Exit demo 70-398 Planning for and Managing Devices in the Enterprise PDF format · free preview

Microsoft 70-398 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/70-398.html

Question 1
Single choice

You support desktop computers and tablets that run Windows 8 Enterprise. All of the computers are able to connect to your company network from the Internet by using DirectAccess.

Your company wants to deploy a new application to the tablets. The deployment solution must meet the following requirements:

You need to deploy the new application to the tablets.

What should you do?

A.

Deploy the application as an Application Virtualization (App-V) package. Install the App- V 4.6 client on the tablets.

B.

Deploy the application as a published application on the Remote Desktop server. Create a Remote Desktop connection on the tablets.

C.

Install the application on a local drive on the tablets.

D.

Install the application in a Windows To Go workspace.

E.

Install Hyper-V on tablets. Install the application on a virtual machine.

F.

Publish the application to Windows Store.

G.

Install the application within a separate Windows 8 installation in a virtual hard disk (VHD) file.
Configure the tablets with dual boot.

H.

Install the application within a separate Windows 8 installation in a VHDX file. Configure tablets with dual boot.

Question 2
Single choice

A company deploys Office 365 in a federated identity model. The environment has two Active Directory Domain Services (AD DS) servers and two Web Application Proxy servers that are not joined to the domain.

All externally published applications that use Windows Authentication and are hosted on-premises must use Active Directory Federation Services (AD FS) to log on.

You need deploy pre-authentication on the Web Application Proxy (WAP) servers.

What should you do first?

A.

Enable Kerberos constrained delegation.

B.

Join the WAP servers to the AD DS domain.

C.

Remove and reinstall the AD FS role.D Remove and reinstall the WAP role.

Question 3
Single choice

You have a Windows 10 Enterprise computer.

The computer has a shared folder named C:\Marketing. The shared folder is on an NTFS volume.

The current NTFS and share permissions are configured as follows.

UserA is a member of both the Everyone group and the Marketing group. UserA must access C:\Marketing from across the network. You need to identify the effective permissions of UserA to the C:\Marketing folder.

What permission should you identify?

A.

Full Control

B.

Read and Execute

C.

Read

D.

Modify

Question 4
Single choice

A company plans to deploy Outlook as a managed app to all users. You deploy Microsoft Intune.

You must deploy an internally developed iOS line of business (LOB) app to all users in the sales department. These users must only be able to share data between Outlook and the internally developed
LOB app.
You need to configure the environment for sales department users.

What should you do?

A.

Configure a security policy that forces encryption.

B.

Use the Intune App Wrapping Tool to repackage the internally developed LOB application.

C.

Upload the internally developed LOB app to the Apple App Store. Deploy the app to all users in the sales department.

D.

Use the Intune App Wrapping Tool to repackage the Outlook application. Set the value for the App ID to match to Application ID of the internally developed LOB application.

Question 5
Single choice

You are a system administrator for a department that has Windows 10 Enterprise computers in a domain

configuration.

You deploy an application to all computers in the domain.

You need to use group policy to restrict certain groups from running the application.

What should you do?

A.

Set up DirectAccess.

B.

Configure AppLocker.

C.

Disable BitLocker.

D.

Run the User State Management Tool.

Question 6
Multiple choice

A company uses Office 365. The company has an on-premises Active Directory Domain Services (AD DS) domain and Azure Active Directory Connect. The company runs an on-premises installation of System Center Configuration Manager. All devices are joined to the domain. All users have AD DS accounts and use their AD DS credentials to access the Office 365 resources.

You plan to use Cloud App Discovery.

You need to deploy a solution.

Which three will achieve the goal? Each correct answer presents a complete solution.

A.

Install the agent by using System Center Operations Manager.

B.

Install the agent by using SystemCenter Configuration Manager.

C.

Install the agent by using Group Policy.

D.

Install the agent manually.

E.

Install the agent by using the Office 365 portal.

Question 7
Single choice

A company deploys Outlook to all users that have iOS and Android devices. The company uses Microsoft Intune to manage mobile devices. You enforce a conditional access policy that requires users to enroll devices in Intune before they can access Exchange ActiveSync data.

Some Android and iOS users access Exchange ActiveSync data by using unmanaged email applications.

You need to ensure that users Exchange ActiveSync data only from Outlook.

What should you do?

A.

Create an Exchange access rule. Select Outlook family and Outlook for Android and iOS as the model.

B.

In Intune, create a new compliance policy that forces email accounts to be managed by Intune.

C.

Create a security group for all users that are not using Outlook as the email applications.

Configure Exchange Online conditional access policy to exempt members of the group.

D.

Configure a custom Open Mobile Alliance Uniform Resource Identifier setting and deploy the setting to all users.

Question 8
Single choice

The company apps need to be made available to all mobile devices. You recently published the new applications in Azure.

What should you do?

A.

In the Microsoft Azure admin portal, add users to the app collection for the apps.

B.

In the MicrosoftAzure admin portal, enable multi-factor authentication.

C.

Instruct users to download the Remote Desktop app from the appropriate vendor app store.

D.

Run the following Windows PowerShell cmdlet:Update-AzureRemoteAppCollection

Question 9
Single choice

A company has an Office 365 E3 subscription. You deploy Enterprise Mobility + Security, Active Directory Federation Services (AD FS), and Microsoft Identity Manager.

You need to implement additional security when users remotely connect to corporate resources.

What should you implement?

A.

System Center Configuration Manager

B.

Microsoft Intune

C.

Azure Rights Management Service

D.

Azure Multi-Factor Authentication

Question 10
Single choice

A company deploys Enterprise Mobility + Security. The company plans to use Azure Active Directory (AD)
Premium to join all new Windows 10 devices.

Users must not be allowed to change the PowerSleep option.

You need to automatically apply custom power policies to all Windows 10 Azure AD joined devices.

What should you do?

A.

From the Azure AD Premium Configuration page, enable automatic device enrollment.

B.

Create a custom Poweroption Group Policy in Active Directory Domain Services (AD DS). Set the value of the PowerSleep option to False.

C.

Configure automatic enrollment into Microsoft Intune. Create and deploy a custom Compliance policy to all Windows 10 devices.

D.

Configure automatic enrollment into Microsoft Intune for all Azure AD Premium joined devices. Apply a custom set of Open Mobile Alliance Uniform Resource Identifier (OMA-URI) settings to configure custom power settings.

Showing 10 of 74 questions · Unlock the full set