NO.1 Your network contains an Active Directory domain named contoso.com. The domain contains
an organizational unit (OU) named IT and an OU named Sales.
All of the help desk user accounts are located in the IT OU. All of the sales user accounts are located
in the Sales OU. The Sales OU contains a global security group named G_Sales. The IT OU contains a
global security group named G_HelpDesk.
You need to ensure that members of G_HelpDesk can perform the following tasks:
- Reset the passwords of the sales users.
- Force the sales users to change their password at their next logon.
What should you do?
A. Right-click the Sales OU and select Delegate Control.
B. Right-click the IT OU and select Delegate Control.
C. Run the Set-ADFineGrainedPasswordPolicycmdlet and specify the -identity parameter.
D. Run the Set-ADAccountPasswordcmdlet and specify the -identity parameter.
G_HelpDesk members need to be allowed to delegate control on the Sales OU as it contains the sales
You can use the Delegation of Control Wizard to delegate the Reset Password permission to the
References: http: //support. microsoft. com/kb/296999/en-us http: //support. microsoft.
com/kb/296999/en-us http: //technet. microsoft. com/en-us/library/cc732524. aspx
NO.2 Your network contains an Active Directory domain named contoso.com. All domain controllers
run Windows Server 2012 R2. One of the domain controllers is named DC1.
The DNS zone for the contoso.com zone is Active Directory-integrated and has the default settings.
A server named Server1 is a DNS server that runs a UNIX-based operating system.
You plan to use Server1 as a secondary DNS server for the contoso.com zone.
You need to ensure that Server1 can host a secondary copy of the contoso.com zone.
What should you do?
A. From DNS Manager, modify the Zone Transfers settings of the contoso.com zone.
B. From DNS Manager, modify the Security settings of DC1.
C. From DNS Manager, modify the Advanced settings of DC1.
D. From Windows PowerShell, run the Set-DnsServerForwardercmdlet and specify the contoso.com
zone as a target.
70-411 受験 70-411 問題例
There are two ways that a secondary DNS server can be added. In both scenarios you will need to add
the new server to the Forwarders list of the primary Domain Controller.
1.The Set-DnsServerForwarder cmdlet changes forwarder settings on a Domain Name System (DNS)
2.From the primary server, open DNS Manager, right click on the server name and select Properties.
Click on the Forwarders tab and click the Edit button in the middle of the dialogue box.
NO.3 Your network contains an Active Directory domain named contoso.com. All domain controllers
run Windows Server 2012 R2. You plan to use fine-grained password policies to customize the
password policy settings ofcontoso.com.
You need to identify to which Active Directory object types you can directly apply the fine-grained
Which two object types should you identify? (Each correct answer presents part of the solution.
A. Global groups
D. Universal groups
E. Domain local groups
First off, your domain functional level must be at Windows Server 2008. Second, Fine-grained
password policies ONLY apply to user objects, and global security groups. Linking them to universal or
domain local groups is ineffective. I know what you're thinking, what about OU's? Nope, Fine-grained
password policy cannot be applied to an organizational unit (OU) directly. The third thing to keep in
mind is, by default only members of the Domain Admins group can set fine-grained password
policies. However, you can delegate this ability to other users if needed.
Fine-grained password policies apply only to user objects (or inetOrgPerson objects if they are used
instead of user objects) and global security groups.
You can apply Password Settings objects (PSOs) to users or global security groups: References: http:
//technet. microsoft. com/en-us/library/cc731589%28v=ws. 10%29. aspx http: //technet. microsoft.
com/en-us/library/cc731589%28v=ws. 10%29. aspx http: //technet. microsoft. com/en-
us/library/cc770848%28v=ws. 10%29. aspx http: //www. brandonlawson. com/active-
NO.4 Your network contains an Active Directory domain named contoso.com. The domain contains
six domain controllers. The domain controllers are configured as shown in the following table.
The network contains a server named Server1 that has the Hyper-v server role installed. DC6 is a
virtual machine that is hosted on Server1.
You need to ensure that you can clone DC6.
Which FSMO role should you transfer to DC2?
A. PDC emulator
B. Rid master
C. Domain naming master
D. Infrastructure master
70-411 評判 70-411 返金
The clone domain controller uses the security context of the source domain controller (the domain
controller whose copy it represents) to contact the Windows Server 2012 R2 Primary Domain
Controller (PDC) emulator operations master role holder (also known as flexible single master
operations, or FSMO). The PDC emulator must be running Windows Server 2012 R2, but it does not
have to be running on a hypervisor.
http: //technet. microsoft. com/en-us/library/hh831734. aspx
IT業界の中でたくさんの野心的な専門家がいって、IT業界の中でより一層頂上まで一歩更に近く立ちたくてMicrosoftの70-411 認定資格試験問題集に参加して認可を得たくて、Microsoft の70-411 認定資格試験問題集が難度の高いので合格率も比較的低いです。Microsoftの70-411 認定資格試験問題集を申し込むのは賢明な選択で今のは競争の激しいIT業界では、絶えず自分を高めるべきです。しかし多くの選択肢があるので君はきっと悩んでいましょう。
JapanCertは最新のHPE0-S37問題集と高品質のC_THR83_1702問題と回答を提供します。JapanCertのHPE0-S46 VCEテストエンジンとMB2-715試験ガイドはあなたが一回で試験に合格するのを助けることができます。高品質の1Z0-327 PDFトレーニング教材は、あなたがより迅速かつ簡単に試験に合格することを100％保証します。試験に合格して認証資格を取るのはそのような簡単なことです。