aiotestking uk

70-413 Exam Questions - Online Test


70-413 Premium VCE File

Learn More 100% Pass Guarantee - Dumps Verified - Instant Download
150 Lectures, 20 Hours

Q1. HOTSPOT - (Topic 8) 

Your network contains an Active Directory forest named northwindtraders.com. 

The client computers in the finance department run either Windows 8.1, Windows 8, or Windows 7. All of the client computers in the marketing department run Windows 8.1. 

You need to design a Network Access Protection (NAP) solution for northwindtraders.com that meets the following requirements: 

. The client computers in the finance department that run Windows 7 must have a firewall enabled and the antivirus software must be up-to-date. 

. The finance computers that run Windows 8.1 or Windows 8 must have automatic updating enabled and the antivirus software must be up-to-date. 

. The client computers in the marketing department must have automatic updating enabled and the antivirus software must be up-to-date. 

. If a computer fails to meet its requirements, the computers must be provided access to a limited set of resources on the network. 

. If a computer meets its requirements, the computer must have full access to the network. 

What is the minimum number of objects that you should create to meet the requirements? To answer, select the appropriate number for each object type in the answer area. 

Answer:  

Q2. - (Topic 8) 

Your network contains multiple servers that run Windows Server 2012. All client computers run Windows 8. 

You need to recommend a centralized solution to download the latest antivirus definitions for Windows Defender. 

What should you include in the recommendation? 

A. Microsoft System Center 2012 Endpoint Protection 

B. Network Access Protection (NAP) 

C. Microsoft System Center Essentials 

D. Windows Server Update Services (WSUS) 

Answer:

Explanation: 

To use WSUS to deploy Windows Defender definition updates to client computers, follow these steps: 

1. Open the WSUS Administrator console, and then click Options at the top of the console. 

2. Click Synchronization Options. 

3. Under Products and Classifications, click Change under Products. 

4. Verify that the Windows Defender check box is selected, and then click OK. 

5. Under Products and Classifications, click Change under Update Classifications. 

6. Verify that the Definition Updates check box is selected, and then click OK. 

7. Optional Update the automatic approval rule. To do this, follow these steps: 

a. At the top of the console, click Options. 

b. Click Automatic Approval Options. 

c. Make sure that the Automatically approve updates for installation by using the following rule check box is selected. 

d. Under Approve for Installation, click Add/Remove Classification. 

e. Verify that the Definition Updates check box is selected, and then click OK. 

8. At the top of the console, click Options. 

9. Click Synchronization Options. 

10. On the taskbar on the left, click Synchronize now. 

11. At the top of the console, click Updates. 

12. Approve any Windows Defender updates that WSUS should deploy. 

Reference: How to use Windows Server Update Services (WSUS) to deploy definition updates to computers that are running Windows Defender 

Q3. - (Topic 1) 

You are planning the implementation of two new servers that will be configured as RADIUS servers. 

You need to recommend which configuration must be performed on the VPN servers. The solution must meet the technical requirements. 

What should you do on each VPN server? 

A. Add a RADIUS client. 

B. Install the Health Registration Authority role service. 

C. Enable DirectAccess. 

D. Modify the authentication provider. 

Answer:

Explanation: 

* Implement RADIUS authentication for VPN connections. 

* The new sales.contoso.com domain will contain a web application that will access data from a Microsoft SQL Server located in the contoso.com domain. The web application must use integrated Windows authentication. Users' credentials must be passed from the web applications to the SQL Server. 

Q4. - (Topic 8) 

Your network contains an Active Directory domain named contoso.com. The functional level of the domain and the forest is Windows Server 2008 R2. 

All domain controllers run Windows Server 2008 R2. 

You plan to deploy a new line-of-business application named App1 that uses claims-based authentication. 

You need to recommend changes to the network to ensure that Active Directory can provide claims for App1. 

What should you include in the recommendation? (Each correct answer presents part of the solution. Choose all that apply.) 

A. From the properties of the computer accounts of the domain controllers, enable Kerberos constrained delegation. 

B. From the Default Domain Controllers Policy, enable the Support for Dynamic Access Control and Kerberos armoring setting. 

C. Deploy Active Directory Lightweight Directory Services (AD LDS). 

D. Raise the domain functional level to Windows Server 2012. 

E. Add domain controllers that run Windows Server 2012. 

Answer: B,E 

Explanation: E: You must perform several steps to enable claims in Server 2012 AD. First, you must upgrade the forest schema to Server 2012. You can do so manually through Adprep, but Microsoft strongly recommends that you add the AD DS role to a new Server 2012 server or upgrade an existing DC to Server 2012. 

B: Once AD can support claims, you must enable them through Group Policy: 

. From the Start screen on a system with AD admin rights, open Group Policy Management and select the Domain Controllers Organizational Unit (OU) in the domain in which you wish to enable claims. 

. Right-click the Default Domain Controllers Policy and select Edit. 

. In the Editor window, drill down to Computer Configuration, Policies, Administrative 

Templates, System, and KDC (Key Distribution Center). . Open.KDC support for claims, compound authentication, and Kerberos armoring. . Select the Enabled radio button..Supported.will appear under.Claims, compound 

authentication for Dynamic Access Control and Kerberos armoring options 

Reference: Enable Claims Support in Windows Server 2012 Active Directory 

Q5. - (Topic 7) 

You need to limit the amount of disk space that is used on the client devices. 

Which Windows PowerShell cmdlet or cmdlets should you run? 

A. Add-BCDataCacheExtcnsion 

B. Set-BCDataCacheEntryMaxAge 

C. Disable-BC and Enablc-BCLocal 

D. Set-BCCache 

E. Clear-BCCache 

Answer:

Explanation: 

Scenario: File shares 

Each branch office connects to the New York data center to retrieve file shares. 

BranchCache distributed mode is enabled in each branch office. The cache on each client 

computer must be a single file. 

Reference: Set-BCCache 

Q6. - (Topic 4) 

You need to recommend a solution for the sales reports. 

What should you include in the recommendation? 

A. BranchCache in distributed cache mode 

B. Offline files 

C. BranchCache in hosted cache mode 

D. Distributed File System (DFS) 

Answer:

Explanation: * Scenario: Server3 has a shared folder that contains sales reports. The sales reports are read frequently by the users in both offices. The reports are generated automatically once per week by an enterprise resource planning (ERP) system. 

* BranchCache is designed to reduce WAN link utilization and improve application responsiveness for branch office workers who access content from servers in remote locations. Branch office client computers use a locally maintained cache of data to reduce traffic over a WAN link. The cache can be distributed across client computers (Distributed Cache mode) or can be housed on a server in the branch (Hosted Cache mode). 

Reference: BranchCache Overview 

Q7. - (Topic 1) 

What method should you use to deploy servers? 

A. WDS 

B. AIK 

C. ADK 

D. EDT 

Answer:

Explanation: WDS is a server role that enables you to remotely deploy Windows operating systems. You can use it to set up new computers by using a network-based installation. This means that you do not have to install each operating system directly from a CD, USB drive, or DVD. 

Reference: What's New in Windows Deployment Services in Windows Server 

Q8. - (Topic 8) 

Your network contains an Active Directory domain named contoso.com. The domain contains multiple sites. You plan to deploy DirectAccess. 

The network security policy states that when client computers connect to the corporate network from the Internet, all of the traffic destined for the Internet must be routed through the corporate network. 

You need to recommend a solution for the planned DirectAccess deployment that meets the security policy requirement. 

What should you include in the recommendation? 

A. Set the ISATAP State to state enabled. 

B. Enable split tunneling. 

C. Set the ISATAP State to state disabled. 

D. Enable force tunneling. 

Answer:

Explanation: 

You can configure DirectAccess clients to send all of their traffic through the tunnels to the DirectAccess server with force tunneling. When force tunneling is configured, DirectAccess clients that detect that they are on the Internet modify their IPv4 default route so that default route IPv4 traffic is not sent. With the exception of local subnet traffic, all traffic sent by the DirectAccess client is IPv6 traffic that goes through tunnels to the DirectAccess server. 

Q9. HOTSPOT - (Topic 8) 

Your network contains an Active Directory domain named contoso.com. You plan to implement multiple DHCP servers. 

An administrator named Admin1 will authorize the DHCP servers. You need to ensure that Admin1 can authorize the planned DHCP servers. 

To which container should you assign Admin1 permissions? To answer, select the appropriate node in the answer area. 

Answer:  

Q10. - (Topic 8) 

Your network contains an Active Directory forest named contoso.com. The forest functional level is Windows Server 2012. 

The forest contains an Active Directory domain. The domain contains a global security group named GPO_Admins that is responsible for managing Group Policies in the forest. 

A second forest named fabrikam.com contains three domains. The forest functional level is Windows Server 2003. 

You need to design a trust infrastructure to ensure that the GPO_Admins group can create, edit, and link Group Policies in every domain of the fabrikam.com forest. 

What should you include in the design? 

More than one answer choice may achieve the goal. Select the BEST answer. 

A. A two-way forest trust 

B. A one-way forest trust 

C. Three external trusts 

D. Three shortcut trusts 

Answer: