You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All domain controllers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed.
You implement DirectAccess. You leave the connection name as the default when you run the DirectAccess wizard.
You want to view the properties of a DirectAccess connection.
In the Networks window, what is the name of the DirectAccess connection?
A. VPN Connection.
B. Remote Access Connection.
C. Local Area Connection.
D. ABC.com.
E. Workplace Connection.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed.
ABC.com has a main office and a branch office. The two offices are connected by a WAN link.
A server in the main office named ABC-SR21 runs the DNS Server role and hosts an Active Directory Integrated primary zone for ABC.com. You install a server named ABC-SR22 in the branch office. ABC-SR22 runs the DNS Server role.
You plan to configure a secondary zone for ABC.com on ABC-SR22.
What do you need to do first?
A. You should modify the ABC.com zone on ABC-SR21 to be a non-Active Directory Integrated primary zone.
B. You should log in to ABC-SR21 and configure an MX record for ABC-SR22.
C. You should log in to ABC-SR21 and configure a zone delegation for ABC-SR22.
D. You should log in to ABC-SR21 and in the properties of the ABC.com zone, add ABC-SR22 as a name server.
You are hired by ABC.com to administrate an Active Directory domain named ABC.com which encompasses a RADIUS server by the name of ABC-SR08 running an installation of Windows Server 2012.
Your senior network administrator has provisioned a VPN server added to the network named ABC-VPN05 and thereafter orders the creation of numerous network policies on ABC-SR08.
Which of the following actions need to be taken if you are assigned the task of having ABC-SR08 configured to accept appeals for authentication from ABC-VPN05?
A. You will need to run the Add-RemoteAccessRadius command on ABC-SR08.
B. You will need to run the Get-NpsRadiusClient command on ABC-SR08.
C. You will need to run the Set-RemoteAccessRadius command on ABC-SR08.
D. You will need to configure the Routing and Remote Access Service (RRAS) role service on ABC-SR08.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed.
All domain controllers in the domain are configured as DNS servers and host an Active Directory integrated zone for ABC.com.
You need to configure a Web server solution to host the company Intranet website.
You configure three Windows Server 2012 R2 servers named ABC-SR17, ABC-SR18 and ABCSR19.
The three Web servers dynamically register their IP addresses and hostnames in the ABC.com DNS zone.
You plan to use DNS Round Robin to distribute connections to http://intranet.ABC.com between the three Web servers.
You need to create the DNS server records.
What DNS records should you create?
A. You should create one Host (A) record for intranet.ABC.com.
B. You should create one Alias (CNAME) record for intranet.ABC.com.
C. You should create three Host (A) records for intranet.ABC.com
D. You should create three Alias (CNAME) records for intranet.ABC.com.
E. You should create one Host (A) record for intranet.ABC.com and three Alias (CNAME) records, one for each Web server.
F. You should create one Alias (CNAME) record for intranet.ABC.com and three Host (A) records, one for each Web server.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed.
All user and computer accounts for the company’s Sales department are located in an organizational unit named Sales.
You must configure group policy object (GPO) for the Sales OU. You download updated administrative template files. You then configure a Central Store on a domain controller.
However, when you open a new GPO for editing using the Group Policy Editor console, you discover that no administrative templates are listed under Computer Configuration \ Administrative Templates.
How can you view the administrative templates in the GPO?
A. You should enable the Computer settings of the GPO.
B. You should copy the .admx and .adml files from %Windir%\Policydefinitions to the central store.
C. You should link the GPO to the Sales OU.
D. You should modify the Security Filtering of the GPO.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed.
A group policy object (GPO) is assigned to an organizational unit (OU) named Sales. The GPO assigns several settings to the computers in the Sales department.
You unlink the GPO from the Sales OU.
You discover that some of the settings applied by the GPO are still in effect on the Sales computers while other setting applied by the GPO have been removed.
Which of the following statements is true?
A. The Restricted Groups security settings still in effect.
B. The unmanaged Administrative Template settings are still in effect.
C. The managed Administrative Template settings are still in effect.
D. The System Services security settings have been removed.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed.
ABC.com has a Production department and a Research department. Each department has a separate subnet in the network.
A server named ABC-SR11 and is configured as a Network Policy Server (NPS) server. ABCSR11 also runs the DHCP server role and has a DHCP scope for the Production subnet and the Research subnet.
You need to configure NPS to ensure that computers on the Production subnet that do not comply with the NPS requirements receive a restrictive set of network policies. You also need to ensure that computers on the Research subnet that do not comply with the NPS requirements receive a more restrictive set of network policies than the non-compliant Production computers.
You configure policies to apply to NAP-Capable Computers.
How can you apply different restrictions to computer based on their subnet?
A. You should configure Connection Properties conditions.
B. You should configure NAS Port Type constraints.
C. You should configure MS-Service Class conditions.
D. You should configure Authentication Methods constraints.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed.
A technician has created a vhdx file containing Windows Server 2012 R2 installation images. You need to view information about the images contained in the vhdx file.
You plan to use Deployment Image Servicing and Management (DISM.exe).
Which parameter should you use with DISM.exe?
A. You should use the get-imageinfo parameter.
B. You should use the get-mountedwiminfo parameter.
C. You should use the list-image parameter.
D. You should use the mount-image parameter.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed. The ABC.com domain has a server named ABC-SR12 that hosts the Deployment Services (WDS) role.
You need to create a Windows Server 2012 R2 image. You decide to use a server named ABCSR14 as a reference computer.
What action should you take?
A. You should use Windows Deployment Services (WDS) to create a discovery image.
B. You should use Windows Deployment Services (WDS) to create a boot image.
C. You should use Windows Deployment Services (WDS) to create a capture image.
D. You should use Windows Deployment Services (WDS) to create a custom install image.
E. You should use Windows Deployment Services (WDS) to create a deployment image.
You work for a company named ABC.com. The ABC.com network consists of a single Active Directory forest named ABC.com. The forest contains a single Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Windows Server 2012 R2 installed.
ABC.com works with a partner company named Redbridge Logistics. The Redbridge Logistics network consists of a single Active Directory forest named RedbridgeLogistics.com. The forest contains a single Active Directory Domain Services (AD DS) domain named RedbridgeLogistics.com. All servers in the RedbridgeLogistics.com domain have Windows Server 2012 R2 installed.
A forest trust exists between the two forests. The two networks are connected by a WAN link.
A server named ABC-SR23 hosts an Active Directory-integrated zone for ABC.com. A server named REDBRIDGE-SR16 hosts an Active Directory-integrated zone for RedbridgeLogistics.com.
RedbridgeLogistics.com plans to install additional DNS servers for the RedbridgeLogistics.com domain.
Users in the ABC.com domain need to be able to resolve names of servers in the RedbridgeLogistics.com domain.
You need to configure a name resolution solution that will ensure that name resolution requests are automatically forwarded to the new RedbridgeLogistics.com DNS servers when they are installed.
What should you do?
A. You should configure a forwarder on ABC-SR23.
B. You should configure a forwarder on REDBRIDGE-SR16.
C. You should configure a secondary zone on ABC-SR23.
D. You should configure a stub zone on REDBRIDGE-SR16.
E. You should configure a stub zone on ABC-SR23.
F. You should configure a conditional forwarder on ABC-SR23.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed and all client computers have either Windows 7 Professional or Windows 8 Pro installed.
A group policy object (GPO) is assigned to an organizational unit (OU) named Sales. The GPO assigns several settings to the computers in the Sales department.
Some users complain that it takes a long time for their computers to start up or shut down.
You suspect that group policy processing may be the cause of the issue.
You want to configure the computers in the Sales department to display status messages that reflect each step in the process of starting, shutting down, logging on, or logging off the system.
How can you configure the computers to display the required information?
A. You should enable the “Activate Shutdown Event Tracker System State Data feature” setting in the GPO.
B. You should enable the “Display Shutdown Event Tracker” setting in the GPO.
C. You should disable the “Remove Boot / Shutdown / Logon / Logoff status messages” setting in the GPO.
D. You should enable the “Display Highly Detailed Status Messages” setting in the GPO.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed.
You need to configure a remote access solution to enable client computers to access network resources.
You install a Windows Server 2012 R2 server named ABC-SR09. You install the Remote Access server role on ABC-SR09.
You need to configure ABC-SR09 to accept authentication requests from computers using 802.1X.
Which authentication method should you configure ABC-SR09 to use?
A. EAP
B. MS-CHAP v2
C. CHAP
D. PAP
E. Machine certificate authentication for IKEv2
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed. Mia works as an IT Technician at ABC.com. Mia is not a member of the Domain Admins group.
You need to enable Mia to link existing Group Policy objects (GPOs) in the domain. Mia must not be able to modify existing GPOs.
Your solution must minimize the administrative privileges assigned to Mia.
Which two of the following actions would achieve the desired result? (Choose two possible answers).
A. Click the Group Policy Objects node in Group Policy Management and add Mia under the Delegation tab.
B. Click the domain node in Group Policy Management and add Mia under the Delegation tab.
C. Right-click the domain node in Active Directory Users and Computers and select Delegate Control.
D. Add Mia to the Group Policy Creator Owners group in Active Directory Users and Computers.
E. In Active Directory Users and Computers, add Mia to the Managed By tab in the properties of the Domain Controllers group.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed.
ABC.com has a main office and a branch office. The two offices are connected by a WAN link. ABC.com has five domain controllers named ABC-DC01, ABC-DC02, ABC-DC03, ABC-DC04 and ABC-DC05. All domain controllers are configured as DNS servers and host an Active Directory integrated zone for ABC.com.
ABC-DC01, ABC-DC03 and ABC-DC05 are located in the main office. ABC-DC02 and ABC-DC04 are located in the branch office.
ABC.com has a Development department located in the main office.
The manager of the Development department has asked you to configure a new Active Directory integrated zone named ABCDev.com.
You need to ensure that the ABCDev.com zone is replicated to only the domain controllers in the main office.
What should you do?
A. You should create the ABCDev.com zone and add the main office domain controllers on the Zone Transfers tab.
B. You should create the ABCDev.com zone and modify the replication scope.
C. You should create an application directory partition that contains the main office domain controllers before creating the ABCDev.com.
D. You should create a global security group that contains the main office domain controllers before creating the ABCDev.com.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed.
The network includes virtual machines (VMs) running on Windows Server 2012 R2 Hyper-V host servers. One of the Hyper-V host servers is named ABC-SR31.
You suspect that the processor load on ABC-SR31 is high and is therefore impacting the performance of the virtual machines (VMs) hosted on the server.
You need to monitor the processor usage on ABC-SR31. You need to measure the total physical processor utilization of the host operating system and all guest VM operating systems.
Which of the following performance monitor counters should you monitor?
A. \Processor(*)\% Processor Time
B. Hyper-V Hypervisor Logical Processor
C. Hyper-V Hypervisor Virtual Processor
D. Hyper-V Hypervisor Root Virtual Processor
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have either Windows Server 2008 R2 or Windows Server 2012 R2 installed.
The network includes virtual machines (VMs) running on Windows Server 2012 R2 Hyper-V host servers.
The Schema Master FSMO role is hosted by Windows Server 2012 R2 domain controller. All other FSMO roles are hosted on Windows Server 2008 R2 domain controllers.
A VM named ABC-DC12 runs Windows Server 2012 R2 and is configured as a domain controller. ABC-DC12 does not hold any FSMO roles.
You want to clone ABC-DC12.
What should you do first?
A. You should transfer the Infrastructure Master FSMO role to a Windows Server 2012 R2 domain controller.
B. You should transfer the Domain Naming Master FSMO role to a Windows Server 2012 R2 domain controller.
C. You should transfer the PDC Emulator FSMO role to a Windows Server 2012 R2 domain controller.
D. You should transfer the Schema Master FSMO role to a Windows Server 2008 R2 domain controller.
E. You should transfer the Relative ID Master FSMO role to a Windows Server 2012 R2 domain controller.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed and all client computers have Windows 8 Pro installed.
ABC.com has users that often work away from the office at customer sites or from home.You have been asked to implement a remote access solution to enable remote users to connect to the network when they are working away from the office.
The remote access solution must ensure that users can connect to the network using TCP port 443.
You install the Routing and Remote Access role on a Windows Server 2012 R2 server.
Which VPN solution should you implement?
A. Point-to-Point Tunneling Protocol (PPTP).
B. Layer 2 Tunneling Protocol (L2TP).
C. Secure Socket Tunneling Protocol (SSTP).
D. DirectAccess.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed.
ABC.com has a Sales department and a Research department. An organizational unit (OU) exists for each department. The OUs contain the user and computer accounts for the respective departments.
The client computers are a mix of portable laptop computers and desktop computers. All client computers have Windows 7 Professional installed.
You configure a group policy object (GPO) named SalesDesktops. You link the GPO to the Sales OU.
You need to ensure that the SalesDesktops GPO applies to only the desktop computers in the Sales department. Your solution should ensure that any new desktop computers added to the Sales OU also receive the SalesDesktops GPO.
How can you ensure that only Sales desktop computers receive the GPO?
A. You should configure Security Filtering.
B. You should modify the GPO precedence order.
C. You should configure WMI filtering.
D. You should modify the GPO enforcement settings.
E. You should modify the GPO status.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed and all client computers have Windows 7 Professional installed. The client computers are a mix of portable laptop computers and desktop computers.
ABC.com has a Sales department and a Research department. An organizational unit (OU) exists for each department. The OUs contain the user and computer accounts for the respective departments.
You configure a group policy object (GPO) named ManagersGPO. You link the GPO to the domain.
You need to ensure that the ManagersGPO is applied to managers in all departments. The ManagersGPO must not be applied to other users.
How can you ensure that only managers receive the GPO?
A. You should configure Security Filtering.
B. You should modify the GPO precedence order.
C. You should configure WMI filtering.
D. You should modify the GPO enforcement settings.
E. You should modify the GPO status.
You work as a Network Administrator at ABC.com. ABC.com has an Active Directory Domain Services (AD DS) domain named ABC.com. All servers in the ABC.com domain have Microsoft Windows Server 2012 R2 installed and all client computers have Windows 8 Pro installed.
ABC.com has a Sales department. An organizational unit (OU) exists for the Sales department and contains the user and computer accounts for the department.
A group policy object (GPO) named SalesGPO is linked to the Sales OU and applies settings to the Sales users and their computers.
You modify some settings in SalesGPO. You need to apply the new settings to the users and computers in the Sales OU as quickly as possible.
Which two of the following tools could you use? (Choose two possible answers).
A. You should use the Group Policy Management Console (GPMC).
B. You should use the Invoke-GPUpdate cmdlet.
C. You should use the Active Directory Sites and Services.
D. You should use the Get-GPO cmdlet.
E. You should use the Secedit command.
F. You should use the Set-GPLink cmdlet.