Skip to content

70-341 Core Solutions of Microsoft Exchange Server Practice Questions

Prepare for 70-341 with more than an answer.

213 questions in the full set20 sample questionsUpdated Aug 11, 2025
Exam fee
$165 USD
Time limit
120 minutes
Questions on the exam
40-60
Passing score
700 (scale 300-1000)
Level
Professional
Valid for
Does not expire (was active certification)
Domains covered on the exam 4
  1. Install, Configure, and Manage the Mailbox Role22.5%
  2. Plan, Install, Configure, and Manage Client Access22.5%
  3. Plan, Install, Configure, and Manage Transport22.5%
  4. Design and Manage an Exchange Infrastructure22.5%
  1. 1

    True or False: In Exchange Server 2013, the Managed Store process (Microsoft.Exchange.Store.Worker.exe) for each mounted database runs under the context of the Local System account.

    Show answer details

    Correct answer: B

    This statement is false. A key architectural change in Exchange 2013 was the introduction of the Managed Store. Each mounted database has its own worker process (Microsoft.Exchange.Store.Worker.exe), but these processes run under the context of the Network Service account, not Local System. This provides better isolation and security compared to previous versions where the entire Information Store ran as a single process under a highly privileged account.

  2. 2

    Your organization has a strict anti-malware policy. You need to configure Exchange 2013's built-in anti-malware protection to delete any message that contains malware, and also send a customized notification message to the internal sender of the infected email. Where do you configure these two settings?

    Show answer details

    Correct answer: B

    The built-in anti-malware capabilities are configured through anti-malware policies in the Exchange Admin Center (EAC) under the 'Protection' section. Within the default (or a custom) policy, you can define the action to take when malware is detected (e.g., 'Delete the entire message') and configure sender notifications, including customizing the text for internal and external senders.

  3. 3

    During a performance analysis of your Exchange 2013 Mailbox servers, you notice that the RPC Client Access service is frequently throttling client connections, leading to user complaints about Outlook being slow or unresponsive. You need to create a new throttling policy that doubles the RPC-related budget for a group of power users without affecting other users. Which cmdlet would you use to create this new policy?

    Show answer details

    Correct answer: B

    Exchange workload management uses throttling policies to control resource consumption by users. To create a custom set of throttling limits for a specific group, you must first create a new policy using New-ThrottlingPolicy. You can then modify its parameters (like RCAPercentTimeInAD, RCAPercentTimeInCAS, etc.) and assign it to the power users. The other cmdlets manage different aspects of the Exchange configuration but are not used for creating user throttling policies.

  4. 4

    You need to grant an auditor named 'AuditUser' the ability to search all mailboxes in the organization for specific keywords, but the auditor must not be able to read any other email or make any changes to the Exchange configuration. Which two actions are required to grant the minimum necessary permissions? (Select TWO).

    Show answer details

    Correct answer: A, E

    The 'Discovery Management' role group is specifically designed for this purpose. It contains the 'Mailbox Search' and 'Legal Hold' roles, which grant permissions to perform In-Place eDiscovery searches across all mailboxes.

    While this is assigned by default, verifying that the necessary role ('Mailbox Search') is part of the role group is a critical step. The combination of adding the user to the correct group and ensuring the group has the correct role provides the required permissions.

  5. 5

    A retail company has two Exchange 2013 Client Access servers (CAS01, CAS02) behind a hardware load balancer. Users report that when accessing OWA externally, they are intermittently re-prompted for their username and password, sometimes multiple times during a session. Internal users do not experience this issue. You suspect an issue with the load balancer configuration. Which setting on the hardware load balancer is the most likely cause of this behavior?

    graph TD Internet --> Firewall --> HLB[Hardware LB] HLB --> CAS01[CAS Server 1] HLB --> CAS02[CAS Server 2]

    Show answer details

    Correct answer: C

    The described behavior is a classic symptom of incorrect load balancer affinity (also known as persistence or stickiness). When a user authenticates to OWA, a session is established with one CAS server. If a subsequent request within the same session is sent to the other CAS server, the user will be prompted to re-authenticate. The load balancer must be configured with client affinity (e.g., source IP or cookie-based) to ensure all requests from a single client session are sent to the same CAS server.

  6. 6

    A financial services firm, Proseware, Inc., is deploying Exchange Server 2013. The security team mandates that all Client Access servers must use Kerberos authentication for Outlook Anywhere clients to enhance security. During testing, you discover that clients are failing to connect and are repeatedly prompted for credentials. You have already configured the InternalClientAuthenticationMethod and ExternalClientAuthenticationMethod on the Outlook Anywhere virtual directory to Ntlm. Which PowerShell cmdlet must be run to enable Kerberos authentication and resolve the connection issue?

    Show answer details

    Correct answer: D

    For Kerberos authentication to function correctly with a Client Access Server array or load-balanced CAS, the credentials must be shared among the servers. This is accomplished by using a shared alternate service account (ASA) credential. The ms-Exch-EPI-Token-Serialization extended right allows Exchange servers to read and write the service principal name (SPN) and encryption keys from the alternate service account in Active Directory. The other cmdlets configure different aspects of authentication but do not address the core requirement of sharing Kerberos credentials.

  7. 7

    A manufacturing company has two Active Directory sites, London and New York, connected by a WAN link with high latency. Each site contains two Exchange 2013 Mailbox servers that are members of a single Database Availability Group (DAG). The company's disaster recovery plan requires a point-in-time recovery capability of 7 days for mailbox databases. An administrator configures a lagged copy of a database in the New York site with a ReplayLagTime of 7 days. However, they are concerned about the log files consuming excessive disk space on the lagged copy server. What configuration ensures that log files are truncated after being inspected by Managed Availability, while still maintaining the 7-day lag?

    Show answer details

    Correct answer: C

    The ReplayLagManagerEnabled property, which is enabled by default, allows the system to automatically play down log files for lagged copies when certain conditions are met, such as low disk space or when the lagged copy has been determined to be the only available copy for a specific period. This feature, also known as lazy log truncation, helps prevent the log drive from filling up while still preserving the intended replay lag for recovery purposes. Circular logging is incompatible with lagged copies. Setting TruncationLagTime delays truncation but is superseded by ReplayLagTime.

  8. 8

    You are the senior Exchange administrator for Wingtip Toys. The company wants to implement a transport rule that prepends '[EXTERNAL]' to the subject line of all emails originating from outside the organization. However, emails from a trusted partner domain, fabrikam.com, should be exempt from this rule. You create a transport rule with a condition 'The sender is located... Outside the organization' and an action 'Prepend the subject of the message with... [EXTERNAL]'. How should you configure the exception to meet the requirement?

    Show answer details

    Correct answer: A

    The most direct and efficient way to exempt a specific domain from a transport rule is to use the 'The sender's domain is...' exception. This condition specifically checks the domain part of the sender's email address. Using 'The sender's IP address is in the range' is less reliable as IP addresses can change. Creating a separate, higher-priority rule to stop processing is more complex than necessary. Using a message header is a valid but less straightforward method for this common requirement.

  9. 9

    A large enterprise is designing its Exchange 2013 infrastructure across three datacenters: DC1, DC2, and DC3. DC1 and DC2 are primary datacenters with good connectivity. DC3 is a secondary datacenter with higher network latency. The design calls for a single 8-member DAG spanning all three sites. The File Share Witness (FSW) will be placed in DC1. To ensure automatic failover between DC1 and DC2 but require manual intervention to fail over to DC3, what configuration is required?

    Show answer details

    Correct answer: C

    To prevent automatic failover to a specific site, you must block the activation of database copies in that site. This is achieved by setting the -DatabaseCopyAutoActivationPolicy parameter on the Mailbox server to Blocked. This ensures that even if the server is part of the DAG and has healthy database copies, Managed Availability will not automatically activate them. A manual server switchover would be required to bring the databases online in DC3. DAC mode is necessary for site resilience but doesn't prevent failover to a specific site. Activation preference influences the target of a failover but doesn't block it.

  10. 10

    You have been tasked with creating a new resource mailbox for a conference room named 'CR101'. The company policy states that all meeting requests for this room must be automatically accepted if the time slot is free, but the organizer's comments should be removed from the meeting invitation. Which two PowerShell cmdlets should you use to accomplish this? (Select TWO).

    Show answer details

    Correct answer: A, C

    The New-Mailbox -Room cmdlet is the correct command to create a new room mailbox, which is a specific type of resource mailbox.

    The Set-CalendarProcessing cmdlet is used to configure the automated booking policies for a resource mailbox. Setting AutomateProcessing to AutoAccept fulfills the requirement for automatic acceptance, and -DeleteComments $true fulfills the requirement to remove comments.

Create an account to continue.