Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains an organizational unit (OU) named 0U1.0U1 contains servers that run sensitive workloads.
You plan to add connection security rules that meet the following requirements:
• The servers in OU 1 must only accept connections from domain-joined
• The servers in OU 1 must only be able to communicate with domain-joined
You create a Group Policy Object (GPO) named GP01 and link GP01 to contoso.com.
You need to configure a connection security rule in GP01 by using Windows Defender Firewall with Advanced Security.
How should you configure the rule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have an on-premises server named Server1 that runs Windows Server. Server1 contains an app named App1 and a firewall named Firewall1. You have an Azure subscription. Internal users connect to App1 by using WebSockets. You need to make App1 available to users on the internet. The solution must minimize the number of inbound ports open on Firewall1. What should you include in the solution?
You have a server named Server1 that runs Windows Server. Server1 has the storage pools shown in the following table. You plan to create a virtual disk named VDisk1 that will use storage tiers. Which pools can you use to create VDisk1?

Storage pools on Server1
You have an on-premises server named Server1 that runs Windows Server and contains a shared folder named Share1. You deploy a new virtual machine named Server2. You need to migrate Share1 to Server2. The solution must meet the following requirements: - Ensure that users can access a UNC path of \\server1\share1 after Server1 is decommissioned. - Minimize administrative effort. What should you use to perform the migration?
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an on-premises server named Server1 that runs Windows Server. You have a Microsoft Sentinel instance. You add the Windows Firewall data connector in Microsoft Sentinel. You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1. Solution: You install the Log Analytics agent on Server1. Does this meet the goal?
You deploy a single-domain Active Directory Domain Services (AD DS) forest named contoso.com. You deploy five servers to the domain. You add the servers to a group named NLBHosts. You plan to configure a Network Load Balancing (NLB) cluster named NLBCluster.contoso.com that will contain the five servers. You need to ensure that the NLB service on the nodes of the cluster can use a group managed service account (gMSA) to authenticate. Which three PowerShell cmdlets should you run in sequence? To answer, move the appropriate cmdlets from the list of cmdlets to the answer area and arrange them in the correct order.

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains a domain controller named DC1 and a member server named Server1. Users cannot sign in to Server1 by using domain credentials and receive the following error message: The trust relationship between this workstation and the primary domain failed. You need to restore domain authentication on Server1 without removing Server1 from the domain. Solution: From Server1, you run Set-ADAccountPassword -Identity " Server1$ " -Reset. Does this meet the goal?
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the users shown in the following table.

The domain has the Group Policy Objects (GPOs) shown in the following table.

The GPOs are configured to map a drive named H as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra ID tenant. Group writeback is enabled in Microsoft Entra Connect. The AD DS domain contains a server named Server1. Server1 contains a shared folder named share1. You have an Azure Storage account named storage2 that uses Microsoft Entra ID-based access control. The storage2 account contains a share named share2. You need to create a security group that meets the following requirements: can contain users from the AD DS domain; can be used to authorize user access to share1 and share2. What should you do?
You have an Active Directory Domain Services (AD DS) domain that contains the domain controllers shown in the following table: DC1 (Schema master), DC2 (Infrastructure master), DC3 (Domain naming master), DC4 (PDC emulator, RID master). The domain contains an app named App1 that uses a custom application partition to store configuration data. You decommission App1. When you attempt to remove the custom application partition, the process fails. Which domain controller is unavailable?

Domain controller FSMO role table


