Microsoft 70-414 Exam Practice Questions (P. 2)
- Full Access (171 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6
Your company has an office in New York.
Many users connect to the office from home by using the Internet.
You deploy an Active Directory Certificate Services (AD CS) infrastructure that contains an enterprise certification authority (CA) named CA1. CA1 is only available from hosts on the internal network.
You need to ensure that the certificate revocation list (CRL) is available to all of the users.
What should you do? (Each correct answer presents part of the solution. Choose all that apply.)
Many users connect to the office from home by using the Internet.
You deploy an Active Directory Certificate Services (AD CS) infrastructure that contains an enterprise certification authority (CA) named CA1. CA1 is only available from hosts on the internal network.
You need to ensure that the certificate revocation list (CRL) is available to all of the users.
What should you do? (Each correct answer presents part of the solution. Choose all that apply.)
- ACreate a scheduled task that copies the CRL files to a Web server.
- BRun the Install-ADCSWebEnrollment cmdlet.
- CRun the Install-EnrollmentPolicyWebService cmdlet.
- DDeploy a Web server that is accessible from the Internet and the internal network.
- EModify the location of the Authority Information Access (AIA).
- FModify the location of the CRL distribution point (CDP).
Correct Answer:
DF
CRLs will be located on Web servers which are Internet facing.
CRLs will be accessed using the HTTP retrieval protocol.
CRLs will be accessed using an external URL of http://dp1.pki.contoso.com/pki
F: To successfully authenticate an Internet Protocol over Secure Hypertext Transfer Protocol (IP-HTTPS)-based connection, DirectAccess clients must be able to check for certificate revocation of the secure sockets layer (SSL) certificate submitted by the DirectAccess server. To successfully perform intranet detection,
DirectAccess clients must be able to check for certificate revocation of the SSL certificate submitted by the network location server. This procedure describes how to do the following:
✑ Create a Web-based certificate revocation list (CRL) distribution point using Internet Information Services (IIS)
✑ Configure permissions on the CRL distribution shared folder
✑ Publish the CRL in the CRL distribution shared folder
DF
CRLs will be located on Web servers which are Internet facing.
CRLs will be accessed using the HTTP retrieval protocol.
CRLs will be accessed using an external URL of http://dp1.pki.contoso.com/pki
F: To successfully authenticate an Internet Protocol over Secure Hypertext Transfer Protocol (IP-HTTPS)-based connection, DirectAccess clients must be able to check for certificate revocation of the secure sockets layer (SSL) certificate submitted by the DirectAccess server. To successfully perform intranet detection,
DirectAccess clients must be able to check for certificate revocation of the SSL certificate submitted by the network location server. This procedure describes how to do the following:
✑ Create a Web-based certificate revocation list (CRL) distribution point using Internet Information Services (IIS)
✑ Configure permissions on the CRL distribution shared folder
✑ Publish the CRL in the CRL distribution shared folder
send
light_mode
delete
Question #7
HOTSPOT -
Your network contains an Active Directory forest named contoso.com. All servers run Windows Server 2012 R2. The forest contains two servers.
The servers are configured as shown in the following table.

You prepare the forest to support Workplace Join and you enable the Device Registration Service (DRS) on Server1.
You need to ensure that Workplace Join meets the following requirements:
✑ Application access must be based on device claims.
✑ Users who attempt to join their device to the workplace through Server2 must be prevented from locking out their Active Directory account due to invalid credentials.
Which cmdlet should you run to achieve each requirement? To answer, select the cmdlet for each requirement in the answer area.
Hot Area:

Your network contains an Active Directory forest named contoso.com. All servers run Windows Server 2012 R2. The forest contains two servers.
The servers are configured as shown in the following table.

You prepare the forest to support Workplace Join and you enable the Device Registration Service (DRS) on Server1.
You need to ensure that Workplace Join meets the following requirements:
✑ Application access must be based on device claims.
✑ Users who attempt to join their device to the workplace through Server2 must be prevented from locking out their Active Directory account due to invalid credentials.
Which cmdlet should you run to achieve each requirement? To answer, select the cmdlet for each requirement in the answer area.
Hot Area:

send
light_mode
delete
Question #8
Your network contains the following roles and applications:
✑ Microsoft SQL Server 2012
✑ Distributed File System (DFS) Replication
✑ Active Directory Domain Services (AD DS)
✑ Active Directory Rights Management Services (AD RMS)
✑ Active Directory Lightweight Directory Services (AD LDS)
You plan to deploy Active Directory Federation Services (AD FS).
You need to identify which deployed services or applications can be used as attribute stores for the planned AD FS deployment.
What should you identify? (Each correct answer presents a complete solution. Choose all that apply.)
✑ Microsoft SQL Server 2012
✑ Distributed File System (DFS) Replication
✑ Active Directory Domain Services (AD DS)
✑ Active Directory Rights Management Services (AD RMS)
✑ Active Directory Lightweight Directory Services (AD LDS)
You plan to deploy Active Directory Federation Services (AD FS).
You need to identify which deployed services or applications can be used as attribute stores for the planned AD FS deployment.
What should you identify? (Each correct answer presents a complete solution. Choose all that apply.)
send
light_mode
delete
Question #9
Your company has 10,000 users located in 25 different sites.
All servers run Windows Server 2012. All client computers run either Windows 7 or Windows 8.
You need to recommend a solution to provide self-service password reset for all of the users.
What should you include in the recommendation?
All servers run Windows Server 2012. All client computers run either Windows 7 or Windows 8.
You need to recommend a solution to provide self-service password reset for all of the users.
What should you include in the recommendation?
- AThe Microsoft System Center 2012 Service Manager Self-Service Portal and Microsoft System Center 2012 Orchestrator runbooks
- BMicrosoft System Center 2012 Operations Manager management packs and Microsoft System Center 2012 Configuration Manager collections
- CThe Microsoft System Center 2012 Service Manager Self-Service Portal and Microsoft System Center 2012 Operation Manager management packs
- DMicrosoft System Center 2012 App Controller and Microsoft System Center 2012 Orchestrator runbooks
- Ethe Microsoft System Center 2012 Service Manager and Microsoft System Center 2012 Configuration Manager collections
- Fthe Microsoft System Center 2012 Orchestrator runbooks and Microsoft System Center 2012 Operation Manager management packs
- Gthe Microsoft System Center 2012 Service Manager Self-Service Portal and Microsoft System Center 2012 App Controller
Correct Answer:
A
A
send
light_mode
delete
Question #10
Your network contains an Active Directory domain named contoso.com. The domain contains 200 servers that run either Windows Server 2012 R2, Windows
Server 2012, or Windows Server 2008 R2. The servers run the following enterprise applications:
✑ Microsoft Exchange Server 2013
✑ Microsoft SQL Server 2014
System Center 2012 R2 Operations Manager is deployed to the domain. Operations Manager monitors all of the servers in the domain. Audit Collection Services
(ACS) is installed.
You need to recommend a monitoring strategy for the domain that meets the following requirements:
✑ A group of administrators must be notified when an error is written to the System log on the servers that run Exchange Server 2013.
✑ A group of administrators must be notified when a specific event is written to The Application log on the servers that run SQL Server 2014.
What is the best approach to achieve the goal? More than one answer choice may achieve the goal. Select the BEST answer.
Server 2012, or Windows Server 2008 R2. The servers run the following enterprise applications:
✑ Microsoft Exchange Server 2013
✑ Microsoft SQL Server 2014
System Center 2012 R2 Operations Manager is deployed to the domain. Operations Manager monitors all of the servers in the domain. Audit Collection Services
(ACS) is installed.
You need to recommend a monitoring strategy for the domain that meets the following requirements:
✑ A group of administrators must be notified when an error is written to the System log on the servers that run Exchange Server 2013.
✑ A group of administrators must be notified when a specific event is written to The Application log on the servers that run SQL Server 2014.
What is the best approach to achieve the goal? More than one answer choice may achieve the goal. Select the BEST answer.
- AFrom Operations Manager, enable audit collection.
- BFrom Operations Manager, implement two monitors.
- CFrom Computer Management, implement one event subscription.
- DFrom Operations Manager, implement two rules.
Correct Answer:
D
D
send
light_mode
delete
All Pages