70-398 Royal Pack Testengine pdf
100% Actual & Verified — 100% PASS
Unlimited access to the world's largest Dumps library!Download 70-398 Dumps Free
Exam Number/Code: 70-398
Exam name: Planning for and Managing Devices in the Enterprise
n questions with full explanations
Certification: Microsoft Certification
Your success in is our sole target and we develop all our in a way that facilitates the attainment of this target. Not only is our material the best you can find, it is also the most detailed and the most updated. for Microsoft 70-398 are written to the highest standards of technical accuracy.
Also have 70-398 free dumps questions for you:
NEW QUESTION 1
You have a computer named Computer1 that runs Windows 10 Enterprise. Computer1 is configured to receive Windows updates from the Internet.
If a user is logged on to Computer1, you need to prevent Computer1 from automatically restarting without the logged on user’s consent after the installation of the Windows updates.
What should you do?
- A. Enable the Defer upgrades setting.
- B. Edit the Automatic App Update scheduled task.
- C. Configure the Choose how updates are delivered setting.
- D. Configure the Choose how updates are installed setting.
Explanation: In the Choose how updates are installed setting, you can use the drop-down menu to choose an option:
The Schedule a restart option will allow the user to choose when the computer is restarted. Of the answers given, this is the only way to prevent Computer1 from automatically restarting without the logged on user’s consent after the installation of the Windows updates.
NEW QUESTION 2
A company plans to actively manage mobile devices.
You need to create a list of all jailbroken devices after they are enrolled. What should you use?
- A. Azure Active Directory
- B. System Center 2012 R2 Configuration Manager SP1
- C. Intune
- D. Azure Active Directory Domain Services
- E. Azure Active Directory Device Registration Service
NEW QUESTION 3
You plan to deploy a Microsoft Azure RemoteApp collection by using a custom template image. The image will contain Microsoft Word and Excel Office 365 ProPlus programs.
You need to install the Word and Excel programs. The solution must minimize the amount of Internet traffic used during installation.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Explanation: The first step is to download the Office Deployment Tool.
You then need to modify the configuration file. This will be used to specify the installation options for Word and Excel.
You then run Setup.exe from the Office Deployment Tool with the /download option to download the required software based on the options in the configuration file.
The final step is to install Word and Excel by running Setup.exe from the Office Deployment Tool with the /configure option to install the required software based on the options in the configuration file.
NEW QUESTION 4
You have a Windows 10 Enterprise computer.
The computer has a shared folder named C:\Marketing. The shared folder is on an NTFS volume.
The current NTFS and share permissions are configured as follows.
UserA is a member of both the Everyone group and the Marketing group. UserA must access C:\Marketing from across the network. You need to identify the effective permissions of UserA to the C:\Marketing folder.
What permission should you identify?
- A. Full Control
- B. Read and Execute
- C. Read
- D. Modify
Explanation: UserA is a member of both the Everyone group and the Marketing group and UserA must access C:\Marketing from across the network.
When accessing a file locally, you combine the NTFS permissions granted to your account either directly or by way of group membership. The ‘least’ restrictive permission is then the permission that applies.
In this question, the NTFS permission is the least restrictive of Read/Execute and Modify… so Modify is the effective permission.
When accessing a folder or file across the network, you combine the effective NTFS permissions (Modify in this case) with the effective Share permissions granted to your account either directly or by way of group membership (Full Control in this case). The ‘most’ restrictive permission is then the permission that applies. Modify is more restrictive than Full Control so Modify is the effective permission.
NEW QUESTION 5
You support desktop computers and tablets that run Windows 8 Enterprise. All of the computers are able to connect to your company network from the Internet by using DirectAccess.
Your company wants to deploy a new application to the tablets. The deployment solution must meet the following requirements:
You need to deploy the new application to the tablets. What should you do?
- A. Deploy the application as an Application Virtualization (App-V) packag
- B. Install the App- V 4.6 client on the tablets.
- C. Deploy the application as a published application on the Remote Desktop serve
- D. Create a Remote Desktop connection on the tablets.
- E. Install the application on a local drive on the tablets.
- F. Install the application in a Windows To Go workspace.
- G. Install Hyper-V on tablet
- H. Install the application on a virtual machine.
- I. Publish the application to Windows Store.
- J. Install the application within a separate Windows 8 installation in a virtual hard disk (VHD) fil
- K. Configure the tablets with dual boot.
- L. Install the application within a separate Windows 8 installation in a VHDX fil
- M. Configure tablets with dual boot.
Explanation: Deploying the application as a published application on the Remote Desktop server will use no disk space on the tablets. Users will be able to access the application by using Remote Desktop Connections. This will also ensure that the application is isolated from other applications on the tablets.
We can use Remote Desktop Connection ‘redirection’ to ensure that the application is able to access files stored on an internal solid-state drive (SSD) on the tablets. Redirection enables access to local resources such as drives, printers etc. in a Remote Desktop Connection.
NEW QUESTION 6
You need to configure access to the custom inventory app for Sales department users.
Which action should you perform to complete each task? To answer, select the appropriate action for each task in the answer area.
NEW QUESTION 7
A company has a policy that all data stored on a corporate mobile device must be encrypted.
You need a management solution that enforces the policy.
Which two management solutions should you use? Each correct answer presents part of the solution.
- A. Windows Server 2012 R2 Active Directory Certificate Services Server role.
- B. Microsoft Exchange ActiveSync.
- C. System Center 2012 R2 Configuration Manager.
- D. Microsoft Operations Management Suite.
- E. Microsoft Intune Mobile Device Management.
NEW QUESTION 8
A company runs Windows 10 Enterprise on all devices and has a single Active Directory Domain Services (AD DS) domain. The company uses Microsoft Intune to manage Windows Phones and iOS devices.
Security updates must be installed as quickly as possible. The update management solution must be able to automatically uninstall updates. You must not deploy any additional development or custom tools.
You need to implement a solution.
In the table below, identify the feature that each solution supports.
NOTE: Make only one selection in each column. Each correct answer is worth one point.
NEW QUESTION 9
A company has tablet devices that run Windows 10. You configure auditing for devices. You need to determine which audit policies are configured on the devices.
What should you do?
- A. At a command prompt, run the following command:auditpol
- B. Run the following Windows PowerShell cmdlet:Get-AdminAuditLogConfig
- C. At a command prompt, run the following command:Dsget
- D. At a command prompt, run the following command:Winrm
- E. Run the following Windows PowerShell cmdlet:Get-AuditLogSearch
NEW QUESTION 10
The company apps need to be made available to all mobile devices. You recently
published the new applications in Azure. What should you do?
- A. In the Microsoft Azure admin portal, add users to the app collection for the apps.
- B. In the MicrosoftAzure admin portal, enable multi-factor authentication.
- C. Instruct users to download the Remote Desktop app from the appropriate vendor app store.
- D. Run the following Windows PowerShell cmdlet:Update-AzureRemoteAppCollection
NEW QUESTION 11
You manage a network that includes Windows 10 Enterprise computers. All of the computers on the network are members of an Active Directory domain.
The company recently proposed a new security policy that prevents users from synchronizing applications settings, browsing history, favorites, and passwords from the computers with their Microsoft accounts.
You need to enforce these security policy requirements on the computers. What should you do?
- A. On the Group Policy Object, configure the Accounts: Block Microsoft accounts Group Policy setting to Users can’t add Microsoft accounts.
- B. On the Group Policy Object, configure the Accounts: Block Microsoft accounts Group Policy setting to Users can’t add or log on with Microsoft accounts.
- C. From each computer, navigate to Change Sync Settings and set the Sync Your Settings options for Apps, Browser, and Passwords to Off.
- D. From each computer, navigate to Change Sync Settings and set the Sync Your Settings option to Off.
Explanation: The computers are members of a domain so the users should be using domain user accounts. We need to block the use of Microsoft accounts.
We could use the Users can’t add Microsoft accounts setting which would mean that users will not be able to create new Microsoft accounts on a computer, switch a local account to a Microsoft account, or connect a domain account to a Microsoft account.
Alternatively, we can also deny the ability to log on to a domain computer with a Microsoft account (and sync computer settings) by using the Users can’t add or log on with Microsoft accounts. This will ensure that the company policy is enforced.
NEW QUESTION 12
You need to create the policy for the Tokyo branch office. What should you use?
- A. Azure Active Directory Device Registration Service
- B. System Center 2012 R2 Configuration Manager SP1
- C. Intune
- D. Azure Active Directory
- E. Azure Active Directory Domain Services
NEW QUESTION 13
A company plans to deploy 100 new Windows 10 devices. Then pilot users are currently testing Windows 10 is not corporate network.
The pilot users report that the Hibernate option is not available. You need to enable hibernation on the Windows 10 devices. Which command should you run?
- A. Powercfg –energy
- B. Powercfg –h off
- C. Powercfg –h on
- D. Powercfg –deviseenablewake
- E. Powercfg -setactive
NEW QUESTION 14
You need to import RemApp1 into the Azure RemoteApp Template Image Library. Which tool should you run first?
- A. Disk2VHD
- B. System Preparation Tool
- C. Application Compatibility Toolkit
- D. Azure Mobile Apps Software Development Kit installer.
NEW QUESTION 15
You need to test the ProseWare MyNotesPro app.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Topic 3, Blue Yonder Airline
Blue Yonder Airlines provides regional commercial jet services in the continental United States. The company also designs, manufactures, and sells custom parts for jet aircraft. The custom parts business is growing rapidly. Blue Yonder airlines has developed a new part that will help airlines comply with new safety regulations. The company has a backlog of customers that would like to purchase the part.
The Sales department has 500 users and the Engineering department has 200 users. All employees work eight hour shifts. The Sales and Engineering teams cannot effectively collaborate on projects. This has resulted in missed deadlines for releasing new products to manufacturing.
Mobile device management
Blue Yonder Airlines has a subscription to Microsoft Intune for Mobile Device Management (MDM). The subscription includes the MDM Authority and Terms and Conditions components. The company has deployed the Network Device Enrollment service, Enterprise Certification Authority, and the Intune Certificate Connector. Blue Yonder Airlines has an on-premises Microsoft Exchange environment.
The company will use a combination of Intune and Azure RemoteApp for Mobile Application Management.
Mobile devices for employees
Blue Yonder Airlines plans to deploy mobile devices to the Sales and Engineering department employees for use while they are outside of the company network. The company plans to deploy the latest iOS devices for Sales department users and Windows 10 tablet devices for Engineering department users.
You configure a Sales group for Sales department users and an Engineering group for Engineering department users. In Intune, you configure a computer device group for Windows 10 devices, and a mobile device group for iOS devices. You synchronize the Sales and Engineering groups with Azure Active Directory (AD).
You have a network file share that is used by Engineering department users to collaborate on projects. The file share is configured with full control permissions. The company is concerned that users may be disrupted if they are suddenly denied access to the file share.
Inventory Management App
Blue Yonder Airlines has developed a custom inventory management app. Sales department users must be able to access the app from enrolled mobile devices. The data that the app uses is considered confidential and must be encrypted.
New product Sales App
You procure a third-party app from a vendor to support new product sales. The data that the app uses is highly confidential. You must restrict access to the app and the app’s data to only Engineering department users. The app has been signed by using a Blue Airlines certificate. This certificate is not trusted by devices that run Windows 10.
Product Request Program App
The company has developed the Product Request Program app as a 32-bit Windows application. The application allows the company to manage the sales fulfillment process. It is also used to record customer requests for new parts and services. You plan to publish the Product Request Program app in Azure RemoteApp and configure access for users in the Engineering and Sales departments. This app is not compatible with the iOS platform and cannot by published by using Intune. You create a virtual machine in Azure that runs Windows Server 2012 R2. You install the Product Request Program app on the virtual machine.
You must ensure that the Sales and Engineering teams can share documents and collaborate effectively. Any collaboration solution must be highly available and must be accessible from the internet. You must restrict access to any shared files to prevent access.
You must restrict permissions to the Engineering file share. You must monitor access to the file share.
You must provide users in the Sales and Engineering departments access to the following resources:
*File Shares hosted in Microsoft SharePoint Online
*The Product Request Program app
You have the following technical requirements:
*Allow all Sales department users to enroll iOS devices for device management andenable encrypted notifications to the devices.
*Employees must be able to access company resources without having to manually install certificates or using an out-of-band process.
*Employees must only access corporate resources from devices that comply withthe company’s security policies.
Mobile device protection policies
*All devices must include a trusted build and must comply with Blue Yonder Airlines password complexity rules.
*You must clear all corporate data from a mobile device when the number of repeated log on failures is more than 10.
*All devices must be protected from data loss in the event that a device is lost or damaged.
*Data that is considered confidential must be encrypted on devices.
Additional technical requirements for Engineering department users and devices
*Users must not be challenged for credentials after they initially enroll a device in Intune.
*Users must be able to access corporate email on enrolled Windows 10 devices.
*Devices must be automatically updated when an update is available. You must configure the Intune agent to prompt for restart no more than one time during normal business hours. System restarts to complete update installations must occur outside of normal business hours.
Sales and Engineering teams
Sales and Engineering department users report that it is difficult to share documents and collaborate on new projects. Blue Yonder Airlines has an urgent need to improve collaboration between the Sales department and Engineering department. Any collaboration solution must be highly available and accessible from the Internet.
Engineering department users report that Intune prompts them to restart their Windows 10 devices every 30 minutes when an update is available for installation. The prompts are disruptive to users.
The Blue Yonder Airlines Security team has detected a vulnerability in Windows 10 devices. Microsoft has released a patch to address the vulnerability. The Security department has issued a service announcement. They request that you deploy the patch to all Windows 10 devices managed by Microsoft Intune.
NEW QUESTION 16
A company plans to deploy Microsoft Office to mobile device users. You purchase Enterprise Mobility + Security licenses and deploy Microsoft Intune.
Company data must only be shared between applications approved by the company and Microsoft Office applications.
You need to ensure that users cannot share data with other applications. What should you do?
- A. Configure a managed application policy that requires a PIN code to access the application on the device.
- B. Configure a conditional access policy that enforces application encryption on all devices.
- C. Deploy and configure Azure Rights Management Services.
- D. Configure a configuration policy that will enable a PIN code and deploy the policy to all Office users.
- E. Configure a managed application policy that will restrict cut, copy, and paste with other non-managed applications.
NEW QUESTION 17
Your company upgrades a research and development department workstation to a Windows 10 Enterprise computer. Two of the workstation’s folders need to be encrypted. The folders are named C:\ProtectedFiles and C:\Backups.
You attempt to encrypt the folders. The output is shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement. NOTE: Each correct selection is worth one point.
Explanation: We can see from the image below that all files and the ProtectedFiles folder were encrypted successfully (There are no errors and there is an [OK] message for each action).
The image below shows that the folder was encrypted successfully (Setting the directory Backups to encrypt new files [OK]).
The file Backup.zip failed to encrypt because the file is read only. The other file, OldBackup.zip was encrypted successfully.
NEW QUESTION 18
A bank deploys Active Directory Rights Management Services (AD RMS). The bank plans to migrate to Azure Rights Management Services (Azure RMS) as an alternative to the on- premises based AD RMS.
The bank must follow regulatory policies that restrict access to certain financial documents. In the table below, identify which function each platform supports.
NOTE: Make only selection in each column. Each correct selection is worth one point.
Topic 2, ProseWare Inc.
ProseWare, Inc.is a software company that specializes in developing smartphone apps that work on multiple platforms. The main office for the company is located in Atlanta. The company has branch offices in Tokyo and Paris.
The company recently published a new game. The game has sold over 10 million copies in the first year. In the same period, 25 million copies of the free version of the game were downloaded. ProseWare also developed a user productivity app named MyNotesPro.
Due to the massive demand for the game and for potential new versions and features, ProseWare plans to increase their staff from 100 to 1,000 employees. The employees will be evenly distributed between the three locations. Each employee will have a tablet device that runs Windows 10.
ProseWare plans to connect all offices together by using high-speed internet links. Each employee will be issued a smartphone that runs Apple iOS, Android, or Windows 10. The quality assurance (QA) department includes 50 employees. Each QA department employee will be issued three smartphone devices, one device for each of the operating
systems. ProseWare uses Microsoft Intune to manage devices. The company has joined the Apple Device Enrollment program.
You create a virtual machine (VM) named RemApp1 in Microsoft Azure by using the Windows Server Remote Desktop Session Host gallery image. Users in the Training department connect to the VM and run several training apps.
You have a file server named FILER01 that runs Windows Server 2012 R2.
In Azure, you create a virtual network and a DNS record. You implement directory synchronization between the on-premises domain and Azure.
You have purchased Remote Desktop Services Client Access Licenses.
All employees will be given access to a suite of ProseWare premium apps that includes MyNotesPro. You must provide access to the apps by using Azure RemoteApp.
The Atlanta corporate headquarters performs training on a weekly basis for all Tokyo and Paris employees. The training is conducted by using Microsoft Skype for Business on Windows 10 Enterprise devices. You configure the devices to display content in the respective language for the location. Some of the trainers in Atlanta speak Japanese or French.
The Chief Technology Officer requires the following reports:
Employees must be able to download and install the appropriate RemoteApp client for their specific mobile device. The procedure for installing RemoteApp clients differs for each mobile operating system. All users must have access to the Azure RemoteApp infrastructure on their mobile devices in order to access the ProseWare premium apps.
All apps must be centrally managed and updated. You must ensure that the apps are available to all employees. Employees must install all apps from a common source location. The ProseWare apps must only be installed on employee devices.
You must import RemApp1 into the Azure RemoteApp Template Image Library. RemApp1 will host the Proseware premium apps.
Some of the apps must be able to access data kept in the on-premises servers at the Atlanta office.
You must design a Work Folders solution on a FILER01. You have the following requirements:
*You must encrypt all data that is synchronized.
*You must synchronize settings every 60 minutes.
*You must restrict the size of each file that is synchronized to 5 gigabytes.
P.S. Surepassexam now are offering 100% pass ensure 70-398 dumps! All 70-398 exam questions have been updated with correct answers: https://www.surepassexam.com/70-398-exam-dumps.html (74 New Questions)
[TRY FREE] BUY 70-398 Full version( pdf+software ):