Your company has an isolated network used for testing. The network contains
20 computers that run Windows 10. THe computers are in a workgroup. During
testing, the computers must remain in the workgroup. You discover that none of
the computers are activated.
You need to recommend a solution to activate the computers without
connecting the network to the internet.
What should you include in the recommendation?
A. Volume Activation Management Tool (VAMT)
B. Key Management Service (KMS)
C. Active Directory-Based activation
D. The Get-WindowsDeveloperLicense cmdlet - ANSWER A. Volume
Activation Management Tool - It allows for a proxy to reach out on behalf of all
devices for activation.
(The answer is not KMS requires a minimum of 25 clients before it can be used
for activation)
You plan to deploy Windows 10 to 100 secure computers. You need to select a
version of Windows 10 that meets the following requirements:
-Uses Microsoft Edge as the default browser.
-Minimizes the attack surface on the computer.
-Supports joining Microsoft Azure Active Directory (Azure AD).
-Only allows the installation of applications from the Microsoft Store.
What is the best version too achieve the goal?
A. Windows 10 Pro in S Mode
B. Windows 10 Home in S Mode
C. Windows 10 Pro
D. Windows 10 Enterprise - ANSWER A. Windows 10 Pro in S Mode - it
supports Domain joining with edge as the default browser.
(B. Windows 10 Home in S mode does NOT support Domain Join... C.
Windows 10 Pro does NOT support Domain Join Either...)
,You have a computer named Computer1 that runs Windows 7. Computer1 has a
local user named User1 who has a customized profile. On Computer1, you
perform a clean installation of Windows 10 without formatting the drives. You
need to migrate the settings of User1 from Windows 7 to Windows 10.
Which two action should you perform?
- Run scanstate.exe specifying C:\Windows.old
- Run Loadstate.exe specifying C:\Users
- PSexec.exe -/Load
-msloadtest.msi - ANSWER You need to run Scanstate.exe on
C:\Windows.old to create the "Store" of user information for import. Then, run
Loadstate.exe on C:\users to actually load the content.
-Because Windows is already installed on the new machine, windows.old is
created so you don't use C:\users to for scanstate.exe because the user file is
located in the Windows.old folder now.
You have a Microsoft Azure AD tenant. Some users sign in to their computer
by using Windows Hello for Business. A user named User1 purchases a new
computer and joins the computer to Azure AD. User1 attempts to configure the
sign-in options and receives the error message - " *Some settings are hidden or
managed by your organization." On the Windows hello customization Screen.
You open device manager and confirm that all the hardware works correctly.
You need to ensure that User1 can use Windows Hello for Business facial
recognition to sign in to the computer. What should you do first?
A. Purchase an infrared (IR) Camera.
B. Upgrade the computer to Windows 10 Enterprise.
C. Enable UEFI Secure Boot.
D. Install a virtual TPM Driver. - ANSWER B. Upgrade the computer to
Windows 10 Enterprise. - Because this user is trying to use WINDOWS
HELLO FOR BUSINESS - this is an ENTERPRISE version of Windows Hello
and therefore the personal use computer would need to have Windows 10
Enterprise installed in order to access the features.
Your company uses Microsoft Deployment Toolkit (MDT) to deploy Windows
10 to new computers. The company purchases 1,000 new computers. You need
to ensure that the Hyper-V feature is enabled on the computers during the
deployment.
What are two possible ways to achieve the goal?
A. Add a task sequence step that adds a provisioning package.
,B. In a Group Policy object (GPO), from Computer COnfiguration, configure
Application Control Policies.
C. Add a custom command to the unattended.xml file.
D. Add a configuration setting to the Windows Deployment Services (WDS).
E. Add a task sequence step that runs DISM.exe. - ANSWER NEED TO
LOOK UP ITS QUESTION 8 Discussion BOARD PICTURE
Your network contains an Active Directory domain that is synced to a Microsoft
Azure ACtive Directory (Azure AD) tenant. You company purchases a
Microsoft 365 subscription. You need to migrate the Documents folder of users
to Microsoft OneDrive for Business.
What should you Configure?
A. One Drive Group Policy Settings.
B. roaming user profiles.
C. Enterprise state Roaming.
D. Folder Redirection Group Policy Settings. - ANSWER A. One Drive group
Policy Settings.
You have a computer named Computer1 that runs Windows 10. The computer
contains a folder that contains sensitive Data. YOu need to log which user reads
the contents of the folder and modifies and deletes files in the folder.
Solution: From the properties of the folder, you configure the auditing settings
and from Audi Policy in the local group Policy you configure Audit Object
Access. Does this meet the goal?
A. Yes.
B. No. - ANSWER A. Yes.
You have a computer named Computer1 that runs Windows 10. The computer
contains a folder that contains sensitive Data. YOu need to log which user reads
the contents of the folder and modifies and deletes files in the folder.
Solution: From the properties of the folder, you configure the Auditing settings
and from the Audit Policy in the local Group Policy, you configure Audi
directory service access. Does this meet the goal?
A. Yes.
B. No. - ANSWER B. No. - Folders and Files are objects, not directory
services.
, You have a computer named Computer1 that runs Windows 10. You turn on
System Protection and create a restore point named Point1. You perform the
following changes:
- Add four files named FIle1.txt, File2.dll, File3.sys, and File4.exe to the
desktop.
- Run a configuration script that adds the following four registry keys:
—Key1 to HKCU
—Key2 to HKClassesRoot
—Key3 to HKLM/System
—Key4 to HKCurrentConfig
You restore Point1. WHich files and registry keys are removed? - ANSWER
File 2, 3, and 4 will be removed as well as all 4 Registry Keys.
(File1.txt - the ".txt" makes it a "Personal file" which will not be removed
during a restore. )
You have 10 computers that run Windows 10.
You have a Windows Server Update Services (WSUS) Server. You need to
configure the computers to install updates from WSUS. Which two settings
should you configure? - ANSWER Both Answers are GPO settings:
1. Configure Auto Updates. (Turn on Updates/Schedule).
2. Configure WIndows Updates Services Location (Put in the WSUS Server
Name/URL)
Your network contains an Active Directory Domain. The Domain contains
1,000 computers that run Windows 10. You discover that when users are on
their lock screen, they see a different background image every day, along with
tips for using different features in Windows 10. You need to disable the tips and
the daily background image for all the Windows 10 computers. Which Group
Policy settings should you modify?
A. Turn off the Windows Welcome Experience.
B. Turn off Windows Spotlight on Settings.
C. Do not suggest third-party content in Windows Spotlight.
D. Turn off all Windows spotlight features. - ANSWER D. Turn off all
Windows Spotlight Features.
You have a file named Reg1.reg that contains the following content.
" Windows Registry Editor Version 5.00
[HKEY_Classes_Root\Directory\Background\Shell\Notepad]
20 computers that run Windows 10. THe computers are in a workgroup. During
testing, the computers must remain in the workgroup. You discover that none of
the computers are activated.
You need to recommend a solution to activate the computers without
connecting the network to the internet.
What should you include in the recommendation?
A. Volume Activation Management Tool (VAMT)
B. Key Management Service (KMS)
C. Active Directory-Based activation
D. The Get-WindowsDeveloperLicense cmdlet - ANSWER A. Volume
Activation Management Tool - It allows for a proxy to reach out on behalf of all
devices for activation.
(The answer is not KMS requires a minimum of 25 clients before it can be used
for activation)
You plan to deploy Windows 10 to 100 secure computers. You need to select a
version of Windows 10 that meets the following requirements:
-Uses Microsoft Edge as the default browser.
-Minimizes the attack surface on the computer.
-Supports joining Microsoft Azure Active Directory (Azure AD).
-Only allows the installation of applications from the Microsoft Store.
What is the best version too achieve the goal?
A. Windows 10 Pro in S Mode
B. Windows 10 Home in S Mode
C. Windows 10 Pro
D. Windows 10 Enterprise - ANSWER A. Windows 10 Pro in S Mode - it
supports Domain joining with edge as the default browser.
(B. Windows 10 Home in S mode does NOT support Domain Join... C.
Windows 10 Pro does NOT support Domain Join Either...)
,You have a computer named Computer1 that runs Windows 7. Computer1 has a
local user named User1 who has a customized profile. On Computer1, you
perform a clean installation of Windows 10 without formatting the drives. You
need to migrate the settings of User1 from Windows 7 to Windows 10.
Which two action should you perform?
- Run scanstate.exe specifying C:\Windows.old
- Run Loadstate.exe specifying C:\Users
- PSexec.exe -/Load
-msloadtest.msi - ANSWER You need to run Scanstate.exe on
C:\Windows.old to create the "Store" of user information for import. Then, run
Loadstate.exe on C:\users to actually load the content.
-Because Windows is already installed on the new machine, windows.old is
created so you don't use C:\users to for scanstate.exe because the user file is
located in the Windows.old folder now.
You have a Microsoft Azure AD tenant. Some users sign in to their computer
by using Windows Hello for Business. A user named User1 purchases a new
computer and joins the computer to Azure AD. User1 attempts to configure the
sign-in options and receives the error message - " *Some settings are hidden or
managed by your organization." On the Windows hello customization Screen.
You open device manager and confirm that all the hardware works correctly.
You need to ensure that User1 can use Windows Hello for Business facial
recognition to sign in to the computer. What should you do first?
A. Purchase an infrared (IR) Camera.
B. Upgrade the computer to Windows 10 Enterprise.
C. Enable UEFI Secure Boot.
D. Install a virtual TPM Driver. - ANSWER B. Upgrade the computer to
Windows 10 Enterprise. - Because this user is trying to use WINDOWS
HELLO FOR BUSINESS - this is an ENTERPRISE version of Windows Hello
and therefore the personal use computer would need to have Windows 10
Enterprise installed in order to access the features.
Your company uses Microsoft Deployment Toolkit (MDT) to deploy Windows
10 to new computers. The company purchases 1,000 new computers. You need
to ensure that the Hyper-V feature is enabled on the computers during the
deployment.
What are two possible ways to achieve the goal?
A. Add a task sequence step that adds a provisioning package.
,B. In a Group Policy object (GPO), from Computer COnfiguration, configure
Application Control Policies.
C. Add a custom command to the unattended.xml file.
D. Add a configuration setting to the Windows Deployment Services (WDS).
E. Add a task sequence step that runs DISM.exe. - ANSWER NEED TO
LOOK UP ITS QUESTION 8 Discussion BOARD PICTURE
Your network contains an Active Directory domain that is synced to a Microsoft
Azure ACtive Directory (Azure AD) tenant. You company purchases a
Microsoft 365 subscription. You need to migrate the Documents folder of users
to Microsoft OneDrive for Business.
What should you Configure?
A. One Drive Group Policy Settings.
B. roaming user profiles.
C. Enterprise state Roaming.
D. Folder Redirection Group Policy Settings. - ANSWER A. One Drive group
Policy Settings.
You have a computer named Computer1 that runs Windows 10. The computer
contains a folder that contains sensitive Data. YOu need to log which user reads
the contents of the folder and modifies and deletes files in the folder.
Solution: From the properties of the folder, you configure the auditing settings
and from Audi Policy in the local group Policy you configure Audit Object
Access. Does this meet the goal?
A. Yes.
B. No. - ANSWER A. Yes.
You have a computer named Computer1 that runs Windows 10. The computer
contains a folder that contains sensitive Data. YOu need to log which user reads
the contents of the folder and modifies and deletes files in the folder.
Solution: From the properties of the folder, you configure the Auditing settings
and from the Audit Policy in the local Group Policy, you configure Audi
directory service access. Does this meet the goal?
A. Yes.
B. No. - ANSWER B. No. - Folders and Files are objects, not directory
services.
, You have a computer named Computer1 that runs Windows 10. You turn on
System Protection and create a restore point named Point1. You perform the
following changes:
- Add four files named FIle1.txt, File2.dll, File3.sys, and File4.exe to the
desktop.
- Run a configuration script that adds the following four registry keys:
—Key1 to HKCU
—Key2 to HKClassesRoot
—Key3 to HKLM/System
—Key4 to HKCurrentConfig
You restore Point1. WHich files and registry keys are removed? - ANSWER
File 2, 3, and 4 will be removed as well as all 4 Registry Keys.
(File1.txt - the ".txt" makes it a "Personal file" which will not be removed
during a restore. )
You have 10 computers that run Windows 10.
You have a Windows Server Update Services (WSUS) Server. You need to
configure the computers to install updates from WSUS. Which two settings
should you configure? - ANSWER Both Answers are GPO settings:
1. Configure Auto Updates. (Turn on Updates/Schedule).
2. Configure WIndows Updates Services Location (Put in the WSUS Server
Name/URL)
Your network contains an Active Directory Domain. The Domain contains
1,000 computers that run Windows 10. You discover that when users are on
their lock screen, they see a different background image every day, along with
tips for using different features in Windows 10. You need to disable the tips and
the daily background image for all the Windows 10 computers. Which Group
Policy settings should you modify?
A. Turn off the Windows Welcome Experience.
B. Turn off Windows Spotlight on Settings.
C. Do not suggest third-party content in Windows Spotlight.
D. Turn off all Windows spotlight features. - ANSWER D. Turn off all
Windows Spotlight Features.
You have a file named Reg1.reg that contains the following content.
" Windows Registry Editor Version 5.00
[HKEY_Classes_Root\Directory\Background\Shell\Notepad]