文件名称:
Microsoft-70-744.pdf
开发工具:
文件大小: 27mb
下载次数: 0
上传时间: 2019-08-31
详细说明:新鲜出炉的微软 70-744 MCSE 最后一门。分享给大家。覆盖率98%Microsoft -70-744
Your network contains an Active Directory domain named contoso. com. all domain controllers run windows
Server 2016
The domain contains a server named Serverl that has Microsoft Security Compliance Manager (SCM)4.0
installed
You export the baseline shown in the following exhibit
(2617e9b1-9672-492b-aefa0505054848c2}
个Eq7eb.6s60
Domain Sysvol
。 Backup
e bkuplnfo
3 items
You have a server named Server2 that is a member of a workgroup
You copy the(2617e9b1-9672-492b-aefa-0505054848c 2) folder to Server2
You need to deploy the baseline settings to Server2
What should you do?
A. Download, install, and then fun the lgpo exe command
B. From Group policy management import a Group Policy object(GPO)
C. From Windows power Shell. run the Restore-GPO cmdlet
D. From Windows Power Shell, run the Import-GPO cmdlet
E. From a command prompt run the secedit. exe command and specify the /import parameter
Answer: D
2of234
Microsoft -70-744
Explanation
References
https://anytecho.wordpresscom/2015/05/22/importing-group-policics-using-powershell-almost/
Question # 3
Note: This question is part of a series of questions that present the same scenario. each question in the series
contains a unique solution that might meet the stated goals. Some question sets might have more than one
correct solution, whilc others might not have a correct solution
After you answer a question in this section, you will not be able to return to It. As a result, these questions
will not appear in the review screen
Your network contains an Active directory domain named contoso. com. All servers run Windows server
2016. All client computers run Windows 10
The relevant objects in the domain are configured as shown in the following table
Server name
Object
Organizational unit(oU)name
Server1
Computer account Servers
Server 2
Computer account Servers
User1
User account
Operations Users
You nced to assign UscrI the right to restore files and folders on Scrverl and server2
Solution: You create a Group policy object(GPO), you link the gpo to the Servers oU, and then you modify
the Users rights Assignment in the gPo
Does this meet the goat?
A, Yes
B. No
Answer: B
Explanation
References
https://tcchnct.microsoftcom/en-us/library/cc771990(v=ws.11).aspx
Question # 4
You plan to use the Security and Audit solution in Microsoft Operations Management Suite (OMs)to monitor
3of234
Microsoft -70-744
servers that run Windows server 2016. The servers are prevented from accessing the Internet
You create an oms workspace and add the security and audit solution
You need to ensure that you can monitor the servers
What should you do first?
A. From Connected Sources, click Download OMS Gateway
B. From Accounts, modify the azure Subscription and data Plan setting
C. From Accounts. add an Automation account
D. From Connected Sources, click Download Windows Agent(32 bit)
Answer: B
Question #:5
You deploy the host guardian Service(hgs
You have several Hyper-V hosts that have older hardware and Trusted Platform Modules(tPms)version 1. 2
You discover that the hyper-V hosts cannot start shielded virtual machines
You need to configure hGs to ensure that the older Hyper -v hosts can host shielded virtual machines. What
should you do?
A. Run the Set-Hgs Server cmdlet and specify the -TrustTpm parameter
B. Run the set-Hgs server cmdlet and specify the TrustActiveDirectory parameter
C. Run the Clear -Hgs Server cmdlet and specify the-Clustername parameter
D. Run the Clear-HgsServer cmdlet and specify the - Force parameter
E. It is not possible to enable older Hyper-V hosts to run Shielded virtual machines
Answer: E
Explanation
Requirements and Limitations There are several requirements for using Shielded yMs and the HGS: One bare
metal host: You can deploy the shielded VMs and the hgs with just one host. However, Microsoftrecommends
that you cluster HGs for high availability. Windows Server 2016 Datacenter Edition: The ability to create and
run Shielded vms and the hgs is onlysupported by windows Server 2016 Datacenter Edition For
Admin-trusted attestation mode: You only need to have server hardware capable of running Hyper-V i
Windows Server 2016 TP5 or higher For TPM-trusted attestation: Your servers must have TPM 2.0 and UEFT
4of234
Microsoft -70-744
2.3. 1 and they must boot in UEFImode The hosts must also have secure boot enabled. Ilyper-yrole: Must be
installed on the guarded host HGS Role: Must be added to a physical host Generation 2 VMS. A fabric AD
domain. An HGS AD, which in Windows server 2016 TP5 is a separate AD infrastructure from your fabric AD
Question # 6
Your network contains an Active directory domain named contoso. com. The domain contains a file server
named serverl that runs Windows server 2016. Serverl has a shared folder named Share l
You plan to create a subfolder in Sharel for each domain user
You need to limit each user to using 100 MB of data in their respective subfolder
The solution must enable the users to be notified when they use 80 percent of the available space in the
subfolder
Which tool should you use?
A. File explorer
B. Shared Folders
C. Server manager
D. Disk management
E. Storage Explorer
F. Computer Management
G. System Configuration
H. File Server Resource Manager(FSRM)
Answer: HI
Question #: 7
YournetworkcontainstwoActiveDirectoryforestsnamedcontoso.comandadatum.com.Contoso.com
containsaHyper-vhostnamedServerl.ServerlisamemberofagroupnamedHyperhosts.Adatum.com
contains a server named Server2, serverl and server2 run windows server 2016
Contoso. com trusts adatum. com
You plan to deploy shielded virtual machines to Serverl
Which component should you install and which cmdlet should you run on Serverl? To answer, select the
appropriate options in the answer area
5of234
Microsoft -70-744
Component to install on Serverl:
The Active Directory Domain Services server role
The Host Guardian Hyper-V Support feature
The Host Guardian Service server role
Cmdlet to run on Server1
Set-Hgs configuration
Get-Hgs Attestation Policy
Export- Hgs Guardia
Import-Hgs Guardian
Answer:
Component to install on Server1:
The Active Directory domain Services server role
The Host Guardian Hyper-V Support featu
he Host Guardian Service server role Tre
Cmdlet to run on serverl
Set-Hgs Chent Configuration
Get-HgsAttestation Baseline Policy K
Export-HgsGuardian
Import-Hgs Guardian
Explanation
Component to install on Server1
The Active Directory Domain Services server role
The Host Guardian Hyper-V Support feature
The host guardian Service server role
Cmdlet to run on server1
Set-Hgs Client Configuration
Get-Hgs AttestationBaselinePolicy
Export-Hgs Guardian
Import-Hgs Guardian
KeyforthisquestionisAdmin-trustedattestationor(admodeforguardedfabric"serverl.contosO.com
6of234
Microsoft -70-744
whileserver2. adatum. com is running the lost guardian service
Hardware: One host is required for initial deployment. To test Hyper V live migration for shielded VMs, you must have at
least two hosts
Hosts must have:
o IOMMU and Second Level Address Translation (SLAD
o TPM 2.0
o UEFI 23. 1 or later
o Configured to boot using UEFI (not BIOS or"legacy"mode)
Secure boot enabled
Operating system: Windows Server 2016 Datacenter edition
IMportant
Make sure you install the latest cumulative update
Role and features: Hyper-V role and the Host Guardian Hyper-V Support feature The Host Guardian Hyper-V Support
feature is only available on Datacenter editions of windows Server 2016.
https://docs.microsoftcom/en-us/windows-server/virtualization/guarded-fabric-shielded-vm/guarded-fabricguar
https://docs.microsoftcom/en-us/windows-server/Virtualization/guarded-fabric-shielded-vm/guarded-fabricconfi
A fabric administrator needs to confirm that Hyper-v hosts can run as guarded hosts. Complete the following steps on at least one
guarded host
1. If you have not afready installed the Hyper-V role and Host Guardian Hyper-V Support feature install them with the
following command:
COpy
Install-Hindows Feature Hyper-V, HostGuardian -IncIudeManagementTools-Restart
2. Configure the host's Key Protection and Attestation URLs:
Through Windows Power Shell: You can configure the Key Protection and Attestation URLs by executing the
Following command in an elevated Windows PowerShell console For , use the Fully Qualified Domain
Name(FQDN) of your HGS cluster (for example, hgs. relecloud com, or ask the HGS administrator to run the Get-
Hgsserver cmdlet on the HGS server to retrieve the URLs)
Aset-hgsclieNtconfigurationAttestationserverur1"http://
(系统自动生成,下载前可以参看下载内容)
下载文件列表
相关说明
- 本站资源为会员上传分享交流与学习,如有侵犯您的权益,请联系我们删除.
- 本站是交换下载平台,提供交流渠道,下载内容来自于网络,除下载问题外,其它问题请自行百度。
- 本站已设置防盗链,请勿用迅雷、QQ旋风等多线程下载软件下载资源,下载后用WinRAR最新版进行解压.
- 如果您发现内容无法下载,请稍后再次尝试;或者到消费记录里找到下载记录反馈给我们.
- 下载后发现下载的内容跟说明不相乎,请到消费记录里找到下载记录反馈给我们,经确认后退回积分.
- 如下载前有疑问,可以通过点击"提供者"的名字,查看对方的联系方式,联系对方咨询.