Home
21.
Over a period of time you have sent a number of S/MIME protected messages. Your private key is stored on a smart card and you have forgotten the PIN number. You do not have a backup of the private key. Your IT department has issued you a new certificate and updated your smart card to use the new certificate. Which of the following will you not be able to do going forward? (Choose two.)
  • A.
    You will not be able to sign emails.
  • B.
    You will not be able to encrypt emails.
  • C.
    You will not be able to read signed emails from others.
  • D.
    You will not be able to read encrypted emails from others that use your previous public key.
  • E.
    You will not be able to read signed emails you have sent that are in your Sent Items folder.
  • F.
    You will not be able to read encrypted emails you have sent to others that are in your Sent Items folder.
  • Answer & Explanation
  • Report
Answer : [D, F]
Explanation :
A. Incorrect: You will be able to sign emails using the new certificate.
B. Incorrect: You will be able to encrypt emails using the new certificate.
C. Incorrect: You will be able to read signed emails from others that use the new certificate.
D. Correct: You do not have your previous private key and so cannot open encrypted emails that use your previous public key.
E. Incorrect: Signed emails are not encrypted and so can still be read.
F. Correct: You need the previous private key to decrypt emails that you previously sent using it. Since you do not have this, you cannot read these emails.
Report
Name Email  
22.
You need to ensure that emails to Fabrikam Bank are guaranteed to be encrypted to and from that organization. You know that the bank uses a cloud hosted anti-spam filtering product and so direct access to their Exchange Servers is not available. What option do you need to look at first?
  • A.
    S/MIME
  • B.
    Domain Secure
  • C.
    Opportunistic TLS
  • D.
    Send connectors with TlsAuthLevel set to DomainValidation
  • Answer & Explanation
  • Report
Answer : [D]
Explanation :
A. Incorrect: S/MIME is user driven and so is not guaranteed to encrypt all communications to the bank.
B. Incorrect: Domain Secure requires direct Exchange Server mailbox role to Exchange Server mailbox role access using MX records and this does not exist in this case.
C. Incorrect: Opportunistic TLS will encrypt if a certificate is available, but if it is not it will go in clear text. Therefore this answer is not going to guarantee encryption.
D. Correct: Setting TlsAuthLevel to DomainValidation and TlsDomain to the name of the certificate that the hosting company is using.
Report
Name Email  
23.
You have installed AD RMS and have integrated it with Exchange Server. Which of the following cmdlets would you use to check that the integration with the IRM service is working? (Choose two.)
  • A.
    Get-RMSConfiguration
  • B.
    Get-IRMConfiguration
  • C.
    Test-RMSConfiguration -Sender dean@contoso.com
  • D.
    Test-IRMConfiguration -Sender dean@contoso.com
  • E.
    Test-RMSConfiguration -Mailbox "Halstead, Dean"
  • F.
    Test-IRMConfiguration -Mailbox "Halstead, Dean"
  • Answer & Explanation
  • Report
Answer : [B, D]
Explanation :
A. Incorrect: This is not the name of the cmdlet. The cmdlet for getting RMS configuration is Get-IRMConfiguration.
B. Correct: This cmdlet will tell you the IRM configuration in your Exchange organization. C. Incorrect: The cmdlet is not correct. The cmdlet for testing RMS is Test-IRMConfiguration.
D. Correct: This is a valid cmdlet and answer for testing IRM.
E. Incorrect: The RMS cmdlet is not the correct name.
F. Incorrect: The IRM cmdlet uses -Sender for testing and not –Mailbox.
Report
Name Email  
24.
Which of the following cmdlets will create a valid Outlook Protection Rule?
  • A.
    New-OutlookProtectionRule "Sent By Compliance Dept." -FromDepartment Compliance -SentToScope Internal -ApplyRightsProtectionTemplate "Do Not Forward" -UserCanOverride $True
  • B.
    New-RMSProtectionRule "Sent By Compliance Dept." -FromDepartment Compliance -SentToScope Internal -ApplyRightsProtectionTemplate "Do Not Forward" -UserCanOverride $True
  • C.
    New-RMSProtectionRule "Sent By Compliance Dept." -FromDepartment Compliance -SentToScope InOrganization -ApplyRightsProtectionTemplate "Do Not Forward" -UserCanOverride $True
  • D.
    New-OutlookProtectionRule "Sent By Compliance Dept." -FromDepartment Compliance -SentToScope InOrganization -ApplyRightsProtectionTemplate "Do Not Forward" -UserCanOverride $True
  • Answer & Explanation
  • Report
Answer : [D]
Explanation :
A. Incorrect: The SentToScope parameter is invalid on this answer.
B. Incorrect: This is an invalid cmdlet.
C. Incorrect: The cmdlet name here is invalid.
D. Correct: This cmdlet is correct.
Report
Name Email  
25.
Which of the following Exchange mailboxes needs to be added to the RMS Super Users group?
  • A.
    SystemMailbox{1f05a927-ee95-41ba-b053-4623ffd69772}
  • B.
    SystemMailbox{e0dc1c29-89c3-4034-b678-e6c29d823ed9}
  • C.
    FederatedEmail.4c1f4d8b-8179-4148-93bf-00a95fa1e042
  • D.
    Migration.8f3e7716-2011-43e4-96b1-aba62d229136
  • Answer & Explanation
  • Report
Answer : [B]
Explanation :
A. Incorrect: This is a valid arbitration mailbox but is not the Federation mailbox.
B. Correct: This is the federation mailbox and so is the one needed for RMS super user rights. Full details of the steps to configure RMS for Exchange Server 2013 can be found at http://technet.microsoft.com/en-us/library/dd351212(v=exchg.150).aspx.
C. Incorrect: This is a valid arbitration mailbox but is not the Federation mailbox.
D. Incorrect: This is a valid arbitration mailbox but is not the Federation mailbox.
Report
Name Email