exam questions

Exam 70-741 All Questions

View all questions & answers for the 70-741 exam

Exam 70-741 topic 1 question 151 discussion

Actual exam question from Microsoft's 70-741
Question #: 151
Topic #: 1
[All 70-741 Questions]

HOTSPOT -
You have a network policy server (NPS) server named NPS1. One network policy is enabled on NPS1. The policy is configured as shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information in the graphic.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TMW
Highly Voted 5 years, 6 months ago
The domain users group isn't listed, so they would not have access unless they were members of one of the groups that are listed. Protected users is the name of a group, not sure how that implies a smart card is in use. I think the answers are: never applies to the user password
upvoted 21 times
Ario
4 years, 9 months ago
Agree with TMW
upvoted 1 times
...
Milos99
4 years ago
Kinda old comment but l will reply anyways to help others to not make same mistake as me. l would agree to you if this was the question, but in fact is incomplete Full question you can find here: https://onedrive.live.com/?authkey=%21AE6YK818YburdH8&cid=C5D77F03F4D4DE29&id=C5D77F03F4D4DE29%21882&parId=C5D77F03F4D4DE29%21881&o=OneUp To summary everything answer is Never applies and smart card (Because of EAP)
upvoted 7 times
CodeMonkey2
3 years, 11 months ago
Thanks for the graphic, smart card makes sense if you look at the Settings applied to the rule.
upvoted 2 times
...
...
...
ar7kaware
Highly Voted 5 years, 2 months ago
this is the rest of the question https://onedrive.live.com/?authkey=%21AE6YK818YburdH8&cid=C5D77F03F4D4DE29&id=C5D77F03F4D4DE29%21882&parId=C5D77F03F4D4DE29%21881&o=OneUp I think the correct answer is (never applies to the user, a virtual smart card)
upvoted 16 times
Jrhord
4 years, 2 months ago
With the extra info supplied here, this makes the given answer correct. Tested in Lab using the Constraint tab - Authentication Methods with "Smart Card or other certificate" the only EAP types selected.
upvoted 2 times
Jrhord
4 years, 2 months ago
By Given answer I mean ar7kaware's answer - never applies to the user & Vitrual smartcard
upvoted 3 times
...
...
...
panda
Most Recent 3 years, 10 months ago
I think 1st answer is "never applies to the user." Further if a user is a memver of the Protected Users or Domain Admins, the answer is "applies to the user on weekdays between 08:00 and 18:00."
upvoted 1 times
...
NickTim
4 years, 1 month ago
As per the link of Kamikazekiller: https://onedrive.live.com/?authkey=%21AE6YK818YburdH8&cid=C5D77F03F4D4DE29&id=C5D77F03F4D4DE29%21882&parId=C5D77F03F4D4DE29%21881&o=OneUp the answer is logic: -Policy never Apply to the users (because only one condition is met) -Smart Card (2 Methods: smart card or other Certificate )
upvoted 2 times
...
Kamikazekiller
4 years, 5 months ago
- Never applies to the user - Virtual smart card
upvoted 3 times
Kamikazekiller
4 years, 5 months ago
As ar7kaware posted, this question is incomplete, the full sentence you can find in the link below: https://onedrive.live.com/?authkey=%21AE6YK818YburdH8&cid=C5D77F03F4D4DE29&id=C5D77F03F4D4DE29%21882&parId=C5D77F03F4D4DE29%21881&o=OneUp It uses Virtual Smart Card, that's why the answer is: - Never applies to the user - Virtual smart card
upvoted 8 times
ricAtic63
4 years ago
Took the InfoSec Bootcamp, and the Never Applies to the User & Virtual Smart Card is the correct answers......
upvoted 1 times
...
...
...
GenjamBhai
4 years, 7 months ago
The condition rules are standalone for each line and can contain multiple conditions within that one rule/line i.e. 1 line = 1 rule (which contains one or more conditions) However, the match needs to happen for 1 rule/line only. System checks for match one rule at a time by the processing order from lowest to highest. Given answer is correct.
upvoted 2 times
stefano1856
4 years, 7 months ago
https://docs.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-np-overview Network policies can be viewed as rules not Condition
upvoted 1 times
...
TA77
4 years, 3 months ago
Answer is Wrong. Those are conditions for one rule only. For that rule to apply, all conditions must be met.
upvoted 1 times
TA77
4 years, 3 months ago
Correct answer is: "never applies to user" & "Smart Card"
upvoted 1 times
...
...
...
lbs
4 years, 8 months ago
I think answer is correct. After first condition is checked and met, second condition is not in question anymore. Virtual Smart Card bcos Authentication method is EAP - Microsoft: Smart Card or other certificate
upvoted 1 times
lbs
4 years, 8 months ago
I made a incorrect assumption. I agree with Trifon and sdjam. The correct answers: Never apply to the user and Virtual Smart Card
upvoted 1 times
...
stefano1856
4 years, 8 months ago
How is checked if user is in Domain Users group ?
upvoted 1 times
ve22
4 years, 8 months ago
You also think "never applies to user"
upvoted 1 times
...
...
...
sdjam
4 years, 9 months ago
Good answer is : 1- Never applies to the user 2- a virtual smart card (the settings conditions is just missing from this capture. The the one drive link) Here is why : In the MCST boot Exam Ref 70-741, Skill 4.3 : Implement NPS CHAPTER 4 page 213, Configure network Policies * Conditions : Contains the basci properties of a connection. You can define multiple conditions. For the policy to apply, the remote client must match ALL of the conditions specified in the policy. These include : ** Membership of a Win Group ** Day and time restrictions ** IP address of the remote client ** Authentication type ** RADIUS client properties, such as IP address or frendly name It's says samething on page 218 : "You can define multiple conditions, all of which must be matched by connection attempt for the policy to apply[...]
upvoted 4 times
...
TestingBoy
4 years, 9 months ago
Network policies can be viewed as rules. Each rule has a set of conditions and settings. NPS compares the conditions of the rule to the properties of connection requests. If a match occurs between the rule and the connection request, the settings defined in the rule are applied to the connection. When multiple network policies are configured in NPS, they are an ordered set of rules. NPS checks each connection request against the first rule in the list, then the second, and so on, until a match is found. Each network policy has a Policy State setting that allows you to enable or disable the policy. When you disable a network policy, NPS does not evaluate the policy when authorizing connection requests. https://docs.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-np-overview So the second policy would never even be look at as the first one gives the domain uses access "this is the rest of the question https://onedrive.live.com/?authkey=%21AE6YK818YburdH8&cid=C5D77F03F4D4DE29&id=C5D77F03F4D4DE29%21882&parId=C5D77F03F4D4DE29%21881&o=OneUp" So the answer looks correct to me.
upvoted 6 times
Trifon
4 years, 9 months ago
But here we have only ONE policy, consisting of two conditions, both of which must be met for the policy to match.
upvoted 4 times
Trifon
4 years, 9 months ago
So "never applies to the user". And "virtual smartcard" because of EAP I would say.
upvoted 3 times
...
...
...
MentalG
4 years, 10 months ago
Never applies to user A virtual smart card Authentication method is EAP - Extensible Authentication Protocol Extensible Authentication Protocol being used is: Microsoft: Smart Card or other certificate
upvoted 2 times
MentalG
4 years, 10 months ago
Please see the rest of the question! ar7kaware provided a link
upvoted 2 times
...
...
ITGEEK
4 years, 11 months ago
After more research on this, i found in the MCSA book that if you have Multiple policies Its important to place these policies in the correct order because once RRAS finds a match it stops processing additional policies. Coming back to the Question: The answers in this question is right.
upvoted 3 times
hard2learn
4 years, 11 months ago
How is the answer in this question is right? based on what?
upvoted 3 times
...
stefano1856
4 years, 8 months ago
you didn't say anything on the question...
upvoted 1 times
...
xosol
4 years, 2 months ago
There aren't multiple policies in this question. It's multiple conditions of one policy. All condtions must match for the policy to get applied. (if the policy does not apply, then it moves on to the next policy.) important difference between policies who only need one match, and conditions of the policy which all need to be matched. Therefore, the correct answer is "Never Applies" because Domain Users is not a condition of the policy, and "Smart Card" - based on the additional picture in one of the comments.
upvoted 4 times
...
...
ThisGuyTho
5 years ago
As network policies are checked in descending order (https://docs.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-np-overview), isn't the answer correct as given because it would match the first condition and never reach the second?
upvoted 3 times
...
coleman
5 years, 1 month ago
never applies to the user
upvoted 16 times
coleman
5 years, 1 month ago
a virtual smart card
upvoted 13 times
ITGEEK
4 years, 11 months ago
you are wrong.
upvoted 4 times
...
...
...
dan
5 years, 3 months ago
I agree with TMW and ovader, I do not see any mention the 1st group being a part of another group - so policy never applies and from most of my recent class knowledge most are PASSWORD, never heard any mentions of virtual smart cards etc. again not trying to read anything into the question per Microsoft.
upvoted 3 times
...
ovader
5 years, 5 months ago
If the conditions (all conditions in policy) do not match the connection request, NPS skips this policy and evaluates other policies, if additional policies are configured. So, first answer is POLICY never applies to the user (not condition), second answer is A PASSWORD
upvoted 7 times
...
dritter
5 years, 9 months ago
It does come from the "Protected Users" group. But I'm still not sure. I only see that NTLM doesn't work with those. https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/how-to-configure-protected-accounts
upvoted 2 times
...
dritter
5 years, 9 months ago
Where comes the virtual smartcard from?
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago