70-413 Exam Questions - Online Test


70-413 Premium VCE File

Learn More 100% Pass Guarantee - Dumps Verified - Instant Download
150 Lectures, 20 Hours

surepassexam.com

Act now and download your Microsoft microsoft 70 413 test today! Do not waste time for the worthless Microsoft microsoft 70 413 tutorials. Download Most recent Microsoft Designing and Implementing a Server Infrastructure exam with real questions and answers and begin to learn Microsoft microsoft 70 413 with a classic professional.

Q31. - (Topic 8) 

Your network contains an Active Directory forest named contoso.com. The forest contains 

a single domain and two sites named Montreal and Vancouver. 

Montreal contains an IP Address Management (IPAM) server named Server1 that is used to manage all of the DHCP servers and the DNS servers in the site. 

Vancouver contains several DHCP servers and several DNS servers. 

In Vancouver, you install the IP Address Management (IPAM) Server feature on a server named Server2. 

You need to recommend which configurations must be performed to ensure that the DHCP servers and the DNS servers in Vancouver are managed by Server2. 

What should you recommend? 

A. Replicate the IPAM database from Server1 to Server2. On Server2, change the manageability status of the DNS servers and the DHCP servers in Vancouver. 

B. Replicate the IPAM database from Server1 to Server2. On Server1, change the manageability status of the DNS servers and the DHCP servers in Vancouver. 

C. From Server2, run the Invoke-IpamGpoProvisioning cmdlet On Server2, change the manageability status of the DNS servers and the DHCP servers in Vancouver. 

D. From Server1, run the Invoke-IpamGpoProvisioning cmdlet. On Server1, change the manageability status of the DNS servers and the DHCP servers in Vancouver. 

Answer:

Explanation: Invoke-IpamGpoProvisioning Creates and links group policies in the specified domain for provisioning required access settings on the servers managed by the computer running the IPAM server. 


Q32. - (Topic 1) 

What method should you use to deploy servers? 

A. WDS 

B. AIK 

C. ADK 

D. EDT 

Answer:

Explanation: WDS is a server role that enables you to remotely deploy Windows operating systems. You can use it to set up new computers by using a network-based installation. This means that you do not have to install each operating system directly from a CD, USB drive, or DVD. 

Reference: What's New in Windows Deployment Services in Windows Server 


Q33. - (Topic 2) 

You need to recommend a trust model. 

What should you include in the recommendation? 

A. A one-way, forest trust that has selective authentication. 

B. A one-way, external trust 

C. A two-way, external trust 

D. A one-way, forest trust that has domain-wide authentication. 

Answer:

Explanation: 

From case study: 

Users in the Montreal office must only be allowed to access shares that are located on 

File01 and File02. The Montreal users must be prevented from accessing any other servers 

in the proseware.com forest regardless of the permissions on the resources. 


Q34. - (Topic 8) 

Your network contains an Active Directory domain named contoso.com. All servers run either Windows Server 2008 R2 or Windows Server 2012. 

Your company uses IP Address Management (IPAM) to manage multiple DHCP servers. 

A user named User1 is a member of the IPAM Users group and is a member of the local Administrators group on each DHCP server. 

When User1 edits a DHCP scope by using IPAM, the user receives the error message shown in the exhibit. (Click the Exhibit button.) 

You need to prevent User1 from receiving the error message when editing DHCP scopes by using IPAM. 

What should you do? 

A. Add User1 to the DHCP Administrators group on each DHCP server. 

B. Add User1 to the IPAM Administrators group. 

C. Run the Set-IpamServerConfig cmdlet. 

D. Run the Invoke-IpamGpoProvisioning cmdlet. 

Answer:

Explanation: 

IPAM Administrators: IPAM Administrators have the privileges to view all IPAM data and perform all IPAM tasks. 

Reference: Walkthrough: Demonstrate IPAM in Windows Server 2012 

http://technet.microsoft.com/en-us/library/hh831622.aspx 


Q35. - (Topic 8) 

Your network contains an Active Directory domain named contoso.com. The domain contains multiple sites. 

You plan to deploy DirectAccess. 

The network security policy states that when client computers connect to the corporate network from the Internet, all of the traffic destined for the Internet must be routed through the corporate network. 

You need to recommend a solution for the planned DirectAccess deployment that meets the security policy requirement. 

Solution: You enable force tunneling. 

Does this meet the goal? 

A. Yes 

B. No 

Answer:

Explanation: DirectAccess. DirectAccess allows connectivity to organizational network resources without the need for traditional virtual private network (VPN) connections. 

DirectAccess allows remote users to securely access internal network file shares, Web sites, and applications without connecting to a virtual private network (VPN). An internal network is also known as a private network or intranet. DirectAccess establishes bi-directional connectivity with an internal network every time a DirectAccess-enabled computer connects to the Internet, even before the user logs on. Users never have to think about connecting to the internal network and IT administrators can manage remote computers outside the office, even when the computers are not connected to the VPN. 


Q36. - (Topic 8) 

Your company has a main office and four branch offices. The main office is located in London. 

The network contains an Active Directory domain named contoso.com. Each office contains one domain controller that runs Windows Server 2012. The Active Directory site topology is configured as shown in the exhibit. (Click the Exhibit button.) 

You discover that when a domain controller in a branch office is offline for maintenance, users in that branch office are authenticated by using the domain controllers in any of the sites. 

You need to recommend changes to Active Directory to ensure that when a domain controller in a branch office is offline, the users in that branch office are authenticated by the domain controllers in London. 

What should you include in the recommendation? 

A. Modify the DC Locator DNS Records settings. 

B. Disable site link bridging. 

C. Modify the site link costs. 

D. Modify the service location (SRV) records in DNS. 

Answer:

Explanation: 

If local DC (domain controller) is not available, DC Locator service will look for another DC in a different site. 


Q37. DRAG DROP - (Topic 7) 

You need to design the DNS zone for App1. 

What should you do? To answer, drag the appropriate resource record to the correct DNS se Each resource record may be used once, more than once, or not at all. You may need to drag split bar between panes or scroll to view content. 

Answer: 


Q38. - (Topic 8) 

Your company has three offices. The offices are located in New York, Chicago, and Atlanta. 

The network contains an Active Directory domain named contoso.com that has three Active Directory sites named Site1, Site2,and Site3. The New York office is located in Site1. The Chicago office is located in Site2. The Atlanta office is located in Site3. There is a local IT staff to manage the servers in each site. The current domain controllers are configured as shown in the following table. 

The company plans to open a fourth office in Montreal that will have a corresponding Active Directory site. Because of budget cuts, a local IT staff will not be established for the Montreal site. 

The Montreal site has the following requirements: 

. Users must be able to authenticate locally. 

. Users must not have the ability to log on to the domain controllers. 

. Domain account passwords must not be obtained from servers in the Montreal 

site. . Network bandwidth between the Montreal site and the other sites must be minimized. . Users in the Montreal office must have access to applications by using Remote Desktop Services (RDS). 

You need to recommend a solution for the servers in the Montreal site. 

What should you recommend? 

A. Only install a domain controller in the Montreal site that has a Server Core installation of Windows Server 2012. 

B. Install a read-only domain controller (RODC) in the New York site. 

C. Install a read-only domain controller (RODC) in the Montreal site. Install a member server in the New York site to host additional server roles. 

D. Install a domain controller in the Montreal site that has a Server Core installation of Windows Server 2012. Install a member server in the Montreal site to host additional server roles, 

Answer:


Q39. - (Topic 8) 

Your company has two divisions named Division1 and Division2. 

The network contains an Active Directory domain named contoso.com. The domain contains two child domains named divisionl.contoso.com and division2.contoso.com. 

The company sells Division1 to another company. 

You need to prevent administrators in contoso.com and division2.contoso.com from gaining administrative access to the resources in divisionl.contoso.com. 

What should you recommend? 

A. Create a new tree in the forest named contoso.secure. Migrate the resources and the accounts in divisionl.contoso.com to contoso.secure. 

B. On the domain controller accounts in divisionl.contoso.com, deny the Enterprise Admins group the Allowed to Authenticate permission. 

C. Create a new forest and migrate the resources and the accounts in divisionl.contoso.com to the new forest. 

D. In divisionl.contoso.com, remove the Enterprise Admins group from the Domain Admins group and remove the Enterprise Admins group from the access control list (ACL) on the divisionl.contoso.com domain object. 

Answer:


Q40. - (Topic 8) 

Your network contains an Active Directory domain named contoso.com. Client computers run either Windows 7 or Windows 8. 

You plan to implement several Group Policy settings that will apply only to laptop computers. 

You need to recommend a Group Policy strategy for the planned deployment. 

What should you include in the recommendation? 

More than one answer choice may achieve the goal. Select the BEST answer. 

A. Loopback processing 

B. WMI filtering 

C. Security filtering 

D. Block inheritance 

Answer:

Explanation: 

Group Policy WMI Filter – Laptop or Desktop Hardware A method to detect hardware as laptop only is to look for the presence of a battery based on the BatteryStatus property of the Win32_Battery class. By using the Win32_Battery class, we can search to see if there is a battery present. If the battery status is not equal to zero (BatteryStatus <> 0 ) then you know that it is a laptop. 

Reference: Group Policy WMI Filter – Laptop or Desktop Hardware