Microsoft 70-741 Exam

Ace your homework & exams now with Quizwiz!

Did you get it right?

Answer question #10 online.

Did you get it right?

Answer question #11 online.

Did you get it right?

Answer question #12 online.

Did you get it right?

Answer question #13 online.

Go To question 103 online

DRAG DROP -You are deploying DirectAccess to a server named DA1. DA1 will be located behind a firewall and will have a single network adapter. The intermediary network will be IPv4.You need to configure the firewall to support DirectAccess.Which firewall rules should you create for each type of traffic? To answer, drag the appropriate ports and protocols to the correct traffic types. Each port and protocol may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.Select and Place:

Did you get it right?

Go to question #52 online

Did you get it right?

Go to question #58 and answer it

Did you get it right?

Go to question #69 online and answer it

Did you get it right?

Go to question 100 online

Did you get it right?

Go to question 111 online

Did you get it right?

Go to question 113 online

did you get it right?

Go to question 117 online

Did you get it right?

Go to question 120 online

Did you get it right?

Go to question 149 online

Did you get it right? Answers are: Never applies to the user a virtual smart card

Go to question 151 online.

Did you get it right?

Go to question 153 online

Did you get it right?

Go to question 154 online

Did you get it right?

Go to question 156 online

Did you get it right?

Go to question 158 online

Did you get it right?

Go to question 23 online

Did you get it right?

Go to question 24 online.

Did you get it right?

Go to question 25 online.

Did you get it right?

Go to question 28 online

Did you get it right?

Go to question 44 online

Go to question 150 online for right answer

HOTSPOT -You have a RADIUS server named RADIUS1. RADIUS1 is configured to use an IP address of 172.23.100.101.You add a wireless access point (wap) named WAP-Secure to your network. You configure WAP-Secure to use an IP address of 10.0.100.101.You need to ensure that WAP-Secure can authenticate to RADIUS1 by using a shared secret key.What command should you run? To answer, select the appropriate options in answer area.Hot Area:

Question 21 online. Check to see if you got it right!

HOTSPOT -Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server2016.Server1 has Microsoft System Center 2016 Virtual Machine Manager (VMM) installed. Server2 has IP Address Management (IPAM) installed.You create a domain user named User1.You need to integrate IPAM and VMM. VMM must use the account of User1 to manage IPAM. The solution must use the principle of least privilege.What should you do on each server? To answer, select the appropriate options in the answer area.Hot Area:

go to question 104 online

HOTSPOT -Your network contains an Active Directory forest named contoso.com. The forest contains a Network Policy Server (NPS) server named Radius1 that runsWindows Server 2016.You need to create a new connection request policy that will allow only Secure Socket Tunneling Protocol (SSTP) connections. Radius1 will manage all authentication requests.Which NAS port type and which authentication method should you configure in the connection request policy? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point.Hot Area:

A. Yes

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution. Determine whether the solution meets the stated goals.Your network contains an Active Directory domain named contoso.com. The domain contains a DNS server named Server1. All client computers run Windows 10.On Server1, you have the following zone configuration.You need to ensure that all of the client computers in the domain perform DNSSEC validation for the fabrikam.com namespace.Solution: From a Group Policy object (GPO) in the domain, you add a rule to the Name Resolution Policy Table (NRPT).Does this meet the goal? A. Yes B. No

No

Question #13Topic 2 Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an IP Address Management (IPAM) server named IPAM1 that runs Windows Server 2016. IPAM1 manages all of the DHCP servers on your network.You are troubleshooting an issue for a client that fails to receive an IP address from DHCP.You need to ensure that from IPAM1, you can view all of the event data for the DHCP leases from the last 24 hours.Solution: From Windows PowerShell, you run the Invoke-IpamServerProvisioning cmdlet.Does this meet the goal?? A. Yes B. No

B. Create a connection request policy on FabRP1. C. Create a network policy on FabRS1.

Refer to the exhibit:You plan to implement a VPN. FabRA1 will use the RADIUS proxy for authentication.You need to ensure that VPN clients can be authenticated and can access internal resources. The solution must ensure that FabRS1 is used as a RADIUS server and FabRP1 is used as a RADIUS proxy.Which two actions should you perform? Each correct answer presents part of the solution. A. Create a connection request policy on FabRS1. B. Create a connection request policy on FabRP1. C. Create a network policy on FabRS1. D. Delete the default connection request policy on FabRS1. E. Create a network policy on FabRP1.

C. Install the Routing role service on Server1.

You are a network administrator for a company named Contoso, Ltd. The network is configured as shown in the exhibit.You install the Remote Access server role on Server2. Server2 has the following configured:✑ Network address translation (NAT)✑ The DHCP Server server roleThe Security Policy of Contoso states that only TCP ports 80 and 443 are allowed from the internet to Server2.You identify the following requirements:✑ Add 28 devices to subnet2 for a temporary project.✑ Configure Server2 to accept VPN connections from the internet.✑ Ensure that devices on Subnet2 obtain TCP/IP settings from DHCP on Server2.What should you do to meet the DHCP connectivity requirement for Subnet2? A. Install the Routing role service on Server2. B. Install the IP address Management (IPAM) Server feature on Server2. C. Install the Routing role service on Server1. D. Install the DHCP Server server role on Server1.

D. Add-DhcpServerv4Reservation

You are implementing a new network. The network contains a DHCP server named DHCP1 that runs Windows Server 2016. DHCP1 contains a scope namedScope1 for the 192.168.0/24 subnet.Your company has the following policy for allocating IP addresses:✑ All server addresses must be excluded from DHCP scopes✑ All client computers must receive IP addresses from Scope1✑ All Windows servers must have IP addresses in the range of 192.168.0.200 to 192.168.0.240✑ All other network devices must have IP addresses in the range of 192.168.0.180 to 192.168.0.199You deploy a print device named Print1.You need to ensure that Print1 adheres to the policy for allocating IP addresses.Which command should you use? A. Add-DhcpServerv4Lease B. Add-DhcpServerv4ExclusionRange C. Add-DhcpServerv4Filter D. Add-DhcpServerv4Reservation

B. No

You have a Hyper-V host named Server1 that hosts a virtual machine named VM1. Server1 and VM1 run Windows Server 2016.The settings for VM1 are configured as shown in the exhibit below.You need to ensure that you can use the Copy-VMFile cmdlet on Server1 to copy files from VM1.Solution: You start the Hyper-V Guest Service Interface service on VM1.Does this meet the goal? A. YES B. NO

D. the Routing role service

You have a server named Server1 that connects directly to multiple networks.You need to configure Server1 as a BGP router.What should you install on Server1? A. the MultiPoint Services server role B. the Network Policy and Access Services server role C. the Network Controller server role D. the Routing role service

D. Run the Get-IpamIpAddressAuditEvent cmdlet.

You have a server named Server1 that runs Windows Server 2016. Server1 is an IP Address Management (IPAM) server that collects DHCP and DNS logs and events for your entire network.You need to get the IP addresses that were assigned to a client computer named Computer1 during the last week.What should you do on Server1? A. From the IPAM node in Server Manager, click IP Address Space, and then review the IP Address Inventory. B. Open Event Viewer and click Windows Logs. Filter the Security log for Computer1. C. Run the Get-IpamDhcpConfigurationEvent cmdlet. D. Run the Get-IpamIpAddressAuditEvent cmdlet.

D. Enable-BCHostedServer Reveal Solution

You have a server that is configured as a hosted BranchCache server.You discover that a Service Connection Point (SCP) is missing for the BranchCache server.What should you run to register the SCP? A. setspn.exe B. Reset-BC C. ntdsutil.exe D. Enable-BCHostedServer

D. From RADIUS Clients and Servers, add RADIUS clients.

You have multiple servers that run Windows Server 2016 and are configured as VPN servers.You deploy a server named NPS1 that has Network Policy Server (NPS) installed.You need to configure NPS1 to accept authentication requests from the VPN servers.What should you configure on NPS1? A. From RADIUS Clients and Servers, add a remote RADIUS server group. B. From Policies, add a connection request policy. C. From Policies, add a network policy. D. From RADIUS Clients and Servers, add RADIUS clients.

A. $ruleproperties.SourceAddressPrefix = "10.10.10.0/24" C. $ruleproperties.Protocol = "ALL" F. $ruleproperties.DestinationAddressPrefix = "*"

You manage a Windows Server 2016 software-defined network.Network Controller is installed on a three-node domain-joined cluster of virtual machines.You need to add a new access control list (ACL) for the network controller to the network interface on a tenant virtual machine. The ACL will have only one rule that prevents only outbound traffic from the 10.10.10.0/24 subnet.You plan to run the following Windows PowerShell commands.$ruleproperties = new-object Microsoft.Windows.NetworkController.AclRuleProperties$ruleproperties.SourcePortRange = "0-65535"$ruleproperties.DestinationPortRange = "0-65535"$ruleproperties.Action = "Deny"$ruleproperties.Priority = "100"$ruleproperties.Type = "Outbound"$ruleproperties.Logging = "Enabled"Which three remaining properties should you add to the rule? Each correct answer presents part of the solution. (Choose three.)NOTE: Each correct selection is worth one point. A. $ruleproperties.SourceAddressPrefix = "10.10.10.0/24" B. $ruleproperties.DestinationAddressPrefix = "10.10.10.0/24" C. $ruleproperties.Protocol = "ALL" D. $ruleproperties.Protocol = "TCP" E. $ruleproperties.SourceAddressPrefix = "*" F. $ruleproperties.DestinationAddressPrefix = "*"

D. Virtual network adapter

You need to implement network virtualization.On which object should you configure the virtual subnet ID? A. Virtual switch B. Hyper-V server C. VM D. Virtual network adapter

No

You need to prevent Server1 from resolving queries from DNS clients located on Subnet4. Server1 must resolve queries from all other DNS clients.Solution: From the Security setting of each zone on Server1, you modify the permissions.Does this meet the goal? A. Yes B. No

C. Microsoft: Protected EAP

Your network contains an Active Directory domain. The domain contains a certification authority (CA) and a Network Policy Server (NPS) server.You plan to deploy Remote Access Always On VPN.Which authentication method should you use? A. Microsoft: EAP-TTLS B. Microsoft: Secured password C. Microsoft: Protected EAP D. Microsoft: EAP-AKA

A. From a Group Policy object (GPO), modify the Name Resolution Policy Table (NRPT).

Your network contains an Active Directory forest named contoso.com. The forest contains two domains named contoso.com and litwareinc.com.Your company recently deployed DirectAccess for the members of a group named DA_Computers. All client computers are members of DA_Computers.You discover that DirectAccess clients can access the resources located in the contoso.com domain only. The clients can access the resources in the litwareinc.com domain by using an L2TP VPN connection to the network.You need to ensure that the DirectAccess clients can access the resources in the litwareinc.com domain.What should you do? A. From a Group Policy object (GPO), modify the Name Resolution Policy Table (NRPT). B. From the properties of the servers in litwareinc.com, configure the delegation settings. C. On an external DNS server, create a zone delegation for litwareinc.com. D. Add the servers in litwareinc.com to the RAS and IAS Servers group.

Did you get it right?

go to question 92 online

No

.Your network contains an Active Directory domain named contoso.com. The domain contains a DHCP server named Server2 than runs Windows Server 2016.Users report that their client computers fail to obtain an IP address.You open the DHCP console as shown in the Exhibit. (Click the Exhibit button.)Scope1 has an address range of 172.16.0.10 to 172.16.0.100 and a prefix length of 23 bits.You need to ensure that all of the client computers on the network can obtain an IP address from Server2.Solution: You run the Reconcile-DhcpServerv4IPRecord cmdlet.Does this meet the goal? A. Yes B. No

No

.Your network contains an Active Directory domain named contoso.com. The domain contains a DHCP server named Server2 than runs Windows Server 2016.Users report that their client computers fail to obtain an IP address.You open the DHCP console as shown in the Exhibit. (Click the Exhibit button.)Scope1 has an address range of 172.16.0.10 to 172.16.0.100 and a prefix length of 23 bits.You need to ensure that all of the client computers on the network can obtain an IP address from Server2.Solution: You run the Repair-DhcpServerv4IPRecord cmdlet.Does this meet the goal?

Go to question 18 online to see if you got it right!

DRAG DROP -You have an internal network that contains multiple subnets.You have a Microsoft Azure subscription that contains multiple virtual networks.You need to deploy a hybrid routing solution between the network and the Azure subscription. The solution must ensure that the computers on all of the networks can connect to each other.You install RAS Gateway and enable BGP routing on the network and in Azure.Which three actions should you perform next in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.Select and Place:

Invoke-IpamServerProvisioning Add-IpamDiscoveryDomain Start-ScheduledTask

DRAG DROP -Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2016.You install IP Address Management (IPAM) on Server1.You need to manually start discovery of the servers that IPAM can manage in contoso.com.Which three cmdlets should you run in sequence? To answer, move the appropriate cmdlets from the list of cmdlets to the answer area and arrange them in the correct order.Select and Place:

Did you get it right?

Go to question 45 online

Did you get it right?

Go to question 46 online

Did you get it right?

Go to question 47 online

Did you get it right? The answers are Implement Failover Clustering Able to see File1.doc in File explorer and will be prevented from opening the file

Go to question 61

Did you get it right?

Go to question 73 online

Did you get it right?

Go to question 74 online

Did you get it right?

Go to question 75 online

Did you get it right?

Go to question 86 online

Did you get it right?

Go to question 94 online

Did you get it right?

Go to question 98 online

Did you get it right?

Go to question 99 online

Go to question 56 online. Did you get it right?

HOTSPOT -On a DNS server that runs Windows Server 2016, you plan to create two new primary zones named adatum.com and contoso.com.You have the following requirements for the zones:✑ Ensure that computers on your network can register records automatically in the adatum.com zone.✑ Ensure that records that are stale for two weeks are purged automatically from the contoso.com zone.What should you configure for each zone? To answer, select the appropriate options in the answer area.Hot Area:

Go to question 97 online to see if you got it right!

HOTSPOT -You are implementing IPv6 addressing for your company by using the following specifications:✑ The global address space is 2001:db8:1234.✑ The company has 100 locations worldwide.✑ Each location has up to 300 subnets.✑ 64 bits will be used for hosts.You need to identify how many bits to use for the locations and the subnets.How many bits should you identify? To answer, drag the appropriate amounts to the correct targets. Each amount may be used once, more than once, or not at all.You may need to drag the split bar between panes or scroll to view content.NOTE: Each correct selection is worth one point.Hot Area:

Set-DaServer -ConnectToAddress

HOTSPOT -You have a DirectAccess server that is accessible by using the name directaccess.fabrikam.com.On the DirectAccess server, you install a new server certificate that has a subject name of directaccess.contoso.com, and then you configure DNS records for directaccess.contoso.com.You need to change the endpoint name for DirectAccess to directaccess.contoso.com.What command should you run? To answer, select the appropriate options in the answer area.Hot Area:

Go to question 152 online. Did you get it right?

HOTSPOT -You have a Hyper-V host named Server1 that runs Windows Server 2016. Server1 connects to your corporate network. The Corporate network uses the10.10.0.0/16 address space.Server1 hosts a virtual machine named VM1, VM1 is configured to have an IP addresses of 172.16.1.54/16.You need to ensure that VM1 can access the resources on the corporate network.What should you do? To answer, select the appropriate options in the answer area.Hot Area:

Go to question 63 for answer!

HOTSPOT -You have a Hyper-V host named Server1 that runs Windows Server 2016. Server1 has two network adaptors named NIC1 and NIC2. Server1 has two virtual switches named vSwitch1 and vSwitch2. NIC1 connects to vSwitch1. NIC2 connects to vSwitch2.Server1 hosts a virtual machine named VM1. VM1 has two network adapters named vmNIC1 and vmNIC2. VmNIC1 connects to vSwitch1. VmNIC2 connects to vSwitch2.You need to create a NIC team on VM1.What should you run on VM1? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point.Hot Area:

Server Authentication/ Server Authentication

HOTSPOT -You have a Remote Access infrastructure.You plan to implement DirectAccess.Which type of certificate should you install on each DirectAccess server? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point.Hot Area: Remote Access Server: Client Authentication IP Security IKE intermediate Server Authentication Network location server: Client Authentication IP Security IKE intermediate Server Authentication

Go to question 142 online

HOTSPOT -You have a virtual machine named VM1 that runs Windows Server 2016. VM1 is a Remote Desktop Services (RDS) server.You need to ensure that only TCP port 3389 can be used to connect to VM1 over the network.Which command should you run on the Hyper-V host? To answer, select the appropriate options in the answer area.Hot Area:

Set-DnsServerForwarder -UseRootHint $False

HOTSPOT -Your network contains an Active Directory domain named contoso.com. The domain contains a DNS server named Server1.Server1 is configured to use a forwarder named server2.contoso.com that has an IP address of 10.0.0.10.You need to prevent Server1 from using root hints if the forwarder is unavailable.What command should you run? To answer, select the appropriate options in the answer area.Hot Area:

Go to question #59

HOTSPOT -Your network contains an Active Directory domain named contoso.com. The domain contains a DNS server named Server1.You enable Response Rate Limiting on Server1.You need to prevent Response Rate Limiting from applying to hosts that reside on the network of 10.0.0.0/24.Which cmdlets should you run? To answer, select the appropriate options in the answer area.Hot Area:

Get-DfsnFolderTarget \\Contoso.com\Namespace1\Folder1

HOTSPOT -Your network contains an Active Directory domain named contoso.com. The domain contains a domain-based Distributed File System (DFS) namespace namedNamespace1.You need to view the shares to which users will be redirected when the users attempt to connect to a folder named Folder1 in the DFS namespace.What cmdlet should you run? To answer, select the appropriate options in the answer area.Hot Area:

Go to question #118 online for right answer NT Authority\ Network Service

HOTSPOT -Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server1 that runs Windows Server 2016.Server1 has IP Address Management (IPAM) installed. IPAM users a Windows Internal Database.You install Microsoft SQL Server on Server1.You plan to move the IPAM database to SQL Server.You need to create a SQL server login for the IPAM service account.For which user should you create the login? To answer, select the appropriate options in the answer area.Hot Area:

No

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You are implementing a secure network. The network contains a DHCP server named Server1 that runs Windows Server 2016.You create a DHCP allow filter that contains all of the computers on the network that are authorized to receive IP addresses.You discover that unauthorized computers can obtain an IP address from Server1.You need to ensure that only authorized computers can receive an IP address from Server1.Solution: You run the following command: Add-DHCPServerv4Filter ""ComputerName Server1 ""MacAddress * -List AllowDoes this meet the goal? A. Yes B. No

No

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You are implementing a secure network. The network contains a DHCP server named Server1 that runs Windows Server 2016.You create a DHCP allow filter that contains all of the computers on the network that are authorized to receive IP addresses.You discover that unauthorized computers can obtain an IP address from Server1.You need to ensure that only authorized computers can receive an IP address from Server1.Solution: You run the following command: Add-DHCPServerv4Filter ""ComputerName Server1 ""MacAddress * -List DenyDoes this meet the goal? A. Yes B. No

No

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You are implementing a secure network. The network contains a DHCP server named Server1 that runs Windows Server 2016.You create a DHCP allow filter that contains all of the computers on the network that are authorized to receive IP addresses.You discover that unauthorized computers can obtain an IP address from Server1.You need to ensure that only authorized computers can receive an IP address from Server1.Solution: You run the following command: Set-DhcpServerv4FilterList ""ComputerName Server1 ""Allow False ""Deny TrueDoes this meet the goal? A. Yes B. No

No

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Hyper-V host named Server 1. The network adapters on Server1 have single root I/O virtualization (SR-IOV) enabled.Server1 hosts a virtual machine named VM1 that runs Windows Server 2016.You need to identify whether SR-IOV is used by VM1.Solution: You sign in to VM1. You open Device Manager and view the properties of the network adapters.Does this meet the goal? A. Yes B. No

Yes

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Hyper-V host named Server 1. The network adapters on Server1 have single root I/O virtualization (SR-IOV) enabled.Server1 hosts a virtual machine named VM1 that runs Windows Server 2016.You need to identify whether SR-IOV is used by VM1.Solution: You sign in to VM1. You run the Get-NetAdapterSriov cmdlet.Does this meet the goal? A. Yes B. No

B. No

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Hyper-V host named Server 1. The network adapters on Server1 have single root I/O virtualization (SR-IOV) enabled.Server1 hosts a virtual machine named VM1 that runs Windows Server 2016.You need to identify whether SR-IOV is used by VM1.Solution: You sign in to VM1. You view the properties of the network connections.Does this meet the goal? A. Yes B. No

No

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Hyper-V host named Server1. The network adapters on Server1 have single root I/O virtualization (SR-IOV) enabled.Server1 hosts a virtual machine named VM1 that runs Windows Server 2016.You need to identify whether SR-IOV is used by VM1.Solution: On Server1, you open Hyper-V Manager and view the Integration Services settings of VM1.Does this meet the goal? A. Yes B. No

A. Yes

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an IP Address Management (IPAM) server named IPAM1 that runs Windows Server 2016. IPAM1 manages all of the DHCP servers on your network.You are troubleshooting an issue for a client that fails to receive an IP address from DHCP.You need to ensure that from IPAM1, you can view all of the event data for the DHCP leases from the last 24 hours.Solution: From Server Manager, you run Retrieve Event Catalog Data.Does this meet the goal? A. Yes B. No

Yes

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an IP Address Management (IPAM) server named IPAM1 that runs Windows Server 2016. IPAM1 manages all of the DHCP servers on your network.You are troubleshooting an issue for a client that fails to receive an IP address from DHCP.You need to ensure that from IPAM1, you can view all of the event data for the DHCP leases from the last 24 hours.Solution: From Task Scheduler, you run the Microsoft\Windows\IPAM\Audit task.Does this meet the goal? A. Yes B. No

No

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an IP Address Management (IPAM) server named IPAM1 that runs Windows Server 2016. IPAM1 manages all of the DHCP servers on your network.You are troubleshooting an issue for a client that fails to receive an IP address from DHCP.You need to ensure that from IPAM1, you can view all of the event data for the DHCP leases from the last 24 hours.Solution: From Windows PowerShell, you run the Set-IpamDHCPServer cmdlet.Does this meet the goal? A. Yes B. No

Yes

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution. Determine whether the solution meets the stated goals.Refer to exhibit:Server1 has two virtual machines named VM1 and VM that run Windows Server 2016. VM1 connects to Private1. VM2 has two network adapters.You need to ensure that VM1 connects to the corporate network by using NAT.Solution: You connect VM1 to Inernal1. You run the New-NetNatIpAddress and the New-NetNat cmdlets on Server1. You configure VM1 to use Server1 as the default gateway.Does this meet the goal? A. Yes B. No

B. No

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution. Determine whether the solution meets the stated goals.Refer to exhibit:Server1 has two virtual machines named VM1 and VM that run Windows Server 2016. VM1 connects to Private1. VM2 has two network adapters.You need to ensure that VM1 connects to the corporate network by using NAT.Solution: You connect VM2 to Private1 and External1. You install the Remote Access server on VM2, and you configure NAT in the Routing and Remote Access console. You configure VM1 and VM2 as the default gateway.Does this meet the goal? A. Yes B. No

Yes

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution. Determine whether the solution meets the stated goals.Refer to exhibit:Server1 has two virtual machines named VM1 and VM that run Windows Server 2016. VM1 connects to Private1. VM2 has two network adapters.You need to ensure that VM1 connects to the corporate network by using NAT.Solution: You connect VM2 to Private1 and External1. You install the Remote Access server on VM2, and you configure NAT in the Routing and Remote Access console. You configure VM1 to use VM2 as the default gateway.Does this meet the goal? A. Yes B. No

No

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution. Determine whether the solution meets the stated goals.Refer to exhibit:Server1 has two virtual machines named VM1 and VM that run Windows Server 2016. VM1 connects to Private1. VM2 has two network adapters.You need to ensure that VM1 connects to the corporate network by using NAT.Solution: You connect VM2 to Private1 and External1. You run the New-NetNatIpAddress and the New-NetNat cmdlets on VM2. You configure VM1 to use VM2 as the default gateway.Does this meet the goal? A. Yes B. No

B. No

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution. Determine whether the solution meets the stated goals.Refer to exhibit:Server1 has two virtual machines named VM1 and VM2 that run Windows Server 2016. VM1 connects to Private1. VM2 has two network adapters.You need to ensure that VM1 connects to the corporate network by using NAT.Solution: You connect VM1 to Inernal1. You run the New-NetNatIpAddress and the New-NetNat cmdlets on Server1. You configure VM1 to use VM2 as the default gateway.Does this meet the goal? A. Yes B. No

No

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution. Determine whether the solution meets the stated goals.Your network contains an Active Directory domain named contoso.com. The domain contains a DNS server named Server1. All client computers run Windows 10.On Server1, you have the following zone configuration.You need to ensure that all of the client computers in the domain perform DNSSEC validation for the fabrikam.com namespace.Solution: From Windows PowerShell on Server1, you run the Add-DnsServerTrustAnchor cmdlet.Does this meet the goal? A. yes B. No

No

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution. Determine whether the solution meets the stated goals.Your network contains an Active Directory domain named contoso.com. The domain contains a DNS server named Server1. All client computers run Windows 10.On Server1, you have the following zone configuration.You need to ensure that all of the client computers in the domain perform DNSSEC validation for the fabrikam.com namespace.Solution: From a Group Policy object (GPO) in the domain, you modify the Network List Manager Policies.Does this meet the goal? A. Yes B. No

F. From IPv4, run the DHCP Policy Configuration Wizard.

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.You have 2000 devices. One hundred of the devices are mobile devices that have physical addresses beginning with 98-5F.You have a DHCP server named Server1.You need to ensure that the mobile devices register their host name by using a DNS suffix of mobile.contoso.com.What should you do on Server1? A. From the properties of IPv4, modify the Conflict detection attempts setting. B. From the properties of Scope1, configure Name Protection. C. From the Properties of IPv4, configure the bindings. D. From IPv4, create a new filter. E. From the properties of Scope1, create an exclusion range. F. From IPv4, run the DHCP Policy Configuration Wizard. G. From Control Panel, modify the properties of Ethernet. H. From Scope1, create a reservation

A. From the properties of Scope1, modify the Conflict detection attempts setting.

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.You have a DHCP server named Server1 that has an IPv4 scope named Scope1.Users report that when they turn on their client computers, it takes a long time to access the network.You validate that it takes a long time for the computers to receive an IP address from Server1.You monitor the network traffic and discover that Server1 issues five ping commands on the network before leasing an IP address.You need to reduce the amount of time it takes for the computers to receive an IP address.What should you do? A. From the properties of Scope1, modify the Conflict detection attempts setting. B. From the properties of Scope1, configure Name Protection. C. From the properties of IPv4, configure the bindings. D. From IPv4, create a new filter. E. From the properties of Scope1, create an exclusion range. F. From IPv4, run the DHCP Policy Configuration Wizard. G. From Control Panel, modify the properties of Ethernet. H. From Scope1, create a reservation.

C. From the properties of IPv4, configure the bindings.

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.You have a DHCP server named Server1 that has three network cards. Each network card is configured to use a static IP address. Each network card connects to a different network segment.Server1 has an IPv4 scope named Scope1.You need to ensure that Server1 only uses one network card when leasing IP addresses in Scope1.What should you do? A. From the properties of Scope1, modify the Conflict detection attempts setting. B. From the properties of Scope1, configure Name Protection. C. From the properties of IPv4, configure the bindings. D. From IPv4, create a new filter. E. From the properties of Scope1, create an exclusion range. F. From IPv4, run the DHCP Policy Configuration Wizard. G. From Control Panel, modify the properties of Ethernet. H. From Scope1, create a reservation.

D. From IPv4, create a new filter.

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.You have a DHCP server named Server1 that has three network cards. Each network card is configured to use a static IP address.You need to prevent all client computers that have physical address beginning with 98-5F from leasing an IP address from Server1.What should you do? A. From the properties of Scope1, modify the Conflict detection attempts setting. B. From the properties of Scope1, configure Name Protection. C. From the properties of IPv4, configure the bindings. D. From IPv4, create a new filter. E. From the properties of Scope1, create an exclusion range. F. From IPv4, run the DHCP Policy Configuration Wizard. G. From Control Panel, modify the properties of Ethernet. H. From Scope1, create a reservation.

D. netsh.exe

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.You have a server named Server1 that runs Windows Server 2016.You install the DHCP Server server role on Server1.You need to authorize DHCP on Server1.What should you run? A. dism.exe B. dns.exe C. dnscmd.exe D. netsh.exe E. Set-DhcpServerDatabase F. Set-DhcpServerv4DnsSetting G. Set-DhcpServerv6DnsSetting H. Set-DNSServerSetting

C. dnscmd.exe

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.You have multiple servers that run Windows Server 2016. You have a server named Server1 that is configured as a domain controller and a DNS server.You need to create an Active Directory-integrated zone on Server1.What should you run? A. dism.exe B. dns.exe C. dnscmd.exe D. netsh.exe E. Set-DhcpServerDatabase F. Set-DhcpServerv4DnsSetting G. Set-DhcpServerv6DnsSetting H. Set-DNSServerSetting

C. dnscmd.exe

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.You have multiple servers that run Windows Server 2016.The DNS Server server role is installed on a server named Server1.You need to configure Server1 to use a DNS forwarder that has an IP address of 192.168.10.15.What should you run? A. dism.exe B. dns.exe C. dnscmd.exe D. netsh.exe E. Set-DhcpServerDatabase F. Set-DhcpServerv4DnsSetting G. Set-DhcpServerv6DnsSetting H. Set-DNSServerSetting

A. dism.exe

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.You have multiple servers that run Windows Server 2016.You need to install the DNS Server server role on one of the servers.What should you run? A. dism.exe B. dns.exe C. dnscmd.exe D. netsh.exe E. Set-DhcpServerDatabase F. Set-DhcpServerv4DnsSetting G. Set-DhcpServerv6DnsSetting H. Set-DNSServerSetting

F. From IPv4, run the DHCP Policy Configuration Wizard.

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.Your company has five departments, including a web research department.You have a DHCP server named Server1 and two DNS servers named DNS1 and DNS2.Server1 has an Ipv4 scope named Scope1. All client computers are configured to use DNS1 for name resolution.You need to ensure that users in the web research department use DNS2 for name resolution.What should you do on Server1? A. From the properties of Scope1, modify the Conflict detection attempts setting. B. From the properties of Scope1, configure Name Protection. C. From the properties of IPv4, configure the bindings. D. From IPv4, create a new filter. E. From the properties of Scope1, create an exclusion range. F. From IPv4, run the DHCP Policy Configuration Wizard. G. From Control Panel, modify the properties of Ethernet. H. From Scope1, create a reservation.

B. From the properties of Scope1, configure Name Protection.

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.Your network contains Windows and non-Windows devices.You have a DHCP server named Server1 that has an IPv4 scope named Scope1.You need to prevent a client computer that uses the same name as an existing registration from updating the registration.What should you do? A. From the properties of Scope1, modify the Conflict detection attempts setting. B. From the properties of Scope1, configure Name Protection. C. From the properties of IPv4, configure the bindings. D. From IPv4, create a new filter. E. From the properties of Scope1, create an exclusion range. F. From IPv4 run the DHCP Policy Configuration Wizard. G. From Control Panel, modify the properties of Ethernet. H. From Scope1, create a reservation.

E. Set-DhcpServerDatabase

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.Your network contains an Active Directory domain named contoso.com. The domain contains a DHCP server named Server2 that runs Windows Server 2016.Server2 has 10 IPv4 scopes.You need to ensure that the scopes are backed up every 30 minutes to the folder D:\DHCPBackup.What should you run? A. dism.exe B. dns.exe C. dnscmd.exe D. netsh.exe E. Set-DhcpServerDatabase F. Set-DhcpServerv4DnsSetting G. Set-DhcpServerv6DnsSetting H. Set-DNSServerSetting

F. Set-DhcpServerv4DnsSetting

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server2 that runs Windows Server 2016.The DHCP Server server role is installed on Server2. The DNS server role is installed on a server named Server3.The network contains 500 non-Windows devices that are registered in the DNS zone of contoso.com.You configure Server2 to lease IP addresses to the non-Windows devices.You need to prevent Server2 from overwriting the host (A) records for the non-Windows devices.What should you run? A. dism.exe B. dns.exe C. dnscmd.exe D. netsh.exe E. Set-DhcpServerDatabase F. Set-DhcpServerv4DnsSetting G. Set-DhcpServerv6DnsSetting H. Set-DNSServerSetting

C. 131.107.0.223

You are a network administrator for a company named Contoso, Ltd. The network is configured as shown in the exhibit.You install the Remote Access server role on Server2. Server2 has the following configured:✑ Network address translation (NAT)✑ The DHCP Server server roleThe Security Policy of Contoso states that only TCP ports 80 and 443 are allowed from the internet to Server2.You identify the following requirements:✑ Add 28 devices to subnet2 for a temporary project.✑ Configure Server2 to accept VPN connections from the internet.✑ Ensure that devices on Subnet2 obtain TCP/IP settings from DHCP on Server2.You add a computer to subnet1. The computer has an IP address of 10.10.0.129. Web1 receives a request from the new computer and sends a response.You need to determine which address Web1 sends the response to.Which IP address should you choose? A. 10.10.0.129 B. 10.10.0.224 C. 131.107.0.223 D. 172.16.128.222

C. Install-NetworkControllerCluster ""Node @{Node1, Node1, Node3} ""ClientAuthentication X509

You are deploying Software Defined Networking (SDN) by using Windows Server 2016.You plan to deploy a three-node Network Controller cluster. You plan to use virtual machines for the network controller and the management client. The virtual machines will NOT be domain-joined.You need to configure authentication for the cluster.Which command should you run? A. Install-NetworkController ""Node @{Node1, Node2, Node3} ""ClientAuthentication X509 B. Install-NetworkControllerCluster ""Node @{Node1, Node1, Node3} ""ClientAuthentication Kerberos C. Install-NetworkControllerCluster ""Node @{Node1, Node1, Node3} ""ClientAuthentication X509 D. Install-NetworkControllerCluster ""Node @{Node1, Node1, Node3} ""ClientAuthentication None E. Install-NetworkController ""Node @{Node1, Node2, Node3} ""ClientAuthentication Kerberos

E. Install the Routing role service on Server2 and configure the NAT routing protocol. Configure Server1 to provide the 003 Router option of 192.168.1.250.

You are deploying a small network that has 30 client computers. The network uses the 192.168.1.0/24 address space. All computers obtain IP configurations from a DHCP server named Server1.You install a server named Server2 that runs Windows Server 2016. Server2 has two network adapters named Internal and Internet. Internet connects to anInternet Service Provider (ISP) and obtains the 131.107.0.10 IP address. Internal connects to the internal network and is configured to use the 192.168.1.250 IP address.You need to provide Internet connectivity for the client computers.What should you do? A. On Server1, stop the DHCP server. On the Internal network adapter on Server2, enable Internet Connection Sharing (ICS). B. On Server2 run the New-NetNat ""Name NAT1 -InternalIPInterfaceAddressPrefix 192.168.1.0/24 cmdlet. Configure Server1 to provide the 003 Router option of 192.168.1.250. C. On Server1, stop the DHCP server. On the Internet adapter on Server2, enable internet Connection Sharing (ICS). D. Recreate the DHCP scope on Server1 to lease addresses from the 131.107.0.0/24 address space. On Server2, change the IP address of the internal network adapter to 131.107.0.1. Configure Server1 to provide the 003 Router option of 131.107.0.1. E. Install the Routing role service on Server2 and configure the NAT routing protocol. Configure Server1 to provide the 003 Router option of 192.168.1.250.

D. Install the Routing role service on Server2 and configure the NAT routing protocol. Configure Server1 to provide the 003 Router option of 192.168.1.250.

You are deploying a small network that has 30 client computers. The network uses the 192.168.1.0/24 address space. All computers obtain IP configurations from a DHCP server named Server1.You install a server named Server2 that runs Windows Server 2016. Server2 has two network adapters named Internal and Internet. Internet connects to anInternet Service Provider (ISP) and obtains the 131.107.0.10 IP address. Internal connects to the internal network and is configured to use the 192.168.1.250 IP address.You need to provide Internet connectivity for the client computers.What should you do? A. On Server2, select the Internet and Internal network adapters and bridge the connections. From the DHCP console on Server1, authorize Server2. B. On Server1, stop the DHCP server. On the Internal network adapter on Server 2, enable Internet Connection Sharing (ICS). C. On Server2 run the New-NetNat Name NAT1 -InternalIPInterfaceAddressPrefix 192.168.1.0/24 cmdlet. Configure Server1 to provide the 003 Router option of 131.107.0.10. D. Install the Routing role service on Server2 and configure the NAT routing protocol. Configure Server1 to provide the 003 Router option of 192.168.1.250.

D. Install the Routing role service on Server2 and configure the NAT routing protocol. Configure Server1 to provide the 003 Router option of 192.168.1.250.

You are deploying a small network that has 30 client computers. The network uses the 192.168.1.0/24 address space. All computers obtain IP configurations from a DHCP server named Server1.You install a server named Server2 that runs Windows Server 2016. Server2 has two network adapters named Internal and Internet. Internet connects to anInternet Service Provider (ISP) and obtains the 131.107.0.10 IP address. Internal connects to the internal network and is configured to use the 192.168.1.250 IP address.You need to provide Internet connectivity for the client computers.What should you do? A. On Server2, select the Internet and Internal network adapters and bridge the connections. From the DHCP console on Server1, authorize Server2. B. On Server1, stop the DHCP server. On the Internal network adapter on Server2, enable Internet Connection Sharing (ICS). C. On Server2 run the New-NetNat ""Name NAT1 -InternalIPInterfaceAddressPrefix 192.168.1.0/24 cmdlet. Configure Server1 to provide the 003 Router option of 131.107.0.10. D. Install the Routing role service on Server2 and configure the NAT routing protocol. Configure Server1 to provide the 003 Router option of 192.168.1.250. E. Install the Routing role service on Server2 and configure the NAT routing protocol. Configure Server1 to provide the 003 Router option of 131.107.0.10. F. Recreate the DHCP scope on Server1 to lease addresses from the 131.107.0.0/24 address space. On Server2, change the IP address of the internal network adapter to 131.107.0.1. Configure Server1 to provide the 003 Router option of 131.107.0.1.

A. Create a connection request policy. C. Add a RADIUS client. E. Create a remote RADIUS server group.

You company has a main office in London. The company has 1,000 users who are located in many countries.You plan to deploy a large remote access solution for the company.The London office has three servers named Server1, Server2, and Server3 that run Windows Server 2016.You plan to use Server1 as a VPN server, Server2 as a RADIUS proxy, and Server3 as a RADIUS server.You need to configure Server2 to support the planned deployment.Which three actions should you perform on Server2? Each correct answer presents part of the solution. A. Create a connection request policy. B. Deploy a Windows container. C. Add a RADIUS client. D. Create a network policy. E. Create a remote RADIUS server group.

F. From IPv4, run the DHCP Policy Configuration Wizard.

You have 2000 devices. One hundred of the devices are mobile devices that have physical addresses beginning with 98-5F.You have a DHCP server named Server1.You need to ensure that the mobile devices register their host name by using a DNS suffix of mobile.contoso.com. A. From the properties of Scopte1, modify the Conflict detection attempts setting. B. From the properties of Scope1, configure Name Protection. C. From the Properties of IPV4, configure the bindings. D. From IPV4, create a new filter. E. From the properties of Scope1, create an exclusion range. F. From IPv4, run the DHCP Policy Configuration Wizard. G. From Control Panel, modify the properties of Ethernet. H. From Scope1, create a reservation

B. From Windows PowerShell on VM1, run the Enable-NetAdapterRSS cmdlet.

You have Hyper-V host named Server1.Server1 has a network adapter that has virtual machine queue (VMQ) enabled. The network adapter connects at 10 Gbps and has an IPV4 address.Server1 hosts a virtual machine named VM1. VM1 has a single network adapter and four processors.You need to distribute the network processing load across the VM1 processors.What should you do? A. From Device Manager on Server1, configure TCP Checksum Offload (IPv4). B. From Windows PowerShell on VM1, run the Enable-NetAdapterRSS cmdlet. C. From Windows PowerShell on Server1, run the Enable-NetAdapterPacketDirect cmdlet. D. From Windows PowerShell on VM1, run the Enable-NetAdapterPacketDirect cmdlet.

C. From Device Manager on VM1, configure Receive Side Scaling.

You have Hyper-V host named Server1.Server1 has a network adapter that has virtual machine queue (VMQ) enabled. The network adapter connects at 10 Gbps and has an IPV4 address.Server1 hosts a virtual machine named VM1. VM1 has a single network adapter and four processors.You need to distribute the network processing load across the VM1 processors.What should you do? A. From Windows PowerShell on Server1, run the Enable-NetAdapterPacketDirect cmdlet. B. From Windows PowerShell on VM1, run the Enable-NetAdapterPacketDirect cmdlet. C. From Device Manager on VM1, configure Receive Side Scaling. D. From Windows PowerShell on Server1, run the Enable-NetAdapterRSS cmdlet.

A. Create a second scope, and then create a superscope.

You have a DHCP server named Server1 that runs Windows Server 2016.You have a single IP subnet.Server1 has an IPv4 scope named Scope1. Scope1 has an IP address range of 10.0.1.10 to 10.0.1.200 and a length of 24 bits.You need to create a second logical IP network on the subnet. The subnet will use an IP address range of 10.0.2.10 to 10.0.2.200 and a length of 24 bits.What should you do? A. Create a second scope, and then create a superscope. B. Create a superscope, and then configure an exclusion range in Scope1. C. Create a new scope, and then modify the IPv4 bindings. D. Create a second scope, and then run the DHCP Split-Scope Configuration Wizard.

B. Configure the IPv6 Server Options

You have a DHCP server named Server1 that runs Windows Server 2016.You plan to implement IPv6 on your network.You need to configure Server1 for stateless DHCPv6.What should you do from the DHCP console? A. Configure the Advanced Properties for Server1 B. Configure the IPv6 Server Options C. Create an IPv6 scope D. Configure the General IPv6 Properties

C. Modify the lease duration.

You have a DHCP server named Server1.Server1 has an IPv4 scope that contains 100 addresses for a subnet named Subnet1. Subnet1 provides guest access to the Internet. There are never more than20 client computers on Subnet1 simultaneously; however, the computers that connect to Subnet1 are rarely the same computers.You discover that some client computers are unable to access the network. The computers that have the issue have IP addresses in the range of 169.254.0.0/16.You need to ensure that all of the computers can connect successfully to the network to access the Internet.What should you do? A. Create a new scope that uses IP addresses in the range of 169.254.0.0/16. B. Modify the scope options. C. Modify the lease duration. D. Configure Network Access Protection (NAP) integration on the existing scope.

C. Create a DHCP policy for the scope.

You have a DHCP server named Server1.Server1 has an IPv4 scope that serves 75 client computers that run Windows 10.When you review the address leases in the DHCP console, you discover several leases for devices that you do not recognize.You need to ensure that only the 75 Windows 10 computers can obtain a lease from the scope.What should you do? A. Run the Add-DhcpServer4ExclusionRange cmdlet. B. Create and enable a DHCP filter. C. Create a DHCP policy for the scope. D. Run the Add-DhcpServer4OptionDefinition cmdlet.

D. For each zone, select Scavenge stale resource records. E. From the Advanced settings of the DNS server properties, select Enable automatic scavenging of state records.

You have a DNS server named DNS1 that hosts several forward lookup zones.You discover that dynamic records exist for computers that there were removed from your network several months ago.You need to ensure that the records are removed automatically.Which two actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point. A. From the Start of Authority (SOA) settings of each zone, configure the Retry interval setting and the Minimum (default) TTL setting. B. For each zone, set Dynamic updates to Secure only. C. From the Start of Authority (SOA) settings of each zone, configure the Refresh interval setting and the Expires after setting. D. For each zone, select Scavenge stale resource records. E. From the Advanced settings of the DNS server properties, select Enable automatic scavenging of state records.

C. Set-DnsServerDiagnostics

You have a DNS server named Server1 that runs Windows Server 2016. Server1 has an Active Directory-integrated zone named adatum.com.All client computers run Windows 10.You recently encountered unexpected responses to DNS client queries in the adatum.com zone.You need to log all the records written to the zone.Which cmdlet should you run? A. Add-DnsServerQueryResolutionPolicy B. Set-DnsServerDsSetting C. Set-DnsServerDiagnostics D. Set-DnsServer

B. Enable Response Rate Limiting (RRL) on Server1

You have a DNS server named Server1 that runs Windows Server 2016. Server1 has two Active Directory-integrated zones named contoso.com and adatum.com.All client computers run Windows 10.Server1 recently experienced millions of erroneous DNS queries causing a denial of service.You need to reduce the likelihood that a similar attack will cause a denial of service. The solution must ensure that Server1 continues to resolve names for clients.What should you do? A. Implement DNS-based Authentication of Named Entities (DANE) B. Enable Response Rate Limiting (RRL) on Server1 C. Configure DNS policies on Server1 D. Sign both adatum.com and contoso.com zones

B. NO

You have a Hyper-V host named Server1 that hosts a virtual machine named VM1. Server1 and VM1 run Windows Server 2016.The settings for VM1 are configured as shown in the exhibit below.You need to ensure that you can use the Copy-VMFile cmdlet on Server1 to copy files from VM1.Solution: You need to enable the Data Exchange integration service for VM1.Does this meet the goal? A. YES B. NO

C. Get-VMSwitch

You have a Hyper-V host named Server1 that runs Windows Server 2016. Server1 has two network adapters that are Remote Direct Memory Access (RDMA)- enabled.You need to verify whether Switch Embedded Teaming (SET) is enabled.Which cmdlet should you use? A. Get-NetworkSwitchFeature B. Get-VMNetworkAdapter C. Get-VMSwitch D. Get-VMNetworkAdapterFailoverConfiguration

B. 192.168.1.78:80

You have a Hyper-V server named Server1 that runs Windows Server 2016. Server1 has an IP address of 192.168.1.78.Server1 has a container named Container1 that hosts a web application on port 84. Container1 has an IP address of 172.16.5.6.Container1 has a port mapping from port 80 on Server1 to port 84 on Container1.You have a server named Server2 that has an IP address of 192.168.1.79.You need to connect to the web application from Server2.To which IP address and port should you connect? A. 172.16.5.6:80 B. 192.168.1.78:80 C. 172.16.5.6:84 D. 192.168.1.78:84

A. Install the Remote Access server role. From the Routing and Remote Access Server Setup Wizard, select Secure connection between two private networks.

You have a Microsoft Azure subscription and an on-premises network.To the on-premises network, you deploy a new server named Server1 that runs Windows Server 2016. In Azure, you configure a virtual gateway on an Azure virtual network.You need to ensure that the computers on the on-premises network can access virtual machines on the Azure virtual network.What should you do on Server1? A. Install the Remote Access server role. From the Routing and Remote Access Server Setup Wizard, select Secure connection between two private networks. B. Install the Data Center Bridging (DCB) feature, and then run the Install-RemoteAccess cmdlet. C. Install the Remote Access server role. From the Routing and Remote Access Server Setup Wizard, select Virtual private network (VPN) access and NAT. D. Install the Data Center Bridging (DCB) feature, and then run the Enable-RemoteAccessRoutingDomain cmdlet.

D. On the Hyper-V hosts, deploy the Network Controller server role to a virtual machine. Add the hosts by running the New-NetworkControllerServer cmdlet.

You have a data center. The data center contains Hyper-V hosts that run Windows Server 2016.You plan to host virtual machines for several customers. The virtual machines will run across any Hyper-V host. The network traffic of each customer will be isolated from the traffic of other customers.You plan to use Software Defined Networking (SDN).You need to recommend how to deploy Network Controller to support the planned deployment.What should you include in the recommendation? A. On the Hyper-V hosts, deploy the Network Controller server role to a virtual machine. Run the Set-NetworkControllerNode cmdlet on the hosts. B. On the Hyper-V hosts, deploy the Network Controller server role. Add every virtual machine by running the New-NetworkControllerServer cmdlet. C. On the Hyper-V hosts, deploy the Network Controller server role. Run the cmdlet on every virtual machine. Set-NetworkControllerNode D. On the Hyper-V hosts, deploy the Network Controller server role to a virtual machine. Add the hosts by running the New-NetworkControllerServer cmdlet.

Add-NetNatStaticMapping -ExternalIPAddress 131.107.50.1 - InternalIPAddress 10.0.0.211

You have a network address translation (NAT) server named NAT1 that has an external IP address of 131.107.50.1 and an internal IP address of 10.0.0.1.You deploy a new server named Web1 that has an IP address of 10.0.0.211.A remote server named app.fabrikam.com has an IP address of 131.107.1.232.You need to make Web1 accessible to app.fabrikam.com through NAT1.What command should you run from NAT1? To answer, select the appropriate options in the answer area.

C. Set-DnsClientNrptRule

You have a remote access server named Server1 that runs Windows Server 2016. Server1 has DirectAccess enabled.You have a proxy server named Server2. All computers on the internet connect to the Internet by using the proxy.On Server1, you run the command Set-DAClient -Force Tunnel Enabled.You need to ensure that when a Direct Access client connects to the network, the client accesses all the Internet resources through the proxy.What should you run on Server1? A. Set-DnsClientGlobalSetting B. Set-DAEntryPoint C. Set-DnsClientNrptRule D. Set-DnsClientNrptGlobal

C. From the properties of each virtual machine, connect to the virtual machine switch. D. On Host1, configure the network address translation (NAT) network. E. On Host1, create an internal virtual machine switch and specify an IP address for the switch.

You have a server named Host1 that runs Windows Server 2016.You configure Host1 as a virtualization host and create 20 new virtual machines on Host1.You need to ensure that all of the virtual machines can connect to the Internet through Host1.Which three actions should you perform? Each correct answer presents part of the solution. A. On a virtual machine, install the Remote Access server role. B. From the properties of each virtual machine, enable virtual LAN identification. C. From the properties of each virtual machine, connect to the virtual machine switch. D. On Host1, configure the network address translation (NAT) network. E. On Host1, create an internal virtual machine switch and specify an IP address for the switch.

B. New-NetIPAddress

You have a server named Server1 that has a Server Core installation of Windows Server 2016. Server1 is configured to obtain an IP address automatically.You need to configure the IPv4 address, netmask, and default gateway manually for a network interface named Ethernet on Server1.What should you run? A. ipconfig.exe B. New-NetIPAddress C. Set-NetAdapter D. Set-NetIPv4Protocol

A. Yes

You have a server named Server1 that has the Network Policy and Access Services server role installed.You create a Shared Secret Network Policy Server (NPS) template named Template1.You need to view the shared secret string used for Template1.Solution: From Windows PowerShell, you run Get-NpsSharedSecretTemplate -Name Template1.Does this meet the goal? A. Yes B. No

Yes

You have a server named Server1 that has the Network Policy and Access Services server role installed.You create a Shared Secret Network Policy Server (NPS) template named Template1.You need to view the shared secret string used for Template1.Solution: From the Network Policy Server console, you export the configuration, and you view the exported XML file.Does this meet the goal? A. Yes B. No

No

You have a server named Server1 that has the Network Policy and Access Services server role installed.You create a Shared Secret Network Policy Server (NPS) template named Template1.You need to view the shared secret string used for Template1.Solution: From the Network Policy Server console, you view the properties of Template1.Does this meet the goal? A. Yes B. No

D. Dnscmd.exe

You have a server named Server1 that runs Windows Server 2016 and is configured as a domain controller. You install the DNS Server server role on Server1. You plan to store a DNS zone in a custom Active Directory partition. You need to create a new Active Directory partition for the zone. What should you use? A. Set-DnsServer B. Active Directory Sites and Services C. Dns.exe D. Dnscmd.exe E. New-ADObject F. Active Directory Administrative Center G. DNS Manager

C. Ntdsutil.exe

You have a server named Server1 that runs Windows Server 2016 and is configured as a domain controller. You install the DNS Server server role on Server1. You plan to store a DNS zone in a custom Active Directory partition. You need to create a new Active Directory partition for the zone. What should you use? A. Set-DnsServer B. Dns.exe C. Ntdsutil.exe D. Active Directory Administrative Center

D. Dnscmd.exe

You have a server named Server1 that runs Windows Server 2016 and is configured as a domain controller.You install the DNS Server server role on Server1.You plan to store a DNS zone in a custom Active Directory partition.You need to create a new Active Directory partition for the zone.What should you use? A. Set-DnsServer B. Active Directory Sites and Services C. Dns.exe D. Dnscmd.exe

D. Dnscmd.exe

You have a server named Server1 that runs Windows Server 2016 and is configured as a domain controller.You install the DNS Server server role on Server1.You plan to store a DNS zone in a custom Active Directory partition.You need to create a new Active Directory partition for the zone.What should you use? A. Set-DnsServer B. Active Directory Sites and Services C. Dns.exe D. Dnscmd.exe E. New-ADObject F. Active Directory Administrative Center G. DNS Manager

B. 066 Boot Server Host Name E. 060 Option 60

You have a server named Server1 that runs Windows Server 2016. Server1 has the DHCP Server and the Windows Deployment Service server roles installed.Server1 is located on the same subnet as client computers.You need to ensure that clients can perform a PXE boot from Server1.Which two IPv4 options should you configure in DHCP? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point. A. 003 Router B. 066 Boot Server Host Name C. 015 DNS Domain Name D. 006 DNS Servers E. 060 Option 60

A. Server1 will attempt to connect directly to 172.20.10.50.

You have a server named Server1 that runs Windows Server 2016. Server1 has the following routing table.What will occur when Server1 attempts to connect to a host that has an IP address of 172.20.10.50? A. Server1 will attempt to connect directly to 172.20.10.50. B. Server1 will route the connection to 10.10.0.2. C. Server1 will silently drop the connection attempt. D. Server1 will route the connection to 192.168.2.1.

B. From Hyper-V Manager on Server1, modify the settings on VM1.

You have a server named Server1 that runs Windows Server 2016. Server1 is a Hyper-V host that hosts a virtual machine named VM1.Server1 has three network adapter cards that are connected to virtual switches named vSwitch1, vSwitch2 and vSwitch3.You configure NIC Teaming on VM1 as shown in the exhibit. (Click the Exhibit button.)You need to ensure that VM1 will retain access to the network if a physical network adapter card fails on Server1.What should you do? A. From Windows PowerShell on VM1, run the Set-VmNetworkAdapterTeamMapping cmdlet. B. From Hyper-V Manager on Server1, modify the settings on VM1. C. From Windows PowerShell on Server1, run the Set-VmNetworkAdapterFailoverConfiguration cmdlet. D. From the properties of the NIC team on VM1, add the adapter named Ethernet to the NIC team.

A. From the IPAM node in Server Manager, click Event Catalog, and then review the IP Address Tracking.

You have a server named Server1 that runs Windows Server 2016. Server1 is an IP Address Management (IPAM) server that collects DHCP and DNS logs and events for your entire network.You need to get the IP addresses that were assigned to a client computer named Computer1 during the last week.What should you do on Server1? A. From the IPAM node in Server Manager, click Event Catalog, and then review the IP Address Tracking. B. Open Event Viewer and click Windows Logs. Filter the Security log for Computer1. C. Run the Export-IpamAddress cmdlet. D. From the IPAM node in Server Manager, click IP Address Space, and then review the IP Address Inventory. E. Run the Get-IpamDhcpConfigurationEvent cmdlet. F. Run the Get-IpamAddress cmdlet.

D. Run the Get-IpamIpAddressAuditEvent cmdlet.

You have a server named Server1 that runs Windows Server 2016. Server1 is an IP Address Management (IPAM) server that collects DHCP and DNS logs and events for your entire network.You need to get the IP addresses that were assigned to a client computer named Computer1 during the last week.What should you do on Server1? A. From the IPAM node in Server Manager, click IP Address Space, and then review the IP Address Inventory. B. Open Event Viewer and click Windows Logs. Filter the Security log for Computer1. C. Run the Get-IpamDhcpConfigurationEvent cmdlet. D. Run the Get-IpamIpAddressAuditEvent cmdlet. E. Open Event Viewer and click Windows Logs. Filter the Forwarded Events log for Computer1. F. Run the Get-IpamAddress cmdlet.

No

You have a server named Server1 that runs Windows Server 2016. Server1 is configured as a VPN server. Server1 is configured to allow domain users to establish VPN connections from 06:00 to 18:00 everyday of the week.You need to ensure that domain users can establish VPN connections only between Monday and Friday.Solution: From Active Directory Users and Computers, you modify the Dial-in Properties of the user accounts.Does this meet the goal? A. Yes B. No

No

You have a server named Server1 that runs Windows Server 2016. Server1 is configured as a VPN server. Server1 is configured to allow domain users to establish VPN connections from 06:00 to 18:00 everyday of the week.You need to ensure that domain users can establish VPN connections only between Monday and Friday.Solution: From Routing and Remote Access, you configure the Properties of Server1.Does this meet the goal? A. Yes B. No

Yes

You have a server named Server1 that runs Windows Server 2016. Server1 is configured as a VPN server. Server1 is configured to allow domain users to establish VPN connections from 06:00 to 18:00 everyday of the week.You need to ensure that domain users can establish VPN connections only between Monday and Friday.Solution: From Server Manager, you modify the Access Policies on Server1.Does this meet the goal? A. Yes B. No

B. SSTP

You have a server named Server1 that runs Windows Server 2016. Server1 is located on the perimeter network, and only inbound TCP port 443 is allowed to connect Server1 from the Internet.You install the Remote Access server role on Server1.You need to configure Server1 to accept VPN connections over port 443.Which VPN protocol should you use? A. PPTP B. SSTP C. L2TP D. IKEv2

B. IKEv2

You have a server named Server1 that runs Windows Server 2016. Server1 will be used as a VPN server. You need to configure Server1 to support VPNReconnect.Which VPN protocol should you use? A. SSTP B. IKEv2 C. PPTP D. L2TP

D. Switch Embedded Teaming (SET)

You have a server named Server1 that runs Windows Server 2016. You install the Hyper-V server role on Server1. Server1 has eight network adapters that are dedicated to virtual machines. The network adapters are Remote Direct Memory Access (RDMA)-enabled.You plan to use Software Defined Networking (SDN). You will host the virtual machines for multiple tenants on the Hyper-V host.You need to ensure that the network connections for the virtual machines are resilient if one or more physical network adapters fail.What should you implement? A. single root I/O virtualization (SR-IOV) B. NIC Teaming on the Hyper-V host C. virtual Receive-side Scaling (vRSS) D. Switch Embedded Teaming (SET)

D. Routing

You have a server named Server1 that runs Windows Server 2016.Server1 has two network cards. One network card connects to your internal network and the other network card connects to the Internet.You plan to use Server1 to provide Internet connectivity for client computers on the internal network.You need to configure Server1 as a network address translation (NAT) server.Which server role or role service should you install on Server1 first? A. Web Application Proxy B. DirectAccess and VPN (RAS) C. Network Controller D. Routing

C. From the IPAM node in Server Manager, assign the IPAM DNS Administrator Role to TECH1 and create a new access policy.

You have a server named Server1 that runs Windows Server 2016.Server1 is an IP Address Management (IPAM) server that collects DHCP and DNS logs and events for your entire network.You need to enable a user named TECH1 to create pointer (PTR), host (A) and service location (SRV) records on all of the DNS servers on the network.What should you do on Server1? A. Run the Set-IpamCustomField cmdlet, and then run the Set-IpamAddressSpace cmdlet. B. Run the Set-IpamCustomField cmdlet, and then run the Set-IpamAccessScope cmdlet. C. From the IPAM node in Server Manager, assign the IPAM DNS Administrator Role to TECH1 and create a new access policy. D. Run the Set-IpamRange cmdlet, and then run the Set-IpamAccessScope cmdlet.

C. From the IPAM node in Server Manager, assign the IPAM DNS Administrator Role to TECH1 and create a new access policy.

You have a server named Server1 that runs Windows Server 2016.Server1 is an IP Address Management (IPAM) server that collects DHCP and DNS logs and events for your entire network.You need to enable a user named TECH1 to create pointer (PTR), host (A) and service location (SRV) records on all of the DNS servers on the network.What should you do on Server1? A. Run the Set-IpamRange cmdlet, and then run the Set-IpamAddressSpace cmdlet. B. Run the Set-IpamCustomField cmdlet, and then run the Set-IpamAccessScope cmdlet. C. From the IPAM node in Server Manager, assign the IPAM DNS Administrator Role to TECH1 and create a new access policy. D. From the IPAM node in Server Manager, assign the IPAM DNS Administrator Role to TECH1 and create a new access scope.

E. From Event Viewer, configure DNS-Server Applications and Services Logs.

You have a server named Server1 that runs Windows Server 2016.Server1 is in a workgroup and has the DNS Server role installed.You need to enable DNS analytical diagnostic logging on Server1.What should you do? A. From Local Group Policy Editor, configure Audit Policy. B. From DNS Manager, configure Monitoring. C. From Windows PowerShell, run the Enable-DnsServerPolicy cmdlet. D. From DNS Manager, configure Event Logging. E. From Event Viewer, configure DNS-Server Applications and Services Logs.

C. the Remote Access server role

You have a server named Server1 that runs Windows Server 2016.You need to configure Server1 as a multitenant RAS Gateway.What should you install on Server1? A. the Network Controller server role B. the Data Center Bridging feature C. the Remote Access server role D. the Network Policy and Access Services server role

A. Remote Direct Memory Access (RDMA)

You have a test environment that includes two servers named Server1 and Server2. The servers run Windows Server 2016.You need to ensure that you can implement SMB Direct between the servers.Which feature should the servers support? A. Remote Direct Memory Access (RDMA) B. Multipath I/O (MPIO) C. Virtual Machine queue (VMQ) D. Single root I/O virtualization (SR-IOV)

B. the Routing role service

You have a virtual machine named Server1 that runs Windows Server 2016.You plan to use Server1 as part of a Software Defined Networking (SDN) solution.You need to implement the Border Gateway Protocol (BGP) on Server1.What should you install? A. the Peer Name Resolution Protocol (PNRP) feature B. the Routing role service C. the Network Device Enrollment Service role service D. the Network Policy and Access Services server role

A. Set-NetAdapterRss

You have a virtual machine named VM1 that runs Windows Server 2016. VM1 hosts a service that requires high network throughput.VM1 has a virtual network adapter that connects to a Hyper-V switch named vSwitch1. vSwitch1 has one network adapter. The network adapter supports RemoteDirect Memory Access (RDMA), the single root I/O virtualization (SR-IOV) interface, Quality of Service (QoS), and Receive Side Scaling (RSS).You need to ensure that the traffic from VM1 can be processed by multiple networking processors.Which Windows PowerShell command should you run on the host of VM1? A. Set-NetAdapterRss B. Set-NetAdapterRdma C. Set-NetAdapterQos D. Set-NetAdapterSriov

B. From Routing and Remote Access, configure the authentication provider.

You have an Active Directory domain named Contoso.com. The domain contains servers named Server1 and Server2 that run Windows Server 2016.You install the Remote Access server role on Server1. You install the Network Policy and Access Services server role on Server2.You need to configure Server1 to use Server2 as a RADIUS server.What should you do? A. From the Connection Manager Administration Kit, create a Connection Manager profile. B. From Routing and Remote Access, configure the authentication provider. C. From Active Directory Users and Computers, modify the Delegation settings of the Server1 computer account. D. From Server Manager, create an Access Policy.

B. the Network Controller server role

You have an Active Directory domain that contains several Hyper-V hosts that run Windows Server 2016.You plan to deploy network virtualization and to centrally manage Datacenter Firewall policies.Which component must you install for the planned deployment? A. the Data Center Bridging feature B. the Network Controller server role C. the Routing role service D. the Canary Network Diagnostics feature

B. Netsh DHCP show server

You have an Active Directory forest that contains 30 servers and 6,000 client computers.You deploy a new DHCP server that runs Windows Server 2016.You need to retrieve the list of the authorized DHCP servers.Which command should you run? A. Get-ADResourceProperty ""Filter DHCP B. Netsh DHCP show server C. Netsh DHCP server initiate auth D. Get-DHCPServerSetting E. Netstat ""p IP ""s -a

C. Get-DHCPServerInDc

You have an Active Directory forest that contains 30 servers and 6,000 client computers.You deploy a new DHCP server that runs Windows Server 2016.You need to retrieve the list of the authorized DHCP servers.Which command should you run? A. Get-DCHPServerDatabase B. Netstat-p IP ""s ""a C. Get-DHCPServerInDc D. Show-ADAuthenticationPolicyExpression-AllowedToAuthenticateTo E. Netsh DHCP server initiate auth F. Get-DHCPServerSetting

C. Get-DHCPServerInDc

You have an Active Directory forest that contains 30 servers and 6,000 client computers.You deploy a new DHCP server that runs Windows Server 2016.You need to retrieve the list of the authorized DHCP servers.Which command should you run? A. Get-DCHPServerDatabase B. Netstat-p IP -s -a C. Get-DHCPServerInDc D. Show-ADAuthenticationPolicyExpression-AllowedToAuthenticateTo

C. From Task Scheduler, modify the Microsoft\Windows\IPAM\Audit task.

You have an IP Address Management (IPAM) deployment that is used to manage all of the DNS servers on your network. IPAM is configured to use Group Policy provisioning.You discover that a user adds a new mail exchanger (MX) record to one of the DNS zones.You want to identify which user added the record.You open Event Catalog on an IPAM server, and you discover that the most recent event occurred yesterday.You need to ensure that the operational events in the event catalog are never older than one hour.What should you do? A. From the properties on the DNS zones, modify the refresh interval. B. From an IPAM_DNS Group Policy object (GPO), modify the Group Policy refresh interval. C. From Task Scheduler, modify the Microsoft\Windows\IPAM\Audit task. D. From Task Scheduler, create a scheduled task that runs the Update-IpamServer cmdlet.

C. IPAM IP Audit Administrators

You have an IP Address Management (IPAM) server named IPAM1 that runs Windows Server 2016. IPAM1 manages 10 DHCP servers.You need provide a user with the ability to track which clients receive which IP addresses from DHCP. The solution must minimize administrative privileges. A. IPAM MSM Administrators B. IPAM ASM Administrators C. IPAM IP Audit Administrators D. IPAM User

D. On each DHCP server, review the DHCP Server operational event log.

You have an IP Address Management (IPAM) server named Server1 that runs Windows Server 2016. You have five DHCP servers. Server1 manages all of theDHCP servers.On Server1, an administrator uses Purge Event Catalog Data to remove all of the events from the last 30 days.You need to view all of these lease requests that were denied during the last two days.What should you do? A. On each DHCP server, run the \Microsoft\Windows\Server Manager\CleanUpOldPerfLogs scheduled task, and then review the event catalog on Server1. B. On Server1, run the Purge Event Catalog Data action and then open Event Viewer on Server1. C. Review the log data in C:\Windows\System32\ipam\Database on Server1. D. On each DHCP server, review the DHCP Server operational event log.

B. an RAS Gateway and Windows Server Software Load Balancing (SLB) nodes

You have an application named App1. App1 is distributed to multiple Hyper-V virtual machines in a multitenant environment.You need to ensure that the traffic is distributed evenly among the virtual machines that host App1.What should you include in the environment? A. Network Controller and Windows Server Network Load Balancing (NLB) nodes B. an RAS Gateway and Windows Server Software Load Balancing (SLB) nodes C. an RAS Gateway and Windows Server Network Load Balancing (NLB) nodes D. Network Controller and Windows Server Software Load Balancing (SLB) nodes

A. From the DHCP console, run the Configure Failover wizard.

You have servers named Server1 and DHCP1. Both servers run Windows Server 2016. DHCP1 contains an IPv4 scope named Scope1.You have 1,000 client computers.You need to configure Server1 to lease IP addresses for Scope1. The solution must ensure that Server1 is used to respond to up to 30 percent of the DHCP client requests only.You install the DHCP Server server role on Server1.What should you do next? A. From the DHCP console, run the Configure Failover wizard. B. From Server Manager, install the Network Load Balancing feature. C. From Server Manager, install the Failover Clustering feature. D. From the DHCP console, create a superscope.

A. From Authentication Methods, select Allow machine certificate authentication for IKEv2.

You have servers that run Windows Server 2016 and devices that run Windows 10 Enterprise.You have a certification authority (CA) that issued computer certificates to all the servers and devices.You plan to allow the Windows 10 devices to connect to the network remotely by using VPN device tunnels.You install the Remote Access server role on a server. From the Routing and Remote Access console, you configure the server for the VPN role.You need to ensure that the Windows 10 devices can establish the VPN tunnel before users sign in to the devices.What should you do on the VPN server? A. From Authentication Methods, select Allow machine certificate authentication for IKEv2. B. Modify the ports properties and add additional SSTP ports. C. From Authentication Methods, select Extensible authentication protocol (EAP). D. Modify the ports properties and add additional IKEv2 ports.

A. Sign the contoso.com zone.

You have two DNS servers named Server1 and Server2.All client computers run Windows 10 and are configured to use Server1 for DNS name resolution.Server2 hosts a primary zone named contoso.com.Your network recently experienced several DNS spoofing attacks on the contoso.com zone.You need to prevent further attacks from succeeding.What should you do on Server2? A. Sign the contoso.com zone. B. Configure Response Rate Limiting (RRL). C. Configure DNS-based Authentication of Named Entities (DANE) for the contoso.com zone. D. Configure the contoso.com zone to be Active Directory-integrated.

A. Configure network virtualization for VM1 and VM2.

You have two Hyper-V hosts named Server1 and Server2 that run Windows Server 2016. Server1 and Server2 are connected to the same network.On Server1 and Server2, you create an external network switch named Switch1.You have the virtual machine shown in the following table.All three virtual machines are connected to Switch1.You need to prevent applications in VM3 from being able to capture network traffic from VM1 or VM2. The solution must ensure that VM1 retains network connectivity.What should you do? A. Configure network virtualization for VM1 and VM2. B. Modify the subnet mask of VM1 and VM2. C. On Server2, configure the VLAN ID setting of Switch1. D. On Server2, create an external switch and connect VM3 to the switch.

C. On Server1 and Server2, configure DHCP failover for Scope1 and Scope2.

You have two servers named Server1 and Server2 that run Windows Server 2016. Both servers have the DHCP Server server role installed.Server1 has a DHCP scope named Scope1. Server2 has a DHCP scope named Scope2.You need to ensure that client computers can get an IP address if a single DHCP server fails. You must be able to control the percentage of requests to which each DHCP server responds during normal network operations.What should you do? A. Add Server1 and Server2 as nodes in a failover cluster, and then configure the DHCP Server server role. B. Add Server1 and Server2 as nodes in a failover cluster, and then configure the quorum mode. C. On Server1 and Server2, configure DHCP failover for Scope1 and Scope2. D. Add Server1 and Server2 as nodes in a failover cluster, and then configure port rules for UDP 67 and UDP 68.

B. Set-DfsrMembership

You have two servers named Server1 and Server2.Server1 contains a folder named D:\Videos that contains large video files.You configure a replication of D:\Videos to Server2 by using Distributed File System (DFS) Replication.You need to increase the size of the staging area for the replicated folder.Which cmdlet should you run? A. Set-DfsrConnection B. Set-DfsrMembership C. Set-DfsrReplicatedFolder D. Set-DfsrServiceConfiguration

A. a network security group (NSG)

You implement Software Defined Networking (SDN) by using the Network Controller server role.You have a virtual network named VNET1 that contains servers used by developers.You need to ensure that only devices from the 192.168.0.0/24 subnet can access the virtual machine in VNET1.What should you configure? A. a network security group (NSG) B. role-based access control C. a universal security group D. Dynamic Access Control

D. 10 days

You network contains an Active Directory domain. The domain contains two DNS servers named Server1 and Server2.Server1 has a DNS zone named contoso.com that has the following configurations:✑ Dynamic updates: Secure only✑ Scavenge stale resource records: Enabled✑ Scavenging period: 1 day✑ No-refresh interval: 3 days✑ Refresh interval: 7 daysAfter how many days will a dynamic record become stale if the timestamp is NOT updated? A. 1 day B. 3 days C. 7 days D. 10 days E. 11 days

C. iDNS

You plan to deploy a Software Defined Networking (SDN) infrastructure.Which service provides name resolution for the virtual machines on a tenant network? A. a smart host B. Network Controller C. iDNS D. iSNS

A. Network Controller

You plan to deploy several Hyper-V hosts that run Windows Server 2016. The deployment will use Software defined Networking (SDN) and VXLAN.Which server role should you install on the network to support the planned deployment? A. Network Controller B. Network Policy and Access Services C. Remote Access D. Host Guardian Service

A. the Data Center Bridging feature

Your company has 10 offices. Each office has a local network that contains several Hyper-V hosts that run Windows Server 2016. All of the offices are connected by high speed, low latency WAN links.You need to ensure that you can use QoS policies for Live Migration traffic between the offices.Which component should you install? A. the Data Center Bridging feature B. the Routing role service C. the Network Controller server role D. the Multipath I/O feature E. the Canary Network Diagnostics feature

D. Deploy a RADIUS proxy to a new server. Configure all of the RADIUS clients to connect to the RADIUS proxy.

Your company has 5,000 users who work remotely.You have 40 VPN servers that host the remote connections for the users.You plan to deploy a RADIUS solution that contains five RADIUS servers.You need to ensure that client authentication requests are distributed evenly between the five RADIUS servers.What should you do? A. Install the Network Load Balancing role service on all of the RADIUS server. Configure all of the RADIUS clients to connect to a virtual IP address. B. Deploy RAS Gateway to a new server. Configure all of the RADIUS clients to connect to RAS Gateway. C. Install the Failover Clustering role service on all of the RADIUS servers. Configure all of the RADIUS clients to connect to the IP address of the cluster. D. Deploy a RADIUS proxy to a new server. Configure all of the RADIUS clients to connect to the RADIUS proxy.

B. Modify the properties of the replication group.

Your company has a main office in London and a branch office in Seattle. The offices connect to each other by using a WAN link.In the London office, you have a Distributed File System (DFS) server named FS1 that contains a folder named Folder1.In the Seattle office, you have a DFS server named FS2.All servers run Windows Server 2016.You configure replication of Folder1 to FS2.Users in both offices frequently add files in Folder1.You monitor DFS Replication, and you discover excessive replication over the WAN link during business hours.You need to reduce the amount of bandwidth used for replication during business hours. The solution must ensure that the users can continue to save content toFolder1.What should you do? A. Modify the quota settings on Folder1 on FS2. B. Modify the properties of the replication group. C. Configure the copy of Folder1 on FS2 as read-only. D. Modify the replicated folder properties of Folder1 on FS1.

D. From Windows PowerShell, run the Add-BgpRouter cmdlet and specify the -LocalASN parameter

Your company has three offices. The offices are located in Seattle, Chicago, and Montreal.You are configuring a new WAN link between the three offices by using the Remote Access server role in Windows Server 2016. You will use Border GatewayProtocol (DGP) as a routing protocol between the sites.You need to configure the server in the Seattle office for BGP routing.What should you do first? A. From Routing and Remote Access, add a new IPv4 routing protocol B. From Windows PowerShell, run the Add-BgpPeer cmdlet and specify the -LocalASN parameter C. From Routing and Remote Access, add a new IPv6 routing protocol D. From Windows PowerShell, run the Add-BgpRouter cmdlet and specify the -LocalASN parameter

D. From Windows PowerShell, run the Add-BgpRouter cmdlet and specify the ""LocalASN parameter

Your company has three offices. The offices are located in Seattle, Chicago, and Montreal.You are configuring a new WAN link between the three offices by using the Remote Access server role in Windows Server 2016. You will use Border GatewayProtocol (DGP) as a routing protocol between the sites.You need to configure the server in the Seattle office for BGP routing.What should you do first? A. From Routing and Remote Access, add a new IPv4 routing protocol B. From Windows PowerShell, run the Add-BgpPeer cmdlet and specify the ""LocalASN parameter C. From Routing and Remote Access, add a new IPv6 routing protocol D. From Windows PowerShell, run the Add-BgpRouter cmdlet and specify the ""LocalASN parameter

D. Modify the size of staging area of Folder1. Reveal Solution

Your company has two main offices. The offices are located in London and Seattle. All servers run Windows Server 2016.In the Seattle office, you have a Distributed File System (DFS) server named FS1. FS1 has a folder named Folder1 that contains large Windows image files.In the London office, you deploy a DFS server named FS2, and you then replicate Folder1 to FS2.After several days, you discover that the replication of certain files failed to complete.You need to ensure that all of the files in Folder1 can replicate to FS2.What should you do? A. Modify the disk quota of the drive that contains Folder1. B. From a command prompt, run dfsutil /purgemupcache. C. Create a quota for Folder1 by using File Server Resource Manager (FSRM). D. Modify the size of staging area of Folder1.

C. 131.107.20.0/29

Your company owns the public Internet IP address range of 131.107.20.0 to 131.107.20.255.You need to create a subnet that supports four hosts. The solution must minimize the number of addresses available to the subnet.Which subnet should you use? A. 131.107.20.16/28 B. 131.107.20.16/30 C. 131.107.20.0/29 D. 131.107.20.0 with subnet mask 255.255.255.224

C. Audit authentication events from DC1.

Your network contains an Active Directory domain named contoso.com that contains a domain controller named DC1. All DNS servers for the network run BIND10.Your perimeter network contains a DHCP server named DHCP1 that runs Windows Server 2016. DHCP1 is a member of a workgroup named WORKGROUP.DHCP1 provides IP address leases to guests accessing the Wi-Fi network.Several engineers access the network remotely by using a VPN connection to a remote access server that runs Windows Server 2016. All of the VPN connections use certificate-based authentication and are subject to access policies in Network Policy Server (NPS). Certificates are issued by an enterprise certification authority (CA) named CA1.All Windows computers on the network are activated by using Key Management Service (KMS). On-premises users use Remote Desktop Services (RDS).You plan to deploy IP Address Management (IPAM) to the network.Which action can you perform on the network by using IPAM? A. Manage the DNS zones on the DNS servers. B. Audit logon events on the RDS server. C. Audit authentication events from DC1. D. Manage activations on the KMS serve

D. Create a DHCP policy that has a condition based on the fully qualified domain name (FQDN) criterion. Configure the DNS properties of the policy.

Your network contains an Active Directory domain named contoso.com. The domain contains a DHCP server named Server1 that runs Windows Server 2016.You have a DHCP scope for the 10.0.0.0/24 IP subnet. One hundred and fifty clients reside in the subnet. Fifty of the DHCP clients are NOT domain-joined.You need to ensure that DHCP clients without a configured DNS suffix register automatically in a DNS zone named workgroup.contoso.com. The other DHCP clients must register in the DNS zone of their respective domain.What should you do? A. Configure the 015 DNS Domain Name scope option in the 10.0.0.0/24 DHCP scope. B. Configure the DNS properties of the 10.0.0.0/24 DHCP scope. C. Create a DHCP policy that has a condition based on the fully qualified domain name (FQDN) criterion. Configure the IP address range properties of the policy. D. Create a DHCP policy that has a condition based on the fully qualified domain name (FQDN) criterion. Configure the DNS properties of the policy.

Yes

Your network contains an Active Directory domain named contoso.com. The domain contains a DHCP server named Server1. All client computers run Windows10 and are configured as DHCP clients.Your helpdesk received calls today from users who failed to access the network from their Windows 10 computer.You open the DHCP console as shown in the exhibit. (Click the Exhibit button.)You need to ensure that all of the Windows 10 computers can receive a DHCP lease.Solution: You activate the scope.Does this meet the goal? A. Yes B. No

No

Your network contains an Active Directory domain named contoso.com. The domain contains a DHCP server named Server1. All client computers run Windows10 and are configured as DHCP clients.Your helpdesk received calls today from users who failed to access the network from their Windows 10 computer.You open the DHCP console as shown in the exhibit. (Click the Exhibit button.)You need to ensure that all of the Windows 10 computers can receive a DHCP lease.Solution: You increase the scope size.Does this meet the goal? A. Yes B. No

No

Your network contains an Active Directory domain named contoso.com. The domain contains a DHCP server named Server1. All client computers run Windows10 and are configured as DHCP clients.Your helpdesk received calls today from users who failed to access the network from their Windows 10 computer.You open the DHCP console as shown in the exhibit. (Click the Exhibit button.)You need to ensure that all of the Windows 10 computers can receive a DHCP lease.Solution: You start the DHCP Server service.Does this meet the goal? A. Yes B. No

B. No

Your network contains an Active Directory domain named contoso.com. The domain contains a DHCP server named Server2 than runs Windows Server 2016.Users report that their client computers fail to obtain an IP address.You open the DHCP console as shown in the Exhibit. (Click the Exhibit button.)Scope1 has an address range of 172.16.0.10 to 172.16.0.100 and a prefix length of 23 bits.You need to ensure that all of the client computers on the network can obtain an IP address from Server2.Solution: You run the Set-DhcpServerv4MulticastScope cmdlet.Does this meet the goal? A. Yes B. No

Yes

Your network contains an Active Directory domain named contoso.com. The domain contains a DHCP server named Server2 than runs Windows Server 2016.Users report that their client computers fail to obtain an IP address.You open the DHCP console as shown in the Exhibit. (Click the Exhibit button.)Scope1 has an address range of 172.16.0.10 to 172.16.0.100 and a prefix length of 23 bits.You need to ensure that all of the client computers on the network can obtain an IP address from Server2.Solution: You run the Set-DhcpServerv4Scope cmdlet.Does this meet the goal? A. Yes B. No

D. Run the Install-NetworkController cmdlet and set ClientAuthentication to Kerberos.

Your network contains an Active Directory domain named contoso.com. The domain contains a Hyper-V host.You are deploying Software Defined Network (SDN) by using Windows Server 2016.You deploy a virtual machine that runs Windows Server 2016, and you install the Network Controller server role.You need to configure the virtual machine as the network controller.What should you do? A. Run the Install-NetworkControllerCluster cmdlet and set ClientAuthentication to X509. B. Run the Install-NetworkController cmdlet and set ClientAuthentication to None. C. Run the Install-NetworkControllerCluster cmdlet and set ClientAuthentication to None. D. Run the Install-NetworkController cmdlet and set ClientAuthentication to Kerberos.

B. Disable access-based enumeration for Namespace1.

Your network contains an Active Directory domain named contoso.com. The domain contains a domain-based Distributed File System (DFS) namespace namedNamespace1 that has access-based enumeration enabled. Namespace1 has a folder named folder1. Folder1 has a target of \\Server1\Folder1.The Permission for folder1 are configured as shown in the following table.Access-based enumeration is disabled for the share of Folder1.You need to ensure that both User1 and User2 can see Folder1 when they access \\Contoso.com\NameSpace1.What should you do? A. Enable access-based enumeration for Folder1. B. Disable access-based enumeration for Namespace1. C. Assign User1 the read NTFS permission to Folder1 D. Deny User1 the read DFS permission to Folder1.

Yes

Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server1 that runs Windows Server 2016 and has the DNS Server role installed. Automatic scavenging of stale records is enabled and the scavenging period is set to 10 days.All client computers dynamically register their names in the contoso.com DNS zone on Server1.You discover that the names of multiple client computers that were removed from the network several weeks ago can still be resolved.You need to configure Server1 to automatically remove the records of the client computers that have been offline for more than 10 days.Solution: You modify the Zone Aging/Scavenging properties of the zone.Does this meet the goal? A. Yes B. No

No

Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server1 that runs Windows Server 2016 and has the DNS Server role installed. Automatic scavenging of stale records is enabled and the scavenging period is set to 10 days.All client computers dynamically register their names in the contoso.com DNS zone on Server1.You discover that the names of multiple client computers that were removed from the network several weeks ago can still be resolved.You need to configure Server1 to automatically remove the records of the client computers that have been offline for more than 10 days.Solution: You run the dnscmd.exe command and specify the /AgeAllRecords parameter for the zone.Does this meet the goal? A. Yes B. No

No

Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server1 that runs Windows Server 2016 and has the DNS Server role installed. Automatic scavenging of stale records is enabled and the scavenging period is set to 10 days.All client computers dynamically register their names in the contoso.com DNS zone on Server1.You discover that the names of multiple client computers that were removed from the network several weeks ago can still be resolved.You need to configure Server1 to automatically remove the records of the client computers that have been offline for more than 10 days.Solution: You set the Time to live (TTL) value of all of the records in the zone.Does this meet the goal? A. Yes B. No

No

Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server1 that runs Windows Server 2016 and has the DNS Server server role installed. Automatic scavenging of stale records is enabled and the scavenging period is set to 10 days.All client computers dynamically register their names in the contoso.com DNS zone on Server1.You discover that the names of multiple client computers that were removed from the network several weeks ago can still be resolved.You need to configure Server1 to automatically remove the records of the client computers that have been offline for more than 10 days.Solution: You set the Expires after value of the zone.Does this meet the goal? A. Yes B. No

B. Run the Set-IpamConfiguration cmdlet.

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2016.Server1 has IP Address Management (IPAM) installed. IPAM is configured to use the Group Policy based provisioning method. The prefix for the IPAM GroupPolicy objects (GPOs) is IP.From Group Policy Management, you manually rename the IPAM GPOs to have a prefix of IPAM.You need to modify the GPO prefix used by IPAM.What should you do? A. Click Configure server discovery in Server Manager. B. Run the Set-IpamConfiguration cmdlet. C. Click Provision the IPAM server in Server Manager. D. Run the Invoke-IpamGpoProvisioning cmdlet.

D. Two DNS zone scopes, two DNS query resolution policies, and the DNS records

Your network contains an Active Directory domain. The domain contains two domain controllers named DC1 and DC2. DC1 and DC2 host an Active Directory- integrated DNS zone named contoso.com.You have two DNS Client Subnets named Subnet1 and Subnet2.You plan to create two DNS records for www.contoso.com. One record will point to 10.1.2.3, and the other record will point to 172.23.6.5.You need to ensure that www.contoso.com resolves to:✑ 10.1.2.3 from Subnet1✑ 172.23.6.5 from Subnet2What should you create? A. One DNS recursion policy, two DNS zone delegations, and the DNS records B. One DNS zone scope, two DNS query resolution policies, and the DNS records C. One DNS query resolution policy, two DNS zone delegations, and the DNS records D. Two DNS zone scopes, two DNS query resolution policies, and the DNS records

Yes

Your network contains an Active Directory forest named contoso.com. The forest has three sites located in London, Paris, and Berlin.The London site contains a web server named Web1 that runs Windows Server 2016.You need to configure Web1 as an HTTP content server for the hosted cache servers located in the Paris and Berlin sites.Solution: You install the BranchCache feature, and then you start the BranchCache service.Does this meet the goal? A. Yes B. No

B. No

Your network contains an Active Directory forest named contoso.com. The forest has three sites located in London, Paris, and Berlin.The London site contains a web server named Web1 that runs Windows Server 2016.You need to configure Web1 as an HTTP content server for the hosted cache servers located in the Paris and Berlin sites.Solution: You install the DFS Replication role service, and then you start the Network Connections service.Does this meet the goal? A. Yes B. No

No

Your network contains an Active Directory forest named contoso.com. The forest has three sites located in London, Paris, and Berlin.The London site contains a web server named Web1 that runs Windows Server 2016.You need to configure Web1 as an HTTP content server for the hosted cache servers located in the Paris and Berlin sites.Solution: You install the Deployment Server role service, and then you restart the World Wide Web Publishing Service.Does this meet the goal? A. Yes B. No

No

Your network contains an Active Directory forest named contoso.com. The forest has three sites located in London, Paris, and Berlin.The London site contains a web server named Web1 that runs Windows Server 2016.You need to configure Web1 as an HTTP content server for the hosted cache servers located in the Paris and Berlin sites.Solution: You install the Static Content role service, and then you restart the IIS Admin Service.Does this meet the goal? A. Yes B. No

B. On Server1, deploy the Network Policy and Access Services role.

Your network contains an Active Directory forest named contoso.com. The functional level of the forest is Windows Server 2012.The forest contains five domain controllers and five VPN servers that run Windows Server 2016.Five hundred users connect to the VPN servers daily.You need to configure a new server named Server1 as a RADIUS server.What should you do first? A. On Server1, deploy the Remote Access server role. B. On Server1, deploy the Network Policy and Access Services role. C. On a domain controller, set the forest functional level to Windows Server 2016. D. On each VPN server, run the New-NpsRadiusClient cmdlet.

D. Create a delegation for research.contoso.com

Your network contains an Active Directory forest named contoso.com.The forest contains five domains. You manage DNS for the contoso.com domain only.You are not responsible for managing DNS for the child domains.The DNS servers in a child domain named research.contoso.com are reconfigured often.You need to ensure that clients in contoso.com can resolve addresses in research.contoso.com. The solution must minimize zone replication traffic.What should you do? A. Create a primary zone for research.contoso.com on the DNS servers of contoso.com B. Create a secondary zone for research.contoso.com on the DNS servers of contoso.com C. Create a stub zone for research.contoso.com on the DNS servers of contoso.com D. Create a delegation for research.contoso.com

A. New-DfsnFolderTarget E. New-SmbShare

Your network contains an Active directory forest named contoso.com. The forest has a Distributed File System (DFS) namespace named \\contoso.com\namespace1.The domain contains a file server named Server1 that runs Windows Server 2016.You create a folder named Folder1 on Server1. You need to use Folder1 as a target for Namespace1. Which two cmdlets should you use? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point. A. New-DfsnFolderTarget B. Install-WindowsFeature C. Grant-DfsnAccess D. New-DfsnFolder E. New-SmbShare

A. Add RADIUS clients and configure network policies.

Your network contains multiple wireless access points (WAPs) that use WPA2-Personal authentication. The network contains an enterprise root certification authority (CA).The security administrator at your company plans to implement WPA2-Enterprise authentication on the WAPs.To support the authentication change, you deploy a server that has Network Policy Server (NPS) installed.You need to configure NPS to authenticate the wireless clients.What should you do on the NPS server? A. Add RADIUS clients and configure network policies. B. Create a remote RADIUS server group and configure connection request policies. C. Create a remote RADIUS server group and install a server certificate. D. Add RADIUS clients and configure connection request policies

B. New-NetRoute

Your network contains three subnets, a production subnet that contains production servers, a development network that contains development servers, and a client network that contains client computers.The development network is used to test applications and reproduces servers that are located on the production network. The development network and the production network use the same IP address range.A developer has a client computer on the client network. The developer reports that when he attempts to connect to the IP address 10.10.1.6 from his computer, he connects to a server on the production network.You need to ensure that when the developer connects to 10.10.1.6, he connects to a sever on the development network.Which cmdlet should you use? A. New-NetNeighbor B. New-NetRoute C. Set-NetTcpSetting D. Set-NetNeighbor


Related study sets

Accounting 2301 -WCJC - Summer 2017

View Set

Chapter 6 Learning OPEN STAX COLLEGE

View Set

Ch. 21: Ideologies and Upheavals

View Set

AP Environmental Science Unit 4: Earth Systems and Resources

View Set