[Newest Version] Easily Pass 70-411 Exam with CertBus Updated Real Microsoft 70-411 Exam Materials

This is a note. Please give me your attention if you are preparing for your Microsoft 70-411 exam. It is really a tough task to pass 70-411 exam. However, CertBus will help you on that with the most comprehensive PDF and VCEs of the latest 70-411 exam questions, covering each and every aspect of 70-411 Administering Windows Server 2012 exam curriculum.

We CertBus has our own expert team. They selected and published the latest 70-411 preparation materials from Microsoft Official Exam-Center: http://www.certbus.com/70-411.html


Your network contains an Active Directory domain named contoso. com. The domain

contains a server named NPS1 that has the Network Policy Server server role installed. All

servers run Windows Server 2012 R2.

You install the Remote Access server role on 10 servers.

You need to ensure that all of the Remote Access servers use the same network policies.

Which two actions should you perform? (Each correct answer presents part of the solution.

Choose two. )

A. Configure each Remote Access server to use the Routing and Remote Access service

(RRAS) to authenticate connection requests.

B. On NPS1, create a remote RADIUS server group. Add all of the Remote Access servers

to the remote RADIUS server group.

C. On NPS1, create a new connection request policy and add a Tunnel-Type and a

Service-Type condition.

D. Configure each Remote Access server to use a RADIUS server named NPS1.

E. On NPS1, create a RADIUS client template and use the template to create RADIUS


Answer: C,D

Explanation: Connection request policies are sets of conditions and settings that allow

network administrators to designate which RADIUS servers perform the authentication and

authorization of connection requests that the server running Network Policy Server (NPS)

receives from RADIUS clients. Connection request policies can be configured to designate

which RADIUS servers are used for RADIUS accounting.

When you configure Network Policy Server (NPS) as a Remote Authentication Dial-In User

Service (RADIUS) proxy, you use NPS to forward connection requests to RADIUS servers

that are capable of processing the connection requests because they can perform

authentication and authorization in the domain where the user or computer account is

located. For example, if you want to forward connection requests to one or more RADIUS

servers in untrusted domains, you can configure NPS as a RADIUS proxy to forward the

requests to the remote RADIUS servers in the untrusted domain.

To configure NPS as a RADIUS proxy, you must create a connection request policy that

contains all of the information required for NPS to evaluate which messages to forward and

where to send the messages.

Ref: http://technet.microsoft.com/en-us/library/cc730866(v=ws.10).aspx


Your network contains an Active Directory domain named contoso. com. All domain

controllers run Windows Server 2012 R2. The domain contains 500 client computers that

run Windows 8 Enterprise.

You implement a Group Policy central store.

You have an application named App1. App1 requires that a custom registry setting be

deployed to all of the computers.

You need to deploy the custom registry setting. The solution must minimize administrator


What should you configure in a Group Policy object (GPO)?

A. The Software Installation settings

B. The Administrative Templates

C. An application control policy

D. The Group Policy preferences

Answer: D


1 Open the Group Policy Management Console . Right-click the Group Policy object

(GPO) that should contain the new preference item, and then click Edit .

1 In the console tree under Computer Configuration or User Configuration , expand

the Preferences folder, and then expand the Windows Settings folder.

1 Right-click the Registry node, point to New , and select Registry Item .

Group Policy preferences provide the means to simplify deployment and standardize

configurations. They add to Group Policy a centralized system for deploying preferences

(that is, settings that users can change later).

You can also use Group Policy preferences to configure applications that are not Group

Policy-aware. By using Group Policy preferences, you can change or delete almost any

registry setting, file or folder, shortcut, and more. You are not limited by the contents of

Administrative Template files. The Group Policy Management

Editor (GPME) includes Group Policy preferences.

http: //technet. microsoft. com/en-us/library/gg699429. aspx

http: //www. unidesk. com/blog/gpos-set-custom-registry-entries-virtual-desktops-disablingmachine-



Your network contains an Active Directory domain named contoso. com. The domain

contains a member server named Server1. Server1 runs Windows Server 2012 R2.

You enable the EventLog-Application event trace session.

You need to set the maximum size of the log file used by the trace session to 10 MB.

From which tab should you perform the configuration? To answer, select the appropriate

tab in the answer area.



Your network contains an Active Directory forest. The forest contains two domains named

contoso. com and fabrikam. com. All of the DNS servers in both of the domains run

Windows Server 2012 R2.

The network contains two servers named Server1 and Server2. Server1 hosts an Active

Directory-integrated zone for contoso. com. Server2 hosts an Active Directory-integrated

zone for fabrikam. com. Server1 and Server2 connect to each other by using a WAN link.

Client computers that connect to Server1 for name resolution cannot resolve names in

fabnkam. com.

You need to configure Server1 to support the resolution of names in fabnkam. com. The

solution must ensure that users in contoso. com can resolve names in fabrikam. com if the

WAN link fails.

What should you do on Server1?

A. Create a stub zone.

B. Add a forwarder.

C. Create a secondary zone.

D. Create a conditional forwarder.

Answer: C


http: //technet. microsoft. com/en-us/library/cc771898. aspx

When a zone that this DNS server hosts is a secondary zone, this DNS server is a

secondary source for information about this zone. The zone at this server must be obtained

from another remote DNS server computer that also hosts the zone

With secondary, you have ability to resolve records from the other domain even if its DNS

servers are temporarily unavailable

While secondary zones contain copies of all the resource records in the corresponding

zone on the master name server, stub zones contain only three kinds of resource records:

A copy of the SOA record for the zone.

Copies of NS records for all name servers authoritative for the zone.

Copies of A records for all name servers authoritative for the zone.

http: //www. windowsnetworking. com/articles-tutorials/windows-2003/DNS_Stub_Zones.


http: //technet. microsoft. com/en-us/library/cc771898. aspx

http: //redmondmag. com/Articles/2004/01/01/The-Long-and-Short-of-Stub-Zones.



Your network contains an Active Directory domain named contoso. com. All domain

controllers run Windows Server 2012 R2.

In a remote site, a support technician installs a server named DC10 that runs Windows

Server 2012 R2. DC10 is currently a member of a workgroup.

You plan to promote DC10 to a read-only domain controller (RODC).

You need to ensure that a user named Contoso\User1 can promote DC10 to a RODC in

the contoso. com domain. The solution must minimize the number of permissions assigned

to User1.

What should you do?

A. From Active Directory Users and Computers, run the Delegation of Control Wizard on

the contoso. com domain object.

B. From Active Directory Administrative Center, pre-create an RODC computer account.

C. From Ntdsutil, run the local roles command.

D. Join DC10 to the domain. Run dsmod and specify the /server switch.

Answer: B


A staged read only domain controller (RODC) installation works in two discrete phases:

1. Staging an unoccupied computer account

2. Attaching an RODC to that account during promotion

Reference: Install a Windows Server 2012 R2 Active Directory Read-Only Domain

Controller (RODC)


Your network contains an Active Directory domain named contoso. com. All domain

controllers run either Windows Server 2008 or Windows Server 2008 R2.

You deploy a new domain controller named DC1 that runs Windows Server 2012 R2.

You log on to DC1 by using an account that is a member of the Domain Admins group.

You discover that you cannot create Password Settings objects (PSOs) by using Active

Directory Administrative Center.

You need to ensure that you can create PSOs from Active Directory Administrative Center.

What should you do?

A. Modify the membership of the Group Policy Creator Owners group.

B. Transfer the PDC emulator operations master role to DC1.

C. Upgrade all of the domain controllers that run Window Server 2008.

D. Raise the functional level of the domain.

Answer: D


Fine-grained password policies allow you to specify multiple password policies within a

single domain so that you can apply different restrictions for password and account lockout

policies to different sets of users in a domain. To use a fine-grained password policy, your

domain functional level must be at least Windows Server 2008. To enable fine-grained

password policies, you first create a Password Settings Object (PSO). You then configure

the same settings that you configure for the password and account lockout policies. You

can create and apply PSOs in the Windows Server 2012 environment by using the Active

Directory Administrative Center (ADAC) or Windows PowerShell.

Step 1: Create a PSO

Applies To: Windows Server 2008, Windows Server 2008 R2

http: //technet. microsoft. com/en-us//library/cc754461(v=ws. 10). aspx


Your network contains an Active Directory domain named contoso. com. The domain

contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced


The domain is renamed to adatum. com.

Group Policies no longer function correctly.

You need to ensure that the existing GPOs are applied to users and computers. You want

to achieve this goal by using the minimum amount of administrative effort.

What should you use?

A. Dcgpofix

B. Get-GPOReport

C. Gpfixup

D. Gpresult

E. Gpedit. msc

F. Import-GPO

G. Restore-GPO

H. Set-GPInheritance

I. Set-GPLink

J. Set-GPPermission

K. Gpupdate

L. Add-ADGroupMember

Answer: C


You can use the gpfixup command-line tool to fix the dependencies that Group Policy

objects (GPOs) and Group Policy links in Active Directory Domain Services (AD DS) have

on Domain Name System (DNS) and NetBIOS names after a domain rename operation.

http: //technet. microsoft. com/en-us/library/hh852336(v=ws. 10). aspx




You manage a server that runs Windows Server 2012 R2. The server has the Windows

Deployment Services server role installed.

You have a desktop computer that has the following configuration:

Computer name: Computer1

Operating system: Windows 8

MAC address: 20-CF-30-65-D0-87

GUID: 979708BF-C04B-4525-9FE0-C4150BB6C618

You need to configure a pre-staged device for Computer1 in the Windows Deployment

Services console.

Which two values should you assign to the device ID? (Each correct answer presents a

complete solution. Choose two. )

A. 20CF3065D08700000000000000000000

B. 979708BFC04B45259FE0C4150BB6C618

C. 979708BF-C04B-452S-9FE0-C4150BB6C618

D. 0000000000000000000020CF306SD087

E. 00000000-0000-0000-0000-C41S0BB6C618

Answer: C,D


In the text box, type the client computer\’s MAC address preceded with twenty zeros or the

globally unique identifier (GUID) in the format: {XXXXXXXX-XXXX-XXXX-XXXXXXXXXXXXXXX}.

* To add or remove pre-staged client to/from AD DS, specify the name of the computer or

the device ID, which is a GUID, media access control (MAC) address, or Dynamic Host

Configuration Protocol (DHCP) identifier associated with the computer.

* Example: Remove a device by using its ID from a specified domain

This command removes the pre-staged device that has the specified ID. The cmdlet

searches the domain named TSQA. Contoso. com for the device.

Windows PowerShell

PS C: \> Remove-WdsClient -DeviceID “5a7a1def-2e1f-4a7b-a792-ae5275b6ef92”

Domain -DomainName “TSQA. Contoso. com”


Your company has a main office and two branch offices. The main office is located in New

York. The branch offices are located in Seattle and Chicago.

The network contains an Active Directory domain named contoso. com. An Active Directory

site exists for each office. Active Directory site links exist between the main office and the

branch offices. All servers run Windows Server 2012 R2.

The domain contains three file servers. The file servers are configured as shown in the

following table.

You implement a Distributed File System (DFS) replication group named ReplGroup.

ReplGroup is used to replicate a folder on each file server. ReplGroup uses a hub and

spoke topology. NYC-SVR1 is configured as the hub server.

You need to ensure that replication can occur if NYC-SVR1 fails.

What should you do?

A. Create an Active Directory site link bridge.

B. Create an Active Directory site link.

C. Modify the properties of Rep1Group.

D. Create a connection in Rep1Group.

Answer: D


Unsure about this answer.




The Bridge all site links option in Active Directory must be enabled. (This option is available

in the Active Directory Sites and Services snap-in. ) Turning off Bridge all site links can

affect the ability of DFS to refer client computers to target computers that have the least

expensive connection cost. An Intersite Topology Generator that is running Windows

Server 2003 relies on the Bridge all site links option being enabled to generate the intersite

cost matrix that DFS requires for its site-costing functionality. If you turn off this option, you

must create site links between the Active Directory sites for which you want DFS to

calculate accurate site costs.

Any sites that are not connected by site links will have the maximum possible cost. For

more information about site link bridging, see


Your network contains an Active Directory domain named contoso. com. All servers run

Windows Server 2012 R2.

Client computers run either Windows 7 or Windows 8. All of the client computers have an

application named App1 installed.

The domain contains a Group Policy object (GPO) named GPO1 that is applied to all of the

client computers.

You need to add a system variable named App1Data to all of the client computers.

Which Group Policy preference should you configure?

A. Environment

B. Ini Files

C. Data Sources

D. Services

Answer: A


Environment Variable preference items allow you to create, update, replace, and delete

user and system environment variables or semicolon-delimited segments of the PATH

variable. Before you create an Environment Variable preference item, you should review

the behavior of each type of action possible with this extension.

CertBus exam braindumps are pass guaranteed. We guarantee your pass for the 70-411 exam successfully with our Microsoft materials. CertBus Administering Windows Server 2012 exam PDF and VCE are the latest and most accurate. We have the best Microsoft in our team to make sure CertBus Administering Windows Server 2012 exam questions and answers are the most valid. CertBus exam Administering Windows Server 2012 exam dumps will help you to be the Microsoft specialist, clear your 70-411 exam and get the final success.

70-411 Latest questions and answers on Google Drive(100% Free Download): https://drive.google.com/file/d/0B_3QX8HGRR1mNzhvYUxTRFllckU/view?usp=sharing

70-411 Microsoft exam dumps (100% Pass Guaranteed) from CertBus: http://www.certbus.com/70-411.html [100% Exam Pass Guaranteed]

Why select/choose CertBus?

Millions of interested professionals can touch the destination of success in exams by certbus.com. products which would be available, affordable, updated and of really best quality to overcome the difficulties of any course outlines. Questions and Answers material is updated in highly outclass manner on regular basis and material is released periodically and is available in testing centers with whom we are maintaining our relationship to get latest material.

Brand Certbus Testking Pass4sure Actualtests Others
Price $45.99 $124.99 $125.99 $189 $69.99-99.99
Up-to-Date Dumps
Free 365 Days Update
Real Questions
Printable PDF
Test Engine
One Time Purchase
Instant Download
Unlimited Install
100% Pass Guarantee
100% Money Back
Secure Payment
Privacy Protection