Home
61.
You are confguring AD FS. Which server should you deploy on your organization’s perimeter network?
  • A.
    Web appplication proxy
  • B.
    Relying-party server
  • C.
    Federation server
  • D.
    Claims-provider server
  • Answer & Explanation
  • Report
Answer : [A]
Explanation :
  • A. Correct: You deploy a web application proxy on a perimeter network.
  • B. Incorrect: The relying-party server is a federation server on a protected network.
  • C. Incorrect: The federation server should be deployed on a protected network.
  • D. Incorrect: The claims-provider server is a federation server on a protected network.
Report
Name Email  
62.
The Wingtip Toys forest hosts a web application that users in the Tailspin Toys forest need to access. You are the system administrator at Tailspin Toys. A single federation server is present in each forest and you are confguring a federated trust. Which of the following statements are true about the deployment solution? (Choose all that apply.)
  • A.
    The AD FS server in the Wingtip Toys forest will function as the claims-provider server.
  • B.
    The AD FS server in the Wingtip Toys forest will function as the relying-party server
  • C.
    You need to confgure a relying-party trust on the AD FS server in the Tailspin Toys forest.
  • D.
    You need to confgure a claims-provider trust on the AD FS server in the Tailspin Toys forest.
  • Answer & Explanation
  • Report
Answer : [B and C]
Explanation :
  • A. Incorrect: The server in the forest that hosts the resources to be accessed functions as the relying-party server.
  • B. Correct: The server in the forest that hosts the resources to be accessed functions as the relying-party server.
  • C. Correct: You confgure a relying-party trust on the claims-provider server. Because the users are in the Tailspin Toys forest, you confgure a relying-party trust on this server.
  • D. Incorrect: You confgure a relying-party trust on the claims-provider server. Because the users are in the Tailspin Toys forest, you confgure a relying-party trust on this server.
Report
Name Email  
63.
The Wingtip Toys forest hosts a web application that users in the Tailspin Toys forest need to access. You are the system administrator at Wingtip Toys. A single federation server is present in each forest and you are confguring a federated trust. Which of the following statements are true about the deployment solution? (Choose all that apply.)
  • A.
    The AD FS server in the Tailspin Toys forest will function as the claims-provider server
  • B.
    The AD FS server in the Tailspin Toys forest will function as the relying-party server.
  • C.
    Confgure a relying-party trust on the Wingtip Toys AD FS server.
  • D.
    Confgure a claims-provider trust on the Wingtip Toys AD FS server.
  • Answer & Explanation
  • Report
Answer : [A and D]
Explanation :
  • A. Correct: The claims-provider server is located in the forest that hosts the user accounts.
  • B. Incorrect: The claims-provider server is located in the forest that hosts the user accounts.
  • C. Incorrect: You confgure the claims-provider trust on the relying-party server, which is located in the forest that hosts the resources.
  • D. Correct: You confgure the claims-provider trust on the relying-party server, which is located in the forest that hosts the resources.
Report
Name Email  
64.
Which of the following authentication types must you enable to support Workplace Join?
  • A.
    Forms
  • B.
    Windows
  • C.
    Certifcate
  • D.
    Device
  • Answer & Explanation
  • Report
Answer : [D]
Explanation :
  • A. Incorrect: Workplace Join uses device authentication.
  • B. Incorrect: Workplace Join uses device authentication.
  • C. Incorrect: Workplace Join uses device authentication.
  • D. Correct: Workplace Join uses device authentication.
Report
Name Email  
65.
Which of the following CA types would you deploy if you wanted to deploy a CA at the top of a hierarchy that could issue signing certifcates to other CAs and which would be taken offline if not issuing, renewing, or revoking signing certifcates?
  • A.
    Enterprise root
  • B.
    Enterprise subordinate
  • C.
    Standalone root
  • D.
    Standalone subordinate
  • Answer & Explanation
  • Report
Answer : [C]
Explanation :
  • A. Incorrect: Because enterprise CAs are integrated into Active Directory, they should not be taken offline.
  • B. Incorrect: Because enterprise CAs are integrated into Active Directory, they should not be taken offline. Additionally, subordinate CAs are not at the top of a CA hierarchy.
  • C. Correct: You can take a standalone root CA offline and it functions as the top of a CA hierarchy.
  • D. Incorrect: Subordinate CAs are not at the top of a CA hierarchy.
Report
Name Email