Microsoft Upgrading Your Skills to MCSA Windows Server 2012 (70-417日本語版) - 70-417日本語 Exam Practice Test

Correct Answer: A Vote an answer
Correct Answer: B Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Correct Answer: D Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
DRAG DROP

Select and Place:
Correct Answer:

Explanation:
1) Policy before rule => false
You should first create the rule and then integrate it to the policy:
From the Microsoft.Press.Exam.Ref.70-417.Oct.2012 book:
Step 1: Create a central access policy that includes claims This step consists of two parts, both of which
you can perform in Active Directory Administrative Center. First, you create one or more central access
rules that include claims. Then, you add those rules to a central access policy.
EXAM TIP:
Normally you'd want to create access rules and then create the central access policy to add them to.
2) Then, we should modify the security settings of the folder after GPO1 is modified, as the CAP settings in
the GPO are configured to make the CAP appear in the advanced security configuration (in the Central
Policy tab).
So we should first configure the GPO and then, once everything is ok, go to the security settings of folder1
to point the Central Access Policy (now available thanks to the GPO) from Microsoft.Press.Exam.Ref.70-
417.Oct.2012
In this step, you configure a policy setting at the domain level that will deliver chosen central access policies
to your file servers. Note that you can't actually enforce a central access policy by using Group Policy. You
use Group Policy only to make desired central access policies available for selection in the Advanced
Security Settings dialog box of all objects within the folder structure on file servers. The policy must then be
applied to the object (usually a folder) manually.
EXAM TIP:
As an alternative to step 3, you can leave selected the "Use Following Permissions as Proposed
Permissions" option, which you can see in Figure 11-15.
This option is used to stage a policy rule.
Staging policies can be used to monitor the effects of a new policy entry before you enable it. You can use
this option with the Group Policy setting name Audit Central Access Policy Staging. For more information,
see the procedure described at the following address:
http://technet.microsoft.com/en-us/library/hh846167.aspx#BKMK_1_2.
http://technet.microsoft.com/en-us/library/hh846167.aspx#BKMK_1_2 (i only put a summary, please feel
free to go check the link)
Deploy a Central Access Policy (Demonstration Steps)
1) Implement: Configure the components and policy:
Create claim types => Create resource properties => Configure a central access rule => Configure a central
access policy (CAP) => Target central access policy to the file server (by adding the CAP to the GPO to
make it enable in the Advanced Security Settings of the folders) => Enable KDC Support for claims,
compound authentication and Kerberos armoring)
2) Deploy the central access policy:
a) Assign the CAP to the appropriate shared folders on the file server
-gpupdate to apply the gpo settings
-update the global ressource properties from AD
-in the folder properties, in Classification tab, select (in this case) the department
-IN SECURITY SETTINGS => ADVANCED => CENTRAL POLICY TAB => SELECT THE ACCESS
CONTROL POLICY
b) Verify that access is appropriately configured.
A few screenshots...

To make it appear in the "Central Policy" tab of the folder To test the effect of the CAP


Once the GPO is applied, and the CAP available to Folder1, we select it.
Correct Answer: B Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).


Correct Answer: C Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Correct Answer: B Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).