Latest Real 70-413 Tests Dumps and VCE Exam Questions 45-50

Ensurepass

QUESTION 45

Your network contains an Active Directory domain named contoso.com. The domain contains an

organizational unit (OU) named OU1. You have a Group Policy object (GPO) named GPO1 that is

linked to contoso.com. GPO1 contains custom security settings. You need to design a Group

Policy strategy to meet the following requirements:

 

Ÿ   The security settings in GPO1 must be applied to all client computers.

Ÿ   Only GPO1 and other GPOs that are linked to OU1 must be applied to the client computers

in OU1.

 

What should you include in the design? (More than one answer choice may achieve the goal.

Select the BEST answer.)

 

A.      Enable the Block Inheritance option at the domain level. Enable the Enforced option on

GPO1.

B.      Enable the Block Inheritance option on OU1. Link GPO1 to OU1.

C.      Enable the Block Inheritance option on OU1. Enable the Enforced option on GPO1.

D.      Enable the Block Inheritance option on OU1. Enable the Enforced option on all of the GPOs

linked to OU1.

 

Correct Answer: C

 

 

QUESTION 46

A new company registers the domain name of contoso.com. The company has a web presence on

the Internet. All Internet resources have names that use a DNS suffix of contoso.com. A

third-party hosts the Internet resources and is responsible for managing the contoso.com DNS

zone on the Internet. The zone contains several hundred records. The company plans to deploy

an Active Directory forest. You need to recommend an Active Directory forest infrastructure to

meet the following requirements:

 

Ÿ   Ensure that users on the internal network can resolve the names of the company’s Internet

resources.

Ÿ   Minimize the amount of administrative effort associated with the addition of new Internet

servers.

 

What should you recommend?

 

A.      A forest that contains a root domain named contoso.com and another domain named

ad.contoso.com.

B.      A forest that contains a root domain named contoso.com and another domain named

contoso.local.

C.      A forest that contains a single domain named contoso.local.

D.      A forest that contains a single domain named contoso.com.

 

Correct Answer: C

 

 

QUESTION 47

Your network contains an Active Directory forest named contoso.com. The forest contains one

domain. Your company plans to open a new division named Division1. A group named

Division1Admins will administer users and groups for Division1. You identify the following

requirements for Division1:

 

Ÿ   All Division1 users must have a complex password that is 14 characters.

Ÿ   Division1Admins must be able to manage the user accounts for Division1.

Ÿ   Division1Admins must be able to create groups, and then delete the groups that they create.

Ÿ   Division1Admins must be able to reset user passwords and force a password change at the

next logon for all Division1 users.

 

You need to recommend changes to the forest to support the Division1 requirements. What

should you recommend? (More than one answer choice may achieve the goal. Select the BEST

answer.)

 

A.      Create a new child domain named divisionl.contoso.com. Move all of the Division1 user

accounts to the new domain. Add the Division1Admin members to the Domain Admins

group. Configure the password policy in a Group Policy object (GPO).

B.      In the forest, create a new organizational unit (OU) named Division1 and add

Division1Admins to the Managed By attribute of the new OU. Move the Division1 user

objects to the new OU. Create a fine-grained password policy for the Division1 users.

C.      Create a new forest. Migrate all of the Division1 user objects to the new forest and add the

Division1Admins members to the Enterprise Admins group. Configure the password policy in

a Group Policy object (GPO).

D.      In the forest, create a new organizational unit (OU) named Division1 and delegate

permissions for the OU to the Division1Admins group. Move all of the Division1 user

accounts to the new OU. Create a fine-grained password policy for the Division1 users.

 

Correct Answer: A

 

 

QUESTION 48

Your network contains an internal network and a perimeter network. The internal network

contains an Active Directory forest named contoso.com. The forest contains a Microsoft Exchange

Server 2010 organization. All of the domain controllers in contoso.com run Windows Server 2012.

The perimeter network contains an Active Directory forest named litware.com. You deploy

Microsoft Forefront Unified Access Gateway (UAG) to litware.com. All of the domain controllers

in litware.com run Windows Server 2012. Some users connect from outside the network to use

Outlook Web App. You need to ensure that external users can authenticate by using client

certificates. What should you do? (More than one answer choice may achieve the goal. Select the

BEST answer.)

 

A.      Enable Kerberos constrained delegation in litware.com.

B.      To the perimeter network, add an Exchange server that has the Client Access server role

installed.

C.      Enable Kerberos delegation in litware.com.

D.      Deploy UAG to contoso.com.

 

Correct Answer: A

 

 

QUESTION 49

Your company has a main office and 20 branch offices. All of the offices connect to each other by

using a WAN link. The network contains an Active Directory forest named contoso.com. The

forest contains a domain for each office. The forest root domain contains all of the server

resources. Each branch office contains two domain controllers for the branch office domain and

one domain controller for the contoso.com domain. Each branch office has a support technician

who is responsible for managing the accounts of their respective office only. You recently

updated all of the WAN links to high-speed WAN links. You need to recommend changes to the

Active Directory infrastructure to meet the following requirements:

 

Ÿ   Reduce the administrative overhead of moving user accounts between the offices.

Ÿ   Ensure that the support technician in each office can manage the user accounts of their

respective office.

 

What should you include in the recommendation?

 

More than one answer choice may achieve the goal. Select the BEST answer.

 

A.      Create shortcut trusts between each child domain.

In the main office, add a domain controller to each branch office domain.

B.      Create a new child domain named corp.contoso.com.

Create a shortcut trust between each child domain and corp.contoso.com.

C.      Move all of the user accounts of all the branch offices to the forest root domain.

Decommission all of the child domains.

D.      Create a new forest root domain named contoso.local.

Move all of the user accounts of all the branch offices to the new forest root domain.

Decommission all of the child domains.

 

Correct Answer: C

 

 

QUESTION 50

Your company, which is named Contoso, Ltd., has a main office and two branch offices. The main

office is located in North America. The branch offices are located in Asia and Europe. You plan to

design an Active Directory forest and domain infrastructure. You need to recommend an Active

Directory design to meet the following requirements:

 

Ÿ   The contact information of all the users in the Europe office must not be visible to the users

in the other offices.

Ÿ   The administrators in each office must be able to control the user settings and the computer

settings of the users in their respective office.

 

The solution must use the least amount of administrative effort. What should you include in the

recommendation?

 

A.      One forest that contains three domains

B.      One forest that contains one domain

C.      Three forests that each contain one domain

D.      Two forests that each contain one domain

 

Correct Answer: B