MICROSOFT OFFICIAL: New Updated 70-413 Exam Questions from Braindump2go 70-413 PDF Dumps and 70-413 VCE Dumps! Welcome to Download the Newest Braindump2go 70-413 VCE&PDF Dumps: http://www.braindump2go.com/70-413.html (211 Q&As)
Braindump2go New Released Microsoft 70-413 Practice Tests Sample Questions Free Download! 100% Same Questions with Actual 70-413 Exam! Guaranteed 100% Pass!
Exam Code: 70-413
Exam Name: Designing and Implementing a Server Infrastructure
Certification Provider: Microsoft
Corresponding Certifications: MCSE, MCSE: Server Infrastructure
70-413 Dumps,70-413 Exam Questions,70-413 Exam PDF,70-413 Book,70-413 E-Book,70-413 PDF Book,70-413 PDF,70-413 VCE,70-413 Designing and Implementing a Server Infrastructure,70-413 Braindump,70-413 Practice Exam,70-413 Study Guide
QUESTION 51
Your network contains an Active Directory domain named contoso.com.
All servers run either Windows Server 2008 R2 or Windows Server 2012.
Your company uses IP Address Management (IPAM) to manage multiple DHCP servers.
A user named User1 is a member of the IPAM Users group and is a member of the local Administrators group on each DHCP server.
When User1 edits a DHCP scope by using IPAM, the user receives the error message shown in the exhibit. (Click the Exhibit button.)
You need to prevent User1 from receiving the error message when editing DHCP scopes by using IPAM.
What should you do?
A. Add User1 to the DHCP Administrators group on each DHCP server.
B. Add User1 to the IPAM Administrators group.
C. Run the Set-IpamServerConfig cmdlet.
D. Run the Invoke-IpamGpoProvisioning cmdlet.
Answer: B
Explanation:
http://technet.microsoft.com/en-us/library/hh831622.aspx
IPAM Administrators: IPAM Administrators have the privileges to view all IPAM data and perform all IPAM tasks.
QUESTION 52
Your network contains an Active Directory forest named corp.contoso.com.
All servers run Windows Server 2012. The network has a perimeter network that contains servers that are accessed from the Internet by using the contoso.com namespace.
The network contains four DNS servers.
The servers are configured as shown in the following table.
All of the client computers on the perimeter network use Server1 and Server2 for name resolution.
You plan to add DNS servers to the corp.contoso.com domain.
You need to ensure that the client computers automatically use the additional name servers.
The solution must ensure that only computers on the perimeter network can resolve names in the corp.contoso.com domain.
Which DNS configuration should you implement on Server1 and Server2? To answer, drag the appropriate DNS configuration to the correct location in the answer area. Each DNS configuration may be used once, more than once, or not at all. Additionally, you may need to drag the split bar between panes or scroll to view content.
Answer:
QUESTION 53
Your network contains an Active Directory domain named contoso.com.
The domain contains multiple sites.
You plan to deploy DirectAccess.
The network security policy states that when client computers connect to the corporate network from the Internet, all of the traffic destined for the Internet must be routed through the corporate network.
You need to recommend a solution for the planned DirectAccess deployment that meets the security policy requirement.
What should you include in the recommendation?
A. Set the ISATAP State to state enabled.
B. Enable split tunneling.
C. Set the ISATAP State to state disabled.
D. Enable force tunneling.
Answer: D
Explanation:
http://blogs.technet.com/b/csstwplatform/archive/2009/12/15/directaccess-how-toconfigure-forcetunneling-forda-so-that-client-are-forced-to-use-ip-https.aspx
You can configure DirectAccess clients to send all of their traffic through the tunnels to the DirectAccess server with force tunneling. When force tunneling is configured, DirectAccess clients that detect that they are on the Internet modify their IPv4 default route so that default route IPv4 traffic is not sent. With the exception of local subnet traffic, all traffic sent by the DirectAccess client is IPv6 traffic that goes through tunnels to the DirectAccess server.
QUESTION 54
Your network contains an Active Directory domain.
You plan to implement a remote access solution that will contain three servers that run Windows Server 2012.
The servers will be configured as shown in the following table.
You need to ensure that all VPN connection requests are authenticated and authorized by either Server2 or Server3.
The solution must ensure that the VPN connections can be authenticated if either Server2 or Server3 fails.
What should you do?
A. On Server1, configure a RADIUS proxy.
Add Server2 and Server3 to a failover cluster.
B. Add Server2 and Server3 to a Network Load Balancing (NLB) cluster.
On Server1, modify the Authentication settings.
C. On Server1, configure a RADIUS proxy.
On Server2 and Server3, add a RADIUS client.
D. On Server2 and Server3, add a RADIUS client.
On Server1, modify the Authentication settings.
Answer: D
Explanation:
http://technet.microsoft.com/en-us/library/cc754033.aspx
QUESTION 55
Your company has a main office.
The network contains an Active Directory domain named contoso.com.
The main office contains a server named Server1 that runs Windows Server 2012.
Server1 has the Remote Access server role installed and is configured to accept incoming SSTP-based VPN connections. All client computers run Windows 7.
The company plans to open a temporary office that will contain a server named Server2 that runs Windows Server 2012 and has the DHCP Server server role installed.
The office will also have 50 client computers and an Internet connection.
You need to recommend a solution to provide the users in the temporary office with access to the resources in the main office.
What should you recommend? More than one answer choice may achieve the goal. Select the BEST answer.
A. Use the Connection Manager Administration Kit (CMAK) to create a connection package
that specifies Server1 as the target for SSTP-based VPN connections.
Manually distribute the CMAK package to each client computer in the temporary office.
B. Install the Remote Access server role on Server2.
From Routing and Remote Access on Server2, add a SSTP-based VPN port.
From DHCP on Server2, configure the default gateway server option.
C. Uses the Connection Manager Administration Kit (CMAK) to create a connection package
that specifies Server1 as the target for SSTP-based VPN connections.
Use a Group Policy object (GPO) to distribute the CMAK package to each client computer
in the temporary office.
D. Install the Remote Access server role on Server2.
From Routing and Remote Access on Server2, configure a demand-dial interface.
From DHCP on Server2, configure the default gateway server option.
Answer: B
Explanation:
ttp://technet.microsoft.com/en-us/library/cc775646(v=ws.10).aspx
The temporary office has an Internet connection and the conditions that would warrant a demand-dial interface do not seem to be indicated in the question namely, PSTN, ISDN, ATM connections or per-minute (time-sensitive) costs of the WAN connection. Also, CMAK makes use of PPTP and L2TP but the question specifies SSTP so it seems there would be less administrative overhead using option “B”.
QUESTION 56
Your network contains an Active Directory domain named contoso.com.
The domain contains servers that run either Windows Server 2008 R2 or Windows Server 2012. All client computers on the internal network are joined to the domain. Some users establish VPN connections to the network by using Windows computers that do not belong to the domain.
All client computers receive IP addresses by using DHCP.
You need to recommend a Network Access Protection (NAP) enforcement method to meet the following requirements:
– Verify whether the client computers have up-to-date antivirus software.
– Provides a warning to users who have virus definitions that are out-of-date.
– Ensure that client computers that have out-of-date virus definitions can connect to the network.
Which NAP enforcement method should you recommend?
A. VPN
B. DHCP
C. IPsec
D. 802.1x
Answer: B
Explanation:
http://technet.microsoft.com/en-us/library/cc733020(v=ws.10).aspx
NAP enforcement for DHCP
DHCP enforcement is deployed with a DHCP Network Access Protection (NAP) enforcement server component, a DHCP enforcement client component, and Network Policy Server (NPS).
Using DHCP enforcement, DHCP servers and NPS can enforce health policy when a computer attempts to lease or renew an IP version 4 (IPv4) address. However, if client computers are configured with a static IP address or are otherwise configured to circumvent the use of DHCP, this enforcement method is not effective.
QUESTION 57
Your network contains an Active Directory domain named contoso.com.
The domain contains a server named Server1 that runs Windows Server 2012.
Server1 resides in the perimeter network and has the Remote Access server role installed.
Some users have laptop computers that run Windows 7 and are joined to the domain.
Some users work from home by using their home computers.
The home computers run either Windows XP, Windows Vista/ Windows 7, or Windows 8.
You need to configure the computers for remote access.
Which three actions should you perform? To answer, move the three appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
QUESTION 58
Your network contains multiple servers that run Windows Server 2012.
All client computers run Windows 8.
You need to recommend a centralized solution to download the latest antivirus definitions for Windows Defender.
What should you include in the recommendation?
A. Microsoft System Center 2012 Endpoint Protection
B. Network Access Protection (NAP)
C. Microsoft System Center Essentials
D. Windows Server Update Services (WSUS)
Answer: D
Explanation:
For those who actually doubt this answer:
http://support.microsoft.com/kb/919772
To use WSUS to deploy Windows Defender definition updates to client computers, follow these steps:
1. Open the WSUS Administrator console, and then click Options at the top of the console.
2. Click Synchronization Options.
3. Under Products and Classifications, click Change under Products.
4. Verify that the Windows Defender check box is selected, and then click OK.
5. Under Products and Classifications, click Change under Update Classifications.
6. Verify that the Definition Updates check box is selected, and then click OK.
7. Optional Update the automatic approval rule. To do this, follow these steps:
a. At the top of the console, click Options.
b. Click Automatic Approval Options.
c. Make sure that the Automatically approve updates for installation by using the following rule check box is selected.
d. Under Approve for Installation, click Add/Remove Classification.
e. Verify that the Definition Updates check box is selected, and then click OK.
8. At the top of the console, click Options.
9. Click Synchronization Options.
10. On the taskbar on the left, click Synchronize now.
11. At the top of the console, click Updates.
12. Approve any Windows Defender updates that WSUS should deploy.
QUESTION 59
Your network contains an Active Directory domain named contoso.com.
The domain contains three VLANs.
The VLANs are configured as shown in the following table.
All client computers run either Windows 7 or Windows 8.
The corporate security policy states that all of the client computers must have the latest security updates installed.
You need to implement a solution to ensure that only the client computers that have all of the required security updates installed can connect to VLAN 1.
The solution must ensure that all other client computers connect to VLAN 3.
Which Network Access Protection (NAP) enforcement method should you implement?
A. VPN
B. DHCP
C. IPsec
D. 802.1x
Answer: D
Explanation:
http://blogs.technet.com/b/wincat/archive/2008/08/19/network-access-protection-using-802-1x-vlan-s-or-portacls-which-is-right-for-you.aspx
The most common method of the list is 802.1x for a variety of reasons. First, the industry has been selling 802.1x network authentication for the last 10 years. 1x gained tremendous popularity as wireless networking became prevalent in the late 90’s and early 2000’s and has been proven to be a viable solution to identifying assets and users on your network. For customers that have invested in 802.1x capable switches and access points, NAP can very easily be implemented to complement what is already in place. The Network Policy Server (NPS) role Windows Server 2008 has been dramatically improved to make 802.1x policy creation much simpler to do.
QUESTION 60
You have a server named Server1 that runs Windows Server 2012.
You have a 3-TB database that will be moved to Server1.
Server1 has the following physical disks:
– Three 2-TB SATA disks that are attached to a single IDE controller
– One 1-TB SATA disk that is attached to a single IDE controller
You need to recommend a solution to ensure that the database can be moved to Server1.
The solution must ensure that the database is available if a single disk fails.
What should you include in the recommendation?
A. Add each disk to a separate storage pool.
Create a mirrored virtual disk.
B. Add two disks to a storage pool.
Add the other disk to another storage pool.
Create a mirrored virtual disk.
C. Add all of the disks to a single storage pool, and then create two simple virtual disks.
D. Add all of the disks to a single storage pool, and then create a parity virtual disk.
Answer: D
Explanation:
http://blogs.technet.com/b/askpfeplat/archive/2012/10/10/windows-server-2012-storagespaces-is-it-foryoucould-be.
http://winsvr.wordpress.com/2013/01/22/storage-space-virtual-disk/
Parity A parity virtual disk is similar to a hardware Redundant Array of Inexpensive Disks (RAID5). Data, along with parity information, is striped across multiple physical disks. Parity enables Storage Spaces to continue to service read and write requests even when a drive has failed. A minimum of three physical disks is required for a parity virtual disk. Note that a parity disk cannot be used in a failover cluster.
2015 Latest Released Microsoft 70-413 Exam Dumps Free Download From Braindump2go Now! All Questions and Answers are chcked again by Braindump2go Experts Team, 100% Real Questions and Correct Answers Guaranteed! Full Money Back Guarantee Show our Confidence in helping you have a 100% Success of Exam 70-413! Just have a try!
FREE DOWNLOAD: NEW UPDATED 70-413 PDF Dumps & 70-413 VCE Dumps from Braindump2go: http://www.braindump2go.com/70-413.html (211 Q&A)