mo

    moonj Member
    Member

    Joined:
    Oct 28, 2015
    Messages:
    33
    Likes Received:
    0
    I got 1 NEW question today, but can't remember the answers,

    the question is like : a company has cloud based service and have 20 customers, each customer has a A/D hosted by this company, you need to setup radius for them, how many radius servers/radius proxy servers and VPN servers you need to set up.
     
  4. il

    ilkman Member
    Member

    Joined:
    Dec 14, 2015
    Messages:
    20
    Likes Received:
    0

    Dear visitor, you need to Register or Login to view links on Certify Chat.

    I got 1 NEW question today, but can't remember the answers,

    the question is like : a company has cloud based service and have 20 customers, each customer has a A/D hosted by this company, you need to setup radius for them, how many radius servers/radius proxy servers and VPN servers you need to set up.
    Click to expand...

    the answer can be
    20 radius server/1 radius proxy. 1 VPN
     
  • il

    ilkman Member
    Member

    Joined:
    Dec 14, 2015
    Messages:
    20
    Likes Received:
    0
    I think C.
    Failover cluster not use minimum adm effort.
    A - conflict
    D- more about sharing dhcp
     
  • il

    ilkman Member
    Member

    Joined:
    Dec 14, 2015
    Messages:
    20
    Likes Received:
    0
    I think A//
     
  • da

    dapenguin Member
    Member

    Joined:
    Oct 30, 2015
    Messages:
    120
    Likes Received:
    0

    Dear visitor, you need to Register or Login to view links on Certify Chat.

    Your network contains two server named DHCP1 and DHCP2 that run Windows Server 2012 and have the DHCP Server server role installed. You need to design a highly available DHCP deployment to meet the following requirements.

    . Deploy stateless DHCPv6
    . Provide Ipv6 options to clients on multiple subnets.
    . Allow for clients to renew existing IPV6 address leases if a single server is unavailable.
    . Minimize administrative effort.

    What should you include in the design?

    A. Configure both servers to provide identical option configuration.
    B. Add DHCP1 and DHCP2 to a failover cluster. Configure the DHCP for high availability.
    C. From DHCP1, configure DHCP Failover in Hot Standby Mode
    D. From DHCP1, configure DHCP Failover in Load Balance Mode.
    Click to expand...
    A is less admin effort, B sounds best
    C and D don't exist for ipv6
    take your pick, i dont even think microsoft has an answer for this one
     
  • il

    ilkman Member
    Member

    Joined:
    Dec 14, 2015
    Messages:
    20
    Likes Received:
    0

    Dear visitor, you need to Register or Login to view links on Certify Chat.

    A is less admin effort, B sounds best
    C and D don't exist for ipv6
    take your pick, i dont even think microsoft has an answer for this one
    Click to expand...

    It is A

    Dear visitor, you need to Register or Login to view links on Certify Chat.


    ...DHCP failover in Windows Server 2012 provides support for a maximum of two DHCP servers, and the failover relationship is limited to IPv4 scopes and subnets. Network nodes using Internet Protocol version 6 (IPv6) typically determine their own IPv6 address using stateless IP auto configuration. In this mode, the DHCP server delivers only the DHCP option configuration, and the server does not maintain any lease state information. A high availability deployment for stateless DHCPv6 is possible by simply setting up two servers with identical option configuration. Even in a stateful DHCPv6 deployment, the scopes do not run under high address utilization, which makes split scope a viable solution for high availability.
     
  • zd

    Member

    Joined:
    Dec 27, 2015
    Messages:
    9
    Likes Received:
    0
    Last dump with corrected answers is valid - it would be nice to have updated VCE/PDF

    NPSProxy question
    There is 100% and 0% answer
    If one of the lower(wining) 5 priority fails second 5 priority gets 100%
    The node with higher priority(loosing) always gets 0%

    Old answer.
    Box 1: On Server2, install the Windows Server Migration Tools.
    Box 2: On Server2, create a deployment folder.
    Box 3: On Server1, register the Windows Server Migration Tools.
    Box 4:On Server2, run the Receive-SmigServerData cmdlet.
    Box 5: On Server1, run the Send-SmigServerData cmdlet.

    -------------------------------


    New answer:
    Box 1: On FS1, install the Windows Server Migration Tools.
    Box 2: On FS1, create a deployment folder.
    Box 3: On FS2, register the Windows Server Migration Tools.
    Box 4:On FS1, run the Receive-SmigServerData cmdlet.
    Box 5: On FS2, run the Send-SmigServerData cmdlet.

    Good luck to You all!
     
  • dr

    dreamcast0642 Member
    Member

    Joined:
    Dec 20, 2015
    Messages:
    27
    Likes Received:
    0
    Q 5
    You are the administrator for a large company.You plan to implement servers in the environment that do not use local hard drives.
    You need to recommend a supported storage solution.Which technology should you recommend?

    A. Clustered NAS
    B. SMB (Scale Out File share/Server)
    C. DVD
    D. iSCSISAN

    New Options too

    A. Cloud Storage
    B. DVD
    C. iSCSISAN
    D. Storage Spaces

    If not
    iSCSISAN choose but have USB, i need choose usb is the best?
     
  • je

    jerseyyo Member
    Member

    Joined:
    Dec 14, 2015
    Messages:
    5
    Likes Received:
    0
    Was trying to understand this question and why answer was 4, 4, 2 but found a lot of different answers online. I did my own research and think that I found the reason, can anyone verify for me?

    Your network contains an Active Directory forest named northwindtraders.com.
    The client computers in the finance department run either Windows 8.1, Windows 8, or Windows7.
    All of the client computers in the marketing department run Windows 8.1.
    You need to design a Network Access Protection (NAP) solution for northwindtraders.com that meets the following requirements:
    - The client computers in the finance department that run Windows 7 must have a firewall enabled and the antivirus
    software must be up-to- date.
    - The finance computers that run Windows 8.1 or Windows 8 must have automatic updating enabled and the antivirus
    software must be up-to- date.
    - The client computers in the marketing department must have automatic updating enabled and the antivirus software must
    be up-to-date.
    - If a computer fails to meet its requirements, the computers must be provided access to a limited set of resources on
    the network.
    - If a computer meets its requirements, the computer must have full access to the network.
    What is the minimum number of objects that you should create to meet the requirements? To answer, select the appropriate number for each object type in the
    answer area.


    //////My Answer//////




    I was confused as well, I did some research and found the below, looks like 4, 4, 2 is correct to me - what do you guys think?


    4 Network Policies
    A. Access granted if Client meets conditions of being in finance department, running Windows 7 and matches Health Policy A
    B. Access limited if Client meets conditions of being in finance department, running Windows 7 and matches Health Policy B
    C. Access granted if Client meets conditions of being a finance computer, running Windows 8/8.1 and matches Health Policy C
    D. Access limited if Client meets conditions of being a finance computer, running Windows 8/8.1 and matches Health Policy C


    Conditions Step 6:

    Dear visitor, you need to Register or Login to view links on Certify Chat.




    Dear visitor, you need to Register or Login to view links on Certify Chat.

    s:

    Dear visitor, you need to Register or Login to view links on Certify Chat.




    4 Health Policies
    A. Client passes all SHV checks for SHV A
    B. Client fails one or more SHV checks for SHV A
    C. Client passes all SHV checks for SHV B
    D. Client fails one or more SHV checks for SHV B
    Health Policies:

    Dear visitor, you need to Register or Login to view links on Certify Chat.


    Create a Health Policy:

    Dear visitor, you need to Register or Login to view links on Certify Chat.


    Step 15:

    Dear visitor, you need to Register or Login to view links on Certify Chat.




    2 SHVs:
    A. A firewall is enabled for all network connections + Antivirus is up to date
    B. Automatic Updating is on + Antivirus is up to date
    Windows Security Health Validator:

    Dear visitor, you need to Register or Login to view links on Certify Chat.




    System Health Validators:

    Dear visitor, you need to Register or Login to view links on Certify Chat.




    Step 13:

    Dear visitor, you need to Register or Login to view links on Certify Chat.

     
  • je

    jerseyyo Member
    Member

    Joined:
    Dec 14, 2015
    Messages:
    5
    Likes Received:
    0
    After doing some other research online I believe the answer to this question is below, can anyone confirm?

    You deploy a web application named WebApp1 to a server named WEB01.
    WAP01 and WEB01 both run Microsoft Windows Server 2012 R2 and are members of the Active Directory Domain Services (AD DS) domain named
    corp.contoso.com.
    You have the following requirements:
    WebApp1 must be available internally at URL

    Dear visitor, you need to Register or Login to view links on Certify Chat.

    by using Kerberos authentication.
    WebApp1 must be available externally at URL

    Dear visitor, you need to Register or Login to view links on Certify Chat.

    by using Active Directory Federation Services
    (AD FS) authentication.
    You need to configure computer accounts.


    WEB01
    http/webapp1.contoso.net
    WAP01
    WEB01

    My research:
    SPN formatting does not include HTTPS, it only needs http service class defined:
    The HTTP service class The HTTP service class differs from the HTTP protocol. Both the HTTP protocol and the HTTPS protocol use the HTTP service class. The service class is the string that identifies the general class of service. Well-known service class names include "www" for a Web service and "ldap" for a directory service. Generally, the service class name can be any string that is unique to the service class. Be aware that the SPN syntax uses a forward slash character (/) to separate elements. Therefore, the forward slash character (/) cannot appear in a service class name.

    Dear visitor, you need to Register or Login to view links on Certify Chat.




    Further proven here:

    Dear visitor, you need to Register or Login to view links on Certify Chat.




    "A string that identifies the general class of service; for example, "SqlServer". There are well-known service class names, such as "www" for a Web service or "ldap" for a directory service. In general, this can be any string that is unique to the service class. Be aware that the SPN syntax uses a forward slash (/) to separate elements, so this character cannot appear in a service class name."


    If you scroll down you'll see this example: "Examples of SPN registrations: HTTP/www.contoso.com – Any page on the Web site on the default TCP port 80 for

    Dear visitor, you need to Register or Login to view links on Certify Chat.

    , that is

    Dear visitor, you need to Register or Login to view links on Certify Chat.

    ."


    Another forum source that states same thing:

    Dear visitor, you need to Register or Login to view links on Certify Chat.

     
  • jeday1

    jeday1 Member
    Member

    Joined:
    Oct 29, 2015
    Messages:
    14
    Likes Received:
    1
    different / changed questions from today

    Dear visitor, you need to Register or Login to view links on Certify Chat.



    good luck to you all ;)
     
  • ne

    nexuses Member
    Member

    Joined:
    Jan 1, 2016
    Messages:
    3
    Likes Received:
    0

    Dear visitor, you need to Register or Login to view links on Certify Chat.

    different / changed questions from today

    Dear visitor, you need to Register or Login to view links on Certify Chat.



    good luck to you all ;)
    Click to expand...
    You can't use DA with Windows XP clients and SSTP can't be use with XP either (Vista SP1 and higher)
     
  • ne

    nexuses Member
    Member

    Joined:
    Jan 1, 2016
    Messages:
    3
    Likes Received:
    0
    You have a server named Server1 that runs Windows Server 2012.
    Server1 has the DNS Server server role installed.
    You need to recommend changes to the DNS infrastructure to protect the cache from cache poisoning attacks.
    What should you configure on Server1?
    A. DNS devolution
    B. DNS Security Extensions (DNSSEC)
    C. DNS cache locking
    D. The global query block list

    Answer is D

    The question was different though; about blocking DNS names
     
  • lu

    luke17 Member
    Member

    Joined:
    Jan 6, 2016
    Messages:
    3
    Likes Received:
    0
    passed today 850. prepared examcollection premium and CertifyChat. 3,4 new questions, maybe some answers in the dump incorrect. all thanks!
     
  • Sh

    Shinning Sun Member
    Member

    Joined:
    Jan 16, 2016
    Messages:
    7
    Likes Received:
    0
    QUESTION 52
    Your network contains an Active Directory forest.
    The forest contains a single domain.
    The forest has five Active Directory sites.
    Each site is associated to two subnets.
    You add a site named Site6 that contains two domain controllers.
    Site6 is associated to one subnet.
    You need to verify whether replication to the domain controllers in Site6 completes successfully.
    Which two possible commands can you use to achieve the goal? Each correct answer presents a complete solution.
    A. Get-ADReplicationSubnet
    B. Get-ADReplicationUpToDatenessVectorTable
    C. repadmin /showattr
    D. Get-ADReplicationSite1ink
    E. repadmin /showrepl
    Correct Answer: BE

    Is this the correct answer for the question??
     
  • Sh

    Shinning Sun Member
    Member

    Joined:
    Jan 16, 2016
    Messages:
    7
    Likes Received:
    0

    Dear visitor, you need to Register or Login to view links on Certify Chat.

    You have a server named Server1 that runs Windows Server 2012.
    Server1 has the DNS Server server role installed.
    You need to recommend changes to the DNS infrastructure to protect the cache from cache poisoning attacks.
    What should you configure on Server1?
    A. DNS devolution
    B. DNS Security Extensions (DNSSEC)
    C. DNS cache locking
    D. The global query block list

    Answer is D

    The question was different though; about blocking DNS names
    Click to expand...
    Why the answer here isn't C?
     
  • ju

    junk01 Member
    Member

    Joined:
    Dec 28, 2015
    Messages:
    39
    Likes Received:
    2
    A global query block list is used to reduce vulnerability associated with dynamic DNS updates.

    But you need to protect the cache from cache poisoning attacks. Cache locking is a new feature available if your DNS server is running Windows Server 2008 R2 or higher. When you enable cache locking, the DNS server will not allow cached records to be overwritten for the duration of the time to live (TTL) value. Cache locking provides for enhanced security against cache poisoning attacks.

    Dear visitor, you need to Register or Login to view links on Certify Chat.



    So its C.
     
  • ju

    junk01 Member
    Member

    Joined:
    Dec 28, 2015
    Messages:
    39
    Likes Received:
    2
    Blocking DNS names is done with the DNS block list (global query block list)
     
  • Share This Page