Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a user named User1. User1 is a member of a group named Group1 and is in an organizational unit (OL)} named OU1.
The domain has minimum password lengths configured as shown in the following table.

What is the minimum password length that User1 should use when changing to a new password?
You need to configure remote administration to meet the security requirements. What should you use?
Which three actions should y ou perform in sequence to meet the security requirements for Webapp1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You are planning the implementation Azure Arc to support the planned changes. You need to configure the environment to support configuration management policies. What should you do?
You need to implement the planned change for Data1.
Which actions should you perform in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

You need to ensure that access to storage1 for the Marketing OU users meets the technical requirements.
What should you implement?
You need to ensure that Automanage meets the technical requirements.
On which Azure virtual machines should you enable Automanage?
You need to implement an availability solution for DHCP that meets the network ing requirements.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

You need to ensure that data availability on SSPace1 meets the technical requirements.
What is the maximum number of physical disks that can fail on each disk? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You need to meet technical requirements for HyperV1.
Which com mand should you run? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You need to ensure that VM3 meets the technical requirements.
What should you install first?
Which two languages can you use for Task1? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
TION NO: 240 SIMULATION
Task 1
You need to ensure that DC2 is the schema master for contoso.com.
Task 1
You need to prevent domain users from saving executable files in a share named \\SRVl\Data. The users must be able to save other files to the share.
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains the servers shown in the following table.

The domain controllers do NOT have internet connectivity.
You plan to implement Azure AD Password Pro tection for the domain.
You need to deploy Azure AD Password Protection agents. The solution must meet the following requirements:
• All Azure AD Password Protection policies must be enforced.
• Agent updates must be applied automatically.
• Administrative effort must be minimized.
What should you do? To answer select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server and has the following disks:
• OSdislcDisk1
o Size: 512 GiB
o Free space: 260 GiB
o Encryption: SSE with PMK
o Storage type: Standard SSD
• Data disk: Disk2
o Size: 512 GiB
o Free space: 45 GiB
o Storage type: Standard HDD
o Encryption: Platform-managed key
You are planning a maintenance strategy for VM1.
You need to identify which task can be performed on Disk2 without causing downtime to VM1.
What should you do on Disk2?
Your network contains two Active Directory Domain Services (AD DS) forests named contoso.com and adatum.com. A two-way external trust exists between contoso.com and adatum.com. The forests contain the servers shown in the following table.

You need to ensure that us ers from contoso.com can access only shared resources hosted on SRV1. The solution must meet the following requirements:
• Ensure that users from adatum.com can access the resources hosted in contoso.com.
• Prevent the contoso.com users from accessing any other resources in adatum.com.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You need to implement the planned changes for the Azure DNS Private Resolver.
Which private DNS zones can you use for name resolution?
Which groups can you add lo Group3 and Groups? To answer, select the appropriate options in the answer area. NOTE Each correct selection is worth one p oint.

You need to meet the security requi rements for passwords.
Where should you configure the components for Azure AD Password Protection? lo answer, drag the appropriate components to the correct locations. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE Each correct selection is worth one point.

You need to meet the technical requirements for VM3
On which volumes can you enable Data Deduplication?
Your network contains an Active Directory Domains Services (AD DS) domain named contoso.com. You implement a central s tore.
You create a new Group Policy Object (GPO) named GP01.
When you attempt to edit GP01, you see the settings shown in the exhibit. (Click the Exhibit tab.) You need to ensure that all settings are available.
Solution: You modify the properties of GPO1.
Does this meet the goal?
Which groups can you add to Group3 and Group5? To answer, select the appropriate options in the answer area.
NOTE: Each correc t selection is worth one point.

You need to meet the technical requirements for the site links. Which users can perform the required tasks?
Task 5
You need to ensure that a DHCP scope named scope! on SRV1 can service client requests.
Your network contains an on-premises Active Directory Domain Services (AD DS) domain. The domain contains a user named User1 and the servers shown in the following table.

User1 is a member of the Protected Users security group.
User1 performs the following actions:
• From Se rver1, establishes a remote PowerShell session on Server2
• From the PowerShell session on Server2, attempts to access a resource on Backup1
The request to access the resource on 8ackup1 is denied.
You need to ensure that User1 can access the resources on Backup1 by using the PowerShell session on Server2. The solution must follow the principle of least privilege and minimize administrative effort.
What should you configure?
You have a server named Server1 that runs Windows Server Server1 has a just-a-bunch-of-disks (JBOD) enclosure attached.
You plan to create a storage pool on Server1 and a virtual disk that will use a mirror layout.
You are considering whether to use a two-way or a three-wa y mirror layout.
What is the minimum number of disks required for each type of minor layout? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You need to meet the technical requirements for VM1.
Which cmdlet should you run first? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Your network contains a Active Directory Domain Service (AD DS) forest named contoso.com. The forest root domain contains a server named server1. contoso.com.
A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains.
You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com.
What should you do first?
You need to meet the technical requirements for User1. The solution must use the principle of least privilege.
What should you do?
You need to meet the technical requirements for Server4.
Which cmdlets should you run on Server1 and Server4? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have an Azure v irtual machine named VM1 that runs Windows Server. You perform the following actions on VM1:
• Create a folder named Folder1 on volume C
• Create a folder named Folder2 on volume D.
• Add a new data disk to VM1 and create a new volume that is assigned driv e letter E.
• Install an app named App1 on volume E.
You plan to resize VM1.
Which objects will present after you resize VM1?
Your on-premises network contains a single-domain Active Directory Domain Services (AD DS) forest. You have an Azure AD tenant named contoso.com. The AD DS forest syncs with the Azure AD tenant by using Azure AD Connect.
You need to ensure that users in the forest that have a custom attribute of NoSync are excluded from synchronization.
How should you configure the Azure AD Connect cloudFiltered attribute, a nd which tool should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Your network con tains an Active Domain Services (AD DS) forest. The forest contains three domains. Each domain contains 10 domain controllers.
You plan to store a DNS zone in a custom active Directory partition.
You need to create the Active Directory partition for the zo ne. The partition replicate to only four of the domain controllers.
What should you use?
You haw an Azure virtual machine named VM1 that runs Windows Server
You need to configure the management of VM1 to meet the following requirements:
• Require administrators to request access to VM1 before establishing a Remote Desktop connection.
• Limit access to VM1 from specific source IP addresses.
• Limit access to VMI to a specific management port
What should you configure?
You have a server named Server1 that runs Windows Serv er. Server1 has a single network interface and the Hyper-V virtual switches shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each co rrect selection is worth one point.

You need to meet the technical requirements for Server1. Which users can currently perform the required tasks?
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains two servers named Server1 and Server2.
Server1 contains a disk named Disk2. Disk2 contains a folder named UserData. UserData is shared to the Domain Users group. Disk2 is configured for deduplication. Server1 is protected by using Azure Backup.
Server1 fails.
You connect Disk2 to Server2.
You need to ensure that you can access all the files on Disk2 as quickly as possible.
What should you do?
You create an Azure virtual machine named Server1 that runs Windows Server.
Server1 has the disk configuration shown in the following exhibit.


Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.
You need to identify which server is the PDC emulator for the domain.
Solution: From Active Directory Sites and Services, you right-click Default-First-Site-Name in the console tree, and then select Properties.
Does this meet the goal?
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Som e question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are planning the deployment of DNS to a new network.
You have three internal DNS servers as shown in the following table.

The contoso.local zone contains zone delegations for east.contoso.local and west.contoso.local. All the DNS servers use root hints.
You need to ensure that all the DNS servers can resolve the names of all the internal namespaces and internet hosts.
Solution: On Server2, you create a conditional forwarder for west.contoso.local. On Server3, you create a conditional for warder for east.contoso.local.
Does this meet the goal?
Note: This question is part of a series of questions that present the same sce nario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are planning the deployment of DNS to a new network.
You have three internal DNS servers as shown in the following table.

The contoso.local zone contains zone delegations for east.conloso.local and west.contoso.local. All the DNS servers use root hints.
You need to ensure that all the DNS servers can resolve the names of all the internal namespaces and internet hosts.
Solution: On Server2 and Ser ver3, you configure a conditional forwarder for contoso.local.
Does this meet the goal?
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains two servers named Server1 and Server2 and the users shown in the following table.

Which users can establish a PowerShell remoting session from Server1 to Server2?