new version dumps of exam 70-411 with free update (part b)

16
Administering Windows Server 2012 R2 Exam (Version: 13.39) Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html 1 QUESTION 21 Your network contains a single Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that hosts the primary DNS zone for contoso.com All servers dynamically register their host names. You install the new Web servers that host identical copies of your company's intranet website. The servers are configured as shown in the following table. You need to use DNS records to load balance name resolution queries for intranet.contoso.com between the two Web servers. What is the minimum number of DNS records that you should create manually? A. 1 B. 2 C. 3 D. 4 Answer: B Explanation: An A records for each IP is needed intranet.contoso.com > 10.0.0.20 intranet.contoso.com > 10.0.0.21 intranet.contoso.com > 10.0.0.22 http://technet.microsoft.com/en-us/library/cc772506.aspx http://technet.microsoft.com/en-us/library/gg398251.aspx QUESTION 22 You have a Direct Access Server named Server1 running Server 2012 R2. You need to add prevent users from accessing websites from an Internet connection What should you configure? A. Split Tunneling B. Security Groups C. Force Tunneling D. Network Settings Answer: C Explanation: To make Internet resources available to DirectAccess clients that use force tunneling, you can use a proxy server, which can receive IPv6-based requests for Internet resources and translate them to requests for IPv4-based Internet resources. http://technet.microsoft.com/en-us/library/jj134204.aspx#BKMK_forcetunnel http://blogs.technet.com/b/tomshinder/archive/2010/03/30/more-on-directaccess-split-tunneling- and-force- tunneling.aspx QUESTION 23 You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the Remote Access server role installed. You need to configure the ports on Server1 to ensure that client computers can establish VPN connections to Server1. The solution must NOT require the use of certificates or pre- shared keys.

Upload: ubliing

Post on 01-Apr-2016

220 views

Category:

Documents


0 download

DESCRIPTION

PassLeader Just Published The New Version Dumps Of Exam 70-411(Administering Windows Server 2012 R2 Exam (Version: 13.39)) With Free Update.-- http://www.passleader.com/70-411.html

TRANSCRIPT

Page 1: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

1

QUESTION 21 Your network contains a single Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that hosts the primary DNS zone for contoso.com All servers dynamically register their host names. You install the new Web servers that host identical copies of your company's intranet website. The servers are configured as shown in the following table.

You need to use DNS records to load balance name resolution queries for intranet.contoso.com between the two Web servers. What is the minimum number of DNS records that you should create manually?

A. 1

B. 2

C. 3

D. 4

Answer: B Explanation: An A records for each IP is needed intranet.contoso.com > 10.0.0.20 intranet.contoso.com > 10.0.0.21 intranet.contoso.com > 10.0.0.22 http://technet.microsoft.com/en-us/library/cc772506.aspx http://technet.microsoft.com/en-us/library/gg398251.aspx QUESTION 22 You have a Direct Access Server named Server1 running Server 2012 R2. You need to add prevent users from accessing websites from an Internet connection What should you configure?

A. Split Tunneling

B. Security Groups

C. Force Tunneling

D. Network Settings

Answer: C Explanation: To make Internet resources available to DirectAccess clients that use force tunneling, you can use a proxy server, which can receive IPv6-based requests for Internet resources and translate them to requests for IPv4-based Internet resources. http://technet.microsoft.com/en-us/library/jj134204.aspx#BKMK_forcetunnel http://blogs.technet.com/b/tomshinder/archive/2010/03/30/more-on-directaccess-split-tunneling-and-force- tunneling.aspx QUESTION 23 You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the Remote Access server role installed. You need to configure the ports on Server1 to ensure that client computers can establish VPN connections to Server1. The solution must NOT require the use of certificates or pre- shared keys.

Page 2: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

2

What should you modify? To answer, select the appropriate object in the answer area.

Answer:

Explanation:

Page 3: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

3

PPTP http://support.microsoft.com/kb/243374 QUESTION 24 Your network contains an Active Directory domain named contoso.com. The functional level of the forest is Windows Server 2008 R2. Computer accounts for the marketing department are in an organizational unit (OU) named Departments \Marketing\Computers. User accounts for the marketing department are in an OU named Departments\Marketing\Users. All of the marketing user accounts are members of a global security group named MarketingUsers. All of the marketing computer accounts are members of a global security group named MarketingComputers. In the domain, you have Group Policy objects (GPOs) as shown in the exhibit. (Click the Exhibit button.)

You create two Password Settings objects named PSO1 and PSO2. PSO1 is applied to MarketingUsers. PSO2 is applied to MarketingComputers.

Page 4: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

4

You need to identify the minimum password length required for each marketing user. What should you identify?

A. 5

B. 6

C. 7

D. 10

E. 12

Answer: D Explanation: PSO1 is applied to the users so min length is 10 QUESTION 25 Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012 R2. You have a Group Policy object (GPO) named GPO1 that contains several custom Administrative templates. You need to filter the GPO to display only settings that will be removed from the registry when the GPO falls out of scope. The solution must only display settings that are either enabled or disabled and that have a comment. How should you configure the filter? To answer, select the appropriate options below. Select three.

Page 5: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

5

A. Set Managed to: Yes

B. Set Managed to: No

C. Set Managed to: Any

D. Set Configured to: Yes

E. Set Configured to: No

F. Set Configured to: Any

G. Set Commented to: Yes

H. Set Commented to: No

I. Set Commented to: Any

Answer: AFG Explanation: A: Set Managed to: Yes There are two kinds of Administrative Template policy settings: Managed and Unmanaged. The Group Policy Client service governs Managed policy settings and removes a policy setting when

Page 6: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

6

it is no longer within scope of the user or computer. F: Set Configured to: Any We want to display both settings that are enable and disabled. G: Set Commented to: Yes Only settings that are commented should be displayed. Note: Filter with Property Filters The Local Group Policy Editor allows you to change the criteria for displaying Administrative Template policy settings. By default, the editor displays all policy settings, including unmanaged policy settings. However, you can use property filters to change how the Local Group Policy Editor displays Administrative Template policy settings. There are three inclusive property filters that you can use to filter Administrative Templates. These property filters include: Managed Configured Commented QUESTION 26 Your network contains an Active Directory domain named contoso.com. You have several Windows PowerShell scripts that execute when users log on to their client computer. You need to ensure that all of the scripts execute completely before the users can access their desktop. Which setting should you configure? To answer, select the appropriate setting in the answer area.

Answer:

Page 7: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

7

Explanation: http://technet.microsoft.com/en-us/library/cc958585.aspx QUESTION 27 Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named dcl.contoso.com. You discover that the Default Domain Policy Group Policy objects (GPOs) and the Default Domain Controllers Policy GPOs were deleted. You need to recover the Default Domain Policy and the Default Domain Controllers Policy GPOs. What should you run?

A. dcgpofix.exe /target:domain

B. gpfixup.exe /dc:dc1.contoso.co,n

C. dcgpofix.exe /target:both

D. gptixup.exe /oldnb:contoso /newnb:dc1

Answer: C Explanation: http://technet.microsoft.com/en-us/library/hh875588(v=ws.10).aspx QUESTION 28 Your network contains an Active Directory domain named contoso.com. Domain controllers run either Windows Server 2008, Windows Server 2008 R2, or Windows Server 2012 R2. You have a Password Settings object (PSOs) named PSO1. You need to view the settings of PSO1. Which tool should you use?

A. Group Policy Management

B. Server Manager

C. Get-ADAccountResultantPasswordReplicationPolicy

D. Active Directory Administrative Center

Answer: D Explanation: http://technet.microsoft.com/en-us/library/cc770848(v=ws.10).aspx Incorrect:

Page 8: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

8

* Get-ADFineGrainedPasswordPolicy Gets one or more Active Directory fine grained password policies. * To store fine-grained password policies, Windows Server 2008 includes two new object classes in the Active Directory Domain Services (AD DS) schema: Password Settings Container Password Settings The Password Settings Container (PSC) object class is created by default under the System container in the domain. It stores the Password Settings objects (PSOs) for that domain. QUESTION 29 Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. You need to prevent all of the GPOs at the site level and at the domain level from being applied to users and computers in an organizational unit (OU) named OU1. You want to achieve this goal by using the minimum amount of Administrative effort. What should you use?

A. dcgpofix

B. Get-GPOReport

C. Gpfixup

D. Gpresult

E. Gptedit.msc

F. Import-GPO

G. Import-GPO

H. Restore-GPO

I. Set-GPInheritance

J. Set-GPLink

K. Set-GPPermission

L. Gpupdate

M. Add-ADGroupMember

Answer: I Explanation: http://technet.microsoft.com/en-us/library/ee461032.aspx http://technet.microsoft.com/en-us/library/cc757050.aspx QUESTION 30 Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. You have two GPOs linked to an organizational unit (OU) named OU1. You need to change the precedence order of the GPOs. What should you use?

A. dcgpofix

B. Get-GPOReport

C. Gpfixup

D. Gpresult

E. Gptedit.msc

F. Import-GPO

G. Restore-GPO

H. Set-GPInheritance

I. Set-GPLink

J. Set-GPPermission

Page 9: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

9

K. Gpupdate

L. Add-ADGroupMember

Answer: I Explanation: The Set-GPLink cmdlet sets the properties of a GPO link. You can set the following properties: -- Enabled. If the GPO link is enabled, the settings of the GPO are applied when Group Policy is processed for the site, domain or OU. -- Enforced. If the GPO link is enforced, it cannot be blocked at a lower-level (in the Group Policy processing hierarchy) container. -- Order. The order specifies the precedence that the settings of the GPO take over conflicting settings in other GPOs that are linked (and enabled) to the same site, domain, or OU. http://technet.microsoft.com/en-us/library/ee461022.aspx QUESTION 31 Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. You need to provide an Administrator named Admin1 with the ability to create GPOs in the domain. The solution must not provide Admin1 with the ability to link GPOs. What should you use?

A. dcgpofix

B. Get-GPOReport

C. Gpfixup

D. Gpresult

E. Gptedit.msc

F. Import-GPO

G. Restore-GPO

H. Set-GPInheritance

I. Set-GPLink

J. Set-GPPermission

K. Gpupdate

L. Add-ADGroupMember

Answer: J Explanation: http://technet.microsoft.com/en-us/library/ee461038.aspx QUESTION 32 Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. The domain contains a GPO named GPO1. GPO1 contains several Group Policy preferences. You need to view all of the preferences configured in GPO1. What should you use?

A. dcgpofix

B. Get-GPOReport

C. Gpfixup

D. Gpresult

E. Gptedit.msc

F. Import-GPO

G. Restore-GPO

Page 10: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

10

H. Set-GPInheritance

I. Set-GPLink

J. Set-GPPermission

K. Gpupdate

L. Add-ADGroupMember

Answer: B Explanation: B. The Get-GPOReport cmdlet generates a report in either XML or HTML format that describes properties and policy settings for a specified GPO or for all GPOs in a domain. The information that is reported for each GPO includes: details, links, security filtering, WMI filtering, delegation, and computer and user configuration http://technet.microsoft.com/en-us/library/ee461027.aspx http://cmdlet.wordpress.com/2011/08/24/episode-3-get-gporeport QUESTION 33 Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. A network Administrator accidentally deletes the Default Domain Policy GPO. You do not have a backup of any of the GPOs. You need to recreate the Default Domain Policy GPO. What should you use?

A. dcgpofix

B. Get-GPOReport

C. Gpfixup

D. Gptedit.msc

E. Import-GPO

F. Restore-GPO

G. Set-GPInheritance

H. Set-GPLink

I. Set-GPPermission

J. Gpupdate

K. Add-ADGroupMember

Answer: A Explanation: Restores the default Group Policy objects to their original state (that is, the default state after initial installation). QUESTION 34 Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. The domain is renamed to adatum.com. Group Policies no longer function correctly. You need to ensure that the existing GPOs are applied to users and computers. You want to achieve this goal by using the minimum amount of Administrative effort. What should you use?

A. dcgpofix

B. Get-GPOReport

C. Gpfixup

D. Gpresult

E. Gptedit.msc

Page 11: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

11

F. Import-GPO

G. Restore-GPO

H. Set-GPInheritance

I. Set-GPLink

J. Set-GPPermission

K. Gpupdate

L. Add-ADGroupMember

Answer: C Explanation: You can use the gpfixup command-line tool to fix the dependencies that Group Policy objects (GPOs) and Group Policy links in Active Directory Domain Services (AD DS) have on Domain Name System (DNS) and NetBIOS names after a domain rename operation. QUESTION 35 Your network contains an Active Directory domain named contoso.com. The domain contains more than 100 Group Policy objects (GPOs). Currently, there are no enforced GPOs. The domain contains a top-level organizational unit (OU) for each department. A group named Group1 contains members from each department. You have a GPO named GPO1 that is linked to the domain. You need to configure GPO1 to apply settings to Group1 only. What should you use?

A. dcgpofix

B. Get-GPOReport

C. Gpfixup

D. Gpresult

E. Gptedit.msc

F. Import-GPO

G. Restore-GPO

H. Set-GPInheritance

I. Set-GPLink

J. Set-GPPermission

K. Gpupdate

L. Add-ADGroupMember

Answer: J Explanation: J. Set-GPPermission grants a level of permissions to a security principal (user, security group, or computer) for one GPO or all the GPOs in a domain. You use the TargetName and TargetType parameters to specify a user, security group, or computer for which to set the permission level. -Replace <SwitchParameter> Specifies that the existing permission level for the group or user is removed before the new permission level is set. If a security principal is already granted a permission level that is higher than the specified permission level and you do not use the Replace parameter, no change is made. http://technet.microsoft.com/en-us/library/ee461038.aspx QUESTION 36 Your network contains an Active Directory domain named contoso.com. A user named User1 creates a central store and opens the Group Policy Management Editor as shown in the exhibit. (Click the Exhibit button.) You need to ensure that the default Administrative Templates appear in GPO1. What should you do? Exhibit:

Page 12: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

12

A. Link a WMI filter to GPO1.

B. Add User1 to the Group Policy Creator Owners group.

C. Configure Security Filtering in GPO1.

D. Copy files from %Windir%\PolicyDefinitions to the central store.

Answer: D Explanation: In earlier operating systems, all the default Administrative Template files are added to the ADM folder of a Group Policy object (GPO) on a domain controller. The GPOs are stored in the SYSVOL folder. The SYSVOL folder is automatically replicated to other domain controllers in the same domain. A policy file uses approximately 2 megabytes (MB) of hard disk space. Because each domain controller stores a distinct version of a policy, replication traffic is increased. In Group Policy for Windows Server 2008 and Windows Vista, if you change Administrative template policy settings on local computers, Sysvol will not be automatically updated with the new .ADMX or .ADML files. This change in behavior is implemented to reduce network load and disk storage requirements, and to prevent conflicts between .ADMX files and. ADML files when edits to Administrative template policy settings are made across different locales. To make sure that any local updates are reflected in Sysvol, you must manually copy the updated .ADMX or .ADML files from the PolicyDefinitions file on the local computer to the Sysvol\PolicyDefinitions folder on the appropriate domain controller. To take advantage of the benefits of .admx files, you must create a Central Store in the SYSVOL folder on a domain controller. The Central Store is a file location that is checked by the Group Policy tools. The Group Policy tools use any .admx files that are in the Central Store. The files that are in the Central Store are later replicated to all domain controllers in the domain. To create a Central Store for .admx and .adml files, create a folder that is named PolicyDefinitions in the following location: \\FQDN\SYSVOL\FQDN\policies http://support.microsoft.com/kb/929841 QUESTION 37 Your network contains a single Active Directory domain named contoso.com. The domain contains an Active Directory site named Site1 and an organizational unit (OU) named OU1. The domain contains a client computer named Client1 that is located in OU1 and Site1. You create five Group Policy objects (GPO).

Page 13: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

13

You need to identify in which order the GPOs will be applied to Client1. In which order should you arrange the listed GPOs? To answer, move all GPOs from the list of GPOs to the answer area and arrange them in the correct order.

Answer:

Explanation: With enforcement, the parent GPO link always has precedence. Applied by order: domain OU OU enforcement domain enforcement site enforcement GPOs are applied according to the Group Policy hierarchy in the following order: local GPO GPOs linked to the site GPOs linked to the domain GPOs linked to OUs. By default, an Active Directory container inherits settings from GPOs that are applied at the next higher level in the hierarchy. Blocking inheritance prevents the settings in GPOs that are linked to

Page 14: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

14

higher-level sites, domains, or organizational units from being automatically inherited by the specified domain or OU, unless the link (at the higher-level container) for a GPO is enforced. Links to a specific site, domain, or organizational unit are applied in reverse sequence based on link order. For example, a GPO with Link Order 1 has highest precedence over other GPOs linked to that container. By default settings in Group Policy Objects (GPOs) get applied in the following order: Local system policies first, then policies on the Active Directory Domain level, then policies on the Active Directory Site level and then the policies for all the Organization Units the computer and user are members of, starting at the root of the domain. The settings that are last applied are the settings in effect. http://blogs.technet.com/b/musings_of_a_technical_tam/archive/2012/02/15/understanding-the-structure-of-a-group-policy-object-part-2.aspx http://technet.microsoft.com/en-us/library/cc757050.aspx QUESTION 38 Your network contains an Active Directory domain named contoso.com. Domain controllers run either Windows Server 2008, Windows Server 2008 R2, or Windows Server 2012 R2. You have a Password Settings object (PSOs) named PSO1. You need to view the settings of PSO1. Which tool should you use?

A. Get-ADFineGrainedPasswordPolicy

B. Get-ADAccountResultantPasswordReplicationPolicy

C. Get-ADDomainControllerPasswordReplicationPolicy

D. Get-ADDefaultDomainPasswordPolicy

Answer: A Explanation: A. Gets one or more Active Directory fine grained password policies. B. Gets the resultant password replication policy for an Active Directory account. C. Gets the members of the allowed list or denied list of a read-only domain controller's password replication policy D. Gets the default password policy for an Active Directory domain. http://technet.microsoft.com/en-us/library/ee617231.aspx ttp://technet.microsoft.com/en-us/library/ee617227.aspx http://technet.microsoft.com/en-us/library/ee617207.aspx http://technet.microsoft.com/en-us/library/ee617244.aspx QUESTION 39 Your network contains a production Active Directory forest named contoso.com and a test Active Directory forest named test.contoso.com. There is no network connectivity between contoso.com and test.contoso.com. The test.contoso.com domain contains a Group Policy object (GPO) named GPO1. You need to apply the settings in GPO1 to the contoso.com domain. Which four actions should you perform? To answer, move the four appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Page 15: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

15

Answer: Box 1: Run the Backup-GPO cmdlet in test.contoso.com. Box 2: Use a removable media to transfer the contents of test.contoso.com to contoso.com Box 3: Run the New-GPO cmdlet in contoso.com. Box 4: Run the Import-GPO cmdlet in contoso.com. Explanation: Note: * Backup-GPO Backs up one GPO or all the GPOs in a domain. The Backup-GPO cmdlet backs up a specified GPO or all the GPOs in a domain to a backup directory. The backup directory and GPO must already exist. * Import-GPO Imports the Group Policy settings from a backed-up GPO into a specified GPO. The Import-GPO cmdlet imports the settings from a GPO backup into a specified target GPO. The target GPO can be in a different domain or forest than that from which the backup was made and it does not have to exist prior to the operation. Incorrect: * (incorrect) Restore-GPO Restores one GPO or all GPOs in a domain from one or more GPO backup files. The Restore-GPO cmdlet restores a GPO backup to the original domain from which it was saved. If the original domain is not available, or if the GPO no longer exists in the domain, the cmdlet fails. * (incorrect) Copy-GPO Copies a GPO. The Copy-GPO cmdlet creates a (destination) GPO and copies the settings from the source GPO to the new GPO. The cmdlet can be used to copy a GPO from one domain to another domain within the same forest. QUESTION 40 Your network contains an Active Directory domain named contoso.com. All user accounts reside in an organizational unit (OU) named OU1. All of the users in the marketing department are members of a group named Marketing. All of the users in the human resources department are members of a group named HR. You create a Group Policy object (GPO) named GPO1. You link GP01 to OU1. You configure the Group Policy preferences of GPO1 to add two shortcuts named Link1 and Link2 to the desktop of each user.

Page 16: New Version Dumps Of Exam 70-411 With Free Update (Part B)

Administering Windows Server 2012 R2 Exam (Version: 13.39)

Get Latest & Actual 70-411 Exam's Question and Answers from PassLeader. http://www.passleader.com/70-411.html

16

You need to ensure that Link1 only appears on the desktop of the users in Marketing and that Link2 only appears on the desktop of the users in HR. What should you configure?

A. Item-level targeting

B. Group Policy Inheritance

C. Security Filtering

D. WMI Filtering

Answer: A Explanation: http://technet.microsoft.com/en-us/library/cc733022.aspx http://technet.microsoft.com/en-us/library/cc779036%28v=ws.10%29.aspx