We offers . "Planning for and Managing Devices in the Enterprise", also known as 70-398 exam, is a Microsoft Certification. This set of posts, Passing the 70-398 exam with , will help you answer those questions. The covers all the knowledge points of the real exam. 100% real and revised by experts!
Online 70-398 free questions and answers of New Version:
NEW QUESTION 1
DRAG DROP
You need to configure the phones for the Sales department users.
In the Intune administration portal, which three steps should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation: References:
https://docs.microsoft.com/en-us/intune/deploy-use/set-up-ios-and-mac-management-with-microsoft-intune
Topic 4, Contoso Ltd
Overview
You are the system administrator for an insurance company named Contoso, Ltd. The company has an on-premises Active Directory Services (AD DS) domain named contoso.com, and a Microsoft Office 365 environment. You deploy the following operating systems across the enterprise:
You configure removable storage usage auditing for all Dallas devices.
Contractors
You hire 25 contractors. The contractors must use their own devices to access Microsoft SharePoint Online sites in the company’s Office 365 environment. They must use Windows BitLocker and store a recovery key in Microsoft OneDrive.
User synchronization and authentication
You need to implement synchronization between the on-premises AD DS domain and the Office 365 environment. The solution must use the latest supported Microsoft technologies.
Users must be able to reset their own passwords by using the Microsoft Office 365 portal. When a user resets their Office 365 password, the password for the user’s on-premises AD DS account must also reset.
Users must be able to sign in to Office 365 by using their AD DS credentials.
Security
You must prevent all users in Seattle except Sales users from using any removable devices. Sales users must be able to fully access locally attached tape drives. Sales users must be prevented from writing to removable drives.
Technical requirements
General
You deploy a new application to the devices in Seattle. Sales department users in Seattle run an application that only works on devices that run windows 7.
You deploy a new display driver to all devices in Dallas.
Backup and Recovery
You create system images for all devices that run Windows 7. You must create a new system image each time you update these devices. You schedule file versioning for these devices to occur at 09:00 and 17:00 each day on Monday through Friday.
All devices that run Windows 10 must back up the C:CompanyDoes folder to a network drive.
You must configure all devices that run Windows 8.1 to use a recovery drive.
Monitoring
You must review and take action on any alerts for Active Directory Federation Services (AD FS) applications. You must create detailed views of AD FS log on patterns. You must minimize the number of open firewall ports.
You must monitor audit events for all devices used by the Marketing user group.
Problem Statements
User1 makes frequent changes to a Microsoft Excel workbook each day. Today at 12:00, User1 overwrites the existing document on a device that runs Windows 7.
Users in Seattle report a variety of computer issues. You must use the quickest method to revert the devices to a working state. Users in Dallas also report issues. You must correct the issues that are interfering with existing applications or files.
NEW QUESTION 2
HOTSPOT
A company integrates Microsoft Intune with System Center 2012 R2 Configuration Manager. The company uses Intune to manage Windows 7 and Windows 10 devices along with mobile devices. Users access company data by using iOS, OS X, Windows Phone, and Android devices.
The company plans to use features of the Microsoft Enterprise Mobility Suite to increase
user mobility and ensure data protection. All users must be able to run a custom 32-bit Windows app. The app cannot be migrated.
You need to ensure that the app is accessible from all devices.
In the table below, for each technology, identify which feature to implement.
NOTE: Make only one selection in each column. Each correct answer is worth one point.
Answer:
Explanation:
NEW QUESTION 3
A company deploys Enterprise Mobility + Security. The company plans to use Azure Active Directory (AD) Premium to join all new Windows 10 devices.
Users must not be allowed to change the PowerSleep option.
You need to automatically apply custom power policies to all Windows 10 Azure AD joined devices.
What should you do?
- A. From the Azure AD Premium Configuration page, enable automatic device enrollment.
- B. Create a custom Poweroption Group Policy in Active Directory Domain Services (AD DS). Set the value of the PowerSleep option to False.
- C. Configure automatic enrollment into Microsoft Intun
- D. Create and deploy a custom Compliance policy to all Windows 10 devices.
- E. Configure automatic enrollment into Microsoft Intune for all Azure AD Premium joined device
- F. Apply a custom set of Open Mobile Alliance Uniform Resource Identifier (OMA- URI) settings to configure custom power settings.
Answer: B
NEW QUESTION 4
You have a computer named Computer1 that runs Windows 10 Enterprise. You plan to install the most recent updates to Computer1.
You need to ensure that you can revert to the current state of Computer1 in the event that the computer becomes unresponsive after the update.
What should you include in your solution?
- A. The Reset this PC option from the Recovery section of the Settings app
- B. The Sync your settings options from the Accounts section of the Settings app
- C. The Backup and Restore (Windows 7) control panel item
- D. The Refresh your PC option from the PC Settings
Answer: C
Explanation: The question states that you need to ensure that you can revert to the current state of Computer1. The question does not specify what exactly the current state is in terms of software configuration but it would be safe to assume that Computer1 has Windows Store Apps installed, desktop applications installed and some previous Windows Updates installed.
The only way to recover the computer to its ‘current’ state is to perform a full backup of the computer before updating it. Then if the computer becomes unresponsive after the update, we can simply restore the backup to return the computer to its state at the time of the backup.
NEW QUESTION 5
You need to publish the ProseWare premium apps. What should you do?
- A. Create a new storage account.
- B. Create a new RemoteApp collection by using the Quick Create option.
- C. Create a new RemoteAppcollection and assign the collection to an existing Azure virtualnetwork.
- D. Create a new Traffic Manager profile.
- E. Create and provision a new ExpressRoute circuit.
Answer: C
Explanation: References:
https://azure.microsoft.com/en-gb/documentation/articles/remoteapp-create-hybrid- deployment/
NEW QUESTION 6
DRAG DROP
You receive the following error message when you attempt to open a Remote Desktop Protocol (RDP) file to make a connection: “The remote session was disconnected because there are no Remote Desktop License Servers available to provide a license. Please contact the server administrator.”
You need to use the RDP file to sign into the virtual machine as administrator and then fix the issue.
In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
NEW QUESTION 7
You have a computer named Computer1 that runs Windows 10 Enterprise. Computer1 is configured to receive Windows updates from the Internet.
If a user is logged on to Computer1, you need to prevent Computer1 from automatically restarting without the logged on user’s consent after the installation of the Windows updates.
What should you do?
- A. Enable the Defer upgrades setting.
- B. Edit the Automatic App Update scheduled task.
- C. Configure the Choose how updates are delivered setting.
- D. Configure the Choose how updates are installed setting.
Answer: D
Explanation: In the Choose how updates are installed setting, you can use the drop-down menu to choose an option:
The Schedule a restart option will allow the user to choose when the computer is restarted. Of the answers given, this is the only way to prevent Computer1 from automatically restarting without the logged on user’s consent after the installation of the Windows updates.
NEW QUESTION 8
HOTSPOT
You have a computer that runs Windows 10 Enterprise that has a local group policy as shown in the following graphic.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Answer:
Explanation: Windows Updates will be downloaded from Windows Server Update Services only. This is determined by the “Specify Intranet Microsoft Update Service Location” setting and the “Do not connect to any Windows Update Internet locations” setting both being ‘Enabled’.
In the “Specify Intranet Microsoft Update Service Location” setting, you can specify the name of the Windows Server Updates Services server.
If a user is logged into the computer and an update requires a restart, the computer will restart when the user signs out. This is determined by the “No auto-restart with logged on users for schedule automatic updates” setting being enabled. This group policy setting creates a registry key named NoAutoRebootWithLoggedOnUsers and sets the value of the key to 1 (enabled).
With this setting enabled, you should be aware that the computer should be restarted at the earliest opportunity in order to complete the installation of the Windows Updates.
NEW QUESTION 9
HOTSPOT
Your company upgrades a research and development department workstation to a Windows 10 Enterprise computer. Two of the workstation’s folders need to be encrypted. The folders are named C:ProtectedFiles and C:Backups.
You attempt to encrypt the folders. The output is shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement. NOTE: Each correct selection is worth one point.
Answer:
Explanation: We can see from the image below that all files and the ProtectedFiles folder were encrypted successfully (There are no errors and there is an [OK] message for each action).
The image below shows that the folder was encrypted successfully (Setting the directory Backups to encrypt new files [OK]).
The file Backup.zip failed to encrypt because the file is read only. The other file, OldBackup.zip was encrypted successfully.
References: https://technet.microsoft.com/en-us/library/bb490878.aspx
NEW QUESTION 10
DRAG DROP
You have a desktop computer and a tablet that both run Windows 10 Enterprise.
The desktop computer is located at your workplace and is a member of an Active Directory domain. The network contains an Application Virtualization (App-V) infrastructure. Several App-V applications are deployed to all desktop computers.
The tablet is located at your home and is a member of a workgroup. Both locations have Internet connectivity.
You need to be able to access all applications that run on the desktop computer from you tablet.
Which actions should you perform on each computer? To answer, drag the appropriate action to the correct computer. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Answer:
Explanation: You can connect to your work computer by using Remote Desktop. You first need to enable Remote Desktop on the work computer. You then run the Remote Desktop Client on the home computer to connect to the work computer.
With Remote Desktop Connection, you can connect to a computer running Windows from another computer running Windows that's connected to the same network or to the Internet. For example, you can use all of your work computer's programs, files, and network resources from your home computer, and it's just like you're sitting in front of your computer at work.
To connect to a remote computer, that computer must be turned on, it must have a network connection, Remote Desktop must be enabled, you must have network access to the remote computer (this could be through the Internet), and you must have permission to connect. For permission to connect, you must be on the list of users. Before you start a connection, it's a good idea to look up the name of the computer you're connecting to and to make sure Remote Desktop connections are allowed through its firewall.
NEW QUESTION 11
DRAG DROP
You need to configure the mobile devices for the Engineering department users.
In the Microsoft Intune administration portal, which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation: References:
https://docs.microsoft.com/en-us/intune/deploy-use/configure-intune-certificate-profiles
NEW QUESTION 12
A company deploys Outlook to all users that have iOS and Android devices. The company uses Microsoft Intune to manage mobile devices. You enforce a conditional access policy that requires users to enroll devices in Intune before they can access Exchange ActiveSync data.
Some Android and iOS users access Exchange ActiveSync data by using unmanaged email applications.
You need to ensure that users Exchange ActiveSync data only from Outlook. What should you do?
- A. Create an Exchange access rul
- B. Select Outlook family and Outlook for Android and iOS as the model.
- C. In Intune, create a new compliance policy that forces email accounts to be managed by Intune.
- D. Create a security group for all users that are not using Outlook as the email application
- E. Configure Exchange Online conditional access policy to exempt members of the group.
- F. Configure a custom Open Mobile Alliance Uniform Resource Identifier setting and deploy the setting to all users.
Answer: A
NEW QUESTION 13
You have a computer named Computer1 that runs Windows 10 Enterprise. Computer1 is a member of an Active Directory domain named contoso.com.
You have a line-of-business universal app named App1. App1 is developed internally. You need to ensure that you can run App1 on Computer1. The solution must meet the
following requirements:
Minimize costs to deploy the app.
Minimize the attack surface on Computer1. What should you do?
- A. Have App1 certified by the Windows Store.
- B. Sign App1 with a certificate issued by a third-party certificate authority.
- C. From the Update & Security setting on Computer1, enable the Sideload apps setting.
- D. Run the Add–AppxProvisionedPackage cmdlet.
Answer: C
Explanation: To install the application, you need to ‘Sideload’ it. First you need to enable the Sideload apps setting.
LOBW indows Store apps that are not signed by the Windows Store can be sideloaded or added to a PC in the enterprise through scripts at runtime on a per-user basis. They can also be provisioned in an image by the enterprise so that the app is registered to each new user profile that's created on the PC. The requirements to sideload the app per-user or in the image are the same, but the Windows PowerShell cmdlets you use to add, get, and remove the apps are different.
Before you can sideload LOB Windows Store apps that are not signed by the Windows Store, you will need to configure the PC.
NEW QUESTION 14
HOTSPOT
You upgrade 15 client devices to Windows 10 Enterprise. You need to configure the devices.
Which Control Panel applets should you use? To answer, select the appropriate applet from each list in the answer area. Each correct answer is worth one point.
Answer:
Explanation:
NEW QUESTION 15
A company plans uses Microsoft Azure to manage directory users. In Azure, you create a virtual network and a DNS record.
You need to set up the connection between the virtual network and your on-premises
network.
Which two actions will achieve the goal? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
- A. Configure the on-premises routing infrastructure to forward traffic destined for the address space of the Azure Virtual Network to the on-premises virtual private network device.
- B. Configure the private IP address space of the Azure Virtual Network.
- C. Manually create DNS records to point to the Azure virtual machines.
- D. Extract the server license certificate key from the configuration data, and transfer the key to an on-premises hardware security module.
Answer: AB
Explanation: References:
https://docs.microsoft.com/en-us/office365/enterprise/connect-an-on-premises-network-to-a-microsoft-azure-virtual-network
NEW QUESTION 16
DRAG DROP
You need to resolve the Security team service announcement.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation: 1: In the Mandatory Updates list, filter by Needing additional approvals, and approve the update.
2: Select the Windows 10 computer device group in the Approval wizard.
3: Configure the approval settings to require install with a deadline as soon as possible.
References:
https://www.credera.com/blog/infrastructure/understanding-windows-updates-for-pcs-with-microsoft-intune/
NEW QUESTION 17
HOTSPOT
You administer Windows 10 Enterprise computers in your company network, including a computer named Wst1. Wst1 is configured with multiple shared printer queues.
Wst1 indicates hardware errors. You decide to migrate the printer queues from Wst1 to a new computer named Client1.
You export the printers on Wst1 to a file. You need to import printers from the file to Client1.
From the Print Management console, which Print Management node should you select? To answer, select the appropriate node in the answer area.
Answer:
Explanation: We have exported the printers on Wst1 to a file. To import printers from the file to Client1, we use the Printer Migration Wizard.
Right-click Print Management, and then click Migrate Printers to open the Printer Migration Wizard. Select Import printer queues and printer drivers from a file, and select the export file. Then complete the wizard.
References: http://blogs.technet.com/b/canitpro/archive/2013/06/17/step-by-step-install-use-and-remove-windows-server-migration-tools.aspx
NEW QUESTION 18
HOTSPOT
A company has a Remote Desktop (RD) Services farm. The farm has six servers that run Windows Server 2008, five RD Session Host servers, and one RD Connection Broker server. User RD profiles are redirected to a hidden folder named PROFILES on a file server named FILTER01.
You must provide a deployment plan for migrating the RD farm to Windows Server 2012 R2. The new farm must use the same file server share to redirect user RD profiles. Users must be able to log on to any server and have the same experience.
You need to configure RD Services.
What should you do? To answer, select the appropriate action from each list in the answer area.
Answer:
Explanation: References:
http://woshub.com/user-profile-disks-in-windows-server-2012-r2-rds/
Recommend!! Get the Full 70-398 dumps in VCE and PDF From Certleader, Welcome to Download: https://www.certleader.com/70-398-dumps.html (New 74 Q&As Version)