Q1. A company with 75,000 employees has an Office 365 tenant.
You need to install the Azure Active Directory Synchronization (AAD Sync) tool by using the least amount of administrative effort.
Which versions of each product should you implement? (Select three)
Select three.
A. .Net 3.5
B. Net 4.0
C. .Net 4.5
D. .Net 4.5.1
E. PowerShell (PS1)
F. PowerShell (PS2)
G. PowerShell (PS3)
H. PowerShell (PS4)
I. SQL Server Express
J. SQL Server 2008
K. SQL Server 2012
L. SQL Server 2014
Answer: D,F,L
Explanation: * The following components need to be installed:
Net 4.5.1
PowerShell (PS3 or better is required)
*Azure AD Sync requires a SQL Server database to store identity data. By default a SQLExpress LocalDB (a light version of SQL Server Express) is installed and the service account for the service is created on the local machine. SQL Server Express has a 10GB size limit that enables you to manage approximately
100.000 objects. This is fine for the scenario in this question.
If you need to manager a higher volume of directory objects, you need to point the installation process to a different version of SQL Server..AAD Sync supports all flavors of Microsoft SQL Server from SQL Server 2008 to SQL Server 2014.
Reference: Install the Azure Active Directory Sync Service
https://msdn.microsoft.com/en-us/library/azure/dn757602.aspx
Q2. An organization implements single sign-on (SSO) for use with Office 365 services. You install an Active Directory Federation Services (AD FS) proxy server.
Users report that they are unable to authenticate. You launch the Event Viewer and view the event information shown in the following screen shot:
You need to ensure that users can authenticate to Office 365.
What should you do?
A. Re-enter the credentials used to establish the trust.
B. Verify the federation server proxy is trusted by the federation service.
C. Re-install the Secure Sockets Layer (SSL) certificate for the federation service.
D. Verify network connectivity between the Federation Service Proxy and federation server.
Answer: A
Q3. DRAG DROP
A company deploys an Office 365 tenant. You install the Active Directory Federation Services (AD FS) server role on a server that runs Windows Server 2012. You install and configure the Federation Service Proxy role service. Users sign in by using the Security Assertion Markup Language (SAML) protocol.
You need to customize the sign-in pages for Office 365.
Which pages should you customize? To answer, drag the appropriate page to the correct customization. Each page may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Answer:
Q4. DRAG DROP
A company plans to implement an Office 365 environment to manage email.
All user accounts must be configured to use only a custom domain.
You need to provision an Office 365 tenant for the company.
Which three actions should you perform in sequence? To answer, move the appropriate
actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
70 DRAG DROP
A company has an Office 365 tenant. You plan to use Office 365 to manage the DNS settings for a custom domain. You purchase the domain through a third-party provider.
You create a custom website. You must host the website through a third-party provider at the IP address 134.170.185.46. You need to configure the correct DNS settings.
What should you do? To answer, drag the appropriate DNS record to the correct DNS target. Each record may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Q5. Your company purchases an Office 365 plan. The company has an Active Directory Domain Services domain.
User1 must manage Office 365 delegation for the company.
You need to ensure that User1 can assign administrative roles to other users.
What should you do?
A. Create an Office 365 tenant and assign User1 the password administrator role.
B. Use a password administrator account to assign the role to User1.
C. Use a user management administrator account to assign the role to User1.
D. Create an Office 365 tenant and assign User1 the global administrator role.
Answer: D
Q6. You have an Exchange Online tenant. User1 reports that they are not able to check their email. Other users can check their email.
You remotely connect to User1's session.
You need to troubleshoot why the user cannot check his email.
What should you use?
A. POP Email test
B. Outlook Connectivity test
C. Microsoft Remote Connectivity Analyzer
D. Microsoft Connectivity Analyzer
E. Outlook Autodiscover test
F. IMAP Email test
Answer: C
Explanation:
Microsoft Remote Connectivity Analyzer (https://testconnectivity.microsoft.com/) can test incoming and outgoing e-mail.
Reference: https://testconnectivity.microsoft.com/
Q7. DRAG DROP
You are the Office 365 administrator for your company.
Users report that their passwords expire too frequently, and they do not receive adequate notice of password expiration.
Account passwords must remain active for the longest duration allowed. Users must receive password expiration notifications as early as possible.
You need to configure the password expiration policy.
How should you set the policy on the password page of the Office 365 admin center? To answer, drag the appropriate duration to the correct location. Each duration may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Answer:
Q8. A company has an Office 365 tenant that has an Enterprise E1 subscription. You configure the policies required for self-service password reset.
You need to ensure that all existing users can perform self-service password resets.
Which Windows PowerShell cmdlet should you run?
A. Set-MsolUser
B. Redo-MsolProvisionUser
C. Set-MsolUserLicense
D. Set-MsolUserPrincipalName
E. Convert-MsolFederatedUser
F. Set-MailUser
G. Set-LinkedUser
H. New-MsolUser
Answer: C
Explanation:
Self-service password reset with on-premises write-back is a Premium-only feature.
Example:
The following command adds the Office 365 for enterprises license to the user.
Set-MsolUserLicense -UserPrincipalName user@contoso.com -AddLicenses
"Contoso:ENTERPRISEPACK"
Note: The Set-MsolUserLicense cmdlet can be used to adjust the licenses for a user. This can include adding a new license, removing a license, updating the license options, or any combination of these actions.
Reference: Set-MsolUserLicense
https://msdn.microsoft.com/en-us/library/azure/dn194094.aspx
Q9. You have a legacy application that needs to send email to employees. The legacy
application runs on a client computer.
The legacy application must send email by using IMAP through Exchange Online.
You need to identify the correct host name and port information.
Which settings should you use?
A. Imap.office365.com and port 993
B. Imap.office365.com and port 143
C. Outlook.office365.com and port 993
D. Outlook.office365.com and port 143
Answer: C
Explanation:
For Office 365 for business, use the following settings.
IMAP4
outlook.office365.com
993 implicit
Reference: Use POP or IMAP to connect to Office 365 for business or Microsoft Exchange accounts https://support.office.com/en-US/Article/Use-POP-or-IMAP-to-connect-to-Office-365-forbusiness-or-Microsoft-Exchange-accounts-44f951cc-2041-47ed-b674-506889ca9d8b
Q10. A company plans to deploy an Office 365 tenant. You have two servers named FS1 and FS2 that have the Federation Service Proxy role service installed.
You must deploy Active Directory Federation Services (AD FS) on Windows Server 2012.
You need to configure name resolution for FS1 and FS2.
What should you do?
A. On FS1 and FS2, add the cluster DNS name and IP address of the federation server farm to the hosts file.
B. On FS1 only, add the cluster DNS name and IP address of the federation server farm to the hosts file.
C. On FS1 only, add the cluster NetBIOS name and IP address of the federation server farm to the LMHOSTS file.
D. On FS1 and FS2, add the cluster NetBIOS name and IP address of the federation server farm to the LMHOSTS file.
Answer: A