- Home
- Server Administration
- Windows
- Administering Windows server 2012 (70-411)
41.
You are the network administrator for a large Active Directory domain named Panek.com.
The domain contains a server named Saturn that runs Windows Server 2012 R2. Saturn
has the DHCP Server role installed. The network contains 400 client computers that run
Windows 7 and Windows 8. All of the client computers are joined to the domain and are
configured DHCP clients. You install a new server named Jupiter that runs Windows Server
2012 R2. On Jupiter, you install the Network Policy Server (NPS) role service, and you
configure Network Access Protection (NAP) to use the DHCP enforcement method. You
need to ensure that Saturn provides a valid default gateway only to computers that pass the
system health validation. Which two actions should you perform? (Each correct answer
presents part of the solution. Choose two.)
- A.From the DHCP console, configure the 016 Swap Server option.
- B.From the DHCP console, enable NAP on all scopes.
- C.From the NAP Client Configuration console, enable the DHCP Quarantine Enforcement client.
- D.From the DHCP console, create a new policy.
- E.From Server Manager, install the Network Policy Server role service.
- Answer & Explanation
- Report
Answer : [B, E]
Explanation :
Explanation :
By setting the Network Policy Server, you can force your DHCP users to use NAP on all of the DHCP scopes. This ensures that client systems meet minimum requirements to connect to a domain network. |
42.
Your network contains an Active Directory domain named Panek.com. The domain
contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the
Network Policy Server (NPS) role service installed. You plan to configure Server1 as a
Network Access Protection (NAP) health policy server for VPN enforcement by using the
Configure NAP Wizard. You need to ensure that you can configure the VPN enforcement
method on Server1 successfully. What should you install on Server1 before you run the
Configure NAP Wizard?
- A.The Host Credential Authorization Protocol (HCAP)
- B.A system health validator (SHV)
- C.The Remote Access server role
- D.A computer certificate
- Answer & Explanation
- Report
Answer : [D]
Explanation :
Explanation :
Servers that are running Network Policy Server (NPS) are required to have a certificate installed on the NPS server. |
43.
You are a network administrator of an Active Directory domain named Stellacon.com. You
have a server named Earth that runs Windows Server 2012 R2. Earth has the DHCP Server
role and the Network Policy Server (NPS) role service installed. You enable Network Access
Protection (NAP) on all of the DHCP scopes on Earth. You need to create a DHCP policy
that will apply to all of the NAP noncompliant DHCP clients. Which criteria should you
specify when you create the DHCP policy?
- A.The relay agent information
- B.The user class
- C.The vendor class
- D.The client identifier
- Answer & Explanation
- Report
Answer : [B]
Explanation :
Explanation :
One advantage of using NAP for DHCP is that you can set up user classes so that specific machines (for example, noncompliant DHCP systems) can get specific rules or limited access to the network. |
44.
Your network contains an Active Directory domain named contoso.com. Network Access
Protection (NAP) is deployed to the domain. You need to create NAP event trace log files
on a client computer. What should you run?
- A.Register-ObjectEvent
- B.Register-EngineEvent
- C.tracert
- D.logman
- Answer & Explanation
- Report
Answer : [D]
Explanation :
Explanation :
Logman creates and manages Event Trace Session and Performance logs, and it allows an administrator to monitor many different applications through the use of the command line. |
45.
Your network contains four Network Policy Server (NPS) servers named ServerA, ServerB,
ServerC, and ServerD. Server1 is configured as a RADIUS proxy that forwards connection
requests to a remote RADIUS server group named Group1. You need to ensure that ServerB
and ServerC receive connection requests. ServerD should receive connection requests only if
both ServerB and ServerC are unavailable. How should you configure Group1?
- A.Change the weight of ServerB and ServerC to 10.
- B.Change the weight of ServerD to 10.
- C.Change the priority of ServerB and ServerC to 10.
- D.Change the priority of ServerD to 10.
- Answer & Explanation
- Report
Answer : [D]
Explanation :
Explanation :
The higher the RADIUS priority number, the less that the RADIUS server gets used. To make sure that RADIUS ServerD is used only when ServerB and ServerC is unavailable, you would set the RADIUS priority from 1 to 10. This way it will get used only when ServerB and ServerC are having issues or are unresponsive. |