You have an Azure Active Directory (Azure AD) tenant named contoso.com
that contains a user named UserA.
You have two computers named Computer1 and Computer2 that run Windows
10 and are joined to contoso.com.
You need to ensure that UserA can connect to Computer2 from Computer1 by
using Remote Desktop.
Which three actions should you perform? Each correct answer presents part of
the solution. - ANSWER - On Computer2, modify the peoperties of UserA
- On Comuter2, enable Remote Desktop
- On Computer2, add the Everyone group to the Remote Desktop Users group
You plan to deploy Windows 10 to 100 secure computers.
You need to select a version of Windows 10 that meets the following
requirements:
Uses Microsoft Edge as the default browser
Minimizes the attack surface on the computer
Supports joining Microsoft Azure Active Directory (Azure AD)
Only allows the installation of applications from the Microsoft Store -
ANSWER Windows 10 Pro in S Mode
You discover that a user used the Service1 account to sign in to Computer1 and
deleted some files.
You need to ensure that the identity used by Application1 cannot be used by a
user to sign in to sign in to the desktop on Computer1. The solution must use
the principle of least privilege.
Solution: On Computer1, you configure Application1 to sign in as the
LocalSystem account and select the Allow service to interact with desktop
check box. You delete the Service1 account.
,Does this meet the goal? - ANSWER No
You discover that a user used the Service1 account to sign in to Computer1 and
deleted some files.
You need to ensure that the identity used by Application1 cannot be used by a
user to sign in to sign in to the desktop on Computer1. The solution must use
the principle of least privilege.
Solution: On Computer1, you assign Service1 the deny log on locally user right.
Does this meet the goal? - ANSWER No
Your company has an isolated network used for testing. The network contains
20 computers that run Windows 10. The computers are in a workgroup. During
testing, the computers must remain in the workgroup.
You discover that none of the computers are activated.
You need to recommend a solution to activate the computers without
connecting the network to the Internet.
What should you include in the recommendation? - ANSWER Volume
Activation Management Tool
Your network contains an Active Directory domain that is synced to a Microsoft
Azure Active Directory (Azure AD) tenant.
Your company purchases a Microsoft 365 subscription.
You need to migrate the Documents folder of users to Microsoft OneDrive for
Business.
What should you configure? - ANSWER OneDrive Group Policy settings
Your company uses Microsoft Deployment Toolkit (MDT) to deploy Windows
10 to new computers.
, The company purchases 1,000 new computers.
You need to ensure that the Hyper-V feature is enabled on the computers during
the deployment.
What are two possible ways to achieve the goal? Each correct answer presents
part of the solution. - ANSWER - Add a task sequence step that adds a
provisioning package
- Add a custom command to the Unattend.xml file
You have a computer named Computer1 that runs Windows 10. The computer
contains a folder. The folder contains sensitive data.
You need to log which user reads the contents of the folder and modifies and
deletes files in the folder.
Solution: From the properties of the folder, you configure the Auditing settings
and from Audit Policy in the local Group Policy, you configure Audit object
access.
Does this meet the goal? - ANSWER Yes
A user named User1 has a computer named Computer1 that runs Windows 10.
User1 connects to a Microsoft Azure virtual machine named VM1 by using
Remote Desktop.
User1 creates a VPN connection to a partner organization.
When the VPN connection is established, User1 cannot connect to VM1. When
User1 disconnects from the VPN, the user can connect to VM1.
You need to ensure that User1 can connect to VM1 while connected to the
VPN.
What should you do? - ANSWER From the properties of VPN1, clear the Use
default gateway on remote network check box
that contains a user named UserA.
You have two computers named Computer1 and Computer2 that run Windows
10 and are joined to contoso.com.
You need to ensure that UserA can connect to Computer2 from Computer1 by
using Remote Desktop.
Which three actions should you perform? Each correct answer presents part of
the solution. - ANSWER - On Computer2, modify the peoperties of UserA
- On Comuter2, enable Remote Desktop
- On Computer2, add the Everyone group to the Remote Desktop Users group
You plan to deploy Windows 10 to 100 secure computers.
You need to select a version of Windows 10 that meets the following
requirements:
Uses Microsoft Edge as the default browser
Minimizes the attack surface on the computer
Supports joining Microsoft Azure Active Directory (Azure AD)
Only allows the installation of applications from the Microsoft Store -
ANSWER Windows 10 Pro in S Mode
You discover that a user used the Service1 account to sign in to Computer1 and
deleted some files.
You need to ensure that the identity used by Application1 cannot be used by a
user to sign in to sign in to the desktop on Computer1. The solution must use
the principle of least privilege.
Solution: On Computer1, you configure Application1 to sign in as the
LocalSystem account and select the Allow service to interact with desktop
check box. You delete the Service1 account.
,Does this meet the goal? - ANSWER No
You discover that a user used the Service1 account to sign in to Computer1 and
deleted some files.
You need to ensure that the identity used by Application1 cannot be used by a
user to sign in to sign in to the desktop on Computer1. The solution must use
the principle of least privilege.
Solution: On Computer1, you assign Service1 the deny log on locally user right.
Does this meet the goal? - ANSWER No
Your company has an isolated network used for testing. The network contains
20 computers that run Windows 10. The computers are in a workgroup. During
testing, the computers must remain in the workgroup.
You discover that none of the computers are activated.
You need to recommend a solution to activate the computers without
connecting the network to the Internet.
What should you include in the recommendation? - ANSWER Volume
Activation Management Tool
Your network contains an Active Directory domain that is synced to a Microsoft
Azure Active Directory (Azure AD) tenant.
Your company purchases a Microsoft 365 subscription.
You need to migrate the Documents folder of users to Microsoft OneDrive for
Business.
What should you configure? - ANSWER OneDrive Group Policy settings
Your company uses Microsoft Deployment Toolkit (MDT) to deploy Windows
10 to new computers.
, The company purchases 1,000 new computers.
You need to ensure that the Hyper-V feature is enabled on the computers during
the deployment.
What are two possible ways to achieve the goal? Each correct answer presents
part of the solution. - ANSWER - Add a task sequence step that adds a
provisioning package
- Add a custom command to the Unattend.xml file
You have a computer named Computer1 that runs Windows 10. The computer
contains a folder. The folder contains sensitive data.
You need to log which user reads the contents of the folder and modifies and
deletes files in the folder.
Solution: From the properties of the folder, you configure the Auditing settings
and from Audit Policy in the local Group Policy, you configure Audit object
access.
Does this meet the goal? - ANSWER Yes
A user named User1 has a computer named Computer1 that runs Windows 10.
User1 connects to a Microsoft Azure virtual machine named VM1 by using
Remote Desktop.
User1 creates a VPN connection to a partner organization.
When the VPN connection is established, User1 cannot connect to VM1. When
User1 disconnects from the VPN, the user can connect to VM1.
You need to ensure that User1 can connect to VM1 while connected to the
VPN.
What should you do? - ANSWER From the properties of VPN1, clear the Use
default gateway on remote network check box