It is more faster and easier to pass the Microsoft 70-417 exam by using Breathing Microsoft Upgrading Your Skills to MCSA Windows Server 2012 questuins and answers. Immediate access to the Improved 70-417 Exam and find the same core area 70-417 questions with professionally verified answers, then PASS your exam with a high score now.

2021 Dec 70-417 practice exam

Q111. RAG DROP 

Your network contains an Active Directory domain named contoso.com. The domain contains a file server named Server1. All servers run Windows Server 2012 R2. 

All domain user accounts have the Division attribute automatically populated as part of the user provisioning process. The Support for Dynamic Access Control and Kerberos armoring policy is enabled for the domain. 

You need to control access to the file shares on Server1 based on the values in the Division attribute and the Division resource property. 

Which three actions should you perform in sequence? 

Answer: 


Q112. OTSPOT 

Your network contains an Active Directory domain named fabrikam.com. You implement DirectAccess and an IKEv2 VPN. You need to view the properties of the VPN connection. Which connection properties should you view? To answer, select the appropriate connection properties in the answer area. 

Answer: 


Q113. OTSPOT 

You have a server that runs Windows Server 2012 R2 and has the iSCSI Target Server role service installed. 

You run the New-IscsiVirtualDisk cmdlet as shown in the New-IscsiVirtualDisk exhibit. (Click the Exhibit button.) 

To answer, complete each statement according to the information presented in the exhibits. Each correct selection is worth one point. 

Answer: 


Q114. Your network contains an Active Directory forest named adatum.com. The forest contains an Active Directory Rights Management Services (AD RMS) cluster. 

A partner company has an Active Directory forest named litwareinc.com. The partner company does not have AD RMS deployed. 

You need to ensure that users in litwareinc.com can consume rights-protected content from adatum.com. 

Which type of trust policy should you create? 

A. At federated trust 

B. A trusted user domain 

C. A trusted publishing domain 

D. Windows Live ID 

Answer:

Explanation: 

A. In AD RMS rights can be assigned to users who have a federated trust with Active Directory Federation Services (AD FS). This enables an organization to share access to rights-protected content with another organization without having to establish a separate Active Directory trust or Active Directory Rights Management Services (AD RMS) infrastructure. http://technet.microsoft.com/en-us/library/dd772651(v=WS.10).aspx http://technet.microsoft.com/en-us/library/cc738707(v=WS.10).aspx http://technet.microsoft.com/en-us/library/cc757344(v=ws.10).aspx 


Q115. RAG DROP 

Your network contains an Active Directory domain named contoso.com. All client computers run Windows 8. 

Group Policy objects (GPOs) are linked to the domain as shown in the exhibit. (Click the Exhibit button.) 

GPO2 contains computer configurations only and GPO3 contains user configurations only. 

You need to configure the GPOs to meet the following requirements: 

. Ensure that GPO2 only applies to the computer accounts in OU2 that have more than one processor. . Ensure that GPO3 only applies to the user accounts in OU3 that are members of a security group named SecureUsers. 

Which setting should you configure in each GPO? 

To answer, drag the appropriate setting to the correct GPO. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. 

Answer: 


Renovate 70-417 answers:

Q116. RAG DROP 

Your network contains two Active Directory forests named contoso.com and adatum.com. All domain controllers run Windows Server 2012 R2. 

A federated trust exists between adatum.com and contoso.com. The trust provides adatum.com users with access to contoso.com resources. 

You need to configure Active Directory Federation Services (AD FS) claim rules for the federated trust. 

The solution must meet the following requirements: 

. In contoso.com, replace an incoming claim type named Group with an outgoing claim type named Role. . In adatum.com, allow users to receive their tokens for the relying party by using their Active Directory group membership as the claim type. 

The AD FS claim rules must use predefined templates. 

Which rule types should you configure on each side of the federated trust? 

To answer, drag the appropriate rule types to the correct location or locations. Each rule type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. 

Answer: 


Q117. Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2. The domain contains two organizational units (OUs) named OU1 and OU2 in the root of the domain. Two Group Policy objects (GPOs) named GPO1 and GP02 are created. GPO1 is linked to OU1. 

GPO2 is linked to OU2. OU1 contains a client computer named Computer1. OU2 contains a user named User1. You need to ensure that the GPOs Applied to Computer1areApplied to User1 when User1 logs on. 

What should you configure? 

A. The GPO Status 

B. WMI Filtering 

C. GPO links 

D. Item-level targeting 

Answer:

Explanation: 

Explanation/Reference: 

Selecting D Item-Level targeting until further notice. 

=== 

Old explanation before answer choice changed was C, GPO Links 

A GPO can be associated (linked) to one or more Active Directory containers, such as a 

site, domain, or organizational unit. Multiple containers can be linked to the same GPO, 

and a single container can have more than one GPO linked to it. If multiple GPOs are 

linked to one container, you can prioritize the order in which GPOs are applied. 

Linking GPOs to Active Directory containers enables an administrator to implement Group 

Policy settings for a broad or narrow portion of the organization, as required. 


Q118. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2 and has the DNS Server server role installed. Server1 is configured to delete automatically the DNS records of client computers that are no longer on the network. A technician confirms that the DNS records are deleted automatically from the contoso.com zone. You discover that the contoso.com zone has many DNS records for servers that were on the network in the past, but have not connected to the network for a long time. 

You need to set the time stamp for all of the DNS records in the contoso.com zone. 

What should you do? 

A. From DNS Manager, modify the Advanced settings from the properties of Server1 

B. From Windows PowerShell, run the Set-DnsServerResourceRecordAging cmdlet 

C. From DNS Manager, modify the Zone Aging/Scavenging Properties 

D. From Windows PowerShell, run the Set-DnsServerZoneAging cmdlet 

Answer:


Q119. You have a server named Server1 that runs Windows Server 2012 R2. 

You create a Data Collector Set (DCS) named DCS1. 

You need to configure DCS1 to log data to D:\logs. 

What should you do? 

A. Right-click DCS1 and click Properties. 

B. Right-click DCS1 and click Save template... 

C. Right-click DCS1 and click Export list... 

D. Right-click DCS1 and click Data Manager... 

Answer:

Explanation: 

It is under the Directory tab from the DCS properties. http://technet.microsoft.com/en-us/library/cc749267.aspx 


Q120. Your network contains an Active Directory domain named contoso.com. The domain 

contains Server 2012 R2 and has the Hyper-V server role installed. 

You need to log the amount of system resources used by each virtual machine. 

What should you do? 

A. From Windows PowerShell, run the Enable-VMResourceMeteringcmdlet. 

B. From Windows System Resource Manager, enable Accounting. 

C. From Windows System Resource Manager, add a resource allocation policy. 

D. From Windows PowerShell, run the Measure-VM cmdlet. 

Answer:

Explanation: 

The Enable-VMResourceMeteringcmdlet collects resource utilization data for a virtual machine or resource pool.