Tag Archives: 70-687 exam questions

2014 Latest Microsoft 70-687 Exam Dump Free Download!(51-60)

QUESTION 51
A company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows 8. A local printer is shared from a client computer. The client computer user is a member of the Sales AD security group.
You need to ensure that members of the Sales security group can print to the shared printer and modify only their own print jobs. Which permission should you grant to the Sales group?

A.    Manage queue
B.    Print
C.    Manage documents
D.    Manage this printer
E.    Manage spooler

Answer: B

QUESTION 52
A company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows Vista and are members of the domain.
A Group Policy object (GPO) configuring a software restriction policy is implemented in the domain to block a specific application. You upgrade a computer to Windows 8 and implement a GPO that configures an AppLocker rule in the domain. The blocked application runs on the Windows 8 computer but not on the Windows Vista computers.
You need to ensure that the application is blocked from running on all computers and the AppLocker rule is applied to the computers in the domain.
What should you do?

A.    Add the blocked application as an additional AppLocker rule to the GPO that configures AppLocker.
B.    Run the Get-AppLockerPolicy Windows PowerShell cmdlet.
C.    Run the Set-ExecutionPolicy Windows PowerShell cmdlet.
D.    Configure the software restriction policy as a local policy on the Windows 8 computer.
E.    Add the blocked application as a software restriction policy to the GPO that configures AppLocker.

Answer: A

QUESTION 53
A company has an Active Directory Domain Services (AD DS) domain. Client computers in the Test department run Windows 8 and are connected to the domain.
You need to ensure that Windows updates are not automatically applied and cannot be enabled by users. What should you do?

A.    Create a Group Policy object (GPO) to enable the Turn on recommended updates via Automatic
Updates policy setting.
B.    Configure Windows Update to install updates automatically.
C.    Create a Group Policy object (GPO) to configure the Remove access to use all Windows Update
features policy setting.
D.    Create a Group Policy object (GPO) to configure the Configure Automatic Updates policy setting.

Answer: C
Explanation:
Remove access to use all Windows Update features:
This Group Policy setting is located in User Configuration\Administrative Templates\Windows Components\Windows Update.
When you enable this setting, the operating system cannot be updated through Windows Update, and Automatic Updates is disabled. Users or administrators can still perform actions such as clicking the Windows Update option on the Start menu, and the Windows Update Web site will appear in the browser. However, it will not be possible to update the operating system through Windows Update, regardless of the type of account being used to log on.

QUESTION 54
A company has 100 client computers that run Windows 8.
You need to assign static IPv6 addresses to the client computers.
Which Windows Powershell cmdlet should you run?

A.    Set-NetTCPSetting
B.    Set-NetIPInterface
C.    Set-NetlPv6Protocol
D.    Set-NetIPAddress

Answer: D
Explanation:
Modifies IP address configuration properties of an existing IP address.

QUESTION 55
A company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows 8 and are joined to the domain. All Sales department employees are members of the Sales organizational unit (CU). AppLocker rules control the installation of applicatior on client computers.
You create a new Group Policy object (GPO) to configure an AppLocker file hash rule. The file hash rule allows an application to run and links the application to the Sales OU. Several minutes later, you establish that the AppLocker rule is not present on some computers within SalesOU and the application cannot run.
You need to quickly ensure that the application can run.
What should you do?

A.    Run the Get-AppLockerPolicy Windows PowerShell cmdlet.
B.    Configure the AppLocker properties to enforce rules.
C.    Run the gpupdate /force command.
D.    Create a new AppLocker file hash condition.

Answer: C

QUESTION 56
You administer Windows 8 laptops in your company network. You install several custom desktop
applications on the laptops. You need to create a custom recovery image for Windows to use when selecting the Refresh your PC option. The custom recovery image must include the custom desktop applications.
Which command should you use to create the custom recovery image?

A.    Recdisc.exe
B.    Recover.exe
C.    Recimg.exe
D.    RecoveryDrive.exe

Answer: A

QUESTION 57
You administer Windows 8 client computers in your company network. A computer that is used by non-administrator users has a directory named C:\Folder1.
A shared collection of Microsoft Excel files is stored in the C:\Folder directory, with non-administrator users being granted modify permissions to the directory.
You discover that some files have been incorrectly modified by a user.
You need to determine which user made changes to the directory’s folder’s files.
Which two actions should you perform? (Each correct answer presents part of the solution.
Choose two.)

A.    Set local policy: Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit
Policy \Audit object access to Failure.
B.    From the Auditing Entry for Folder1, set the Principal to Guests, and then set the Type to Failure
for the Modify permission.
C.    From the Auditing Entry for Folder1, set the Principal to Everyone, and then set the Type to Success
for the Modify permission.
D.    Set local policy: Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit
Policy \Audit object access to Success.

Answer: CD
Explanation:
We must audit for success, as we want to know which user has modified the file.

QUESTION 58
A company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows 8. Portable client computers no longer connect to the corporate wireless network.
You need to ensure that when the corporate wireless network is available, the computers always connect to it automatically. Which two actions would achieve the goal? (Each correct answer presents a complete solution.
Choose two.)

A.    Create a Group Policy object (GPO) to configure a wireless network policy. Link the GPO to the
organizational unit that contains the computers.
B.    Configure the corporate wireless network as an unmetered network.
C.    Configure the corporate wireless network as a preferred network.
D.    Manually connect to the corporate wireless network and select the option to connect automatically
to that network.

Answer: CD

QUESTION 59
A company has client computers that run Windows 8. The client computers are connected to a corporate private network. Users are currently unable to connect from their home computers to their work computers by using Remote Desktop.
You need to ensure that users can remotely connect to their office computers by using Remote Desktop. Users must not be able to access any other corporate network resource from their home computers. Which setting should you configure on the home computers?

A.    Virtual Private Network connection
B.    Remote Desktop local resources
C.    DirectAccess connection
D.    Remote Desktop Gateway IP address

Answer: D
Explanation:
http://technet.microsoft.com/en-us/library/cc731435.aspx
Remote Desktop Gateway allows a home computer to remote into the work computer. The Work computer can access corporate network resources, just as if the worker was at the workstation, but the HOME COMPUTER cannot access corporate resources.
RD RAPs will enable us to control remote user access to internal network resources. With RD CAPs we can control which Users or Computers can connect via RDP.
VPN provides the HOME computer with an IP Address directly of the Corporate private network, giving the HOME computer access to the corporate private resources

QUESTION 60
A company has 100 client computers that run Windows 8. The client computers are connected to a corporate private network. Users are currently unable to connect from their home computers to their work computers by using Remote Desktop.
You need to ensure that users can remotely connect to their office computers by using Remote Desktop. Users must not be able to access any other corporate network resource from their home computers. What should you do?

A.    Configure a Virtual Private Network connection.
B.    Configure the Remote Desktop Gateway IP address in the advanced Remote Desktop Connection
settings on each client.
C.    Configure the local resource settings of the Remote Desktop connection.
D.    Configure a DirectAccess connection.

Answer: B
Explanation:
While connecting the computers you will find a couple of options related to VPN and
Desktop Assistance.
See Understanding Authorization Policies for Remote Desktop Gateway:
http://technet.microsoft.com/en-us/library/cc731435.aspx
RD RAPs will enable us to control remote user access to internal network resources.
With RD CAPs we can control which Users or Computers can connect via RDP.
Configure the Remote Desktop Gateway IP address in the advanced Remote Desktop
Connection settings on each client.
 clip_image001
DirectAccess is for Windows Server 2008/2012/Win 7 Ultimate/Enterprise/Win 8 Enterprise
only.
RD Gateway setup is only for servers.
Create VPN through manage networks. File -> Allow incoming connections.
Connect through Internet and create VPN which will allow one computer at a time to view
the hosts resources, and only the hosts resources unlike standard VPNs.

Passing Microsoft 70-687 Exam successfully in a short time! Just using Braindump2go’s Latest Microsoft 70-687 Dump:http://www.braindump2go.com/70-687.html

2014 Latest Microsoft 70-687 Exam Dump Free Download!(41-50)

QUESTION 41
You update the video card driver on a computer that runs Windows 8. You can no longer configure the display settings to extend the display to a projector.
You need to restore the display options as quickly as possible and retain all user data.
What should you do?

A.    Roll back the video card driver to the previous version.
B.    Run the DisplaySwitch/extend command.
C.    Run the sic /scannow command.
D.    start the computer from the Windows 8 installation media and perform a system image recovery.

Answer: A

QUESTION 42
A company has client computers that run Windows 8. Each computer has two hard drives. You
need to create a dynamic volume on each computer that maximizes write performance. Which
kind of dynamic volume should you create?

A.    Striped volume
B.    RAID 5 volume
C.    Spanned volume
D.    Mirrored volume

Answer: A

QUESTION 43
A company has client computers that run Windows 8. The corporate network is configured for tPv4 and IPv6.
You need to disable Media Sensing for IPv6 on the client computers without affecting IPv4 communications. What should you do on each client computer?

A.    Run the Disable-NetAdapterBinding Windows PowerShell cmdlet.
B.    Run the Disable-NetAdapter Windows PowerShell cmdlet.
C.    Run the Set-NetlPv6Protocol Windows PowerShell cmdlet.
D.    Run the Set-NetlPv4Protocol Windows PowerShell cmdlet.

Answer: C
Explanation:
http://technet.microsoft.com/en-us/library/hh826144.aspx
Set-NetIPv6Protocol [-DhcpMediaSense<DhcpMediaSense>]
Modifies the DHCPMediaSense property. This parameter value provides a mechanism for the network adapter to notify the protocol stack of media connect and disconnect events. These events trigger the DHCP client to take some action, such as attempting to renew a DHCP lease or removing routes related to a disconnected network. One application of Media Sense enables the network parameters on the notebook computer of a roaming user to automatically and transparently update without rebooting when the user moves from one location to another. The acceptable values for this parameter are:
— Enabled: DhcpMediaSense set to Enabled.
— Disabled: DhcpMediaSense is set to Disabled.
The default value is Enabled.

QUESTION 44
A company has 100 client computers that run Windows 8. The client computers are members of a workgroup. A custom application requires a Windows Firewall exception on each client computer.
You need to configure the exception on the client computers without affecting existing firewall settings. Which Windows PowerShell cmdlet should you run on each client computer?

A.    New-NetFirewallRule
B.    Set-NetFirewallSetting
C.    Set-NetFirewallRule
D.    Set-NetFirewallProfile
E.    New-NetIPSecMainModeRule

Answer: A
Explanation:
Creates a new inbound or outbound firewall rule and adds the rule to the target computer.
http://technet.microsoft.com/en-us/library/jj554908.aspx
DisplayName “Allow Inbound Telnet” -Direction Inbound -Program %SystemRoot% New-NetFirewallRule – \System32\tlntsvr.exe -RemoteAddress LocalSubnet -Action Allow

QUESTION 45
A company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows 8 and are members of the domain. Client computers maintain a list of sites in the Internet Explorer Restricted Sites security zone. Users of one client computer are able to download and install an application from a site within the Restricted Sites zone.
You need to ensure that users of the computer can install applications only from sites that are not in the Restricted Sites zone.
What should you do?

A.    Run the Set-ExecutionPolicy Windows PowerShell cmdlet.
B.    Configure the Software Restriction Policy settings in the local Group Policy of the computer.
C.    Add the blocked application as a software restriction policy to the GPO that configures AppLocker.
D.    Run the Cet-AppLockerPolicy Windows PowerShell cmdlet.
E.    Add the blocked application as an additional AppLocker rule to the GPO that configures AppLocker.

Answer: B
Explanation:
Only Software Restriction policy allows for the control of applications from a network zone; AppLocker does not.
 clip_image002

QUESTION 46
A company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows 8. A local printer is shared from a client computer. The client computer user is a member of the Sales AD security group.
You need to ensure that members of the Sales security group can modify the order of documents in the print queue, but not delete the printer share. Which permission should you grant to the Sales group?

A.    Manage queue
B.    Manage this printer
C.    Print
D.    Manage spooler
E.    Manage documents

Answer: E

QUESTION 47
Your computer runs Windows 8 and is connected to an Active Directory Domain Services (AD DS) domain. You create a folder and share the folder with everyone in your organization.
You need to modify the NTFS permissions of the folder to meet the following criteria:
– Users from the Marketing security group must be able to open files, but not modify them.
– Users from the Supervisors security group must be able to create, modify, and delete files.
Which permissions should you set?
Users from both groups must not be able to delete the folder.

A.    Assign the Marketing group the Read permission. Assign the Supervisors group the Read and
Write permissions and the Delete Subfolders and Files special permission.
B.    Assign the Marketing group the Read and Write permissions.
Assign the Supervisors group the Full Control permission.
C.    Assign the Marketing group the Read and Write permissions. Assign the Supervisors group the
Modify permission and the Delete Subfolders and Files special permission.
D.    Assign the Marketing group the Read permission. Assign the Supervisors group the Read and
Write permissions and the Delete special permission.

Answer: A

QUESTION 48
A company has client computers that run Windows 8.
The company implements the following security requirements:
– All client computers must use two-factor authentication.
– At least one authentication method must include exactly four characters or gestures.
You need to choose authentication methods that comply with the security requirements. Which two authentication methods should you choose? (Each correct answer presents part of the solution. Choose two.)

A.    PIN
B.    Biometric authentication
C.    Picture password
D.    Microsoft account

Answer: AB
Explanation:
Something the user knows: PIN (4 digits)
One might be tempted to think the photo for the picture password is something the User has. But it is something the User knows, too:
He knows how to draw the gestures (maximum 3 gestures supported with picture password), and it is no physical object (like a token, smart card …)
The MS Account is too something the user knows.
So the answer must be Biometric authentication.
Two-factor authentication requires the use of two of the three authentication factors:
Something the user knows (e.g., password, PIN); Something the user has (physical Object) (e.g., ATM card, smart card); and Something the user is (e.g., biometric characteristic, such as a fingerprint).
The factors are identified in the standards and regulations for access to U.S. Federal Government systems.

QUESTION 49
A company has client computers that run Windows 8. The company implements the following security requirements:
– All client computers must use two-factor authentication.
– At least one authentication method must include more than four characters or gestures.
You need to choose authentication methods that comply with the security requirements. Which two authentication methods should you choose? (Each correct answer presents part of the solution. Choose two.)

A.    PIN
B.    Biometric authentication
C.    Picture Password
D.    Microsoft Account

Answer: BD
Explanation:
More than 4 characters are of course supported with the Microsoft Account. It is something the user knows. The picture password would be another thing the user knows (gestures). So there’s only MS Account and Biometric authentication left.
Two-factor authentication requires the use of two of the three authentication factors:
Something the user knows (e.g., password, PIN); Something the user has (physical Object) (e.g., ATM card, smart card); and Something the user is (e.g., biometric characteristic, such as a fingerprint).
The factors are identified in the standards and regulations for access to U.S. Federal Government systems.

QUESTION 50
Your computer runs Windows 8 and is connected to an Active Directory Domain Services (AD DS) domain. You create a folder and share the folder with everyone in your organization.
You need to modify the NTFS permissions of the folder to meet the following criteria:
– Users from the Supervisors AD security group must be able to open files, but not modify them.
– Users from the Marketing AD security group must be able to create, modify, and delete files.
– Users from both groups must not be able to delete the folder.
Which permissions should you set?

A.    Assign the Supervisors group the Read and Write permissions. Assign the Marketing group the Modify
permission and the Delete Subfolders and Files special permission.
B.    Assign the Supervisors group the Read and Write permissions. Assign the Marketing group the Full
Control permission.
C.    Assign the supervisors group the Read permission. Assign the Marketing group the Read and Write
permissions and the Delete Subfolders and Files special permission.
D.    Assign the Supervisors group the Read permission. Assign the Marketing group the Read and Write
permissions and the Delete special permission.

Answer: C

Passing Microsoft 70-687 Exam successfully in a short time! Just using Braindump2go’s Latest Microsoft 70-687 Dump:http://www.braindump2go.com/70-687.html

2014 Latest Microsoft 70-687 Exam Dump Free Download!(31-40)

QUESTION 31
A company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows 8.
You need to minimize the amount of Trusted Platform Module (TPM) authorization information that is stored in the registry. What should you do?

A.    Enable Platform Configuration Register indices (PCRs) 0, 2, 4, and 11 for the Configure TPM
validation profile for native UEFI firmware configuration policy setting.
B.    Create a Group Policy object (GPO) that disables the Configure the level of TPM owner authorization
information available to operating system policy setting.
C.    Create a Group Policy object (GPO) that sets the Configure the level of TPM owner authorization
information available to operating system policy setting to None.
D.    Create a Group Policy object (GPO) that enables the Turn on TPM Local Encryption policy setting.

Answer: C

QUESTION 32
A company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows 8 and are joined to the domain.
You have the following requirements:
– Ensure that files in shared network folders are available offline.
– Minimize all data access times.
– Reduce network bandwidth usage.
You need to configure Group Policy settings to meet the requirements.
What should you do first?

A.    Enable the Enable file synchronization on costed networks policy setting.
B.    Enable and configure the Configure slow-link mode policy setting.
C.    Enable and configure the specify administratively assigned Offline Files policy setting.
D.    Enable the Synchronize all offline files when logging on policy setting.

Answer: B
Explanation:
Enable the Always Offline Mode to Provide Faster Access to Files: To enable the Always Offline Configure slow-link mode policy setting and set the latency to mode, use Group Policy to enable the 1 (millisecond).
Doing so causes client computers running Windows 8 or Windows Server 2012 to automatically use the Always Offline mode.
http://technet.microsoft.com/en-us/library/hh968298.aspx

QUESTION 33
A company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows 8 and are joined to the domain.
You have the following requirements:
– Ensure that files in shared network folders are available offline.
– Maximize efficiency for users who connect to shared network folders from a mobile device.
You need to configure Group Policy settings to meet the requirements.
What should you do first?

A.    Enable and configure the Configure slow-link mode policy setting.
B.    Enable the Enable file synchronization on costed networks policy setting.
C.    Enable the Synchronize all offline files when logging on policy setting.
D.    Enable and configure the Specify administratively assigned Offline Files policy setting.

Answer: B
Explanation:
 clip_image002[45]

clip_image002[47]

QUESTION 34
A company has a main office and several branch offices. The company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows 8. All printers are deployed to all client computers by using Group Policy.
When a user attempts to print from his portable client computer while at a branch office, the main office printer is set as his default printer.
You need to ensure that a location-specific default printer for each branch office is set for the user.
What should you do?

A.    Create a Group Policy object (GPO) that enables the Computer location policy setting.
B.    In the Manage Default Printers dialog box, select the Always use the same printer as my default
printer option.
C.    In the Manage Default Printers dialog box, select the Change my default printer when I change
networks option.
D.    Create a Group Policy object (GPO) that enables the Allow Print Spooler to accept client connections
policy setting.

Answer: C

QUESTION 35
A computer runs Windows 8. You install an application by running an .msi file.
You need to apply a patch to the application. Which command should you run?

A.    dism /Online /add-package:C:\MyPatch.msp
B.    dism /get-AppPatches /get-PackageInfo:C:\MyPatch.msp
C.    msiexec /x “C:\MyPatch.msp”
D.    msiexec /p “C:\MyPatch.msp”

Answer: D

QUESTION 36
A company has client computers that run Windows 8. Users can run applications that have been downloaded from the Internet only with administrator approval. You need to ensure that users can run downloaded applications without administrator approval. What should you do?

A.    Set the Internet zone privacy level to Low.
B.    Set the Internet zone security level to Medium.
C.    Set the User Account Control (UAC) settings to Never notify.
D.    Turn off Windows SmartScreen.

Answer: A

QUESTION 37
You manage computers that run Windows 8. You plan to install a desktop app named MarketingApp on one of the client computers. You need to display a progress bar to the user while installing the app. Which command should you run?

A.    msiexec /i marketingapp.msi /qn
B.    msiexec /i marketingapp.msi /qb
C.    msiexec /x marketingapp.msi /qb
D.    msiexec /x marketingapp.msi /qn

Answer: B
Explanation:
http://technet.microsoft.com/en-us/library/cc759262(v=ws.10).aspx
/i installs or configures a product /qbdisplays a basic user interface

QUESTION 38
A company has client computers that run Windows 8. You set up new virtual private network (VPN) connections on all client computers. The VPN connections require the use of a smart card for authentication.
Users are unable to connect to the corporate network by using the VPN connections. The connection properties are configured as shown in the exhibit. (Click the Exhibit button.)
 clip_image001[13]
You need to ensure that the client computers can connect to the corporate network.
What should you do?

A.    Enable Challenge Handshake Authentication Protocol (CHAP).
B.    Change the VPN type to IKEv2.
C.    In the advanced settings, select Use preshared key for authentication.
D.    Change the authentication setting to Use Extensible Authentication Protocol (EAP).

Answer: D

QUESTION 39
You update the video card driver on a portable computer that runs Windows 8. When a user connects the portable computer to an external monitor, the external monitor duplicates the display on the portable computer screen.
You need to ensure that the user can display additional desktop space on the external monitor.
What should you do?

A.    Run the DisplaySwitch /extend command.
B.    Start the computer from the Windows 8 installation media and perform a system image recovery.
C.    Roll back the video card driver to the previous version.
D.    Run the sic /scannow command.

Answer: A

QUESTION 40
A company has client computers that run Windows 8. You attempt to roll back a driver for a specific device on a client computer. The Roll Back Driver button is unavailable in Device Manager.
You need to roll back the driver to the previous version.
What should you do first?

A.    In the system properties for hardware, modify the device installation settings.
B.    Disable driver signature enforcement.
C.    In the local Group Policy, modify the device installation restrictions.
D.    Run Device Manager as an Administrator.

Answer: D

Passing Microsoft 70-687 Exam successfully in a short time! Just using Braindump2go’s Latest Microsoft 70-687 Dump:http://www.braindump2go.com/70-687.html

2014 Latest Microsoft 70-687 Exam Dump Free Download!(21-30)

QUESTION 21
You administer Windows 8 Enterprise client computers in your company network.
You change settings on a reference computer by using the Windows Firewall with Advanced Security tool. You want to apply the same settings to other computers.
You need to save the Windows Firewall with Advanced Security configuration settings from the reference computer. You also need to be able to import the configuration settings into a Group Policy object later.
What should you do?

A.    Run the netsh advfirewall export c:\settings.xrnl command.
B.    Run the netsh advfirewall export c:\settings.txt command.
C.    Run the netsh advfirewall export c:\settinqs.wfw command.
D.    Run the netsh firewall export c:\settings.xml command.

Answer: C
Explanation:
*Netsh advfirewall is a command-line tool for Windows Firewall with Advanced Security that helps with the creation, administration, and monitoring of Windows Firewall and IPsec settings and provides an alternative to console-based management. T
* Export subcommand
Exports the Windows Firewall with Advanced Security configuration in the current store to a file. This file can be used with the import command to restore the Windows Firewall with Advanced Security service configuration to a store on the same or to a different computer.
Syntax
export [ Path ] FileName
Parameters
[ Path ] FileName
Required. Specifies, by name, the file where the Windows Firewall with Advanced Security configuration will be written. If the path, file name, or both contain spaces, quotation marks must be used. If you do not specify Path then the command places the file in your current folder. The recommended file name extension is .wfw.
Example
In the following example, the command exports the complete Windows Firewall with Advanced Security service configuration to the file C:\temp\wfas.wfw.
export c:\temp\wfas.wfw
Reference:Netsh Commands for Windows Firewall with Advanced Security

QUESTION 22
You administer Windows 8 Pro computers in your company network. A server named Server1 runs Windows Server 2012. Server1 allows incoming VPN and Remote Desktop connections.
A remote user requires access to files on Server1.
You need to prevent the user from downloading any files from Server1 to his local computer. Your solution must ensure that the user can read the files on Server1.
What should you do?

A.    Create a new VPN connection. Disable local drive mappings.
B.    Create a new Remote Desktop connection.
C.    Set the Local Computer policy to Disable drives redirection for Remote Desktop Services.
D.    Create a new Remote Desktop connection. Set the Local Computer policy to Disable clipboard redirection
for Remote Desktop Services.

Answer: C

QUESTION 23
A company has 10 client computers that run Windows 8.
An employee updates a device driver on her computer and then restarts the computer. Windows does not start successfully. You start the computer in Safe Mode.
You need to identify the most recently installed driver and gather the maximum amount of information about the driver installation.
What should you do?

A.    In Device Manager, run a scan for hardware changes.
B.    In the Event Viewer console, display the Hardware Events log.
C.    In the Programs and Features Control Panel item, display the installed updates.
D.    Display the contents of the Windows\inf\setupapi.dev.log file.

Answer: D

QUESTION 24
Employees are permitted to bring personally owned portable computers that run Windows 8 to the office. They are permitted to install corporate applications by using the management infrastructure agent and access corporate email by using Windows Mail.
An employee’s personally owned portable computer is stolen.
You need to protect the corporate applications and email messages on the computer.
Which two actions should you perform? (Each correct answer presents part of the solution.
Choose two.)

A.    Prevent the computer from connecting to the corporate wireless network.
B.    Disconnect the computer from the management infrastructure.
C.    Change the user’s password.
D.    Initiate a remote wipe.

Answer: CD
Explanation:
D: A Remote Wipe is the process where a device is selected from a central Microsoft Exchange or management console and chosen to be wiped, for example if the device has been lost by the owner. The Remote Wipe command is then sent to the device via ActiveSync.
For a device such as a Windows Phone, all data is deleted, including email, contacts, calendar for all accounts and other data on the device such as documents and picture.
However, when ActiveSync Remote Wipe is performed against a Windows 8 or Windows RT device, the scope of the wipe is more limited. Only the email, contacts, and calendar for information stored in thebuiltin Mail applicationare deleted. Other data on the system is not deleted, including information from the Microsoft Office Outlook client.

QUESTION 25
A company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows 8. Portable client computers connect to the corporate wireless network.
You have the following requirements:
– Prevent users from configuring a wireless network by using settings from a USB flash drive.
– Do not affect the use of other USB devices.
You need to create a Group Policy object (GPO) to meet the requirements.
Which GPO should you create?

A.    A GPO that disables the Allow only USB root hub connected Enhanced Storage Features policy setting.
B.    A GPO that enables wireless policy processing.
C.    A GPO that prohibits connections to mobile broadband networks when roaming.
D.    A GPO that configures Windows Connect Now settings.

Answer: D
Explanation:
Computer Configuration\Policies\Administrative Templates\Network\Windows Connect Now
Turn Off Ability To Configure Using A USB Flash Drive setting:
Prevents Windows from being able to store a Windows Connect Now configuration to a UFD. Because the Windows Connect Now information stored on a UFD contains information that can allow computers to access your protected wireless network, you might choose to disable this setting to improve the security of your wireless networks.
http://sourcedaddy.com/windows-7/windows-connect-now-in-windows-7.html

QUESTION 26
A company has an Active Directory Domain Services (AD DS) domain with one physical domain controller. All client computers run Windows 8. A client computer hosts a Windows 8 virtual machine (VM) test environment.
The VMs are connected to a private virtual switch that is configured as shown in the Virtual Switch Manager exhibit:
 clip_image002[37]
You have the following requirements:
– Configure the test environment to allow VMs to communicate with the host machine.
– Minimize impact on the host machine.
You need to meet the requirements.
What should you do?

A.    Create a new virtual switch with a Private Network [CP1] connection type.
B.    Create a new virtual switch with an ExternalNetwork connection type.
C.    Change the VLAN ID of the private virtual switch to Enable Virtual LAN identification.
D.    Create a new virtual switch with an Internal Network connection type.

Answer: D
Explanation:
http://technet.microsoft.com/en-us/library/cc816585(v=ws.10).aspx
 clip_image002[39]
Private will not allow communication with the host machine. External will allow communication with the host machine but also allow access to other machines on the host machine’s network which is not a requirement.

QUESTION 27
A portable computer that runs Windows 8 uses a mobile broadband connection for the corporate wireless network. The computer also has a wired corporate network connection. The computer successfully downloads Windows updates when connected to either network.
You need to ensure that the computer automatically downloads updates by using Windows Update only while connected to the wired corporate network connection.
What should you do?

A.    Set the corporate wireless network to metered.
B.    Set the corporate wireless network to non-metered.
C.    Configure the Specify intranet Microsoft update service location local Group Policy setting.
D.    Configure a Windows Firewall connection security rule.

Answer: A
Explanation:
http://www.windowsnetworking.com/articles_tutorials/Using-Wireless-Networks-Windows-8.html
You can also set particular networks as a metered connection, which will then disable Windows Update from downloading updates (except for critical security patches) and possibly disable or reduce data usage from other Microsoft and non-Microsoft applications as well.

QUESTION 28
A company has an Active Directory Domain Services (AD DS) domain with one physical domain controller. All client computers run Windows 8. A client computer hosts a Windows 8 virtual machine (VM) test environment.
The VMs are connected to a private virtual switch that is configured as shown in the Virtual Switch Manager exhibit:
 clip_image002[41]
The VMS are unable to connect to the domain controller.
You have the following requirements:
– Configure the test environment to allow VMs to communicate with the domain controller.
– Ensure that the VMs can communicate with other VMS fl the test environment when the domain controller is unavailable.
You need to meet the requirements.
What should you do first?
 clip_image002[43]

A.    Create a new virtual switch with an Internal Network connection type.
B.    Create a new virtual switch with a Private Network connection type.
C.    Create a new virtual switch with an External Network connection type.
D.    Change the connection type of the private virtual switch to Internal only.

Answer: C

QUESTION 29
A portable computer that runs Windows 8 uses a mobile broadband connection for the corporate wireless network. The computer also has a wired corporate network connection. The computer successfully downloads Windows updates when connected to either network.
You need to ensure that the computer automatically downloads updates by using Windows Update while also connected to the wireless corporate network connection. What should you do?

A.    Set the corporate wireless network to metered.
B.    Set the corporate wireless network to non-metered.
C.    Configure the Specify intranet Microsoft update service location local Group Policy setting.
D.    Configure a Windows Firewall connection security rule.

Answer: B
Explanation:
Setting a Wireless network to METERED allows only critical Windows Updates using that connection. Setting a Wireless network to NON-METERED allows all Windows Updates using that connection.
Source: http://windows.microsoft.com/en-US/windows-8/metered-internet-connections-frequently-asked-questions

QUESTION 30
A company has an Active Directory Domain Services domain. All client computers run Windows 8 and are joined to the domain. You run the ipconfiq command on a client computer.
The following output depicts the results.
Ethernet adapter Local Area Connection 3:
 clip_image001[11]
You need to ensure that you can establish a DirectAccess connection from the client computer to the network. What should you do?

A.    Create a new VPN connection.
B.    Remove the computer from the domain.
C.    Enable IPv6 on the network adapter.
D.    Configure a static IPv4 address.

Answer: C
Passing Microsoft 70-687 Exam successfully in a short time! Just using Braindump2go’s Latest Microsoft 70-687 Dump:http://www.braindump2go.com/70-687.html

2014 Latest Microsoft 70-687 Exam Dump Free Download!(11-20)

QUESTION 11
You administer a group of 10 client computers that run Windows 8. The client computers are members of a local workgroup. Employees log on to the client computers by using their Microsoft accounts.
The company plans to use Windows BitLocker Drive Encryption.
You need to back up the BitLocker recovery key. Which two options can you use? (Each correct answer presents a complete solution. Choose two.)

A.    Save the recovery key to a file on the BitLocker-encrypted drive.
B.    Save the recovery key in the Credential Store.
C.    Save the recovery key to SkyDrive.
D.    Print the recovery key.

Answer: AD
Explanation:
One of the new features in Windows 8 for BitLocker is the ability to backup your BitLocker recovery key to a Microsoft account. During the process before encryption begins, a user is prompted for a location to make a backup copy of the recovery key. Save to your Microsoft account has been added along with save to a file and print the recovery key.
 clip_image001[4]

QUESTION 12
You administer Windows 8 computers in your company network.
You install a new video driver. The computer will not start properly after restart. You are able to enter Safe Mode with Command Prompt. You need to be able to start normally. You also need to ensure that user data is not lost.
What should you do?

A.    Run the rstrui.exe command.
B.    Roll back the driver.
C.    Turn on File History.
D.    Create a restore point.

Answer: B

QUESTION 13
You administer Windows 8 Pro client computers in your company network. You need to configure
a backup and recovery solution that meets the following requirements:
– Recovers the system if it doesn’t start.
– Recovers the system if the hard drive fails.
Which two actions should you perform? (Each correct answer presents part of the solution.
Choose two.)

A.    Turn on File History.
B.    Create a storage space.
C.    Configure system protection.
D.    Create a system repair disk.
E.    Create a system image backup.

Answer: DE
Explanation:
* In the event that you are unable to start Windows or wish to restore your hard drives to a previous backup you can use the System Image Recovery program from the Windows 7 or Windows 8 Recovery Environment.
* You should create a system repair disk, which can be used to boot your PC and restore it using the system image backup, in the event of a hard drive issue or other hardware failure.
Incorrect:
C: System protection is a feature that regularly creates and saves information about your computer’s system files and settings. System protection also saves previous versions of files that you’ve modified. It saves these files in restore points, which are created just before significant system events, such as the installation of a program or device driver. They’re also created automatically once every seven days if no other restore points were created in the previous seven days, but you can create restore points manually at any time.

QUESTION 14
A company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows 7. You plan to upgrade the client computers to Windows 8 Pro.
You need to choose the methods that do not require the manual entry of a product key during the upgrade. Which two methods should you choose? (Each correct answer presents a complete solution. Choose two.)

A.    Use the Volume Activation Management Tool.
B.    Use the Microsoft Deployment Toolkit.
C.    Use the Windows 8 online upgrade tool.
D.    Create a catalog (.clg) file by using Windows System Image Manager (SIM).

Answer: AB
Explanation:
A: Volume Activation Management Tool (VAMT) 2.0 is a managed MMC plug-in. VAMT uses Windows Management Instrumentation (WMI) to configure managed systems. A convenient command line interface (CLI) allows automated, scheduled VAMT tasks without UI interaction. Using the VAMT console, administrators can perform many activation-related tasks on remote computers:
Manage product keys obtained from the Volume Licensing Service Center (VLSC) or other sources including retail and Microsoft subscription programs such as MSDN, TechNet and partner programs –
– and product activations using those keys.
Activate remote systems using Key Management Service (KMS), Multiple Activation Key (MAK) or retail activation methods.
Perform disconnected proxy activation and reactivation of systems without each system having to connect with Microsoft activation services individually. Assist with license compliance by enabling IT administrators to monitor system license state, including whether systems are licensed and running genuine Windows or Office.
B: Deploy Windows and Office 2010 with Microsoft Deployment Toolkit 2012 Update 1. MDT is the recommended process and toolset for automating desktop and server deployment. MDT provides you with the following benefits:
Unified tools and processes, including a set of guidance, for deploying desktops and servers in a common deployment console.
Reduced deployment time and standardized desktop and server images, along with improved security and ongoing configuration management.

QUESTION 15
You administer computers in your company network. All computers in the network belong to a single Active Directory Domain Services (AD DS) domain. The network includes Windows Server 2012 servers located in a perimeter network.
You add a new Windows 8 computer to the perimeter network. You enable only Remote Desktop access to the Windows 8 computer from other computers located outside the perimeter network.
You need to use the Windows 8 computer to manage the Windows servers in the perimeter network.
What should you do?

A.    Add the Windows 8 computer as a Trusted Host to the servers.
B.    Enable PowerShell Remoting on the Windows 8 computer.
C.    Add the Windows 8 computer as a Trusted Host to computers outside the perimeter network.
D.    Install Remote Server Administration Tools for Windows 8 (RSAT) on the Windows 8 computer.

Answer: B

QUESTION 16
A company has client computers that run Windows 8. Each computer has two hard drives. You
need to create a dynamic volume on each computer to support the following features:
– Fault tolerance
– Fast write performance
What kind of dynamic volume should you create?

A.    Striped volume
B.    Spanned volume
C.    RAID 5 volume
D.    Mirrored volume

Answer: D

QUESTION 17
You administer Windows 8 Enterprise computers in your company’s Active Directory Domain Services (AD DS) domain. Your company uses several peripheral devices. The drivers for these devices are not available on Windows Update.
You need to ensure that the drivers install when users connect these devices to their computers. What should you do?

A.    For the Group Policy setting Prioritize all digitally signed drivers equally during the driver ranking and
selection process, select Disabled.
B.    From Device Manager, find the detected scanner device and select Update Driver.
C.    Add the following registry key to the computers:
HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/Current Version/DevicePath.
Add °/osystemroot%\inf and the UNC path to the drivers share.
D.    For the Group Policy setting Configure driver search locations, select Enabled. Make the drivers available
on the UNC path to the driver’s share.

Answer: C

QUESTION 18
A company has client computers that run Windows 8. Each computer has two hard drives.
You need to create a dynamic volume on each computer that maximizes write performance with data fault tolerance.
Which kind of dynamic volume should you create?

A.    Striped Volume
B.    RAID 5 Volume
C.    Spanned Volume
D.    Mirrored Volume

Answer: D

QUESTION 19
A company network contains two workgroups named Workgroup1 and Workgroup2. Workgroup1 contains computers that run Windows 7. Workgroup2 contains computers that run Windows 8.
You run the Enable-PSRemoting Windows PowerShell cmdlet on the Workgroup2 computers.
You need to ensure that administrators can manage the Workgroup1 computers from the Workgroup2 computers by using Windows PowerShell Remoting.1
Which two actions should you perform? (Each correct answer presents part of the complete solution. Choose two.)

A.    Install Windows PowerShell 2.0 on the Workgroup1 computers.
B.    Run the winrm quickconfig command on the Workgroup2 computers.
C.    On the Workgroup1 computers, add the Workgroup2 computers to the trusted hosts in Windows
Remote Management (WinRM).
D.    Run the winrrn quickconfig command on the Workgroup1 computers.
E.    On the Workgroup2 computers, add the Workgroup1 computers to the trusted hosts in Windows
Remote Management (WinRM).

Answer: BC
Explanation:
B: If you cannot connect to a remote host, verify that the service on the remote host is running and is accepting requests by running the following command on the remote host:
winrm quickconfig
This command analyzes and configures the WinRM service.
C: To enable authentication, you need to add the remote computer to the list of trusted hosts for the local computer in WinRM. To do so, type:
winrm s winrm/config/client ‘@{TrustedHosts=”RemoteComputer”}’ Here, RemoteComputer should be the name of the remote computer, such as:
winrm s winrm/config/client ‘@{TrustedHosts=”CorpServer56″}’
Incorrect:
Not A: The Windows PowerShell remoting features are supported by the WS-Management protocol and the Windows Remote Management (WinRM) service that implements WS- Management in Windows. Computers running Windows 7 and later include WinRM 2.0 or later. On computersrunning earlier versions of Windows, you need to install WinRM 2.0 or later as appropriate and if supported.
Reference:Enable and Use Remote Commands in Windows PowerShell

QUESTION 20
A computer that runs Windows B has two hard disk drives. The user stores data files in specific storage locations outside of the standard libraries on both drives.
File search results are delayed.
You need to return relevant search results more quickly.
What should you do?

A.    Remove all directories from indexed locations.
B.    Add the specific storage locations to indexed locations.
C.    Allow indexing of file contents in non-indexed locations.
D.    Add encrypted files to the index.

Answer: B
Passing Microsoft 70-687 Exam successfully in a short time! Just using Braindump2go’s Latest Microsoft 70-687 Dump:http://www.braindump2go.com/70-687.html

2014 Latest Microsoft 70-687 Exam Dump Free Download!(1-10)

QUESTION 1
A company has 10 portable client computers that run windows 8.1
The portable client computers have the network connections described in the following table+
 clip_image001
None of the computers can discover other computers or devices, regardless of which connection they use.
You need to configure the connections so that the computers can discover other computers or devices only while connected to the CorpWired or CorpWifi connections.
What should you do on the client computers?

A.    For the CorpWired connection, select Yes, turn on sharing and connect to devices.
B.    Change the CorpWired connection to public. Turn on network discovery for the Public profile.
For the Hotsport connection, select No, don’t turn on sharing or connect to devices.
C.    For the CorpWifi connection, select Yes, turn on sharing and connect to devices.
D.    Turn on network discovery for the Private profile
E.    Turn on network discovery for the Public profile

Answer: B
Explanation:
By design Public profile as Sharing set to no and Private profile set to Yes
But it Says “None of the computers can discover other computers or devices, regardless of which
connection they use” so you need to review the full config. You can change it by doing that Firewall Profil (for Windows 7)
http://technet.microsoft.com/en-us/library/getting-started-wfas-firewall-profiles-ipsec%28v=ws.10%29.aspx

QUESTION 2
A company has 10 client computers that run Windows 8. Employees log on to resources by using multiple accounts. You need to back up the user name and password for each logon account. What should you do on each client computer?

A.    Back up each user’s Personal Information Exchange PKCS #12 (.pfx) certificate.
B.    Use Credential Manager to save the information to a USB flash drive.
C.    Use File History to back up the ntuser.dat file.
D.    Run the Export-Certificate Windows PowerShell cmdlet.

Answer: B

QUESTION 3
You administer windows 8 computers in you company network. all computers include Windows 8
compatible trusted platform modele (TPM). You configure a computer that will run a credit processing application. You need to ensure that the computer requires a user to enter a PIN code when starting the computer. Which policy should you configure? (to answer, select the appropriate policy in the answer area.)
 clip_image002

A.    Allow Secure Boot for Integrity validation
B.    Require Additional authentication at startup
C.    Allow enhanced PINs for Startup
D.    Configure minimum PIN length for startupalocal

Answer: B
Explanation:
 clip_image002[4]

QUESTION 4
A company has client computers that run Windows 8. You implement an AppLocker file hash rule that allows an application to run. You then apply a service pack to the application. When users attempt to run the application, the application is blocked by Group Policy. You need to ensure that the application runs. What should you do?

A.    Enable the Reschedule Automatic Updates scheduled installations Group Policy setting.
B.    Set the wired network connection to non-metered.
C.    Set the wired network connection to metered.
D.    Configure the Automatic Maintenance setting.

Answer: B

QUESTION 5
A company has an Active Directory Domain Services (AD DS) domain. The corporate environment includes a Windows Software Update Services (WSUS) server. All client computers run Windows 8 and a custom web application. The company has a Microsoft Software Assurance for Volume Licensing agreement.
After deploying Windows Updates to the computers, the web application stops responding. You establish that a specific optional update installed by Windows Update is causing the problem. In the Windows Update Control Panel item, the option to remove the update is unavailable.
You need to remove the optional update from one client computer.
What should you do?

A.    Install and run the Debugging tools for Windows.
B.    Clear the SusClientID registry value on the client computer.
C.    Restart the computer from a Diagnostic and Repair Toolset (DaRT) boot disk and use the Crash
Analyzer tool.
D.    Run the wuauclt /resetauthorization command on the client computer.
E.    Restart the computer from a Diagnostic and Repair Toolset (DaRT) boot disk and use the Hotfix
Uninstaller tool.

Answer: E

QUESTION 6
A client computer that runs Windows 8 has two hard disk drives: a system drive and a data drive.
You are preparing to back up the computer prior to installing a developing software product.
You have the following requirements:
– The system disk that is part of the backup must be mountable from within Windows.
– The system disk that is part of the backup must be bootable.
– The backup must be viable to restore in the event of a hard disk failure.
– The backup must contain data from both hard disk drives.
You need to select a backup method. Which method should you use?

A.    System repair disk
B.    Storage pool
C.    System image
D.    File History

Answer: C

QUESTION 7
You administer Windows 8 client computers in your company network.
You receive a virtual hard disk (VHD) file that has Windows 8 Pro preinstalled, along with several business applications.
You need to configure your client computer to start from either the VHD file or from your current operating system.
Which three actions should you perform? (Each correct answer presents part of the solution.
Choose three.)

A.    Import the contents of the system store from a file.
B.    Export the contents of the system store into a file.
C.    Attach the VHD file by using Disk Management.
D.    Make the VHD disk bootable.
E.    Create a new empty boot configuration data store.
F.    Create a new entry in the boot configuration data store.

Answer: CDF
Explanation:
F: Commands to add an existing VHD to your boot menu:
bcdedit /copy {originalguid} /d “New Windows 7 Installation” bcdedit /set {newguid} device vhd=[D:]\Image.vhd
bcdedit /set {newguid} osdevice vhd=[D:]\Image.vhd
bcdedit /set {newguid} detecthal on

QUESTION 8
A company has client computers that run Windows 8. The client computer systems frequently use IPSec tunnels to securely transmit data. You need to configure the IPSec tunnels to use 256-bit encryption keys.
Which encryption type should you use?

A.    3DES
B.    DES
C.    RSA
D.    AES

Answer: D

QUESTION 9
You are configuring a computer that will be used in a kiosk in a public area. You install a new internal hard drive. You need to protect the computer from starting an unauthorized operating
system. What should you do?

A.    • Ensure that the computer BIOS supports Unified Extensible Firmware Interface (UEFI) and is enabled.
• Install Windows 8 Pro 64-bit using UEFI and install it on the internal hard drive.
B.    • Install Windows 8 Pro 64-bit on the internal hard drive.
• Enable BitLocker on the internal hard disk.
C.    • Partition the internal hard drive as MBR disk.
• Install Windows 8 Enterprise 64-bit.
D.    • Partition the internal hard drive as GPT disk.
• Install Windows 8 Pro 64-bit.

Answer: A

QUESTION 10
A desktop computer that runs Windows 8 downloads updates but does not install them. The
computer is connected to the corporate network by using a wired network connection. You
need to ensure that the computer automatically installs updates. What should you do?

A.    Set the wired network connection to non-metered.
B.    Configure the Automatic Maintenance setting.
C.    Enable the Reschedule Automatic Updates scheduled installations Group Policy setting.
D.    Set the wired network connection to metered.

Answer: B

Passing Microsoft 70-687 Exam successfully in a short time! Just using Braindump2go’s Latest Microsoft 70-687 Dump:http://www.braindump2go.com/70-687.html

Pages: 1 2 3 4