We offer 100% money rear guarantee. If you don?¡¥t get certified within the first attempt, email us your current score transcript and we can return your current money. While simple as that. Its time to look at actions proper now. Start off earlier and acquire certified earlier. Testking.internet provide 7/24 on-line customer assist. Our workers are usually knowledgeable along with dedicated which in turn promise you satisfactory answers to just about any questions.

2021 Dec 70-417 test engine

Q221. Your network contains a server named Server1 and 10 Web servers. All servers run Windows Server 2012 R2. 

You create a Windows PowerShell Desired State Configuration (DSC) to push the settings from Server1 to all of the Web servers. 

On Server1, you modify the file set for the Web servers.You need to ensure that all of the Web servers have the latest configurations. 

Which cmdlet should you run on Server1? 

A. Restore-DcsConfiguration 

B. Set DcsLocalConfigurationManager 

C. Start-DcsConfiguration 

D. Get-DcsConfiguration 

Answer:


Q222. OTSPOT 

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Active Directory Certificate Services server role installed and configured. 

For all users, you are deploying smart cards for logon. You are using an enrollment agent to enroll the smart card certificates for the users. 

You need to configure the Contoso Smartcard Logon certificate template to support the use of the enrollment agent. 

Which setting should you modify? To answer, select the appropriate setting in the answer area. 

Answer: 

172. Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2. 

An organizational unit (OU) named OU1 contains 200 client computers that run Windows 8 Enterprise. A Group Policy object (GPO) named GPO1 is linked to OU1. 

You make a change to GPO1. 

You need to force all of the computers in OU1 to refresh their Group Policy settings immediately. The solution must minimize administrative effort. 

Which tool should you use? 

A. The Set-AdComputercmdlet 

B. Group Policy Management Console (GPMC) 

C. Server Manager 

D. TheGpupdate command 

Answer:

Explanation: 

In the previous versions of Windows, this was accomplished by having the user run 

GPUpdate.exe on their computer. Starting with Windows Server? 2012 and Windows?8, 

you can now remotely refresh Group Policy settings for all computers in an OU from one 

central location through the Group Policy Management Console (GPMC). Or you can use 

the Invoke-GPUpdate cmdlet to refresh Group Policy for a set of computers, not limited to 

the OU structure, for example, if the computers are located in the default computers 

container. Note: Group Policy Management Console (GPMC) is a scriptable Microsoft 

Management Console (MMC) snap-in, providing a single administrative tool for managing 

Group Policy across the enterprise. GPMC is the standard tool for managing Group Policy. 

Incorrect: 

Not B: Secedit configures and analyzes system security by comparing your current 

configuration to at least one template. 

Reference: Force a Remote Group Policy Refresh (GPUpdate) 


Q223. OTSPOT 

Your network contains an Active Directory domain named contoso.com. 

You have a failover cluster named Cluster1 that contains two nodes named Server1 and Server2. Both servers run Windows Server 2012 R2 and have the Hyper-V server role installed. 

You plan to create two virtual machines that will run an application named App1. App1 will store data on a virtual hard drive named App1data.vhdx. App1data.vhdx will be shared by both virtual machines. 

The network contains the following shared folders: 

An SMB file share named Share1 that is hosted on a Scale-Out File Server. An SMB file share named Share2 that is hosted on a standalone file server. An NFS share named Share3 that is hosted on a standalone file server. 

You need to ensure that both virtual machines can use App1data.vhdx simultaneously. 

What should you do? 

To answer, select the appropriate configurations in the answer area. 

... 

Answer: 


Q224. Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012 R2. DC1 is backed up daily. 

The domain has the Active Directory Recycle Bin enabled. 

During routine maintenance, you delete 500 inactive user accounts and 100 inactive groups. One of the deleted groups is named Group1. Some of the deleted user accounts are members of some of the deleted groups. 

For documentation purposes, you must provide a list of the members of Group1 before the group was deleted. 

You need to identify the names of the users who were members of Group1 prior to its deletion. You want to achieve this goal by using the minimum amount of administrative effort. 

What should you do first? 

A. Reactivate the tombstone of Group1. 

B. Use the Recycle Bin to restore Group1. 

C. Perform an authoritative restore of Group1. 

D. Mount the most recent Active Directory backup. 

Answer:

Explanation: 

You can use the Active Directory database mounting tool (Dsamain.exe) and a Lightweight Directory Access Protocol (LDAP) tool, such as Ldp.exe or Active Directory Users and Computers, to identify which backup has the last safe state of the forest. The Active Directory database mounting tool, which is included in Windows Server 2008 and later Windows Server operating systems, exposes Active Directory data that is stored in backups or snapshots as an LDAP server. Then, you can use an LDAP tool to browse the data. This approach has the advantage of not requiring you to restart any DC in Directory Services Restore Mode (DSRM) to examine the contents of the backup of AD DS. 


Q225. Your network contain an active directory domain named Contoso.com. The domain contains two servers named server1 and server2 that run Windows Server 2012 R2. You create a security template named template1 by using the security template snap-in. You need to apply template1 to server2. 

Which tool should you use? 

A. Security Configuration and Analysis 

B. Server Manager 

C. Security Template 

D. Computer management 

Answer:


Abreast of the times 70-417 torrent:

Q226. In Windows Server 2012 R2, you can remove the Server Graphical Shell, resulting in the "Minimal Server Interface." This is similar to a Server with a GUI installation except that some features are not installed. 

Which of the following features is not installed in this scenario? 

A. MMC 

B. Windows Explorer 

C. Control Panel (subset) 

D. Server Manager 

Answer:

Explanation: 

When you choose the minimal server interface option Internet Explorer 10, Windows Explorer, the desktop, and the Start screen are not installed. Microsoft Management Console (MMC), Server Manager, and a subset of Control Panel are still present. 


Q227. Your network contains an Active Directory domain named contoso.com. The domain 

contains a server named Server1. Server1 runs Windows Server 2012 R2. 

You need to create 3-TB virtual hard disk (VHD) on Server1. 

Which tool should you use? 

A. New-StorageSubsytemVirtualDisk 

B. New-VirtualDisk 

C. Server Manager 

D. Computer Management 

Answer:

Explanation: 

NOT A Share and Storage will only let you create a VHD on a storage pool 

NOT B Server Manager, can't find where to create this. 

NOT C Is this powershell ? the command should be NEW-VHD 

(http://blogs.technet.com/b/heyscriptingguy/archive/2013/06/07/powertip-create-a- new-vhd-with-windows-powershell.aspx) 

D Computer management is the only valid yet non available answer. 

I'd be left with C, hoping they'd have the good powershell command. 

Note: 

From @L_Ranger, Computer Management is not an option anymore. 

Back to New-VirtualDisk 

Old explanation : D (Computer management) 

For Server 2012: 

http://technet.microsoft.com/en-us/library/dd851645.aspx 

For Server 2008: 

http://www.techrepublic.com/blog/the-enterprise-cloud/build-vhds-offline-with-server-manager/ With the Server Manager snap-in, you can create and attach a .VHD file directly. 

Figure A shows the drop-down box where a.VHD file can be created and attached. Figure 


Q228. Your network contains an Active Directory domain named adatum.com. The domain contains a server named Server1 that runs WindowsServer 2012 R2. Server1 is configured as a Network Policy Server (NPS) server and as a DHCP server. 

You need to ensure that only computers that send a statement of health are checked for Network Access Protection (NAP) health requirements. 

Which two settings should you configure? (Each correct answer presents part of the solution. Choose two.) 

A. The NAS Port Type constraints 

B. The MS-Service Class conditions 

C. The Health Policies conditions 

D. The NAP-Capable Computers conditions 

E. The Called Station ID constraints 

Answer: C,D 

Explanation: 

Explanation The NAP-Capable ensures that the machine is able to send a statement of health, and the Health Policy tells it which policy to evaluate against. 


Q229. Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2. 

You are creating a central access rule named Test Finance that will be used to audit members of the Authenticated users group for access failure to shared folders in the finance department. 

You need to ensure that access requests are unaffected when the rule is published. 

What should you do? 

A. Set the Permissions to Use the following permissions as proposed permissions. 

B. Add a Resource condition to the current permissions entry for the Authenticated Users principal. 

C. Set the Permissions to Use following permissions as current permissions. 

D. Add a User condition to the current permissions entry for the Authenticated Users principal. 

Answer:

Explanation: 

http://technet.microsoft.com/en-us/library/jj134043.aspx 


Q230. OTSPOT 

Your network contains an Active Directory domain named contoso.com. 

All DNS servers host a DNS zone named adatum.com. The adatum.com zone is not Active 

Directory-integrated. 

An administrator modifies the start of authority (SOA) record for the adatum.com zone. 

After the modification, you discover that when you add or modify DNS records in the 

adatum.com zone, the changes are not transferred to the DNS servers that host secondary 

copies of the adatum.com zone. 

You need to ensure that the records are transferred to all the copies of the adatum.com 

zone. 

What should you modify in the SOA record for the adatum.com zone? To answer, select the appropriate setting in the answer area. 

Answer: 

252. Your manager has asked you to configure the company Windows Server 2008 domain controller. He wants all new computer accounts to be placed in the General OU, when computers join the domain. 

Which command should you use to accomplish this? 

A. Netdom 

B. Dsmove 

C. None of these 

D. Redircmp 

Answer:

Explanation: 

http://technet.microsoft.com/en-us/library/cc770619(v=ws.10).aspx