70-417 Exam Details

  • Exam Code
    :70-417
  • Exam Name
    :Upgrading Your Skills to MCSA Windows Server 2012
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :711 Q&As
  • Last Updated
    :Feb 03, 2022

Microsoft 70-417 Online Questions & Answers

  • Question 351:

    Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server 1. Server1 runs Windows Server 2012 R2 and has the Hyper-V server role installed. You create an external virtual switch named Switch1. Switch1 has the following configurations:

    -Connection type: External network

    -Single-root I/O virtualization (SR-IOV): Enabled Ten virtual machines connect to Switch1.

    You need to ensure that all of the virtual machines that connect to Switch1 are isolated from the external network and can connect to each other only. The solution must minimize network downtime for the virtual machines. What should you do?

    A. Remove Switch1 and recreate Switch1 as an internal network.
    B. Change the Connection type of Switch1 to Private network.
    C. Change the Connection type of Switch1 to Internal network.
    D. Remove Switch1 and recreate Switch1 as a private network.

  • Question 352:

    Your role of Network Administrator at ABC.com includes the management of the Active Directory Domain Services (AD DS) domain named ABC.com. All servers on the network run Windows Server 2012.

    The corporate Web site www.ABC.com is hosted on a Windows Server 2012 Web Server hosted on the corporate network. A public IP address is mapped to the private IP address of the Web Server to provide Internet access to the corporate Web site. DirectAccess is enabled on the network using the default configuration to enable external users to access resources on the corporate network when they are away from the office. Company security policy states that all connections from outside the office to www.ABC.com must come through the corporate firewall using the external IP address of the Web site.

    How can you ensure that external users cannot connect to www.ABC.com using a DirectAccess connection?

    A. By running the Set-DAClientExperienceConfiguration cmdlet.
    B. By modifying the Name Resolution Policy.
    C. By modifying the external IP address assigned to the Web server.
    D. By running the Remove-DAEntryPointTableItem cmdlet.

  • Question 353:

    Your network contains an Active Directory domain named contoso.com. The domain contains three servers named Server1, Server2, and Server3 that run Windows Server 2012 R2. All three servers have the Hyper-V server role installed and

    the Failover Clustering feature installed.

    Server1 and Server2 are nodes in a failover cluster named Cluster1. Several highly available virtual machines run on Cluster1. Cluster1 has that Hyper-V Replica Broker role installed. The Hyper-V Replica Broker currently runs on Server1.

    Server3 currently has no virtual machines.

    You need to configure Cluster1 to be a replica server for Server3 and Server3 to be a replica server for Cluster1.

    Which two tools should you use? {Each correct answer presents part of the solution. Choose two.)

    A. The Hyper-V Manager console connected to Server3
    B. The Failover Cluster Manager console connected to Server3
    C. The Hyper-V Manager console connected to Server1.
    D. The Failover Cluster Manager console connected to Cluster1
    E. The Hyper-V Manager console connected to Server2

  • Question 354:

    You have a server named Server1 that runs Windows Server 2012 R2. You download and install the Microsoft Online Backup Service Agent on Server1.

    You need to ensure that you can configure an online backup from Windows Server Backup.

    What should you do first?

    A. From a command prompt, run wbadmin.exe enable backup.
    B. From Windows Server Backup, run the Register Server Wizard.
    C. From the Services console, modify the Log On settings of the Microsoft Online Backup Service Agent.
    D. From Computer Management, add the Server1 computer account to the Backup Operators group.

  • Question 355:

    Your network contains an Active Directory domain named contoso.com. The domain functional level is Windows Server 2008. All domain controllers run Windows Server 2008 R2.

    The domain contains a file server named Server1 that runs Windows Server 2012.

    Server1 has a BitLocker Drive Encryption (BitLocker)-encrypted drive.

    Server1 uses a Trusted Platform Module (TPM) chip.

    You enable the Turn on TPM backup to Active Directory Domain Services policy setting by using a Group Policy object (GPO). You need to ensure that you can back up the BitLocker recovery information to Active Directory.

    What should you do?

    A. Raise the forest functional level to Windows Server 2008 R2.
    B. Enable the Configure the level of TPM owner authorization information available to the operating system policy setting and set the Operating system managed TPM authentication level to None.
    C. Add a BitLocker data recovery agent.
    D. Import the TpmSchemaExtension.ldf and TpmSchemaExtensionACLChanges.ldf schema extensions to the Active Directory schema.

  • Question 356:

    Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.

    Your network contains one Active Directory domain named contoso.com. The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. The domain contains an administrator account named

    Admin1. You need to prevent Admin1 from creating more than 100 objects in the domain partition.

    Which tool should you use?

    A. the ntdsutil command.
    B. the Set-ADDomain cmdlet.
    C. the Install-ADDSDornain cmdlet.
    D. the dsadd command.
    E. the dsamain command.
    F. the dsmgmt command.
    G. the net user command.
    H. the Set-ADForest cmdlet.

  • Question 357:

    HOTSPOT

    Your network contains one Active Directory domain. The domain contains an enterprise certification authority (CA). You need to ensure that members of a group named Group1 can issue certificates for the User certificate template only.

    Which two tabs should you use to perform the configuration? To answer, select the appropriate tabs in the answer area.

    Hot Area:

  • Question 358:

    HOTSPOT

    Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2.

    Server1 has the Active Directory Federation Services (AD FS) server role installed.

    Adatum.com is a partner organization.

    You are helping the administrator of adatum.com set up a federated trust between adatum.com and contoso.com. The administrator of adatum.com asks you to provide a file containing the federation metadata of contoso.com.

    You need to identify the location of the federation metadata file. Which node in the AD FS console should you select?

    To answer, select the appropriate node in the answer area.

    Hot Area:

  • Question 359:

    You have a server named Server1 that runs Windows Server 2012 R2. You apply a security policy to Server1 by using the Security Configuration Wizard (SCW).

    You plan to roll back the security policy. You need to identify the setting that are prevented from rolling back using the SCW.

    Which setting should you identify?

    A. the outbound authentication methods
    B. the system access control lists (SACLs)
    C. the service startup mode
    D. the network security rules

  • Question 360:

    You work as a Network Administrator at ABC.com. The network contains a single Active Directory Domain Services (AD DS) domain named ABC.com which spans two sites. The company has a main office and a branch office. The two

    offices are connected by a slow Wide Area Network (WAN) link.

    Both offices have servers running Windows Server 2008 R2 Service Pack 1 (SP1) and Windows Server 2012.

    A Windows Server 2012 server named ABC-MainHV1 in the main office runs the Hyper-V Server role. ABC-MainHV1 hosts Virtual Machines (VMs) primarily used by users in the main office. You install a Windows Server 2012 server named

    ABC-BranchHV1 in the branch office and configure it to run the Hyper-V Server role. You configure a VM named BranchVM1 on ABCBranchHV1.

    You need to configure the virtual environment to ensure that if ABC-BranchHV1 fails, you can run BranchVM1 on ABC-MainHV1. Which two of the following steps should you perform? (Choose two).

    A. You should select the "Enable this computer as a replica server" in the Replication Configuration settings on ABC-MainHV1.
    B. You should select the "Enable this computer as a replica server" in the Replication Configuration settings on ABC- BranchHV1.
    C. Enable replication on BranchVM1.
    D. Change the storage location of the VHD file for BranchVM1.
    E. Export BranchVM1.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-417 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.