70-697 practice questions
You administer computers that run Windows XP Professional. These computers have a wide range of line of business (LOB) applications installed.
You want to migrate from Windows XP Professional to Windows 10 Enterprise.
You need to identify which application will prompt users for elevated privileges.
What should you do first?
A. Configure the advanced audit setting on the Windows 10 Enterprise computers before you install the LOB applications.
B. Install the Microsoft Assessment and Planning (MAP) Toolkit.
C. Install the Microsoft Application Compatibility Toolkit (ACT).
D. Install User Experience Virtualization (UE-V) on the Windows 10 Enterprise computers before you install the LOB applications.
Discussion forum
Question
Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details in a question apply only to that question.
You need to change the password used for an L2TP VPN connection.
Which Control Panel application should you use?
A. Work Folders
B. Phone and Modem
C. Credential Manager
D. Sync Center
E. System
F. Network and Sharing Center
G. RemoteApp and Desktop Connections
H. Power Options
Discussion forum
Question
You administer Windows 10 Enterprise tablets that are members of an Active Directory domain. Your company policy allows users to download and install only certain few Windows Store apps.
You have created a new AppLocker Packaged Apps policy to help enforce the company policy.
You need to test the new AppLocker Packaged Apps policy before you implement it for the entire company.
What should you do?
A. Open PowerShell and run the Get–AppLockerPolicy –Effective cmdlet to retrieve the AppLocker effective policy.
B. Open Group Policy Management console and enforce the new AppLocker policy in Audit Only mode.
C. Open Group Policy Management console and run the Group Policy Modeling Wizard.
D. Open Group Policy Management console and run the Group Policy Results Wizard.
Discussion forum
Question
You manage desktop computers on your company network. The finance department uses computers that rub Widows 7 Enterprise and a 32-bit legacy application.
The application has some compatibility issues with Widows 10 Enterprise. The application uses domain single sign-on for authentication.
The vendor releases a new version of the application that is fully compatible with Windows 10 Enterprise These versions cannot be installed on the same computer due to HKEY_CURRENT_USER registry setting conflicts.
You need to migrate the finance department computers Widows 10 Enterprise while meeting the following requirements:
✑ Users are able to use the original version of the application while validating the new version.
✑ Once the new version is validated, the old version is removed with minimal effort.
Users authenticate only once to use the application.
Which technology should you choose?
A. Microsoft Application Compatibility Toolkit (ACT)
B. Hyper-V
C. Microsoft Application Virtualization (App-V)
D. User Experience Virtualization (UE-V)
Discussion forum
Question
Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.
You have five computers that runs Windows 10. Each computer is used by a different user. All of the computers are members of the same workgroup.
You need to ensure that all of the users can access the files located in one anothers libraries. Access must be granted based on a shared password.
What should you configure?
A. share permissions
B. account policies
C. HomeGroup settings
D. application control policies
E. NTFS permissions
F. Microsoft OneDrive
G. Encrypting File System (EFS) settings
H. software restriction policies
Discussion forum
Question
Your company network includes a main office and multiple small branch offices. All of the computers in the branch offices run Windows 10 Enterprise and are members of an Active Directory domain. The company has no plans to deploy any servers in the branch offices.
Users from some branch offices report that it takes a long time to open documents from a file server that is located in the main office.
You need to enable BranchCache on all computers located in the branch offices.
What should you do?
A. Open Group Policy Editor and enable BranchCache in Distributed Cache mode for the computers in the branch offices.
B. Open PowerShell and run the Enable–BCHostedClients cmdlet on the computers in the branch offices.
C. Open Group Policy Editor and Enable BranchCache in a Hosted Cache mode for the computers in the branch offices.
D. Open PowerShell, run the Set–BCCache cmdlet on computers in the branch offices.
Discussion forum
Question
A company has an Active Directory Domain Services (AD DS) domain. All client computers run Windows 10 Enterprise.
You are configuring security for a portable client computer that does not have a Trusted Platform Module (TPM) chip installed.
You need to configure local Group Policy to tum on Windows BitLocker Drive Encryption on the computer.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE Each correct selection is worth one point.
A. Enable the Enforce drive encryption type on operating system drives policy setting.
B. Enable the option to allow BitLocker without a compatible TPM.
C. Enable the Require additional authentication at startup policy setting.
D. Configure the TPM validation profile to enable Platform Configuration Register indices (PCRs) 0, 2, 4, and 11.
Discussion forum
Question
You have a computer that runs Windows 10 and has BitLocker Drive Encryption (BitLocker) configured.
You need to change the BitLocker PIN for the drive.
What should you run?
A. the repair–bde.exe Windows script file
B. the Enable–BitLocker cmdlet
C. the bitsadmin.exe command
D. the manage–bde.exe command
Discussion forum
Question
You have a computer named Client1. Client1 is joined to an Active Directory domain.
You need to join Client1 to an Azure Active Directory (Azure AD) tenant.
What should you do first?
A. From the Local Group Policy Editor, modify the Add workstations to domain policy.
B. From the network adapter properties, modify the DNS suffix.
C. From System Control Panel, configure the computer to be a member of a workgroup.
D. From the System in the Settings app, modify the sign-in options.
Discussion forum
Question
You manage Windows 10 Enterprise desktop and laptop computers for your company. They are part of a Windows Server 2012 R2 Active Directory Domain
Services (AD DS) environment. The system administrators implement DFS for flexibility and availability. Laptops are able to connect to the companys private network by using local Ethernet or secure wireless.
Three users report that their files on the server are missing, and they no longer have drive G.
You need to ensure that the three users computers can access the DFS namespace so that you can troubleshoot by using the DFS client.
What should you do?
A. Ascertain whether the three users are connected through a wireless or wired connection.
B. Ensure that the three users have access to the domain NETLOGON share.
C. Ensure that the Net Logon service is running on all servers that are hosting the DFS namespace.
D. Verify that a share is defined on the folder to which drive G is being mapped.
Discussion forum
Question
You are an IT professional for a bank. All of the users files on the external drives are encrypted by using EFS.
You replace a users computer with a new Windows 10 Enterprise computer. The user needs to connect her external hard drive to the new computer. You have the original computers certificate and key.
You need to import the certificate and key onto the new computer.
Into which certificate store should you import the certificate and key?
A. Untrusted Certificates
B. Trusted Root Certification Authorities
C. Personal
D. Trusted Publishers
Discussion forum
Question
You administer Windows 10 Enterprise tablets that are members of an Active Directory domain.
You want to create an archived copy of My Documents folders that are stored on the tablets. You create a standard domain user account to run a backup task.
You need to grant the backup task user account access to the folders.
What should you do?
A. Add the backup task account to the Remote Management Users group on a domain controller.
B. Add the backup task account to the Backup Operators group on every tablet.
C. Add the backup task account to the Backup Operators group on a domain controller.
D. Set the backup task account as NTFS owner on all the folders.
Discussion forum
Question
You support Windows 10 Enterprise computers. Your company protects all laptops by using the BitLocker Network Unlock feature.
Some employees work from home.
You need to ensure that employees can log on to their laptops when they work from home.
What should you do?
A. Have users run the Manage-bde.exe –unlock command before they disconnect from the company network.
B. Ensure that the Trusted Platform Module (TPM) chips in the laptops are version 1.2 or greater.
C. Enable BitLocker To Go.
D. Provide employees with their BitLocker PINs.
Discussion forum
Question
You administer Windows 10 Enterprise. Your network includes an Active Directory domain and a standalone server in a perimeter network that runs Windows Server 2008 R2
Your company purchases five new tablets that run Windows 8. The tablets will be used to access domain resources and shared folders located on the standalone server.
You need to implement single sign-on (SSO) authentication for tablet users. You also need to ensure that you can audit personnel access to the shared folder.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Create a new Microsoft account for each user.
B. Ensure that the local account for each user on the stand-alone server uses the same password as the corresponding Microsoft account.
C. Join the tablets to a domain.
D. Join the tablets to the same workgroup as the stand-alone server.
E. Enable a guest account on the stand-alone server.
F. On the stand-alone server, create user accounts that have the same logon names and passwords as the user domain accounts.
Discussion forum
Question
You have a computer named Client1. Client 1 is joined to an Active Directory domain.
You need to join Client1 to an Azure Active Directory (Azure AD) tenant.
What should you do first?
A. From User Accounts in Control Panel, configure the Manage User Accounts settings.
B. From Computer Management, modify the membership for the Network Configuration Operators group.
C. From the System in the Settings app, click Disconnect from organization.
D. From the Local Group Policy Editor, modify the Add workstations to domain policy.
Discussion forum
Question