Home
46.
You had a working AD FS server that has been working for one year, and today it stopped authenticating users. Which of the following would be your first consideration given that it has been installed for one year?
  • A.
    The token signing certificate has expired.
  • B.
    The Windows Server is not activated and has shut down.
  • C.
    Your third-party digital certificate has expired.
  • D.
    Your user accounts passwords have expired
  • Answer & Explanation
  • Report
Answer : [A, C]
Explanation :
A. Correct: The token signing certificate is valid for one year.
B. Incorrect: Non-activated servers will not shut down after one year.
C. Correct: This might be the answer, though you might have a multi-year certificate, but it is a good step to check.
D. Incorrect: This would not stop AD FS from working. AD FS would tell you your password had expired and would need changing.
Report
Name Email  
47.
What Exchange Management Shell cmdlet do you use to get the TXT string you need to enter into public DNS for a federation trust if you have closed the Federation Trust Wizard?
  • A.
    Get-HybridConfiguration -GetFederationTrustString AllDomains
  • B.
    Get-FederationTrustString -DomainName
  • C.
    Get-TXTRecord -FQDN
  • D.
    Get-FederatedDomainProof -DomainName
  • Answer & Explanation
  • Report
Answer : [D]
Explanation :
A. Incorrect: Even though the Hybrid Configuration Wizard configures federation trusts, it only does it for the on-premises to Exchange Online domains. Therefore, you do not change the federation trust with the HybridConfiguration cmdlets.
B. Incorrect: This is not a valid cmdlet.
C. Incorrect: Even though this would appear to be a valid cmdlet becaue the TXT record is required, the value is not obtained via this invalid cmdlet.
D. Correct: This cmdlet will retrieve the TXT record value required.
Report
Name Email  
48.
An Office 365 administrator wants to allow users to publish their calendars online. What do they need to do in Exchange Online?
  • A.
    Nothing is required because anonymous sharing is the default.
  • B.
    They need to create a new sharing policy for anonymous usage and update the OWA virtual directories for their tenant in the cloud.
  • C.
    They need to create a new sharing policy and assign it to the users who need it.
  • D.
    This feature is not available in Exchange Online.
  • Answer & Explanation
  • Report
Answer : [A]
Explanation :
A. Correct: The default behavior in Exchange Online is to allow anonymous calendar sharing.
B. Incorrect: The default sharing policy is already configured for anonymous and the tenant administrator does not have access to the OWA virtual directories in Exchange Online.
C. Incorrect: The default sharing policy is already configured for anonymous access.
D. Incorrect: This is not correct. Anonymous sharing is available in Exchange Online.
Report
Name Email  
49.
You need to restrict calendar sharing between a remote organization to a select group of users. How would you do this?
  • A.
    Ensure that the allowed users share their calendar with the remote domain and the others do not.
  • B.
    Create an organization relationship that is restricted to members of a security group.
  • C.
    You cannot restrict organization relationships more specifically than to the entire domain.
  • D.
    Use Add-MailboxFolderPermission to change the permissions on calendar of the recipient mailbox to publish it to the Internet.
  • Answer & Explanation
  • Report
Answer : [B]
Explanation :
A. Incorrect: Organization relationships are used to set this sharing in place and not permissions on calendars.
B. Correct: A security group is used to restrict the right to access calendar or free/ busy information on the organization relationship.

C. Incorrect: This is not true. You can restrict to the membership of a single group.
D. Incorrect: Organization relationships are used to set this sharing in place and not permissions on calendars.
Report
Name Email  
50.
Which of the following subject and subject alternative names would be needed on a digital certificate for a 2007 to 2013 migration?
  • A.
    legacy.contoso.com; mail.contoso.com; legacy-autodiscover.contoso.com; autodiscover.contoso.com.
  • B.
    legacy.contoso.com; mail.contoso.com; legacy.mail.contoso.com; autodiscover. contoso.com
  • C.
    mail.contoso.com; autodiscover.contoso.com
  • D.
    legacy.contoso.com; mail.contoso.com; autodiscover.contoso.com
  • Answer & Explanation
  • Report
Answer : [D]
Explanation :
A. Incorrect: This digital certificate contains a legacy namespace for AutoDiscover, which is not required.
B. Incorrect: This digital certificate contains two legacy namespaces, legacy.contoso.
com and legacy.mail.contoso.com. Only one is required and either one would do, but legacy.contoso.com requires less configuration on DNS (it is not a subzone) and so is recommended.
C. Incorrect: This digital certificate does not contain a legacy namespace as required for Exchange 2007 coexistence.
D. Correct: This is a correct example for a 2007 coexistence digital certificate.
Report
Name Email