You work as a Network Administrator at ABC.com where you manage a Windows Server 2012 R2 Active Directory Domain Services (AD DS) domain named ABC.com.
The ABC.com network has a server named ABC-SR25 that is configured as a Network Policy Server (NPS). ABC-SR25 is to be decommissioned and will be replaced by a server named ABCSR28. You must use the same NPS configurations on ABC-SR28.
You export the configuration settings on ABC-SR25 to a file.
Which of the following actions should you take to have the settings imported to ABC-Sr28?
A. You should configure SQL Server Logging Properties and Network Policies.
B. You should configure Network Policies and Connection Request Policies.
C. You should configure SQL Server Logging Properties on ABC-SR28
D. You should configure Connection Request policies and RADIUS Clients.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers on the network have Windows Server 2012 R2 installed.
Some users work from home. The users working at home often use their own computers that are not members of the ABC.com domain.
You need to implement a VPN solution to enable users working from home to connect to network resources.
You want to use to use certificate-based authentication on a server running Network Policy Server (NPS) for VPN connections.
You install a Windows Server 2012 R2 server named ABC-SR27. You install the Network Policy and Access Services server role on ABC-SR27.
You obtain a certificate from a third party Certification Authority. You need to ensure that ABCSR27 trusts the certificate to enable the server to perform the certificate based VPN authentication.
You need to identify which certificate store in the Certificates console to import the certificate.
Which store should you identify?
A. Personal under Current User.
B. Trusted Root Certification Authorities under Current User.
C. Client Authentication Issuers under Current User.
D. Personal under Local Computer.
E. Trusted Root Certification Authorities under Local Computer.
F. Client Authentication Issuers under Local Computer.
You administer a Microsoft Windows Server 2012 domain named ABC.com. ABC.com utilizes two computers named ABC-DC01 and ABC-SR01. ABC-DC01 is configured as a DNS, DHCP and RADIUS server and ABC-SR01 is configured as a Web Server and Network Policy Server (NPS).
During the course of the day you receive instruction to ensure ABC-SR01 forwards all accounting requests received to ABC-DC01.
What action should be taken?
A. You should consider creating a remote RADIUS server group named KingRemote and access the Network Policies node of the NPS configuration.
B. You should consider creating a remote RADIUS server group named KingRemote and access the Connection Request Policies node of the NPS configuration.
C. You should consider creating a remote RADIUS server group named KingRemote and access the Health Policies node of the NPS configuration.
D. You should consider creating a remote RADIUS server group named KingRemote and access the Remediation Server Groups node of the NPS configuration.
You work as a Network Administrator at ABC.com where you manage a Windows Server 2012 R2 Active Directory Domain Services (AD DS) domain named ABC.com.
You receive instruction to restore the Default Domain Policy GPO which the junior administrator had deleted. No backup of the Group Policy Objects (GPOs) exist.
Which of the following actions should you take?
A. You should run the Set-GPLink cmdlet.
B. You should run the Set-GPPermissions cmdlet.
C. You should run the Set-GPRegistryValue cmdlet.
D. You should run the GpfixupGpresult command.
E. You should run the New-GPLink cmdlet.
F. You should run the Dcgpofix command.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. The servers on the ABC.com network have Windows Server 2012 R2 installed.
The Active Directory contains 100 organizational units (OUs) and 200 group policy objects (GPOs).
You need to assign GPOs to OUs and modify the order of precedence of existing linked GPOs.
Which two of the following PowerShell cmdlets should you use? (Choose two)
A. You should run the Set-GPInheritance cmdlet.
B. You should run the Set-GPLink cmdlet.
C. You should run the Set-GPPermissions cmdlet.
D. You should run the Set-GPRegistryValue cmdlet.
E. You should run the New-GPO cmdlet.
F. You should run the New-GPLink cmdlet.
G. You should run the Set-GPO cmdlet.
You work as a Network Administrator at ABC.com. ABC.com has a forest with two Active Directory Domain Services (AD DS) domains named ABC.com and dev.ABC.com. The servers in the forest have Windows Server 2012 R2 installed.
The dev.ABC.com domain is used for test purposes including the testing of Group Policy Objects (GPOs). There are 100 GPOs configured in the dev.ABC.com domain.
The dev.ABC.com was recently renamed. Since then, many of the GPOs are not working correctly.
You need to fix the domain name dependencies in the GPOs and Group Policy links.
What should you do?
A. You should run the Set-GPLink cmdlet.
B. You should run the Gpfixup utility.
C. You should run the Set-GPO cmdlet.
D. You should run the Dcgpofix utility.
E. You should run the Rendom utility.
F. You should run the Convert utility.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. The servers on the ABC.com network have Windows Server 2012 R2 installed and the client computers have either Windows 7 Professional or Windows 8 Pro installed.
The Active Directory contains organizational units for each company department. The Sales OU contains two global security groups named SalesUsers and SalesManagers.
You link a group policy object (GPO) to the Sales OU.
Sales Managers complain that there are now restrictions on their client computers.
You need to modify the GPO so that it applies to members of the SalesUsers group but not members of the SalesManagers group.
Which of the following command or cmdlets should you run?
A. You should run the Set-GPLink cmdlet.
B. You should run the Set-GPPermissions cmdlet.
C. You should run the Set-GPO cmdlet.
D. You should run the Set-GPInheritance cmdlet.
E. You should run the Gpupdate cmdlet.
F. You should run the Gpfixup cmdlet.
You work as a Network Administrator at ABC.com where you manage a Windows Server 2012 Active Directory Domain Services (AD DS) domain named ABC.com.
During the course of the week you receive instruction to configure ABC-DC01 to record all information regarding access to devices with removable storage.
Which of the following actions should you take?
A. You should configure the Account Logon auditing category.
B. You should configure the Detailed Tracking auditing category.
C. You should configure the DS Access auditing category.
D. You should configure the Object Access auditing category.
You administer a Microsoft Windows Server 2012 domain named ABC.com. ABC.com utilizes three computers named ABC-DC01, ABC-DC02 and ABC-SR01. ABC-DC01 hosts the PDC emulator, Infrastructure master and DHCP server roles.
ABC-DC02 is configured as a RID master, DNS and EFS server with ABC-SR01 configured as the
Web server, NPS and Schema master. During the course of the day you receive instruction to point-out configurations which would prevent ABC.com from utilizing a Distributed File System (DFS) namespace.
Which factors should you consider?
A. You should consider the Namespace Server and Namespace Settings utilized.
B. You should consider the operating systems and roles hosted by the servers utilized.
C. You should consider the RID master, Schema master and PDC emulator role locations.
D. You should consider the functional level configured for the domain.
You work as a Network Administrator at ABC.com where you manage a Windows Server 2012 R2 Active Directory Domain Services (AD DS) domain named ABC.com. The ABC.com network has an organizational unit (OU) named FileServ that stores the computer accounts for all file servers the domain.
You need to be able to track access files located in a shared folder named Confidential and in the SYSVOL on the file servers.
Which of the actions should you consider?
A. You should audit Account Logon and Object Access.
B. You should audit Object Access.
C. You should audit Global Object Access Auditing and DS Access.
D. You should audit Directory Service Access.
You administer a Microsoft Windows Server 2012 domain named ABC.com. The ABC.com domain has a server named ABC-DC01 which hosts the DNS service, DHCP and File Server Resource Manager role service. ABC.com Development division members utilize a folder named DevShare for storage purposes. You are required to configure a notification solution that is triggered by Development division members causing File Screening Auditing to occur.
Which of the following actions should you take on ABC-DC01?
A. You should configure a file group.
B. You should configure a file screen template.
C. You should configure Quota Management.
D. You should configure File Management Tasks.
E. You should configure a storage report task.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. The servers on the ABC.com network have Windows Server 2012 R2 installed and the client computers have Windows 7 Enterprise installed. The ABC.com network is divided into several sites. The network also has a Distributed File System (DFS) namespace with a target folder for each site.
You notice that a network user named Rory Allen frequently accesses a DFS target folder from different sites. The company’s data access policy states that users must only be allowed to access DFS target folders from their site and not from other sites.
Which of the following actions should you take to have all users comply with the data access policy?
A. You should configure the client computers to make use of DirectAccess.
B. You should enable the Bridge all site links option in Active Directory Sites and Services.
C. You should configure the Referral settings for the DFS namespace.
D. You should configure Work Folders for the client computers.
E. You should modify the Active Directory site links.
F. You should configure IP address-to-site mappings of the client computers in Active Directory.
G. You should run the Dfsutil.exe /pktflush command on the client computers.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. The servers on the ABC.com network have Windows Server 2012 installed and the client computers have Windows 8 Enterprise installed.
Hard disk information is secured using BitLocker Drive Encryption (Bitlocker). ABC.com wants a solution implemented using the minimum server features and roles to support the Network Unlock feature.
Which of the following servers should be utilized for the feature?
A. A NPS Server
B. A DHCP server
C. A DFS Server
D. A Windows Deployment Server
E. An Application Server
F. A Web Server
G. A File and Print Server
H. A Windows Server Update Services server
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. The servers on the ABC.com network have Windows Server 2012 R2 installed and the client computers have either Windows 7 Professional or Windows 8 Pro installed.
A group policy object (GPO) is applied to the client computers. The GPO assigns several Windows PowerShell scripts that run when a user logs in to their client computer.
Users complain that it takes a long time for the desktop to appear when logging on to client computers. How can you reduce the time it takes for the desktop to appear when users log on to client computers?
A. You should set the “Run startup scripts asynchronously” GPO setting to Enabled.
B. You should set the “Run startup scripts asynchronously” GPO setting to Disabled.
C. You should set the “Run logon scripts synchronously” GPO setting to Enabled.
D. You should set the “Run logon scripts synchronously” GPO setting to Disabled.
You administer a Microsoft Windows Server 2012 domain named ABC.com. ABC.com domain controllers run Microsoft Windows Server 2012 and client computers run Microsoft Windows 8.
ABC.com Marketing division members utilize portable computers which are in an organizational unit (OU) named Marketers. You are required to utilize Group policy to configure connections for Internet utilization.
Which settings should be configured?
A. You should configure Software Settings of the User Configuration in the Group Policy Object (GPO).
B. You should configure Windows Settings of the User Configuration in the Group Policy Object (GPO).
C. You should configure Windows Connect Now of the User Configuration in the Group Policy Object (GPO).
D. You should configure Network Connections and Network Options of the User Configuration in the Group Policy Object (GPO).
You administer a Microsoft Windows Server 2012 domain named ABC.com. The ABC.com domain has a server named ABC-DC01 configured as a NPS, Web Server and File Server. During the course of the week you receive complaints from users stating Internet Explorer 10 and Internet Explorer 11 never starts at the company homepage. ABC.com wants you to ensure client computers browsing starts at www.ABC.com.
Which of the following actions should you take?
A. You should configure the Startup of Internet Explorer 10 to Start with tabs from the last session.
B. You should configure the Tabs section of Internet Explorer 11 to choose which pages are displayed in tabs.
C. You should consider utilizing F5 after opening the Internet Explorer 10 and Internet Explorer 11 settings.
D. You should consider utilizing the dcgpofix.exe and GPupdate commands.
You administer a Microsoft Windows Server 2012 domain named ABC.com. ABC.com utilizes a server named ABC-SR08 to which you are required to have Windows Server Update Services (WSUS) configured to support Secure Sockets Layer (SSL).
Which of the following commands need to be run in conjunction with the appropriate facility in order to accomplish this?
A. You will need to run the wsusutil.exe command by utilizing Internet Information Services (IIS) Manager and modify the bindings as well as the connection strings of the WSUS website.
B. You will need to run the iisreset.exe command by utilizing Internet Information Services (IIS) Manager and modify the bindings of the WSUS website.
C. You will need to run the wsusutil.exe command by utilizing the SMS_SCI_Component class in WSUS Configuration Manager, thereafter have a server certificate installed.
D. You will need to run the iisreset.exe command by utilizing Internet Information Services (IIS) Manager and modify the connection strings of the WSUS website.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed. The ABC.com network has a server named ABC-SR21 that hosts the Windows Server Update Services (WSUS), NPS and DNS services.
All client computers on the ABC.com network have Windows 7 Enterprise. You want to create a Group Policy object (GPO) that will configure the client computers to receive Windows updates from ABC-SR21 and install the updates after business hours on every Saturday.
Which of the following actions should you take?
A. You should configure the Turn on Software Notifications settings in the GPO.
B. You should configure the Turn on recommended updates via Automatic Updates settings in the GPO.
C. You should configure the Allow Automatic Updates immediate installation settings in the GPO.
D. You should configure the Configure Automatic Updates settings in the GPO.
E. You should configure the Automatic Updates detection frequency settings in the GPO.
F. You should configure the Reschedule Automatic Updates scheduled installations settings in the GPO.
G. You should configure the Enable client-side targeting settings in the GPO.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed.
ABC.com wants you to collect information about the registry setting on a domain controller named ABC-DC33, as well as information about the Active Directory data that is replicated from ABCDC33 to the other domain controllers.
What actions should you take?
A. You should create a Data Collector Set (DCS) and configure it to collect System configuration information. Then create a Data Collector Performance Counter Alert.
B. You should create a Performance Counter and configure a Performance Alert.
C. You should create a Data Collector Set (DCS) and configure it to collect Performance Counter. Then configure a Performance Alert.
D. You should create a Data Collector Set (DCS) and configure it to collect System Configuration Information and Performance Counter data.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. The network includes physical servers and a virtual infrastructure based on Windows Server 2012 R2 Hyper-V. All servers have Windows Server 2012 R2 installed.
The network includes servers running Windows Server 2008 R2 Service Pack 1 (SP1) and Windows Server 2012 R2.
You have a Virtual Hard Disk (VHD) named Win12.vhd. Win12.vhd contains an image of Windows Server 2012 R2. You use Win12.vhd to deploy Windows Server 2012 R2 servers on the network.
You need to apply some updates to Win12.vhd using Deployment Image Servicing and Management (DISM). The updates are in a file named updates.cab.
You plan to use the following command to apply the updates.
Dism /Image:C:\VHDs\Win12.vhd /Add-Package /PackagePath:C:\Packages\updates.cab
You need to ensure that any updates in the cab file that require a reboot are not installed.
How should you modify the DISM command?
A. You should replace the /Add-Package option with the /Add-ProvisionedAppxPackage option.
B. You should append the /PreventPending option.
C. You should append the /IgnoreCheck option.
D. You should replace the /Add-Package option with the /Enable-Feature option.