Microsoft Configuring Windows 10 Devices - 070-697 Exam Practice Test
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are the system administrator for a sales company. You manage the Microsoft Office 365 environment for your company. You are investigating the requirements for Office 365 data loss prevention (DLP). All users have an Enterprise E5 license.
You must ensure that all users are prevented from storing social security numbers in Office 365.
You need to implement a DLP policy that meets the requirement.
Solution: Create a DLP policy with Yammer as a content source location.
Does the solution meet the goal?
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are the system administrator for a sales company. You manage the Microsoft Office 365 environment for your company. You are investigating the requirements for Office 365 data loss prevention (DLP). All users have an Enterprise E5 license.
You must ensure that all users are prevented from storing social security numbers in Office 365.
You need to implement a DLP policy that meets the requirement.
Solution: Create a DLP policy with Yammer as a content source location.
Does the solution meet the goal?
Correct Answer: A
You have a computer that runs Windows 8.0.
You create a system image backup on the computer and then you upgrade to Windows 10 Enterprise.
You need to access a file from the backup.
The solution must use the least amount of administrative effort.
What should you do?
You create a system image backup on the computer and then you upgrade to Windows 10 Enterprise.
You need to access a file from the backup.
The solution must use the least amount of administrative effort.
What should you do?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
You support Windows 10 Enterprise computers that are members of an Active Directory domain. Your company policy defines the list of approved Windows Store apps that are allowed for download and installation.
You have created a new AppLocker Packaged Apps policy to help enforce the company policy.
You need to test the new AppLocker Packaged Apps policy before you implement it for the entire company.
What should you do?
You have created a new AppLocker Packaged Apps policy to help enforce the company policy.
You need to test the new AppLocker Packaged Apps policy before you implement it for the entire company.
What should you do?
Correct Answer: C
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
You manage a corporate network. All servers run Windows Server 2016. All servers and client devices are joined to an Active Directory Domain Services (AD DS) domain named adatum.com. The use of VPN servers on the network is strictly prohibited.
Users must be able to access the corporate network in addition to Work Folders when they work at home on Windows 10 devices. You install, configure, and publish the certificate revocation list (CRL) for an internal Active Directory Certificate Services (AD CS) server.
You need to configure the environment to allow your users to register devices.
Solution: You create a DNS CNAME record of enterpriseregistration.adatum.com. You deploy Active Directory Federation Services (AD FS) and point the DNS record to your AD FS server. You deploy a Web Application Proxy server for the clients to connect to establish Internet connectivity to the device registration connection.
Does the solution meet the goal?
Users must be able to access the corporate network in addition to Work Folders when they work at home on Windows 10 devices. You install, configure, and publish the certificate revocation list (CRL) for an internal Active Directory Certificate Services (AD CS) server.
You need to configure the environment to allow your users to register devices.
Solution: You create a DNS CNAME record of enterpriseregistration.adatum.com. You deploy Active Directory Federation Services (AD FS) and point the DNS record to your AD FS server. You deploy a Web Application Proxy server for the clients to connect to establish Internet connectivity to the device registration connection.
Does the solution meet the goal?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You administer devices in your corporate environment. The company allows employees to bring their own devices (BYOD). All BYOD devices must run Windows 10. For employees who elect to not use BYOD, the company provides a corporate laptop.
The company has a Microsoft Intune subscription and all BYOD devices have the Intune client installed. None of the BYOD devices are joined to the domain. All the corporate standard devices are managed by System Center Configuration Manager (SCCM).
You have an application that was developed in house that must be installed on all the BYOD devices.
The application must be installed automatically on the BYOD devices without any user intervention.
Solution: You download and install a sideloading product activation key on all of the BYOD devices. You upload the application to the Intune storage and configure the app deployment action as required install.
Does the solution meet the goal?
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You administer devices in your corporate environment. The company allows employees to bring their own devices (BYOD). All BYOD devices must run Windows 10. For employees who elect to not use BYOD, the company provides a corporate laptop.
The company has a Microsoft Intune subscription and all BYOD devices have the Intune client installed. None of the BYOD devices are joined to the domain. All the corporate standard devices are managed by System Center Configuration Manager (SCCM).
You have an application that was developed in house that must be installed on all the BYOD devices.
The application must be installed automatically on the BYOD devices without any user intervention.
Solution: You download and install a sideloading product activation key on all of the BYOD devices. You upload the application to the Intune storage and configure the app deployment action as required install.
Does the solution meet the goal?
Correct Answer: B
You have a server that runs Windows Server 2012 R2 server named Server1. Server1 has Remote Desktop Services (RDS) installed. You create a session collection named Session1 and publish a RemoteApp in Session1.
Server1 has an application named App1. The executable for App1 is C:\Apps\App1.exe.
You need to ensure that App1 is available as a RemoteApp in Session1.
What command should you run? To answer, select the appropriate options in the answer area.


Server1 has an application named App1. The executable for App1 is C:\Apps\App1.exe.
You need to ensure that App1 is available as a RemoteApp in Session1.
What command should you run? To answer, select the appropriate options in the answer area.


Correct Answer:

Explanation

We need to publish App1 as a RemoteApp. We do this with the New-RDRemoteApp cmdlet.
The -CollectionName parameter allows us to specify the session as "Session1". The display name for the App1 will be "App1".
The -FilePath parameter allows us to specify the path to the executable for App1.
You have a Microsoft Intune subscription.
You create two compliance policies named Comp1 and Comp2. You create a configuration policy named ConfigPol1. The settings in each policy do not conflict with other policies.
Comp1 has low security settings. Comp2 has medium security settings. ConfigPol1 has high security settings.
You have a device named Device1. Device1 is a member of groups that have Comp1, Comp2 and ConfigPol1 applied.
You need to identify which policies with be enforced on Device1.
What should you identify?
You create two compliance policies named Comp1 and Comp2. You create a configuration policy named ConfigPol1. The settings in each policy do not conflict with other policies.
Comp1 has low security settings. Comp2 has medium security settings. ConfigPol1 has high security settings.
You have a device named Device1. Device1 is a member of groups that have Comp1, Comp2 and ConfigPol1 applied.
You need to identify which policies with be enforced on Device1.
What should you identify?
Correct Answer: C
You administer 100 Windows 10 Enterprise laptops in your company network.
You have a wireless access point that requires 802.1x authentication. Authentication requests are forwarded to a RADIUS server.
You need to configure the laptops to connect to the wireless access point. Your solution must ensure that laptops authenticate to the RADIUS server by using stored credentials.
Which three actions should you perform in sequence? To answer, move the appropriate three actions from the list of actions to the answer area and arrange them in the correct order.

You have a wireless access point that requires 802.1x authentication. Authentication requests are forwarded to a RADIUS server.
You need to configure the laptops to connect to the wireless access point. Your solution must ensure that laptops authenticate to the RADIUS server by using stored credentials.
Which three actions should you perform in sequence? To answer, move the appropriate three actions from the list of actions to the answer area and arrange them in the correct order.

Correct Answer:

Explanation

You administer desktop computers in your company network.
You are developing User State Migration Tool (USMT) procedures.
You need to ensure that the files located in C:\projects are included in the migration package.
What should you do?

You are developing User State Migration Tool (USMT) procedures.
You need to ensure that the files located in C:\projects are included in the migration package.
What should you do?

Correct Answer: D
You are using sysprep to prepare a system for imaging.
You want to reset the security ID (SID) and clear the event logs.
Which option should you use?
You want to reset the security ID (SID) and clear the event logs.
Which option should you use?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A company has a main office located in Miami, and branch offices in Boston, Los Angeles and Portland. The Office Networks are configured as described in the following table.

A management computer in the main office, named COMPUTER1, runs windows 8 and several third-party management applications.
You need to meet the following requirements:
* Ensure that only users in the Boston office can connect to COMPUTER1 by using http.
* Ensure that only users in the Los Angeles office can connect COMPUTER1 by using https
* Ensure that only users in the Portland office can connect to COMPUTER1 by using FTP.
You are configuring access to COMPUTER1. How should you configure windows firewall?


A management computer in the main office, named COMPUTER1, runs windows 8 and several third-party management applications.
You need to meet the following requirements:
* Ensure that only users in the Boston office can connect to COMPUTER1 by using http.
* Ensure that only users in the Los Angeles office can connect COMPUTER1 by using https
* Ensure that only users in the Portland office can connect to COMPUTER1 by using FTP.
You are configuring access to COMPUTER1. How should you configure windows firewall?

Correct Answer:

Explanation

* First Row: 10.20.0.0/16, 21, TCP
The Portland users, on network 10.20.0.0/16, need FTP, which uses TCP port 21.
* Second Row: 10.30.0.0/16, 80, TCP
The Boston users, on network10.30.0.0/16, need HTTP, which uses TCP port 80.
*Third row:10.40.0.0/16, 443, TCP
The Los Angles users, on network 10.40.0.0/16, need HTTPS, which uses TCP port 443.
References: https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers