Exam Code: 70-398 (Practice Exam Latest Test Questions VCE PDF)
Exam Name: Planning for and Managing Devices in the Enterprise
Certification Provider: Microsoft
Free Today! Guaranteed Training- Pass 70-398 Exam.

Q17. You manage an Active Directory Domain Services (AD DS) domain that has 500 devices. All devices run Windows 7 Enterprise Edition. You deploy System Center 2012 R2 Configuration Manager SP1.

You plan to upgrade all devices to Windows 10 Enterprise and encrypt the devices by using Microsoft BitLocker Administration and Monitoring (MBAM), Data secured with BitLocker must not be stored on USB devices.

You need to ensure that existing devices are ready for the upgrade. What should you do?

A. Implement MBAM in thedomain. Create an MBAM group policy and apply the policy to all devices.

B. Verify that the System Center Configuration Manager agent is installed on all devices.

C. In the system BIOS, verify that all devices have a Trusted Platform Module (TPM) 1.2 or higher chip. Enable the TPM chip.

D. Integrate MBAM with System Center Configuration Manager. Deploy the BitLocker prepare task sequence to all laptop computers.

E. From System Center Configuration Manager, create a custom deploy task sequence that enables MBAM. Deploy the task sequence to all Windows 7 devices.

Answer: B


Q18. HOTSPOT

A company integrates Microsoft Intune with System Center 2012 R2 Configuration Manager. The company uses Intune to manage Windows 7 and Windows 10 devices along with mobile devices. Users access company data by using iOS, OS X, Windows Phone, and Android devices.

The company plans to use features of the Microsoft Enterprise Mobility Suite to increase user mobility and ensure data protection. All users must be able to run a custom 32-bit Windows app. The app cannot be migrated.

You need to ensure that the app is accessible from all devices.

In the table below, for each technology, identify which feature to implement.

NOTE: Make only one selection in each column. Each correct answer is worth one point.

Answer:


Q19. A company deploys Office 365 in a federated identity model. The environment has two Active Directory Domain Services (AD DS) servers and two Web Application Proxy servers that are not joined to the domain.

All externally published applications that use Windows Authentication and are hosted on- premises must use Active Directory Federation Services (AD FS) to log on.

You need deploy pre-authentication on the Web Application Proxy (WAP) servers. What should you do first?

A. Enable Kerberos constrained delegation.

B. Join the WAP servers to the AD DS domain.

C. Remove and reinstall the AD FS role.D Remove and reinstall the WAP role.

Answer: B


Q20. HOTSPOT

You administer Office 365 and Azure Active Directory (AD) for a car rental company. You also manage an on-premises Active Directory Domain Services (AD DS) domain. You implement Active Federation Services (AD FS).

You plan to implement Azure AD Connect Health.

You need to ensure that you can install and configure Azure AD Connect Health.

What should you do? To answer, select the appropriate option from each list in the answer area.

Answer:

Explanation:

References:

https://azure.microsoft.com/en-us/documentation/articles/active-directory-aadconnect-health-agent-install/#Requirements


Q21. A company has a policy that all data stored on a corporate mobile device must be encrypted.

You need a management solution that enforces the policy.

Which two management solutions should you use? Each correct answer presents part of the solution.

A. Windows Server 2012 R2 Active Directory Certificate Services Server role.

B. Microsoft Exchange ActiveSync.

C. System Center 2012 R2 Configuration Manager.

D. Microsoft Operations Management Suite.

E. Microsoft Intune Mobile Device Management.

Answer: B,E


Q22. DRAG DROPĀ 

You manage 500 laptop devices and 250 desktop devices that run Windows 10. All devices are joined to an Active Directory Domain Services (AD DS) domain. You also manage a Windows Server 2012 R2 file server named FILE01.

All user document folders must be located on FILE01.

You need to ensure that the mobile users can access documents offline.

Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:


Q23. DRAG DROP

A company plans to upgrade all devices from Windows 7 to Windows 10. All Windows 10 devices belong to an organizational unit (OU) named Desktops. All devices for users in the sales department are enrolled in Azure Active Directory (AD). All users belong to an OU named Employees.

Users in the finance department must not be able to modify the power policy settings. You need to apply the power policy.

What should you do? To answer, drag the appropriate option to the correct item. Each option may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

Answer:


Q24. HOTSPOT

A company runs Windows 10 Enterprise on all devices and has a single Active Directory Domain Services (AD DS) domain. The company uses Microsoft Intune to manage

Windows Phones and iOS devices.

Security updates must be installed as quickly as possible. The update management solution must be able to automatically uninstall updates. You must not deploy any additional development or custom tools.

You need to implement a solution.

In the table below, identify the feature that each solution supports.

NOTE: Make only one selection in each column. Each correct answer is worth one point.

Answer: