Our Microsoft 70-417 simulated tests contain everything you will encounter from the real exam. Actualtestss IT professionals are committed to generating the most precise and original Microsoft Microsoft practice questions and answers which are written with large standards of accuracy. All the 70-417 training materials are presented throughout Pdf files and Analyze Engine software. You are able to download them in your PC for no cost. Pdf files are printable and portable and the test engine are downloadable.

2021 Dec 70-417 practice

Q101. OTSPOT 

Your network contains an Active Directory domain named contoso.com. 

You have several Windows PowerShell scripts that execute when client computers start. 

When a client computer starts, you discover that it takes a long time before users are 

prompted to log on. 

You need to reduce the amount of time it takes for the client computers to start. The 

solution must not prevent scripts from completing successfully. 

Which setting should you configure? 

To answer, select the appropriate setting in the answer area. 

Answer: 


Q102. Your network contains an Active Directory domain named contoso.com. The Active 

Directory Recycle bin is enabled for contoso.com. 

A support technician accidentally deletes a user account named User1. 

You need to restore the User1 account. 

Which tool should you use? 

A. Ldp 

B. Esentutl 

C. Active Directory Administrative Center 

D. Ntdsutil 

Answer:

Explanation: 

http://technet.microsoft.com/nl-nl/library/dd379509(v=ws.10).aspx#BKMK_2 http://technet.microsoft.com/en-us/magazine/2007.09.tombstones.aspx http://technet.microsoft.com/en-us/library/hh875546.aspx http://technet.microsoft.com/en-us/library/dd560651(v=ws.10).aspx 


Q103. You have a server named Server1 that runs Windows Server 2012 R2. 

You install the File and Storage Services server role on Server1. 

From Windows Explorer, you view the properties of a folder named Folder1 and you 

discover that the Classification tab is missing. 

You need to ensure that you can assign classifications to Folder1 from Windows Explorer 

manually. 

What should you do? 

A. Install the File Server Resource Manager role service. 

B. From Folder Options, clear Hide protected operating system files (Recommended). 

C. Install the Share and Storage Management Tools. 

D. From Folder Options, select the Always show menus. 

Answer:

Explanation: 

B. Classification Management is a feature of FSRM http://technet.microsoft.com/en-us/library/dd759252.aspx http://technet.microsoft.com/en-us/library/dd758759(v=WS.10).aspx 


Q104. Your network contains an Active Directory domain named contoso.com. The domain contains four servers. The servers are configured as shown in the following table. 

You plan to deploy an enterprise certification authority (CA) on a server named Servers. Server5 will be used to issue certificates to domain-joined computers and workgroup computers. 

You need to identify which server you must use as the certificate revocation list (CRL) distribution point for Server5. 

Which server should you identify? 

A. Server1 

B. Server3 

C. Server4 

D. Server2 

Answer:

Explanation: 

CDP (and AD CS) always uses a Web Server NB: this CDP must be accessible from outside the AD, but here we don't have to wonder about that as there's only one web server. 

http://technet.microsoft.com/fr-fr/library/cc782183%28v=ws.10%29.aspx 

Selecting a CRL Distribution Point Because CRLs are valid only for a limited time, PKI clients need to retrieve a new CRL periodically. Windows Server 2003 PKI Applications look in the CRL distribution point extension for a URL that points to a network location from which the CRL object can be retrieved. Because CRLs for enterprise CAs are stored in Active Directory, they can be accessed by means of LDAP. In comparison, because CRLs for stand-alone CAs are stored in a directory on the server, they can be accessed by means of HTTP, FTP, and so on as long as the CA is online. Therefore, you should set the CRL distribution point after the CA has been installed. 

The system account writes the CRL to its distribution point, whether the CRL is published manually or is published according to an established schedule. Therefore you must ensure that the system accounts for CAs have permission to write to the CRL distribution point. Because the CRL path is also included in every certificate, you must define the CRL location and its access path before deploying certificates. If an Application performs revocation checking and a valid CRL is not available on the local computer, it rejects the certificate. 

You can modify the CRL distribution point by using the Certification Authority MMC snap-in. In this way, you can change the location where the CRL is published to meet the needs of users in your organization. You must move the CRL distribution point from the CA configuration folder to a Web server to change the location of the CRL, and you must move each new CRL to the new distribution point, or else the chain will break when the previous CRL expires. 

Note On root CAs, you must also modify the CRL distribution point in the CAPolicy.inf file so that the root CA certificate references the correct CDP and AIA paths, if specified. If you are using certificates on the Internet, you must have at least one HTTPs-accessible location for all certificates that are not limited to internal use. 

http://technet.microsoft.com/en-us/library/cc771079.aspx Configuring Certificate Revocation It is not always possible to contact a CA or other trusted server for information about the validity of a certificate. To effectively support certificate status checking, a client must be able to access revocation data to determine whether the certificate is valid or has been revoked. To support a variety of scenarios, Active Directory Certificate Services (AD CS) supports industry-standard methods of certificate revocation. These include publication of certificate revocation lists (CRLs) and delta CRLs, which can be made available to clients from a variety of locations, including Active Directory Domain Services (AD DS), Web servers, and network file shares. 


Q105. Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All domain controllers run Windows Server 2012 R2. The domain contains two domain controllers. The domain controllers are configured as shown in the following table. 

Active Directory Recycle Bin is enabled. You discover that a support technician accidentally removed 100 users from an Active Directory group named Group1 an hour ago. You need to restore the membership of Group1. 

What should you do? 

A. Export and import data by using Dsamain. 

B. Apply a virtual machine snapshot to VM1. 

C. Recover the items by using Active Directory Recycle Bin. 

D. Modify the isRecycled attribute of Group1. 

Answer:

Explanation: 

As far as the benefits of the Windows 2012 Recycle Bin, they are the same as the Windows 2008 R2 recycle bin with the exception of the new user interface which makes it more user-friendly. These additional benefits include: All deleted AD object information including attributes, passwords and group membership can be selected in mass then undeleted from the user interface instantly or via Powershell User-friendly and intuitive interface to filter on AD objects and a time period • Can undelete containers with all child objects https://www.simple-talk.com/sysadmin/exchange/the-active-directory-recycle-bin-in-windows-server-2008-r2/ http://communities.quest.com/community/quest-itexpert/blog/2012/09/24/the-windows-server-2012-recycle-bin-and-recovery-manager-for-active- directory 


Improved 70-417 exam cost:

Q106. Your network contains a Hyper-V host named Server1 that hosts 20 virtual machines. 

You need to view the amount of memory resources and processor resources each virtual machine uses currently. 

Which tool should you use on Server1? 

A. Resource Monitor 

B. Task Manager 

C. Hyper-V Manager 

D. Windows System Resource Manager (WSRM) 

Answer:

Explanation: 

You get it from the Hyper-V Manager 


Q107. You have a server named Server1. 

You install the IP Address Management (IPAM) Server feature on Server1. 

You need to provide a user named User1 with the ability to set the access scope of all the DHCP servers that are managed by IPAM. The solution must use the principle of least privilege. 

Which user role should you assign to User1? 

A. IP Address Record Administrator Role 

B. IPAM Administrator Role 

C. IPAM MSM Administrator Role 

D. IPAM DHCP Scope Administrator Role 

Answer:

Explanation: 

Explanation IPAM ASM Administrators IPAM ASM Administrators is a local security group on an IPAM server that is created when you install the IPAM feature. Members of this group have all the privileges of the IPAM Users security group, and can perform IP address space tasks in addition to IPAM common management tasks. Note: When you install IPAM Server, the following local role-based IPAM security groups are created: IPAM Users IPAM MSM Administrators IPAM ASM Administrators IPAM IP Audit Administrators IPAM Administrators Incorrect: not B: Too much privileges. IPAM Administrators IPAM Administrators is a local security group on an IPAM server that is created when you install the IPAM feature. Members of this group have privileges to view all IPAM data and perform all IPAM tasks. 


Q108. Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server1 that has the Active Directory Federation Services server role installed. All servers run Windows Server 2012. 

You complete the Active Directory Federation Services Configuration Wizard on Server1. 

You need to ensure that client devices on the internal network can use Workplace Join. 

Which two actions should you perform on Server1? (Each correct answer presents part of the solution. Choose two.) 

A. Run Enable AdfsDeviceRegistration -PrepareActiveDirectory. 

B. Edit the multi-factor authentication global authentication policy settings. 

C. Edit the primary authentication global authentication policy settings. 

D. Run Set-AdfsProxyPropertiesHttpPort 80. 

E. Run Enable-AdfsDeviceRegistration. 

Answer: C,E 

Explanation: 

* To enable Device Registration Service 

On your federation server, open a Windows PowerShell command window and type: 

Enable-AdfsDeviceRegistration 

Repeat this step on each federation farm node in your AD FS farm.. 

Enable seamless second factor authentication Seamless second factor authentication is an enhancement in AD FS that provides an added level of access protection to corporate resources and applications from external devices that are trying to access them. When a personal device is Workplace Joined, it becomes a ‘known’ device and administrators can use this information to drive conditional access and gate access to resources. To enable seamless second factor authentication, persistent single sign-on (SSO) and conditional access for Workplace Joined devices In the AD FS Management console, navigate to Authentication Policies. Select Edit Global Primary Authentication. Select the check box next to Enable Device Authentication, and then click OK. 


Q109. OTSPOT 

Your network contains an Active Directory domain named contoso.com. The relevant servers in the domain are configured as shown in the following table. 

You plan to create a shared folder on Server1 named Share1. Share1 must only be accessed by users who are using computers that are joined to the domain. 

You need to identify which servers must be upgraded to support the requirements of Share1. 

In the table below, identify which computers require an upgrade and which computers do not require an upgrade. Make only one selection in each row. Each correct selection is worth one point. 

Answer: 


Q110. Your network contains two servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 and Server2 are part of a workgroup. 

On Server1 and Server2, you create a local user account named Admin1. You add the account to the local Administrators group. On both servers, Admin1 has the same password. 

You log on to Server1 as Admin1. You open Computer Management and you connect to Server2. 

When you attempt to create a scheduled task, view the event logs, and manage the shared folders, you receive Access Denied messages. 

You need to ensure that you can administer Server2 remotely from Server1 by using Computer Management. What should you configure on Server2? 

A. From Local Users and Groups, modify the membership of the Remote Management Users group. 

B. From Server Manager, modify the Remote Management setting. 

C. From Windows Firewall, modify the Windows Management Instrumentation (WMI) firewall rule. 

D. From Registry Editor, configure the LocalAccountTokenFilterPolicyresgistry value 

Answer: