Which two actions should you perform?

Your network contains an Active Directory domain named contoso.com. The domain contains three
servers. The servers are configured as shown in the following table.

You need to ensure that end-to-end encryption is used between clients and Server2 when the clients
connect to the network by using DirectAccess.
Which two actions should you perform? (Each correct answer presents part of the solution. Choose
two.)

Your network contains an Active Directory domain named contoso.com. The domain contains three
servers. The servers are configured as shown in the following table.

You need to ensure that end-to-end encryption is used between clients and Server2 when the clients
connect to the network by using DirectAccess.
Which two actions should you perform? (Each correct answer presents part of the solution. Choose
two.)

A.
From the Remote Access Management Console, reload the configuration.

B.
Add Server2 to a security group in Active Directory.

C.
Restart the IPSec Policy Agent service on Server2.

D.
From the Remote Access Management Console, modify the Infrastructure Servers settings.

E.
From the Remote Access Management Console, modify the Application Servers settings.

Explanation:
Unsure about these answers:
A public key infrastructure must be deployed.
Windows Firewall must be enabled on all profiles.
ISATAP in the corporate network is not supported. If you are using ISATAP, you should remove it and
use native IPv6.
Computers that are running the following operating systems are supported as DirectAccess clients:
Windows Server® 2012 R2
Windows 8.1 Enterprise
Windows Server® 2012
Windows 8 Enterprise
Windows Server® 2008 R2
Windows 7 Ultimate
Windows 7 Enterprise
Force tunnel configuration is not supported with KerbProxy authentication.
Changing policies by using a feature other than the DirectAccess management console or Windows
PowerShell cmdlets is not supported.
Separating NAT64/DNS64 and IPHTTPS server roles on another server is not supported.



Leave a Reply 6

Your email address will not be published. Required fields are marked *

1 × three =


Hitokiri

Hitokiri

Answer B and E, no explanation Sorry..

testtaker

testtaker

to allow ipsec the server that needs the ipsec connection needs to be added to the application servers in DA. The wizard that allows you to modify the app servers in DA takes only groups hence the server needs to be added to a group

jay z

jay z

To configure application servers
In the middle pane of the Remote Access Management console, in the Step 4 Application Servers area, click Configure.
In the DirectAccess Application Server Setup Wizard, to require authentication to selected application servers, click Extend authentication to selected application servers. Click Add to select the application server security group.
To limit access to only the servers in the application server security group, select the Allow access only to servers included in the security groups check box.
To use authentication without encryption, select the Do not encrypt traffic. Use authentication only check box.
Click Finish.