Pass Your Microsoft 70-411 Exam Easy!

Get 100% Real Exam Questions, Accurate & Verified Answers By IT Experts

Fast Updates & Instant Download!

Certification Exam: 70-411 (Administering Windows Server 2012)
70-411 Premium VCE File

Microsoft 70-411 Premium File

306 Questions & Answers

Last Update: Feb 16, 2024

$69.99

70-411 Bundle gives you unlimited access to "70-411" files. However, this does not replace the need for a .vce exam simulator. To download VCE exam simulator click here
70-411 Premium VCE File
Microsoft 70-411 Premium File

306 Questions & Answers

Last Update: Feb 16, 2024

$69.99

Microsoft 70-411 Exam Bundle gives you unlimited access to "70-411" files. However, this does not replace the need for a .vce exam simulator. To download your .vce exam simulator click here

Download Free 70-411 Exam Questions

Exam 70-411 - Administering Windows Server 2012
Size: 39.74 MB
Posted Date: Wednesday, November 13, 2013
# of downloads: 75197
Free Download:
  Download Free 70-411 Exam Questions
Exam
70-411 - Administering Windows Server 2012
Size
39.74 MB
Posted Date
Wednesday, November 13, 2013
# of downloads
75197
Comments
* The most recent comment are at the top
Pages:  [<<]  [<]  1 2 3 4 5 6 7 8  [>]  [>>]
  • hokie
  • Gambia
  • Sep 24, 2015

Please can you send me 70-411 and 70-412
I really need your help.

  • Sep 24, 2015
  • Eliran
  • Israel
  • Sep 24, 2015

Hi everybody ! How many questions should be in this dump ??? The size looks very scary !!! Thanks.

  • Sep 24, 2015
  • A
  • India
  • Sep 24, 2015

Please send the latest and valid dumps in pdf to enchanted2k10@yahoo.com.Thanks .writing this exam next week

  • Sep 24, 2015
  • Roberto
  • France
  • Sep 24, 2015

please send me the latest dump to Roberto@hotmail.nl

  • Sep 24, 2015
  • NinjaRural
  • Brazil
  • Sep 24, 2015

Please can you send the last pdf questions

ninja_rural@yahoo.com.br

  • Sep 24, 2015
  • NinjaRural
  • Brazil
  • Sep 24, 2015

Hello there , can anyone please sent me the last questions pdf.

  • Sep 24, 2015
  • Richie
  • United Kingdom
  • Sep 23, 2015

The Premium dump should be valid as it was updated 2 days after the new questions were released.

  • Sep 23, 2015
  • Pashos
  • Russian Federation
  • Sep 23, 2015

please send me the latest dump to pashos_nix@hotmail.com

  • Sep 23, 2015
  • Anusha
  • India
  • Sep 23, 2015

Can you please mail me the valid PDF
anushasmiles2006@gmail.com

  • Sep 23, 2015
  • nandosal
  • Uruguay
  • Sep 23, 2015

Sebastian,
Do you know if the dump Sacriestory it's valid?

  • Sep 23, 2015
  • Sebastian
  • Australia
  • Sep 23, 2015

can someone PLEASE send me the lastest dump. anyone with the copy of Sacriestory please email me at dh7679@yahoo.com

I have failed twice now so I need help.
thanks!

  • Sep 23, 2015
  • saudi arabia
  • Saudi Arabia
  • Sep 23, 2015

pass today with 7xx but there are new questions

Q1: you have windows server update server named server 1 is synchronize from microsoft. you plan to deploy new wsus server name server 2 will synchronize update from server 1 . identify witch port must be open?
-3389
-8530
-443
-80

Q:you deploy wsus named server 1 . you plan to use (GPO) to configure all clients to use server 1 as microsoft update server . you need to ensure that the computer assigned to the correct computer group automatically when GPO is deployed? choose two
-from update services condole,manually create the computer group
-from windows powershell ,run add-wsuscomputer cmdlt
-from windows powershell run,approve wsusupdate cmdlt
-from the update services console,modify the product and classifications options
-from the update services console,modify computer option

Q3:your network contain one active directory . you pilot direct access on the network. during the pilot deployment,you enable direct access only for a group named contoso/test computers.ones the pilot is complete, you need to enable direct access for all of client computers in the domain what should you do?
- from group policy management,modify the security filtering of an object named direct access server sitting group policy
- from group policy management, modify the security filtering of an object named direct access client sitting group policy
-from windows powershell,run set-DAclient cmdlt
-from active directory user and computer ,modify the membership of the windows authorization access group

Q4:you have server name server 1. you enable bitlocker drive encryption (bitlocker) on server 1 . you need to change the password for the trusted platform moudle (TPM) chip?
-initialize - TPM
-bdeHDcfg.exe
-manage - bde.exe
-repair -bde.exe

Q5:you plan to decommission a domain controller that holds several operation master role in the table below select
1- witch tool to use to transfer domain naming master
2- witch tool use to transfer the infrastructure master
-active directory domain and trust
-active directory schema
-active directory site and service
-active directory user and computer
- security configuration wizard (scw)

  • Sep 23, 2015
  • lowblood
  • Hong Kong
  • Sep 23, 2015

hi logan, please send me the new dump, my email is lowblood1987@gmail.com. thanks man

  • Sep 23, 2015
  • Amey Haldankar
  • India
  • Sep 23, 2015

Hi Logan, could you please email me the latest dump? ameyhaldankar@live.in

  • Sep 23, 2015
  • winda
  • Indonesia
  • Sep 23, 2015

Could you send me a the latest and valid 70-411 dump to unggulianawinda@gmail.com, thank you

  • Sep 23, 2015
  • ZoRo
  • Cambodia
  • Sep 23, 2015

Hi All, I'm going to take this exam next week.
Could you please send me a the latest 70-411 dump .My email is bunthoeurn.sien@yahoo.com
thank you

  • Sep 23, 2015
  • reynold
  • United States
  • Sep 22, 2015

hi logan, please send me the dump, my email is reynold_aky@hotmail.com. thanks man

  • Sep 22, 2015
  • piet
  • Netherlands
  • Sep 22, 2015

is there any one who has a pdf file?


vragenpiet@outlook.com

  • Sep 22, 2015
  • Rainier Narboneta
  • Philippines
  • Sep 22, 2015

Could anybody send me the pdf file? Here's my email: Archrainiernarboneta@gmail.com

thanks!

  • Sep 22, 2015
  • Alan
  • Hong Kong
  • Sep 22, 2015

Could you please send me a the latest 70-411 dump .My email is one362006@yahoo.com.hk,thank you.

  • Sep 22, 2015
  • Rico
  • Trinidad And Tobago
  • Sep 22, 2015

Please send me the PDF file for this ricardo_4193@hotmail.com

  • Sep 22, 2015
  • nandosal
  • Uruguay
  • Sep 21, 2015

Hi everyone, this vce it's valid?
Thanks

  • Sep 21, 2015
  • Hoze
  • United States
  • Sep 21, 2015

Please send to me the latest 70-411 dump plz?? Thx

  • Sep 21, 2015
  • Hoze
  • United States
  • Sep 21, 2015

Please send to me the latest 70-411 dump plz?? Thx

  • Sep 21, 2015
  • djmight
  • Nigeria
  • Sep 21, 2015

Could you please send me a the latest 70-411 dump .My email is ogunmusid@gmail.com
Thanks

  • Sep 21, 2015
  • jesus trujillo
  • Spain
  • Sep 21, 2015

Hi friends,

I need archive pdf o vce for exam 411, please send me to: trujillomarquezjesus@gmail.com thanks !!!ยช!

  • Sep 21, 2015
  • Sergio - BZL
  • Brazil
  • Sep 19, 2015

Folks, I passed today 7XX with Sacriestory and some comments in this blog. Thank you all!

  • Sep 19, 2015
  • ibrahim
  • Kuwait
  • Sep 18, 2015

could anyone send me the updated dump to eng.ibrahim.nagy@gmail.com

  • Sep 18, 2015
  • Appleo
  • India
  • Sep 18, 2015

Hey I am planning to give 70-411 next week,please send me the updated dump to appdownleo@gmail.com

  • Sep 18, 2015
  • Jeremy
  • Malaysia
  • Sep 18, 2015

@ Logan, could you please email me latest the dump at jeremy_liong@yahoo.com

Thank you!!

  • Sep 18, 2015
  • ahmed
  • Egypt
  • Sep 18, 2015

thanks GOD pass with this dumb today 742

  • Sep 18, 2015
  • Fernando Flores
  • United States
  • Sep 17, 2015

@ Logan, could you please email me the dump at fernandofv81@hotmail.com? Thanks in advance!

  • Sep 17, 2015
  • sangarapandian
  • Qatar
  • Sep 17, 2015

Hi Logan, could you please email me the latest dump? shankar.tvd@gmail.com

  • Sep 17, 2015
  • Tippmann
  • United States
  • Sep 17, 2015

@Logan Please kindly send me the Latest 70-411 dump my email is cbw.corp@gmail.com

  • Sep 17, 2015
  • Peanut-Tech
  • United States
  • Sep 17, 2015

@Bobo
Thanks for the help with 410. I am now trolling the net to see what the 411 is for 70-411. When the Indians fall a little short of passing then I know I am in for a challenge.

  • Sep 17, 2015
  • ALaa
  • Saudi Arabia
  • Sep 17, 2015

it is valid in Saudi Arabia

  • Sep 17, 2015
  • Umair
  • Netherlands
  • Sep 17, 2015

Pleas can anyone send me the Latest dumps to
muslim_pray@hotmail.com

  • Sep 17, 2015
  • testrunner
  • Romania
  • Sep 17, 2015

Sacriestory valid now. Confirmed. Took the exam yesterday n got 8xx. 95% convered in this dump. Not perfect tho, but enough for passing the exam. try to google it dudes.

  • Sep 17, 2015
  • DNS
  • United States
  • Sep 16, 2015

Hi Ivar can you please help me out wit the updated Dump. dns.shongwe@gmail.com

  • Sep 16, 2015
  • Johnny
  • United Kingdom
  • Sep 16, 2015

Hi Logan, could you please email me the latest dump? johnnyaxeireland@gmail.com
Can't thank you enough buddy

  • Sep 16, 2015
  • Johnny
  • United Kingdom
  • Sep 16, 2015

Logan, could you please send the valid dump to me as well? Thanks buddy!

  • Sep 16, 2015
  • Mani
  • India
  • Sep 16, 2015

Could you please send me a the latest 70-411 dump .My email is Manigandan.rd84@gmail.com

  • Sep 16, 2015
  • Greatnayo
  • Nigeria
  • Sep 16, 2015

@Logan Please kindly send me the Latest 70-411 vce dump. My email is greatnayo@gmail.com

  • Sep 16, 2015
  • harsha
  • Sri Lanka
  • Sep 16, 2015

Hi @Logan,
Could you please send me a the latest 70-411 dump .My email is harshabba@gmail.com
Thanks

  • Sep 16, 2015
  • michael
  • United States
  • Sep 15, 2015

Can you please send me a copy of your dump

  • Sep 15, 2015
  • Ivar
  • Canada
  • Sep 15, 2015

I used Sacriestory, and it was perfect! I would say 90% of the questions were there, and if not, about 2-3 could have been found on Snowden. About 5 were no where to be found. Some (2-3) were reworded. Passed with 7xx today, Spet 15, 2015.

  • Sep 15, 2015
  • Mohan Narayanan
  • Sri Lanka
  • Sep 15, 2015

Hi Logan can you please send me the latest dump to mohan.colombo@gmail.com. Thanks...

  • Sep 15, 2015
  • Mohan Narayanan
  • Sri Lanka
  • Sep 15, 2015

Hi Logan can you please send me the latest dump to mohan.colombo@gmail.com. Thanks...

  • Sep 15, 2015
  • Jean de Dieu
  • Rwanda
  • Sep 15, 2015

Please, may you send a valid dumps for MCSE Server infrastructure exams to jeantwa@gmail.com. Thanks

  • Sep 15, 2015
  • Dumi
  • South Africa
  • Sep 15, 2015

Logan can you PLEASE send me the Sacriestory dump. d.k.macheke@gmail.com

  • Sep 15, 2015
  • Bisharat Akram
  • United States
  • Sep 15, 2015

Mr Logan can you plz send that file which you prepared for your exam.alibisharat@hotmail.com

  • Sep 15, 2015
  • sadae
  • Kenya
  • Sep 15, 2015

please email me at sadaemo@gmail.com

  • Sep 15, 2015
  • joakja2008
  • Singapore
  • Sep 15, 2015

Hi @Logan,
can you please send me a the latest 70-411 dump .My email is joakja2008@gmail.com
thanks in advance

  • Sep 15, 2015
  • Derrick Lafayette
  • United States
  • Sep 14, 2015

Logan can you PLEASE send me the Sacriestory dump. dlafayette24@gmail.com I don't know where to find it. Thanks man, people have been failing this test all summer.

  • Sep 14, 2015
  • SH@X
  • Kuwait
  • Sep 14, 2015

Hi Logan.Can You Please Send Me the latest Dump 70-411.My Email ahmedshaker.exam@outlook.com

  • Sep 14, 2015
  • Abdallah binothman
  • Saudi Arabia
  • Sep 14, 2015

pass today with 7xx

  • Sep 14, 2015
  • Bram
  • Netherlands
  • Sep 14, 2015

Passed with 828 using the Sacriestory dump

  • Sep 14, 2015
  • Silvia
  • Italy
  • Sep 14, 2015

Hi!
Please, can someone send me the pdf file?
You could save my life... :)
lady.nekosix@yahoo.it

  • Sep 14, 2015
  • bestyohan
  • South Korea
  • Sep 14, 2015

Hi Logan.can you please send me a the latest 70-411 dump .My email is bestyohan@naver.com thanks in advance

  • Sep 14, 2015
  • FadlyD
  • Indonesia
  • Sep 13, 2015

Dumps is valid, passed in friday sept 11th 2015 with 871 scores.
Refer question : Britany, adeline, angus, snowden, russel, stanley

  • Sep 13, 2015
  • Logan
  • South Africa
  • Sep 12, 2015

Hi Fis, just download the Sacriestory dump most of the new questions is in there.

  • Sep 12, 2015
  • Buhle Mahlaba
  • South Africa
  • Sep 12, 2015

hi Logan please send me latest dump for 70-411 buhlem1@outlook.com or mrhle@yahoo.com. I failed last week I want to try it again soon, please man thanks.

  • Sep 12, 2015
  • testslash
  • Canada
  • Sep 12, 2015

Hey dude, where did u guys find the right VCE tools to open Sacriestory dump? I got the dump but every VCE tool I've got at hand is not working for it.

  • Sep 12, 2015
  • taha hassan
  • Egypt
  • Sep 12, 2015

am going to exam next Thursday so i hope if one have the last uvdate for this dump 70-411 "vce" please send it to me in this e-mail tahaelnuba@hotmail.com

  • Sep 12, 2015
  • taha hassan
  • Egypt
  • Sep 12, 2015

pleas any one have last update for dump 70-411 sending to me in that e-mail tahaelnuba@hotmail.com

  • Sep 12, 2015
  • kholofelo
  • South Africa
  • Sep 11, 2015

@ logan can you please email me the dump you used Kholofelomanaka@gmail.com

  • Sep 11, 2015
  • Lerato
  • United States
  • Sep 11, 2015

hey Logan,please share with us some exam tips.......
.

  • Sep 11, 2015
  • lan
  • India
  • Sep 11, 2015

is this dump valid ?

  • Sep 11, 2015
  • Fis
  • South Africa
  • Sep 11, 2015

Hi Logan.can you please send me a the latest 70-411 dump .My email is sergemundeke @gmail.com or call me on 0787089119. plz

  • Sep 11, 2015
  • Logan
  • South Africa
  • Sep 11, 2015

Past today with 807 , studied Sacriestory dump.

  • Sep 11, 2015
  • JRueda
  • Colombia
  • Sep 10, 2015

Passed today with 742. thanks a lot!!!

  • Sep 10, 2015
  • Afzal
  • Sweden
  • Sep 10, 2015

Passed today to get dumps in PDF or VCE email afzal343@gmail.com

  • Sep 10, 2015
  • Tim
  • United States
  • Sep 10, 2015

JRueda -

For #2 it looks like "D"

https://technet.microsoft.com/en-us/library/Cc708550(v=WS.10).aspx (See Step 2)

  • Sep 10, 2015
  • Les
  • South Africa
  • Sep 10, 2015

Personal

  • Sep 10, 2015
  • Paulo
  • Germany
  • Sep 10, 2015

Matue is: local computer โ€“> personal

http://www.aiotestking.com/microsoft/which-store-should-you-import-the-certificate-2/

http://www.vcp550dumps.com/braindump2go-100-money-back-guarantee-for-100-passing-70-411-exam-using-new-updated-microsoft-70-411-exam-dumps-76-90.html

  • Sep 10, 2015
  • Matue
  • Azerbaijan
  • Sep 10, 2015

Hi all,
This is one of HOT area question cant share picture but question is below,please help me .

You have a server named server1 that has the WEb server (IIS) server role installed.You obtain a Web server certificate.You need to configure a website on Server1 to use Secure Socket Layer (SSL).To which store should you import the certificate ?


Personal
or
Trusted Root Certification Authorities.

????

  • Sep 10, 2015
  • Ambika
  • India
  • Sep 10, 2015

This question is mary forum:
5 Question about group policy preferences relating to mapped drives;
If X already exists, it must NOT make any changes
If Y already exists, change the UNC path, but leave the contents of it
โ€ข Create
โ€ข Delete
โ€ข Replace
โ€ข Update

Anyone know the answer?

Answer : Create 100% sure. Yesterday cleared the exam with 750

ambika_rose@yahoo.in

  • Sep 10, 2015
  • Frank
  • Australia
  • Sep 09, 2015

Its Create and Updated

  • Sep 09, 2015
  • RIRG
  • Colombia
  • Sep 08, 2015

This question is mary forum:
5 Question about group policy preferences relating to mapped drives;
If X already exists, it must NOT make any changes
If Y already exists, change the UNC path, but leave the contents of it
โ€ข Create
โ€ข Delete
โ€ข Replace
โ€ข Update

Anyone know the answer?

  • Sep 08, 2015
  • JRueda
  • Colombia
  • Sep 08, 2015

Please, anyone have the right answer for this question ?
You have a group managed Service Account name Account01. Only three servers named Server01, Server02 and Server03 are allowed to use Account01 service account.
You plan to decommission Server01.
You need to prevent Server01 from using the Account01 service account. The solution must ensure that Server02 and Server03 continue to use the Account01 service account
What command should you run? To answer, select the appropriate options in the answer area.

Answer : Set-ADServiceAccount -Name Account01 -PrincipalsAllowedToRetrieveManagedPassword Server02 Server03

a. Set-ADServiceAccount
b. Uninstall-ADServiceAccount
c. remove-ADServiceAccount
d. ???

I think the answer is C: remove-ADServiceAccount

https://technet.microsoft.com/en-us/library/ee617190.aspx

  • Sep 08, 2015
  • Josef_the_Great
  • Germany
  • Sep 08, 2015

Passed today with 7XX. 4 New Questions. Cannot remember the detailed questions and answers but I will try:

1. DFS Replication: Which command for replication of Files? - "Robocopy.exe" Which command for replication of Database? - "ExportDFSRClone".

2. Created admx File and copied to central store. Trying to edit settings a warning pops up: "An appropriate resource file could not be found for file \\domainname.com\sysvol\domainname.com\Policies\PolicyDefinitions\anyfile.admx (error = 2): The system cannot find the file specified" What is wrong? - adml-File is missing!

3. Create Service Account: Service NT\Service1. You see the Service1 Properties Popup. The question is: What kind of Account is the service Account used on the computer? - "virtual Account" , Which account is used when this Serviceaccount gets into Network? - If a service accesses the network while running as a virtual account, it accesses resources as the !computer account! (DOMAIN\Computername$).

  • Sep 08, 2015
  • Josef_The_Great
  • Germany
  • Sep 07, 2015

@JRueda:

1: C. Get-ADDomainControllerPasswordReplicationPolicyUsage
Source(https://technet.microsoft.com/en-us/library/ee617194.aspx)
2: D. Get-ADDomain
In the question clearly mention that which domain controller must be online when cloning a domain controller.That means PDC emulator must be available during cloning operation. So you can check it using this command.
Source(http://thelazyadmin.com/2013/08/discover-fsmo-roles-with-powershell/)

  • Sep 07, 2015
  • Josef_The_Great
  • Germany
  • Sep 07, 2015

Hey RIRG:
The correct answer is here:
https://technet.microsoft.com/en-us/library/cc512680.aspx

By default, the data recovery agent is defined to be the administrator account. On stand-alone workstations and workgroup machines, the administrator account is the local administrator; on domain-joined machines, the administrator account is the first domain controllerโ€™s administrator account.

I think the first one is in the Contoso Domain, so the Agent should be Contoso/Administrator. The other ones seem to be a local machine. It depends how the question introduced the machines. But I would say these are local ones. So the agent should be Server1/Administrator in both cases.
But it really depends on how the question in the exam is created.
Greetz

  • Sep 07, 2015
  • Lhong
  • Thailand
  • Sep 07, 2015

Failed today 595 (feel surprise), got 49 questions, not sure around 4 questions while take exam.
I studied only PT300 because Snowden and Angus have same as PT300. But PT300 is newest version.
In the exam around 40 quetions came from PT300 and can't get 100% in any part of exam that prove PT300 still more incorrect answers
Be honest, just study only PT300 and review all questions these think incorrect.

New questions (mostly from older post)
WSUS
server01 update from Microsoft update and server02 update through from server01
server01 configured to require SSL cert., both server are in the same DC (cause not require FQDN in the answer choices)
Which command should configure on server02
A. ...
B. ...
C. wsusutil.exe configuressl server01
D. wsusutil.exe configuressl server02
C or D, I choose D

GPO
question show 3 image tab to view, can't remember questions, it to long
1. SYSVOL or something(not sure), DC2(C:\Windows\PolicyDefinitions, show around 20 .txt files)
2. SYSVOL or something(not sure), Client (\\contoso.com\...not sure...\PolicyDefinitions, show empty)
3. GPO (not sure), DC1(In the gpedit.msc, under Administrative templates, show empty)

have 3 answers are Yes or No with description
1. What happens if you delete the PolicyDefinitions folder in SYSVOL,
2. do the settings appear in the GPO? How about (not sure)
3. if you create a new GPO (on DC2 not sure), do the settings appear under administrative templates for that new GPO

RODC
You need to identify which security principals are authorized to have their password cached on RODC1?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy
I choose A.

New questions from Peter (found 3 of 10)
1. Q3: You need to prevent Server01 from using the Account01 service account. The solution must ensure that Server02 and Server03 continue to use the Account01 service account
What command should you run? To answer, select the appropriate options in the answer area.

It's drop-down list to select, I choose
Set-ADServiceAccount
-SAMAccountNAme
-PrincipalsAllowedToReteriveMamagedPassword

2. Q4 You need to identify which domain controller must be online when cloning a domain controller.
Which cmdlet should you use?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy
I choose D.

3. Q7 You need to identify which user accounts were authenticated by RODC1.
Which cmdlet should you use?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy
I choose C.

rest of questions come from PT300 and I 100% sure have selectd choice follows as PT300 But still Failed

Cheer

  • Sep 07, 2015
  • Frank
  • Australia
  • Sep 06, 2015

I believe this is the answer

File1 has been encrypted by Contoso\admin1
File2 has been encrypted by Server1\admin1
File3 has been encrypted by Server1\administrator

You need to back up the DRA agents.
Who is the owner of each of the agents.

There is a selection of drop down boxes. You should to select one in every file
File1 : Contoso\admin
Contoso\administrator < Answer
Server1\admin1
Server1\administrator

File2 : Contoso\admin
Contoso\administrator
Server1\admin1
Server1\administrator < Answer

File3 : Contoso\admin
Contoso\administrator
Server1\admin1
Server1\administrator < Answer

https://technet.microsoft.com/en-us/library/cc512680.aspx

By default, the data recovery agent is defined to be the administrator account. On stand-alone workstations and workgroup machines, the administrator account is the local administrator; on domain-joined machines, the administrator account is the first domain controllerโ€™s administrator account.

  • Sep 06, 2015
  • RIRG
  • Colombia
  • Sep 04, 2015

New question, Does anyone know the answer for this question?

You have a group managed Service Account name Account01. Only three servers named Server01, Server02 and Server03 are allowed to use Account01 service account.
You plan to decommission Server01.
You need to prevent Server01 from using the Account01 service account. The solution must ensure that Server02 and Server03 continue to use the Account01 service account
What command should you run? To answer, select the appropriate options in the answer area.

Answer :

a. Set-ADServiceAccount
b. Uninstall-ADServiceAccount
c. remove-ADServiceAccount
D. ???

  • Sep 04, 2015
  • RIRG
  • Colombia
  • Sep 04, 2015

Please, anyone have the right answer for this questions ?

File1 has been encrypted by Contoso\admin1
File2 has been encrypted by Server1\admin1
File3 has been encrypted by Server1\administrator

You need to back up the DRA agents.
Who is the owner of each of the agents.

There is a selection of drop down boxes. You should to select one in every file
File1 : Contoso\admin
Contoso\administrator
Server1\admin1
Server1\administrator

File2 : Contoso\admin
Contoso\administrator
Server1\admin1
Server1\administrator

File3 : Contoso\admin
Contoso\administrator
Server1\admin1
Server1\administrator

  • Sep 04, 2015
  • sameer
  • Sri Lanka
  • Sep 04, 2015

I sat the exam today and I Failed only 29 question from this dump so do not depend on this dump refer some new dumps which contain NPS, NAS, health, wsus, DFS FSRM, VPN, all are new questions if anyone have any dumps please let me know this is my email ID shameer.anon@gmail.com

  • Sep 04, 2015
  • Josef_the_Great
  • Germany
  • Sep 03, 2015

RIRG your answer is not correct:
Is about policy of Bitlocker (Computer Configuration->Policies->Administrative Templates->Windows Components->Bitlocker Drive Encryption, click on the appropriate folder for your configuration. In this example, I'm configuring bitlocker to encrypt the OS drive.)

-PIN at startup
-Recovery save in AD
you have to choose two , the picture have this items:

Allow enhanced PINs for startup
Allow network unlock at startup
Allow Secure Boot for integrity validation
Choose how BitLocker-protected operating system drives can be recovered
Configure minimum PIN length for startup
Configure TPM platform validation profile (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2)
Configure TPM platform validation profile for BIOS-based firmware configurations
Configure TPM platform validation profile for native UEFI firmware configurations
Configure use of hardware-based encryption for operating system drives
Configure use of passwords for operating system drives
Disallow standard users from changing the PIN or password
Enable use of BitLocker authentication requiring preboot keyboard input on slates
Enforce drive encryption type on operating system drives
Require additional authentication at startup
Require additional authentication at startup (Windows Server 2008 and Windows Vista)
Reset platform validation data after BitLocker recovery
Use enhanced Boot Configuration Data validation profile

THE CORRECT ANWSER IS:
-Require Additional authentication at startup
-Choose how Bitlocker-protected os drives can be recovered
100% correct!

  • Sep 03, 2015
  • Randhir
  • Australia
  • Sep 03, 2015

Hi Rocky,

I researched all the question in these dumps. Find out right answers and find associated cmds with topics. I think questions in dumps are enough to pass exam but you need to research for right answers.

Plus get right answers for new questions posted as well. It will get you through.

Thanks

  • Sep 03, 2015
  • ajay R
  • India
  • Sep 02, 2015

Your network contains an Active Directory domain named contoso.com. The domain
contains a Web server named www.contoso.com. The Web server is available on the
Internet.
You implement DirectAccess by using the default configuration.
You need to ensure that users never attempt to connect to www.contoso.com by using
DirectAccess. The solution must not prevent the users from using DirectAccess to access
other resources in contoso.com.
Which settings should you configure in a Group Policy object (GPO)?
A. DirectAccess Client Experience Settings
B. DNS Client
C. Name Resolution Policy
D. Network Connections

ANSWER : C (Name Resolution Policy)

  • Sep 02, 2015
  • ajay
  • India
  • Sep 02, 2015

you need to identify witch security principal are authorized to have their password cashed on rodc1

answer = Get-ADdomaincontrollerPasswordReplicationPolicy

  • Sep 02, 2015
  • pangchn
  • New Zealand
  • Sep 02, 2015

Finally pass with 700+ at my 4th shot in 411, Thanks to all here.
Share some question in the exam:

1.Create a starter gpo call Starter_GPO, and assign edit permission to a group Group1
Create a new gpo called GPO1
which the following answer is correct
A.*** in GPO1
B.change Administrative Template in GPO1
C.change the Group policy preference of Starter_GPO
D.change the permission of Starter_GPO
Someone said answer is C, I also choose A in the exam, but not sure for the correct answer

2.want to encypt a drive without TPM.
The correct answer is
Require additional authentication at startup
because I got 100% in this section

3.when install a new WSUS server,can not choose the France language.
The correct answer is:
change language in upstream server

4.a modify question about DSC1, in vce ask to change the path. in exam ask to export to another server
Correct answer is:
Save Template

  • Sep 02, 2015
  • Josh from UK
  • United Kingdom
  • Sep 01, 2015

Passed today with 7XX. Studied Angus, Mary and new questions posted here. Here is what I remember:

- q127 from Angus but replaced .mp3 with .avi
- q98 from Angus but processing order was switched to match policy number i.e. Policy 1 had processing order 1 now.
-question similar to q147 from Angus. This time interrupt time was 2%, no privileged time bar and Processor information % was 98. Options were driver malfunction, insufficient ram, insufficient processors and excessive paging.

  • Sep 01, 2015
  • Metry Smaan
  • Egypt
  • Sep 01, 2015

Peter could you please give me the answers for the new questions as i fail in this exam in it

  • Sep 01, 2015
  • Mark
  • Netherlands
  • Sep 01, 2015

is this dump still valid?

  • Sep 01, 2015
  • Derrick Lafayette
  • United States
  • Aug 31, 2015

Need new dump can you break that down once more, I got confused on which questions for which dump. Is 38 a nat question?

  • Aug 31, 2015
  • Muldi
  • Poland
  • Aug 31, 2015

@RIRG
Correct answers for Your question:
"Is about policy of Bitlocker (Computer Configuration->Policies->Administrative Templates->Windows Components->Bitlocker Drive Encryption, click on the appropriate folder for your configuration. In this example, I'm configuring bitlocker to encrypt the OS drive.

-PIN at startup
-Recovery save in AD
you have to choose two:"
- Choose how BitLocker-protected operating system drives can be recovered
- Require additional authentication at startup

  • Aug 31, 2015
  • RJ
  • India
  • Aug 30, 2015

I took the exam and these questions were there;

Your network contains an Active Directory domain named contoso.com. The domain
contains a Web server named www.contoso.com. The Web server is available on the
Internet.
You implement DirectAccess by using the default configuration.
You need to ensure that users never attempt to connect to www.contoso.com by using
DirectAccess. The solution must not prevent the users from using DirectAccess to access
other resources in contoso.com.
Which settings should you configure in a Group Policy object (GPO)?
A.
DirectAccess Client Experience Settings
B.
DNS Client
C.
Name Resolution Policy
D.
Network Connections

You have Windows Server 2012 R2 installation media that contains a file named
Install.wim. You need to identify the permissions of the mounted images in Install.wim.
What should you do?
A.
Run dism.exe and specify the /get-mountedwiminfo parameter.
B.
Run imagex.exe and specify the /verify parameter.
C.
Run imagex.exe and specify the /ref parameter.
D.
Run dism.exe and specify the/get-imageinfo parameter.

  • Aug 30, 2015
  • Neednewdump
  • United States
  • Aug 30, 2015

Q6,7,10,13,14,15 mary, 18,21,22,26, 27rem,29,30,38 nat,42,44,45,63,83,84,86,90,95,99,103,112,115,117,126,
127, you need to tell a technician how to add french and English lanage to your server how would you do that,145,153,168,173,174,178,187,190,191,192,195

Angus Q6,10,q27,29,31,32,37,38,42,44,104,105,109,121,124,126,138,140,147,150, mapping drives x and y do nothing if created already, or ipdate delete replace not sure, because it was plain as jane. 159,161,162,,179,180,187

Anette q7,38,q50
These questions are on the the test, that I took its not much, but it may help

I had a question about cloning domains some online and some off line, these are identical to what I had and a couple very simular, I had alot of PSOs on my second go around of this damn test.

This test was completely different from my first go at it,

  • Aug 30, 2015
  • Need updated dumps
  • United States
  • Aug 29, 2015

I had questions about cloning domains online and off,

I had a question about LDAP

Bitlocker on and off

  • Aug 29, 2015
  • Iceman
  • United Kingdom
  • Aug 29, 2015

I've just quickly been through the practice Tests and at first I thought they were all new questions but most of them actually came from Angus's dump. I would say around 30+ and then around 10-15 new questions. So Glad I spent most of my time looking at Mary's

  • Aug 29, 2015
  • ICEMAN
  • United Kingdom
  • Aug 29, 2015

Failed again today - Lots of new questions.

Only had a couple of the RODC ones from the ones already mentioned. They have added some more RODC ones asking about finding out who can authentic with the RODC.

Lots of NPS questions and multiple choice ones.

  • Aug 29, 2015
  • Muza
  • India
  • Aug 29, 2015

Wrote today, failed, got 600. Studied angus, snowden and many online questions. Also the new questions posted by Peter. But none of them came and again new 15 questions. Some questions came from angus also had changed answer options. I believe Microsoft have 50 new questions set on server, and whoever writes exam gets randomly new questions along with old. old dumps can only provide unto 60-70% questions, rest is all NEW. This is getting hell difficult to pass this exam. We want new dumps for those new questions. and sorry I don't remember full questions which I got.
I remember some,
virtual cloning of RODC
some from firewall port- options were 443, 33689, 80

I suggest not to write this exam until valid dumps come out

  • Aug 29, 2015
  • M.H
  • Egypt
  • Aug 29, 2015

if anyone passed this exam last week please post the new questions which outside the dump

thx

  • Aug 29, 2015
  • RIRG
  • Colombia
  • Aug 28, 2015

I failed today 640.
new question, something like:Is about policy of Bitlocker (Computer Configuration->Policies->Administrative Templates->Windows Components->Bitlocker Drive Encryption, click on the appropriate folder for your configuration. In this example, I'm configuring bitlocker to encrypt the OS drive.)

-PIN at startup
-Recovery save in AD
you have to choose two , the picture have this items:

Allow enhanced PINs for startup
Allow network unlock at startup
Allow Secure Boot for integrity validation
Choose how BitLocker-protected operating system drives can be recovered
Configure minimum PIN length for startup
Configure TPM platform validation profile (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2)
Configure TPM platform validation profile for BIOS-based firmware configurations
Configure TPM platform validation profile for native UEFI firmware configurations
Configure use of hardware-based encryption for operating system drives
Configure use of passwords for operating system drives
Disallow standard users from changing the PIN or password
Enable use of BitLocker authentication requiring preboot keyboard input on slates
Enforce drive encryption type on operating system drives
Require additional authentication at startup
Require additional authentication at startup (Windows Server 2008 and Windows Vista)
Reset platform validation data after BitLocker recovery
Use enhanced Boot Configuration Data validation profile

My answer was:
Allow enhanced PINs for startup
Allow Secure Boot for integrity validation

  • Aug 28, 2015
  • lilly
  • United States
  • Aug 28, 2015

I think the answer is: Get-ADAccountAuthorizationGroup

https://social.technet.microsoft.com/Forums/scriptcenter/en-US/9af9e2f0-4430-4af5-bedb-2e100ea0638c/error-when-running-getadaccountauthorizationgroup-cmdlet?forum=winserverpowershell

Can anyone confirm?

for this one:

you need to identify witch security principal are authorized to have their password cashed on rodc1

  • Aug 28, 2015
  • Bobo
  • Netherlands
  • Aug 28, 2015

I am more than happy to create a new dump/VCE. To do that I have to gather the new questions from here and its quite some work. Anybodu alrwady gathered this and can send me a text file or something? I will create a VCE with the correct answer, explanation of the answer (if possible and necessary) and the related technet article (if possible)

I already did it for 410 but until now they did not make my VCE available.But it will come next week I think.

  • Aug 28, 2015
  • Lhong
  • Thailand
  • Aug 28, 2015

first question from Haqqani

answer, Get-ADDomainControllerPasswordReplicationPolicyUsage

refer. https://technet.microsoft.com/en-us/library/ee617194.aspx

  • Aug 28, 2015
  • AnakNgTeteng
  • Philippines
  • Aug 28, 2015

Any new dumps please? is there any compilation of the new questions below? Thanks!

  • Aug 28, 2015
  • JRueda
  • Colombia
  • Aug 27, 2015

Does anyone know the answer for this question. A or D?

Note: This Question is part of series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in the series. Information and detailed provided in a question apply only to that question.
You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1.
The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2.
You need to identify which domain controller must be online when cloning a domain controller.
Which cmdlet should you use?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy


second question:
is AdDomain?
What are the prerequisites to make sure an RODC is able to be cloned?

  • Aug 27, 2015
  • JRueda
  • Colombia
  • Aug 27, 2015

failed today with 670. One new question about bitlocker. I donยดt remember the question but the answer is a picture with policy, is this:
Computer Configuration->Policies->Administrative Templates->Windows Components->Bitlocker Drive Encryption->Operating system Drives.

you have to select one:

Allow network unlock at startup
Allow Secure Boot for integrity validation
Require additional authentication at startup
Require additional authentication at startup (Windows Server 2008 and Windows Vista)
Disallow standard users from changing the PIN or password
Enable use of BitLocker authentication requiring preboot keyboard input on slates
Allow enhanced PINs for startup
Configure minimum PIN length for startup
Configure use of hardware-based encryption for operating system drives
Enforce drive encryption type on operating system drives
Configure use of passwords for operating system drives
Choose how BitLocker-protected operating system drives can be recovered
Configure TPM platform validation profile for BIOS-based firmware configurations
Configure TPM platform validation profile (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2)
Configure TPM platform validation profile for native UEFI firmware configurations
Reset platform validation data after BitLocker recovery
Use enhanced Boot Configuration Data validation profile

  • Aug 27, 2015
  • Lhong
  • Thailand
  • Aug 27, 2015

Refer to Peter questions, Here should be correct answers.

1. Microsoft Report Viewer 2008 Redistributable Package
Microsoft .Net Framework 2.0

2. From the Automatic Approvals options, modify the advanced settings.

3. Set-ADServiceAccount -Name Account01 -PrincipalsAllowedToRetrieveManagedPassword Server02 Server03

4. Get-ADDomain

5. Get-ADOptionalFeature

6. Get-ADDomain

7. Get-ADDomainControllerPasswordReplicationPolicyUsage

8. Force tunneling is enabled.

9. Install-WindowsFeature

10. Run Set-KDSConfiguration and then run New-ADServiceAccount โ€“Name โ€œservice01โ€ โ€“DNSHostName service01.contoso.com

  • Aug 27, 2015
  • Khalid
  • Oman
  • Aug 27, 2015

What about the premium guys?

  • Aug 27, 2015
  • Rocky
  • Canada
  • Aug 25, 2015

Hi Randhir. Can you explain in detail that how did you passed it and if you remember new questions then post it please

  • Aug 25, 2015
  • Haqqani
  • India
  • Aug 25, 2015

Hi ALL ,Yesterday i took this exam failed 580.I was shock I thought 80 % i will get need be careful.you should have clarity in Concept and question.New question are 6 to 7 came from this comments around 4 new question i found
.In this VCE some answers are wrong.Question are reworded should be very careful
i remberber two question
1).You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1.
The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2.
You need to identify which user accounts password policy were authenticated by RODC1.
Which cmdlet should you use?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy

2) WSUS installation update trough SSl

a) Wsustil.exr use ssl
i don't rembeber remaining option

I am writing again on saturday .plz all post as much as new question

  • Aug 25, 2015
  • tboy
  • Netherlands
  • Aug 25, 2015

@Rocky are you creating a new dump?

  • Aug 25, 2015
  • Sacriestory
  • Mexico
  • Aug 24, 2015

Hey Guys, the 411 exam from Microsoft is freaky hard. I failed today Terrible, just 4 question from here and just 1 for Wish1. tottaly different

  • Aug 24, 2015
  • John Milad
  • Egypt
  • Aug 24, 2015

This dump is not valid in Egypt too

  • Aug 24, 2015
  • John Milad
  • Egypt
  • Aug 24, 2015

The dump is invalid in Egypt too.

  • Aug 24, 2015
  • Rocky
  • Canada
  • Aug 23, 2015

Hi, New questions are coming. So really need to work hard. Recently took exam but still... IF you know new questions post it asap

  • Aug 23, 2015
  • Shlok_007
  • India
  • Aug 22, 2015

You have a group managed Service Account name Account01. Only three servers named Server01, Server02 and Server03 are allowed to use Account01 service account.
You plan to decommission Server01.
You need to prevent Server01 from using the Account01 service account. The solution must ensure that Server02 and Server03 continue to use the Account01 service account
What command should you run? To answer, select the appropriate options in the answer area.

Answer : Set-ADServiceAccount -Name Account01 -PrincipalsAllowedToRetrieveManagedPassword Server02 Server03


https://technet.microsoft.com/en-us/library/jj128431.aspx

read this url and under it read decommission of a member from farm.

  • Aug 22, 2015
  • Vu
  • Vietnam
  • Aug 22, 2015

Passed at 700 on Friday.
I studied ADELINE only (this dump gives me 100% correct answer on NPS section), and updated new questions which people mentioned.
I can remember some new questions but can't remember the answer choices:
1/ an aministrative template was already in Central Store. When you create and edit a new GPO, you receive an error says it can't find the template file. What is the problem?

2/ which tools to export DFS file, DFS database?

3/ NT Service\ > what type is this service account? What right to run this service account?

Some old questions are already in the dump but were changed a little bit, so be carefull to read it and check the answer.

  • Aug 22, 2015
  • Randhir
  • Australia
  • Aug 22, 2015

Hi Guys,

Yesterday I passed with 7XX plus. My tip is to do lot of search on all the topic. Practice questions are exam question have lots of difference.

Good luck everyone.

I would like to thank everyone who posted new questions helped passing this exam.

Thanks

  • Aug 22, 2015
  • Vu
  • Vietnam
  • Aug 22, 2015

Passed at 700 on Friday.
I studied ADELINE only (this dump gives me 100% correct answer on NPS section), and updated new questions which people mentioned.
I can remember some new questions but can't remember the answer choices:
1/ an aministrative template was already in Central Store. When you create and edit a new GPO, you receive an error says it can't find the template file. What is the problem?

2/ which tools to export DFS file, DFS database?

3/ NT Service\ > what type is this service account? What right to run this service account?

Some old questions are already in the dump but were changed a little bit, so be carefull to read it and check the answer.

  • Aug 22, 2015
  • Sergio - Brazil
  • Brazil
  • Aug 22, 2015

Hello folks,
Does anyone know the answer for this question pls?

Q10: You have the following Windows PowerShell output.
PS C:\Users\Administrator> New-AdServiceAccount service01 โ€“DNSHostName service01.contoso.com New-ADServiceAccount : Key does not exist
At line : 1 char : 1
+ New-ADServicAccount service01
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: {CN=service01,CNโ€ฆ =contoso,DC=com:String} [New-ADServiceAccount], ADException
+FullyQualifiedErrorId :
ActiveDirectoryserver : -2146893811,Microsoft. ActiveDirectory . Management . Commands . NewADServiceAccount

You need to create a Managed service Account.
What should you do?

A. Run Set-KDSConfiguration and then run New-ADServiceAccount โ€“Name โ€œservice01โ€ โ€“DNSHostName service01.contoso.com

B. Run New-AuthenticationPolicySilo, and then run New-ADServiceAccount โ€“ Name โ€œservice01โ€ โ€“ DNSHostName

C. Run New-ADServiceAccount - Name โ€œservice01โ€ โ€“ DNSHostName service01.contoso.com โ€“ RestrictToSingleComputer

D. Run New-ADServiceAccount - Name โ€œservice01โ€ โ€“ DNSHostName service01.contoso.com โ€“ SAMAccountName service01.

  • Aug 22, 2015
  • klosedotorg
  • United States
  • Aug 21, 2015

Same score in my second shot: 670

  • Aug 21, 2015
  • NunoFCPorto
  • Portugal
  • Aug 21, 2015

Rocky the reply of your question is Set-ADServiceAccount -SAMAccountNAme Server02,Server03
-Server Server02$,Server03$ because that command configure the account service on that servers

  • Aug 21, 2015
  • NunoFCPorto
  • Portugal
  • Aug 20, 2015

The comment of the Rocky is option A

  • Aug 20, 2015
  • Derrick Lafayette
  • United States
  • Aug 20, 2015

Rocky I believe the answer is: Remove-ADServiceAccount -DNSHostName Server01

  • Aug 20, 2015
  • Frank
  • Australia
  • Aug 20, 2015

Rocky Answer is below
Set-ADServiceAccount -Name Account01 -PrincipalsAllowedToRetrieveManagedPassword Server02 Server03

  • Aug 20, 2015
  • Rocky
  • Canada
  • Aug 20, 2015

You have a group managed Service Account name Account01. Only three servers named Server01, Server02 and Server03 are allowed to use Account01 service account.
You plan to decommission Server01.
You need to prevent Server01 from using the Account01 service account. The solution must ensure that Server02 and Server03 continue to use the Account01 service account
What command should you run? To answer, select the appropriate options in the answer area.

Answer Area Account01
Remove-ADServiceAccount -DNSHostName Server01
Reset-ADServiceAccount -PrincipalsAllowedToReteriveMamagedPassword Server01$
Set-ADServiceAccount -SAMAccountNAme Server02,Server03
-Server Server02$,Server03$

Anyone know exact answer ??

  • Aug 20, 2015
  • Rocky
  • Canada
  • Aug 20, 2015

You need to identify which domain controller must be online when cloning a domain controller. Which cmdlet should you use? Ans is D

Randhir : answer is C

  • Aug 20, 2015
  • Frank
  • Australia
  • Aug 19, 2015

Sat the exam again and got a 685. A lot of the old questions have been reworded.

Got a question that said

File1 has been encrypted by Contoso\admin1
File2 has been encrypted by Server1\admin1
File3 has been encrypted by Server1\administrator

You need to back up the DRA agents.
Who is the owner of each of the agents.

There is a selection of drop down boxes.

  • Aug 19, 2015
  • Jamie
  • Netherlands
  • Aug 19, 2015

@Dumi

Answer for Q305 is Get-ADDomain you need to locate the PDC

  • Aug 19, 2015
  • Dumi
  • United States
  • Aug 19, 2015

NEW QUESTION 305
Note: This Question is part of series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in the series. Information and detailed provided in a question apply only to that question.
You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1. The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2. You need to identify which domain controller must be online when cloning a domain controller. Which cmdlet should you use?
A.ย ย ย  Get-ADGroupMember
B.ย ย ย  Get-ADDomainControllerPasswordReplicationPolicy
C.ย ย ย  Get-ADDomainControllerPasswordReplicationPolicyUsage
D.ย ย ย  Get-ADDomain
E.ย ย ย  Get-ADOptionalFeature
F.ย ย ย  Get-ADAccountAuthorizationGroup
G.ย ย ย  Get-ADAuthenticationPolicySlio
H.ย ย ย  Get-ADAuthenticationPolicy
Answer: A
NEW QUESTION 306
Note: This Question is part of series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in the series. Information and detailed provided in a question apply only to that question.
You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1. The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2. You need to identify whether deleted objects can be recovered from the Active Directory Recycle Bin. Which cmdlet should you use?
A.ย ย ย  Get-ADGroupMember
B.ย ย ย  Get-ADDomainControllerPasswordReplicationPolicy
C.ย ย ย  Get-ADDomainControllerPasswordReplicationPolicyUsage
D.ย ย ย  Get-ADDomain
E.ย ย ย  Get-ADOptionalFeature
F.ย ย ย  Get-ADAccountAuthorizationGroup
G.ย ย ย  Get-ADAuthenticationPolicySlio
H.ย ย ย  Get-ADAuthenticationPolicy
Answer: E
NEW QUESTION 307
Note: This Question is part of series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in the series. Information and detailed provided in a question apply only to that question.
You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1. The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2. You need to identify whether the members of the protected Users group will be prevented from authenticating by using NTLM. Which cmdlet should you use?
A.ย ย ย  Get-ADGroupMember
B.ย ย ย  Get-ADDomainControllerPasswordReplicationPolicy
C.ย ย ย  Get-ADDomainControllerPasswordReplicationPolicyUsage
D.ย ย ย  Get-ADDomain
E.ย ย ย  Get-ADOptionalFeature
F.ย ย ย  Get-ADAccountAuthorizationGroup
G.ย ย ย  Get-ADAuthenticationPolicySlio
H.ย ย ย  Get-ADAuthenticationPolicy
Answer: D

  • Aug 19, 2015
  • Randhir Singh
  • Australia
  • Aug 18, 2015

Can someone confirm answer for following question:


Your network contains an Active Directory domain named contoso.com. All domaincontrollers run Windows Server 2012 R2. One of the domain controllers is named DC1. The DNS zone for the contoso.com zone is Active Directory-integrated and has the defaultsettings. A server named Server1 is a DNS server that runs a UNIX-based operating system. You plan to use Server1 as a secondary DNS server for the contoso.com zone.
Question No : 189
Microsoft 70-411 : Practice Test"A Composite Solution With Just One Click" - Certification Guaranteed257


You need to ensure that Server1 can host a secondary copy of the contoso.com zone. What should you do?
A.
From DNS Manager, modify the Advanced settings of DC1.
B.
From DNS Manager, modify the Zone Transfers settings of the contoso.com zone.
C.
From Windows PowerShell, run the Set-DnsServerForwardercmdlet and specify thecontoso.com zone as a target.
D.
From DNS Manager, modify the Security settings of DC1

  • Aug 18, 2015
  • Tpl
  • Poland
  • Aug 18, 2015

@ICEMAN

In reference to questions: "You need to identify whether the members of the protected Users group will be prevented from authenticating by using NTLM."

I think:
Forest functional level is 2012 not domain. We don't know what the level has domain.

  • Aug 18, 2015
  • hay13
  • United States
  • Aug 18, 2015

Will post all the questions that I have seen in the thread by summarizing them together and I would really appreciate it if everyone could jump in to answer or confirm that the questions the faster everyone pitches in the faster we will be able to get this test done with. Team work!!!

  • Aug 18, 2015
  • Macky
  • Canada
  • Aug 17, 2015

You need to ensure that user settings are saved...

answer is C

To set up Roaming User Profiles on user accounts

โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“

1.In Active Directory Administration Center, navigate to the Users container (or OU) in the appropriate domain.

2.Select all users to which you want to assign a roaming user profile, right-click the users and then click Properties.

3.In the Profile section, select the Profile path: checkbox and then enter the path to the file share where you want to store the userโ€™s roaming user profile, followed by %username% (which is automatically replaced with the user name the first time the user signs in). For example:

\\fs1.corp.contoso.com\User Profiles$\%username%

To specify a mandatory roaming user profile, specify the path to the NTuser.man file that you created previously, for example, \\fs1.corp.contoso.com\User Profiles$\default. For more information, see Creating a Mandatory User Profile.

4.Click OK.

  • Aug 17, 2015
  • Phil
  • Ireland
  • Aug 17, 2015

1) How do you enable SSL for downstream wsus server.
On the WSUS server, run the command:

wsusutil configuressl certificateName

https://technet.microsoft.com/en-us/library/cc708467(v=ws.10).aspx

  • Aug 17, 2015
  • Apex
  • South Africa
  • Aug 17, 2015

Randhir the answer is C:From the properties of each user account, configure the User profile settings.

  • Aug 17, 2015
  • Derrick Lafayette
  • United States
  • Aug 17, 2015

Randhir the Answer is C

  • Aug 17, 2015
  • joel
  • Mauritius
  • Aug 17, 2015

Any one for latest dump..please

  • Aug 17, 2015
  • Apex
  • South Africa
  • Aug 17, 2015

I wrote the exam on friday failed with 655. I studied Angus and preety much had questions from that file and 10 of these new questions. The answers for these new questions are not correct. thank you very much for help peter, volvo and others.

  • Aug 17, 2015
  • Randhir
  • Australia
  • Aug 17, 2015

Can anyone confirm right answer for this question.


Your network contains an Active Directory domain named adatum.com. The domain
contains a file server named Server1 that runs Windows Server 2012 R2.
All client computers run Windows 7.
You need to ensure that user settings are saved to \\Server1 \Users\.
What should you do?

A.
From the properties of each user account, configure the Home folder settings.

B.
From a Group Policy object (GPO), configure the Folder Redirection settings.

C.
From the properties of each user account, configure the User profile settings.

D.
From a Group Policy object (GPO), configure the Drive Maps preference.

  • Aug 17, 2015
  • VIRII
  • Netherlands
  • Aug 17, 2015

Just failed with 685...

  • Aug 17, 2015
  • Kamote
  • Philippines
  • Aug 17, 2015

This dump is no longer valid.

A lot of CMDLet questions are in the exam. I only got 511. :(

  • Aug 17, 2015
  • Red
  • United States
  • Aug 14, 2015

Some new questions:
1) How do you enable SSL for downstream wsus server.
2) How do you limit which downstream wsus servers that can get updates from the upstream server.
3) Image of an an empty PoliciyDefinitions folder in SYSVOL. Is the Central Store enabled? Image of a GPO with no settings under Administrative Templates, but the Administrative templates are local on the computer. What happens if you delete the PolicyDefinitions folder in SYSVOL, do the settings appear in the GPO? How about if you create a new GPO, do the settings appear under administrative templates for that new GPO?

  • Aug 14, 2015
  • Daniel
  • Hungary
  • Aug 14, 2015

I failed today with 670 but i thought i got it...
Some new questions i can recall:
-DNS SPF record
4 answer: NS, MX, TXT, ?
I guess it was txt
https://support.office.com/en-za/article/Create-DNS-records-for-Office-365-using-Windows-based-DNS-9eec911d-5773-422c-9593-40e1147ffbde?ui=en-US&rs=en-ZA&ad=ZA

Export DFS question:
Which tool to use to (drop down menu):
Export files
Export datebase

There was a service user question with a panel like this:
http://www.coretechnologies.com/WindowsServices/services-control-panel-log-on-tab.jpg
but the user name was nt service\service
You had to define what kind of user account and service account is it (drop down menu)

And there were 2 new RODC question the answers are the same.
1. Which DC were authorized for virtual dc cloning or something like this.
2. Which security principals have their pasword cached on the RODC-s or something like this.

  • Aug 14, 2015
  • Daniel
  • Hungary
  • Aug 14, 2015

Please don't ask every day if this dump is valid or not. You only have to read the comments to know that they are not valid.

  • Aug 14, 2015
  • Deckard
  • Brazil
  • Aug 13, 2015

This is valid in Brazil ? tips for studies?

  • Aug 13, 2015
  • Charles - BZL
  • United States
  • Aug 13, 2015

Hello folks,
I felt my exam yesterday 08/12 easy, with the questions of Mary and Snowden plus the questions of Peter (France) but at the end I failed with 660 I got surprised. We need or wait new dumps or really solve the questions of Peter. However, the ideal would be to do the exam as soon as possible otherwise we will need to starting studying all over again.

  • Aug 13, 2015
  • Roel
  • Netherlands
  • Aug 13, 2015

Failed today with 685!

Waiting for the new dumps, because I failed on these questions. There's something about them witch make the actual answers diferent then we all think. All other categories scored between 800 and 100. New questions count for 40% in my exam

  • Aug 13, 2015
  • Steve
  • United States
  • Aug 13, 2015

Does anyone know if the new passguide might have the new questions. I just saw it was last updated on there site on 08\03...Just Curious

  • Aug 13, 2015
  • human
  • United States
  • Aug 13, 2015

tested today on 12-AUG-2015 and to be honest, most of the questions came from Mary's exam and what Peter posted below...this felt like the easiest exam despite what others are saying HOWEVER, I failed with a 4XX. I was surprised. Outside the dump and the new questions posted here, there were like 5 new I'd not seen, like a 3 drop down question involving file01/02/03.docx files, or a two part bitlocker exhibit. Felt like the ones I missed counted the most, or I just aced a bunch of wrong answers lol

  • Aug 13, 2015
  • Charles - BZL
  • Brazil
  • Aug 13, 2015

I failed today with 660. I studied Snowden and Mary. We really need to get the correct answers for the questions of Peter (France). If we get the correct answers it's possible to pass

  • Aug 13, 2015
  • Iceman
  • United Kingdom
  • Aug 12, 2015

Q6: Note: This Question is part of series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in the series. Information and detailed provided in a question apply only to that question.
You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1.
The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2.
You need to identify whether the members of the protected Users group will be prevented from authenticating by using NTLM.
Which cmdlet should you use?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy

Im an idiot and its late at night - You have to check the domain functional level first.

Therefore its D!

  • Aug 12, 2015
  • Iceman
  • United Kingdom
  • Aug 12, 2015

Q7: Note: This Question is part of series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in the series. Information and detailed provided in a question apply only to that question.
You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1.
The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2.
You need to identify which user accounts were authenticated by RODC1.
Which cmdlet should you use?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy

Get-ADDomainControllerPasswordReplicationPolicyUsage

Gets the Active Directory accounts that are authenticated by a read-only domain controller or that are in the revealed list of the domain controller.

https://technet.microsoft.com/en-us/library/hh852193(v=wps.630).aspx

  • Aug 12, 2015
  • Iceman
  • United Kingdom
  • Aug 12, 2015

Q5: Note: This Question is part of series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in the series. Information and detailed provided in a question apply only to that question.
You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1.
The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2.
You need to identify whether deleted objects can be recovered from the Active Directory Recycle Bin.
Which cmdlet should you use?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy

You need to see if the feature is turned on. Therefore it is Get-ADOptionalFeature

  • Aug 12, 2015
  • Iceman
  • United Kingdom
  • Aug 12, 2015

@Roel

@Peter (and the rest of yall)

Don't fall for this one!! NTLM is not allowed in 2012 R2 for protected users! Thing is that you must look up the Domain Functional Level to see if it is 2012R2!.
Answer should be: get-AdDomain (to see the functional level).

It tells you the functional level of the domain in the Questions - Its Server 2012 - Therefore you don't need to check the level.

Get-ADAuthenticationPolicy will show you the policy's.

  • Aug 12, 2015
  • Iceman
  • United Kingdom
  • Aug 12, 2015

Q7: Note: This Question is part of series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in the series. Information and detailed provided in a question apply only to that question.
You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1.
The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2.
You need to identify which user accounts were authenticated by RODC1.
Which cmdlet should you use?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy

Simple Internet Checks confirms the answer is C:

Gets the Active Directory accounts that are authenticated by a read-only domain controller or that are in the revealed list of the domain controller.

  • Aug 12, 2015
  • lcfrancoi
  • Brazil
  • Aug 12, 2015

This dump still valid?

  • Aug 12, 2015
  • Lyle
  • South Africa
  • Aug 12, 2015

Hey people. Below is a list I have compiled from the previous comments to the new questions. Feel free to correct any answers that you have researched or are 100% sure is the correct answer. Thanks

  • Aug 12, 2015
  • Roel
  • Netherlands
  • Aug 12, 2015

@Derrick Lafayette,

To answer you question: C. Get-ADDomainControllerPasswordReplicationPolicyUsage

This will get you a list of all the passwords that have been replicated to the RODC.
The RODC caches these when users get authenticated by this DC.

  • Aug 12, 2015
  • PeterXu
  • Canada
  • Aug 11, 2015

Hi All,

I recall there is one question about what kind of DNS record to be created, so that the new added server can send or receive email. don't remember the detail. My guess to that question is MX record. But I am not sure.

  • Aug 11, 2015
  • Derrick Lafayette
  • United States
  • Aug 11, 2015

Thanks Roel. I was stuck on that question for a while. What did you get for this question?

Q7: Note: This Question is part of series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in the series. Information and detailed provided in a question apply only to that question.
You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1.
The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2.
You need to identify which user accounts were authenticated by RODC1.
Which cmdlet should you use?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy

I believe the answer is C.

  • Aug 11, 2015
  • Roel
  • Netherlands
  • Aug 10, 2015

@Peter (and the rest of yall)

Don't fall for this one!! NTLM is not allowed in 2012 R2 for protected users! Thing is that you must look up the Domain Functional Level to see if it is 2012R2!.
Answer should be: get-AdDomain (to see the functional level).

Q6: Note: This Question is part of series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in the series. Information and detailed provided in a question apply only to that question.
You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1.
The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2.
You need to identify whether the members of the protected Users group will be prevented from authenticating by using NTLM.
Which cmdlet should you use?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy

  • Aug 10, 2015
  • ibrahim
  • Kuwait
  • Aug 10, 2015

is this dump still valid

  • Aug 10, 2015
  • Shahin Hosain
  • Bangladesh
  • Aug 09, 2015

Is this valid in Bangladesh
I want to seat tomorrow.

  • Aug 09, 2015
  • Gal Sela
  • Israel
  • Aug 08, 2015

Hi Peter,

Regarding the questions you added, Question 3 I believe missing an answer, there sould be another option Uninstall-ADDServiceAccount, Can you confirm that plz ?

  • Aug 08, 2015
  • Ahmad
  • United Arab Emirates
  • Aug 08, 2015

Thank you so much Peter (France). I remember those questions were exactly the ones in my first shot. But I am also quite sure that they are not the only ones. I would really appreciate if you could post the remaining ones too if you have or any one else who witness them. Many thanks again for your efforts!

  • Aug 08, 2015
  • saudi arabia
  • Saudi Arabia
  • Aug 08, 2015

some of the new questions
1- you need to identify witch security principal are authorized to have their password cashed on rodc1

2- how to export DFS files
and DFS database

  • Aug 08, 2015
  • Tamer
  • Egypt
  • Aug 08, 2015

@peter .. we need the answers as well :)
Than Q

  • Aug 08, 2015
  • Rach
  • Belgium
  • Aug 08, 2015

hello, do you have the answer for the question below?????

  • Aug 08, 2015
  • Gal Sela
  • Israel
  • Aug 07, 2015

Hi Peter, Great job i remember more than 50% of the questions from the last exam i took a week ago, Do you or anyone else have the right answer for those questions ?

thx

  • Aug 07, 2015
  • Derrick Lafayette
  • United States
  • Aug 07, 2015

My attempt to answer Peter's questions.

Question 1: A,B
Question 2: B (Guess)
Question 3: A
Question 4: A
Question 5: E
Nothing for 6 and 7
Question 8: C
Questions 9: C
For the managed Service account : C

  • Aug 07, 2015
  • ibrahim
  • Kuwait
  • Aug 07, 2015

which one is better Andus or Snowden ??

  • Aug 07, 2015
  • Peter
  • France
  • Aug 06, 2015

These are the New Question In Exam

-----------------------------------

Q1: You deploy a windows Server Update (WSUS) server named Server01.
You need to ensure that you can view update reports and computer reports on server01.
Which two components should you install? Each correct answer presents part of the solution.

A. Microsoft Report Viewer 2008 Redistributable Package
B. Microsoft .Net Framework 2.0
C. Microsoft SQL Server 2008 R2 Builder 3.0
D. Microsoft XPS Viewer
E. Microsoft SQL Server 2012 reporting Services (SSRS)

Q2: You deploy a windows Server Update (WSUS) server named Server01.
You need to prevent the WSUS service on Server01 from being updated automatically.
What should you do from the update service console?

A. From the Product and Classification options, modify the Products setting.
B. From the Automatic Approvals options, modify the Advanced settings.
C. From the Product and Classification options, modify the Classifications setting.
D. From the Automatic Approvals options, modify the Default Automatic Approval rule.


Q3: You have a group managed Service Account name Account01. Only three servers named Server01, Server02 and Server03 are allowed to use Account01 service account.
You plan to decommission Server01.
You need to prevent Server01 from using the Account01 service account. The solution must ensure that Server02 and Server03 continue to use the Account01 service account
What command should you run? To answer, select the appropriate options in the answer area.

Answer Area Account01
Remove-ADServiceAccount -DNSHostName Server01
Reset-ADServiceAccount -PrincipalsAllowedToReteriveMamagedPassword Server01$
Set-ADServiceAccount -SAMAccountNAme Server02,Server03
-Server Server02$,Server03$


Q4: Note: This Question is part of series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in the series. Information and detailed provided in a question apply only to that question.
You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1.
The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2.
You need to identify which domain controller must be online when cloning a domain controller.
Which cmdlet should you use?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy
Q5: Note: This Question is part of series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in the series. Information and detailed provided in a question apply only to that question.
You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1.
The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2.
You need to identify whether deleted objects can be recovered from the Active Directory Recycle Bin.
Which cmdlet should you use?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy

Q6: Note: This Question is part of series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in the series. Information and detailed provided in a question apply only to that question.
You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1.
The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2.
You need to identify whether the members of the protected Users group will be prevented from authenticating by using NTLM.
Which cmdlet should you use?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy


Q7: Note: This Question is part of series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in the series. Information and detailed provided in a question apply only to that question.
You network contains one Active Directory domain named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2012 R2. All client computer run Windows 8.1.
The domain contains 10 domain controllers and a read-only domain controller (RODC) named RODC01. All domain controllers and RODCs are hosted on a Hyper-V host that runs Windows Server 2012 R2.
You need to identify which user accounts were authenticated by RODC1.
Which cmdlet should you use?
A. Get-ADGroupMember
B. Get-ADDomainControllerPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicyUsage
D. Get-ADDomain
E. Get-ADOptionalFeature
F. Get-ADAccountAuthorizationGroup
G. Get-ADAuthenticationPolicySlio
H. Get-ADAuthenticationPolicy


Q8: Your Company is testing DirectAccess on Windows Server 2012 R2.
Users report that when they connect to the corporate network by using DirectAccess, access to Internet websites and Internet hosts is slow. The users report that when they disconnect from DirectAccess, acces to the internet websites and the internet hosts is much faster.
You need to identify the most likely cause of the performance issue.
What should you identify?

A. DirectAccess uses a self-signed certificate.
B. The corporate firewall blocks TCP port 8080.
C. Force tunneling is enabled.
D. The DNS suffix list is empty
Q9: Your network contains one Active Directory domain named contoso.com. The domain contains a file server named Server01 that runs Windows Server 2012 R2. Server01 has an operating system drive and a data drive. Server01 has a trusted Platform Module (TPM).
Which cmdlet should you run first?

A. Enable-TPMAutoProvisioning
B. Unblock-TPM
C. Install-WindowsFeature
D. Lock-BitLocker


Q10: You have the following Windows PowerShell output.
PS C:\Users\Administrator> New-AdServiceAccount service01 โ€“DNSHostName service01.contoso.com New-ADServiceAccount : Key does not exist
At line : 1 char : 1
+ New-ADServicAccount service01
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: {CN=service01,CNโ€ฆ =contoso,DC=com:String} [New-ADServiceAccount], ADException
+FullyQualifiedErrorId :
ActiveDirectoryserver : -2146893811,Microsoft. ActiveDirectory . Management . Commands . NewADServiceAccount

You need to create a Managed service Account.
What should you do?

A. Run Set-KDSConfiguration and then run New-ADServiceAccount โ€“Name โ€œservice01โ€ โ€“DNSHostName service01.contoso.com

B. Run New-AuthenticationPolicySilo, and then run New-ADServiceAccount โ€“ Name โ€œservice01โ€ โ€“ DNSHostName

C. Run New-ADServiceAccount - Name โ€œservice01โ€ โ€“ DNSHostName service01.contoso.com โ€“ RestrictToSingleComputer

D. Run New-ADServiceAccount - Name โ€œservice01โ€ โ€“ DNSHostName service01.contoso.com โ€“ SAMAccountName service01.

  • Aug 06, 2015
  • Randhir
  • Australia
  • Aug 05, 2015

I remember there was another question in my exam related to EFS

  • Aug 05, 2015
  • steve
  • United States
  • Aug 05, 2015

There are new questions on the test, would they ever revive questions from earlier versions of this exam? I noticed on Microsoft.actualtests.70-411.v2015-07-30.by.pt300q.vce there are older questions on this one, when I researched them I found them on boards from 2013. Just Curious

  • Aug 05, 2015
  • Gal Sela
  • Israel
  • Aug 04, 2015

as anyone recall the following questions :
1. about bitlocker decryption agent, which user name will use to decrypte ? there was a drop list and 3 cases to choose from, 1 from local account and 2 from domain account scenarios.
2. the 10 dc's and 1 rodc - a pack of 4-5 questions related RODC, it will help if someone remember the questions correctly

thx

  • Aug 04, 2015
  • Gal Sela
  • Israel
  • Aug 04, 2015

there was one question - how to add a comment in the GPO - the answer though the edit of the gpo object

  • Aug 04, 2015
  • Scat_Man
  • Djibouti
  • Aug 04, 2015

Those questions are from the dumps, we want the new questions posted

  • Aug 04, 2015
  • RIRG
  • Colombia
  • Aug 04, 2015

Hi Josef_the_Great, I think the answers are:
1. E.the Dcpromo command
2. Server 1: WDS
3. D.The referral settings of the namespace
4. D.Audit Policy\Audit object Access y F.Advanced Audit Policy Configuration\Object Access
5. C.From the Network Policy Server console, configure a Windows Security Health Validator (WSHV) policy.

  • Aug 04, 2015
  • Me
  • Hungary
  • Aug 04, 2015

1. E
2. WDS
3. D
4, D,F
5, A?

  • Aug 04, 2015
  • Randhir Singh
  • Australia
  • Aug 04, 2015

Hi Tamor,

I tried few dumps and site but unfortunately couldn't find any latest dump.

Make sure to learn all AD commands that may help in passing. If possible please upload new exam questions.

Thanks

  • Aug 04, 2015
  • Brian
  • Philippines
  • Aug 04, 2015

a lot of new questions.new dump please

  • Aug 04, 2015
  • Me
  • Hungary
  • Aug 03, 2015

Hi,

really are you using 2013 november dump? why?

  • Aug 03, 2015
  • Daniel
  • India
  • Aug 03, 2015

RODC Questins

1. You need to identify which domain controllers are authorized to be cloned by using virtual domain controller cloning

2. You need to identify whether the members of the protected Users group will be prevented from authenticating by using NTLM

3.You need to identify which security principals are authorized to have their password cached on RODC1.

which cmdlet?

  • Aug 03, 2015
  • snowy
  • China
  • Aug 03, 2015

@Kay I mean as we remembered our exam question after answered our test.One person remember one question it'll be ok for next person to answer 411 exam .

  • Aug 03, 2015
  • Tamer
  • Egypt
  • Aug 03, 2015

hi guys .. does anybody know where can i find the new questions .. or anybody took the second shot can till us what he did

  • Aug 03, 2015
  • Randhir
  • Australia
  • Aug 02, 2015

Hi Guys,

I got a question something like bullet direct Access. I dont remember the question does anyone remember that question.

Thanks

  • Aug 02, 2015
  • Randhir
  • Australia
  • Aug 01, 2015

In my exam questions there was a question related to ADSIEdit. I donn't exactly remember the question. Is there anyone remember that question.

Thanks

  • Aug 01, 2015
  • Ali
  • South Africa
  • Jul 31, 2015

This Dump is not longer valid.I studied Angus and Showden... Failed Today with 625.South Africa

  • Jul 31, 2015
  • Ahmad
  • United Arab Emirates
  • Jul 31, 2015

Whoever takes the next exam please write the exact questions. Right now all the new questions are written in confusing form. I will surely write them if I remember even if I fail. Many thanks in advance! Cheers!

  • Jul 31, 2015
  • David
  • United States
  • Jul 31, 2015

I studied the Angus and Gerald dumps and same as a lot of recent comments, about 15 or so were new out of the 49 questions in my exam.. I also failed with a 670 score. The comments about the new questions are exactly what I had in my exam.

Multiple questions about RODCs.

Which Protected Accounts use NTLM (none - protected accounts cannot use NTLM, so the accounts cannot be a member of a specific group - so the answer is GetADGroup)

AD Recycle Bin (Get-ADOptionalFeature)

To view generated reports for WSUS on Server 2012 as a minimum you'll need?
โ€ขMicrosoft report viewer 2008 distributable
โ€ข.Net Framework 2.0
See technote: http://www.genelaisne.com/viewing-reports-in-windows-server-2012-wsus/


An additional one I recall had something to do with "You get an error when creating a new Managed Service account", and it mentioned an error with a "key". Doing some research I found this technote that says you need to create a KDS Root Key first:

http://blogs.technet.com/b/askpfeplat/archive/2012/12/17/windows-server-2012-group-managed-service-accounts.aspx

Hopefully the comments already posted will help me with my exam retake next week.

  • Jul 31, 2015
  • BLUE
  • United States
  • Jul 30, 2015

I sat this two days ago. Failed by 1-2 questions. Dump is %60 valid. Some questions had different answer sets however. Had set of questions related to 10DCs and an RODC (same as volvo mentioned below). Also several bitlocker questions.

Also had a question that presented a failed powershell cmdlet for a GMSA 'key does not exist'. Answer was to run cmdlet Add-KDSRootKey first

  • Jul 30, 2015
  • Derrick Lafayette
  • United States
  • Jul 30, 2015

For the question about the WSUS firewall config, you must open port 8530, and 8531.

For the question of GPO: What PS cmd will disable site/domain policy for ou1, my guess is Remove-GPLINK

  • Jul 30, 2015
  • Randhir
  • Australia
  • Jul 30, 2015

I thinks It is very good Idea to write down new questions and solve to pass exam

  • Jul 30, 2015
Pages:  [<<]  [<]  1 2 3 4 5 6 7 8  [>]  [>>]

Add Comments

Only Registered Members Can Download VCE Files or View Training Courses

Please fill out your email address below in order to Download VCE files or view Training Courses. Registration is Free and Easy - you simply need to provide an email address.

  • Trusted By 1.2M IT Certification Candidates Every Month
  • VCE Files Simulate Real Exam Environment
  • Instant Download After Registration.
Please provide a correct e-mail address
A confirmation link will be sent to this email address to verify your login.
Already Member? Click Here to Login

Log into your ExamCollection Account

Please Log In to download VCE file or view Training Course

Please provide a correct E-mail address

Please provide your Password (min. 6 characters)

Only registered Examcollection.com members can download vce files or view training courses.

Registration is free and easy - just provide your E-mail address. Click Here to Register

SPECIAL OFFER: GET 10% OFF

ExamCollection Premium

ExamCollection Premium Files

Pass your Exam with ExamCollection's PREMIUM files!

  • ExamCollection Certified Safe Files
  • Guaranteed to have ACTUAL Exam Questions
  • Up-to-Date Exam Study Material - Verified by Experts
  • Instant Downloads
Enter Your Email Address to Receive Your 10% Off Discount Code
A Confirmation Link will be sent to this email address to verify your login
We value your privacy. We will not rent or sell your email address

SPECIAL OFFER: GET 10% OFF

Use Discount Code:

MIN10OFF

A confirmation link was sent to your e-mail.
Please check your mailbox for a message from support@examcollection.com and follow the directions.

Next

Download Free Demo of VCE Exam Simulator

Experience Avanset VCE Exam Simulator for yourself.

Simply submit your e-mail address below to get started with our interactive software demo of your free trial.

Free Demo Limits: In the demo version you will be able to access only first 5 questions from exam.