aiotestking uk

70-410 Exam Questions - Online Test


70-410 Premium VCE File

Learn More 100% Pass Guarantee - Dumps Verified - Instant Download
150 Lectures, 20 Hours

Q1. - (Topic 3) 

You run a Windows 2012 R2 Hyper-V Role Server, you need to shrink the size of files.vhd. 

Which PowerShell cmdlet option you should run first? 

A. Dismount-VHD 

B. Mount-VHD 

C. Resize-VHD 

D. Convert-VHD 

Answer:

Q2. - (Topic 3) 

Your network contains an Active Directory domain named contoso.com. The domain contains 500 servers that run Windows Server 2012 R2. 

You have a written security policy that states the following: 

Only required ports must be open on the servers. 

All of the servers must have Windows Firewall enabled. 

Client computers used by administrators must be allowed to access all of the ports 

on all of the servers. 

Client computers used by the administrators must be authenticated before the 

client computers can access the servers. 

You have a client computer named Computer1 that runs Windows 8. 

... . 

You need to ensure that you can use Computer1 to access all of the ports on all of the servers successfully. The solution must adhere to the security policy. 

Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.) 

A. On Computer1, create a connection security rule. 

B. On all of the servers, create an outbound rule and select the Allow the connection if it is secure option. 

C. On all of the servers, create an inbound rule and select the Allow the connection if it is secure option. 

D. On Computer1, create an inbound rule and select the Allow the connection if it is secure option. 

E. On Computer1, create an outbound rule and select the Allow the connection if it is secure option. 

F. On all of the servers, create a connection security rule. 

Answer: A,C,F 

Explanation: 

Unlike firewall rules, which operate unilaterally, connection security rules require that both 

communicating computers have a policy with connection security rules or another 

compatible IPsec policy. 

Traffic that matches a firewall rule that uses the Allow connection if it is secure setting 

bypasses Windows Firewall. The rule can filter the traffic by IP address, port, or protocol. 

This method is supported on Windows Vista or Windows Server 2008. 

References: 

http://technet.microsoft.com/en-us/library/cc772021.aspx 

http://technet.microsoft.com/en-us/library/cc753463.aspx 

Q3. - (Topic 3) 

You work as a senior administrator at Contoso.com. The Contoso.com network consists of a single domain named Contoso.com. All servers on the Contoso.com network have Windows Server 2012 R2 installed, and all workstations have Windows 8 installed. 

You are running a training exercise for junior administrators. You are currently discussing a Windows PowerShell cmdlet that activates previously de-activated firewall rules. 

Which of the following is the cmdlet being discussed? 

A. Set-NetFirewallRule 

B. Enable-NetFirewallRule 

C. Set-NetIPsecRule 

D. Enable-NetIPsecRule 

Answer:

Explanation: 

Enable-NetFirewallRule – Enables a previously disabled firewall rule. 

Q4. HOTSPOT - (Topic 2) 

Your network contains an Active Directory forest. The forest contains two domains named Domain1 and Domain2. 

Domain1 contains a file server named Server1. Server1 has a shared folder named Share1. 

Domain2 contains 50 users who require access to Share1. 

You need to create groups in each domain to meet the following requirements: 

. In Domain1, create a group named Group1. Group1 must be granted access to Share1. . In Domain2, create a group named Group2. Group2 must contain the user accounts of the 50 users. . Permission to Share1 must only be assigned directly to Group1. 

Which type of groups should you create and which group nesting strategy should you use? 

To answer, select the appropriate configuration in the answer area. 

Answer:  

Q5. - (Topic 3) 

You work as an administrator at Contoso.com. The Contoso.com network consists of a single domain named Contoso.com. All servers on the Contoso.com network have Windows Server 2012 installed. 

Contoso.com has a server, named ENSUREPASS-SR07, which has the AD DS, DHCP, and DNS server roles installed. Contoso.com also has a server, named ENSUREPASS-SR08, which has the DHCP, and Remote Access server roles installed. You have configured a server, which has the File and Storage Services server role installed, to automatically acquire an IP address. 

The server is named ENSUREPASS-SR09. You then create a filter on ENSUREPASS-SR07. 

Which of the following is a reason for this configuration? 

A. To make sure that ENSUREPASS-SR07 issues ENSUREPASS-SR09 an IP address. 

B. To make sure that ENSUREPASS-SR07 does not issue ENSUREPASS-SR09 an IP address. 

C. To make sure that ENSUREPASS-SR09 acquires a constant IP address from ENSUREPASS-SR08 only. 

D. To make sure that ENSUREPASS-SR09 is configured with a static IP address. 

Answer:

Q6. - (Topic 1) 

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The domain contains two domain controllers named DC1 and DC2 that run Windows Server 2012 R2. 

The domain contains a user named User1 and a global security group named Group1. 

You need to add a new domain controller to the domain. 

You install Windows Server 2012 R2 on a new server named DC3. 

Which cmdlet should you run next? 

A. Add-AdPrincipalGroupMembership 

B. Install-AddsDomainController 

C. Install WindowsFeature 

D. Install AddsDomain 

E. Rename-AdObject 

F. Set-AdAccountControl 

G. Set-AdGroup 

H. Set-User 

Answer:

Explanation: 

It is the 2nd step when installing a DC by powershell on a fresh server. 

Q7. - (Topic 2) 

You have a server named Server2 that runs Windows Server 2012 R2. 

A network technician installs a new disk on Server2 and creates a new volume. 

The properties of the new volume are shown in the exhibit. (Click the Exhibit button.) 

You need to ensure that you can enable NTFS disk quotas for volume D. 

What should you do first? 

A. Format volume D 

B. Install the File Server Resource Manager role service 

C. Run the convert.exe command 

D. Convert the disk to a dynamic disk 

Answer:

Explanation: 

To be able to use a NEW disk so that you can enable NTFS disk quotas, in other word REFS to NTFS, it requires formatting first. 

Q8. - (Topic 3) 

A company’s network administrator needs to ensure a specific IP address is never assigned by a Windows Server 2012 R2 DHCP server to any device connecting to the network. 

Which of the following should the administrator configure on the Windows Server 2012 R2 DHCP server? 

A. Reservation 

B. Scope options 

C. NAP 

D. Scope properties 

Answer:

Explanation: 

Configuring an IP address as a reservation will restrict a DHCP server’s assignment of that address unless a specific MAC address makes a request for the address. Exclusion is for not use the IP Address or range inside the Scope Pool, Filter is for not use theMAC Address or range. Quick Tip: Policies can also be defined per scope or server. Policy based assignment (PBA) allows an administrator to group DHCP clients by specific attributes based on fields contained in the DHCP client request packet. This feature allows for targeted administration and greater control of configuration parameters delivered to network devices. 

Q9. - (Topic 3) 

You work as an administrator at Contoso.com. The Contoso.com network consists of a single domain named Contoso.com. All servers on the Contoso.com network have Windows Server 2012 R2 installed. You have been instructed to make sure that a server, named ENSUREPASS-SR07, is configured to be managed remotely from ENSUREPASS-SR01 using Server Manager. 

Which of the following is not a valid option to take? (Choose all that apply.) 

A. You could access the server manager on ENSUREPASS-SR07. 

B. You could access the server manager on ENSUREPASS-SR13. 

C. You could run the %windir%\system32\Configure-SMRemoting.exe from an elevated command prompt on ENSUREPASS-SR13. 

D. You could run the Configure-SMRemoting.exe – enable cmdlet on ENSUREPASS-SR07. 

Answer: B,C 

Q10. - (Topic 1) 

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The domain contains two domain controllers named DC1 and DC2 that run Windows Server 2012 R2. 

The domain contains a user named User1 and a global security group named Group1. 

You need to modify the SAM account name of Group1. 

Which cmdlet should you run? 

A. Add-AdPrincipalGroupMembership 

B. Install-AddsDomainController 

C. Install-WindowsFeature 

D. Install-AddsDomain 

E. Rename-AdObject 

F. Set AdAccountControl 

G. Set-AdGroup 

H. Set-User 

Answer: