[Free] 2017(Sep) EnsurePass Pass4sure Microsoft 70-744 Dumps with VCE and PDF 21-30

EnsurePass
2017 Sep Microsoft Official New Released 70-744
100% Free Download! 100% Pass Guaranteed!
http://www.EnsurePass.com/70-744.html

Securing Windows Server 2016

Question No: 21

Note: Thi* question is part of a series of questions that present the same scenario. Each

question In the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to It. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory forest named contoso.com. All servers run Windows Server 2016. The forest contains 2#W client computers that run Windows 10. All client computers are deployed (rom a customized Windows image.

You need to deploy 10 Pnvileged Access Workstations (PAWs). The solution must ensure that administrators can access several client applications used by all users.

Solution: You deploy 10 physical computers and configure each wie as a virtualization host You deploy the operating system on each host by using the customized Windows image.

On each host you create a guest virtual machine and configure the virtual machine as a PAW.

Does this meet the goal?

  1. Yes

  2. No

Answer: B

Question No: 22

Note: This question is port of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question In the series. Each question is Independent of the other questions In this series. Information and details provided in a question apply only to that question.

Vour network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2016 and a Nano Server named Nano1.

Nano1 has two volumes named C and D. You are signed in to Server1.

You need to configure Data Deduplication on Nano1. Which tool should you use?

  1. File Explorer

  2. Shared Folders

  3. Server Manager

  4. Disk Management

  5. Storage Explorer

  6. Computer Management

  7. System Configuration

  8. File Server Resource Manager (FSRM)

Answer: A

Question No: 23

Note: This question b part of a series of questions that present the same scenario. Each question In the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear In the review screen.

Your network contains an Active Directory domain named contow.com. All servers run Windows Server 2016. All client computers run Windows 10.

The relevant objects in the domain are configured as shown in the following table.

Ensurepass 2017 PDF and VCE

You need to assign User1 the right to restore files and folders on Server1 and Server2.

Solution: You create a Group Policy object (GPO), link it to the Operations Users OU, and modify the Users Rights Assignment in the GPO.

Does this meet the goal?

  1. Yes

  2. No

Answer: B

Question No: 24

Your network contains an Active Directory domain named contoso.com. The domain contains 100 servers.

You deploy the Local Administrator Password Solution (LAPS) to the network.

You deploy a new server named FinanceServer5, and join FinanceServerS to the domain.

You need to ensure that the passwords of the local administrators of FinanceServer5 are available to the LAPS administrators.

What should you do?

  1. On FinanceServerS, register AdmPwd.dll.

  2. On FmanceServerS, install the LAPS Windows PowerShell module.

  3. In the domain, modify the permissions for the computer account of FmanceServer5.

  4. In the domain, modify the permissions of the Domain Controllers organizational unit (OU).

Answer: B

Question No: 25

Vout network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2016.

The domain contains a server named Serverl that has Microsoft Security Compliance Manager (SCM) 4.0 installed.

You export the baseline shown in the following exhibit.

Ensurepass 2017 PDF and VCE

You have a server named Server2 that is a member of a workgroup.

You copy the (2617e9b1-9672-492b-aefa-0505054848c2) folder to Server2. You need to deploy the baseline settings to Server2.

What should you do?

  1. Download, install, and then fun the Lgpo.exe command.

  2. From Group Policy Management import a Group Policy object (GPO).

  3. From Windows PowerShell, run the Restore-GPO cmdlet.

  4. From Windows PowerShell, run the Import-GPO cmdlet.

  5. From a command prompt run the secedit.exe command and specify the /import parameter.

Answer: D

Question No: 26

Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.

Start of repeated scenario

Your network contains an Active Directory domain named contoso.com. The functional level of the forest and the domain is Windows Server 2008 R2.

The domain contains the servers configured as shown in the following table.

Ensurepass 2017 PDF and VCE

All servers run Windows Server 2016. All client computers run Windows 10.

You have an organizational unit (OU) named Marketing that contains the computers in the marketing department You have an OU named Finance that contains the computers in the

finance department You have an OU named AppServers that contains application servers. A Group Policy object (GPO) named GP1 is linked to the Marketing OU. A GPO named GP2 is linked to the AppServers OU.

You install Windows Defender on Nano1.

End of repeated scenario

You plan to implement BitLocker Drive Encryption (BitLocker) on the operating system volumes of the application servers.

You need to ensure that the BitLocker recovery keys are stored in Active Directory. Which Group Policy setting should you configure?

  1. System cryptography; Force strong key protection (or user keys stored on the computer

  2. Store Bittocker recovery information in Active Directory Domain Services (Windows Server 2008 and Windows Vista)

  3. System cryptography: Use FIPS compliant algorithms for encryption, hashing and signing

  4. Choose how BitLocker-protected operating system drives can be recovered

Answer: C

Question No: 27 HOTSPOT

Your network contains two Active Directory forests named contoso.com and adatum.com. Contoso.com contains a Hyper-V host named Server1. Server1 is a member of a group named HyperHosts. Adatum.com contains a server named Server2. Server1 and Server2 run Windows Server 2016.

Contoso.com trusts adatum.com.

You plan to deploy shielded virtual machines to Server1 and to configure Admin-trusted attestation on Server2.

Which component should you install and which cmdlet should you run on Server2? To answer, select the appropriate options in the answer area.

Ensurepass 2017 PDF and VCE

Answer:

Ensurepass 2017 PDF and VCE

Question No: 28

Note: Thts question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question In this section, you will NOT be able to return to It. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain named contoso.com. The domain contains a computer named Computer1 that runs Windows 10. Computer1 connects to a home network and a corporate network.

The corporate network uses the 172.16.0.0/24 address space internally. Computerl runs an application named App1 that listens to port 8080.

You need to prevent connections to App1 when Computer1 is connected to the home network.

Solution: From Windows Firewall in the Control Panel, you add an application and allow the application to communicate through the firewall on a Private network.

Does this meet the goal?

  1. Yes

  2. No

Answer: B

Question No: 29

Your network contains an Active Directory domain named contoso.com. The domain contains five servers. All servers run Windows Server 2016.

A new secunty policy states that you must modify the infrastructure to meet the following requirements:

*Limit the nghts of administrators.

*Minimize the attack surface of the forest

*Support Multi-Factor authentication for administrators.

You need to recommend a solution that meets the new secunty policy requirements. What should you recommend deploying?

  1. an administrative forest

  2. domain isolation

  3. an administrative domain in contoso.com

  4. the Local Administrator Password Solution (LAPS)

Answer: A

Question No: 30

Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.

Start of repeated scenario

Your network contains an Active Directory domain named contoso.com. The functional level of the forest and the domain is Windows Server 2008 R2.

The domain contains the servers configured as shown in the following table.

Ensurepass 2017 PDF and VCE

All servers run Windows Server 2016. All client computers run Windows 10.

You have an organizational unit (OU) named Marketing that contains the computers in the marketing department You have an OU named finance that contains the computers in the finance department You have an OU named AppServers that contains application servers. A Group Policy object (GPO) named GP1 is linked to the Marketing OU. A GPO named GP2 is linked to the AppServers OU.

You install Windows Defender on Nano1.

End of repeated scenario

You need to exclude D:\Folder1 on Nano1 from being scanned by Windows Defender. Which cmdlet should you run?

  1. Set-StorageSetting

  2. Set-FsrmFileScreenException

  3. Set-MpPreference

  4. Set-DtcAdvancedSetting

Answer: A

100% Free Download!
Download Free Demo:70-744 Demo PDF
100% Pass Guaranteed!
Download 2017 EnsurePass 70-744 Full Exam PDF and VCE

EnsurePass ExamCollection Testking
Lowest Price Guarantee Yes No No
Up-to-Dated Yes No No
Real Questions Yes No No
Explanation Yes No No
PDF VCE Yes No No
Free VCE Simulator Yes No No
Instant Download Yes No No

2017 EnsurePass IT Certification PDF and VCE

[Free] 2017(Sep) EnsurePass Pass4sure Microsoft 70-744 Dumps with VCE and PDF 11-20

EnsurePass
2017 Sep Microsoft Official New Released 70-744
100% Free Download! 100% Pass Guaranteed!
http://www.EnsurePass.com/70-744.html

Securing Windows Server 2016

Question No: 11

Note: This question is part of a series of question that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is Independent of the other questions in this series. Information and details provided in a question apply only to that question.

Your network contains an Active Directory domain named contoso.com. The domain contains a file server named Server1 that runs Windows Server 2016.

Server1 has a volume named Volume1.

Dynamic Access Control is configured. A resource property named Property1 was created in the domain.

You need to ensure that Property1 is set to a value of Big for all of the files in Volume1 that

are larger than 10 MB. Which tool should you use?

  1. File Explorer

  2. Shared Folders

  3. Server Manager

  4. Disk Management

  5. Storage Explorer

  6. Computer Management

  7. System Configuration

  8. File Server Resource Manager (FSRM)

Answer: F

Question No: 12

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server5 that has the Windows Server Update Services server role installed.

You need to configure Windows Server Update Services (WSUS) on Server5 to use SSI. You install a certificate in the local Computer store.

Which two tools should you use? Each correct answer presents part of the solution.

  1. Wsusutil

  2. Netsh

  3. Internet Information Services (IIS) Manager

  4. Server Manager

  5. Update Services

Answer: B,C

Question No: 13

Your network contains an Active Directory domain named contoso.com. You create a Microsoft Operations Management Suite (OMS) workspace. You need to connect several computers directly to the workspace.

Which two pieces of information do you require? Each correct answer presents part of the solution.

  1. the ID of the workspace

  2. the name of the workspace

  3. the URL of the workspace

  4. the key of the workspace

Answer: A

Question No: 14

Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.

Start of repeated scenario

Your network contains an Active Directory domain named contoso.com. The functional level of the forest and the domain is Windows Server 2008 R2.

The domain contains the servers configured as shown in the following table.

Ensurepass 2017 PDF and VCE

All servers run Windows Server 2016. All client computers run Windows 10.

You have an organizational unit (OU) named Marketing that contains the computers in the marketing department. You have an OU named Finance that contains the computers in the finance department. You have an OU named AppServers that contains application servers. A Group Policy object (GPO) named GP1 is linked to the Marketing OU. A GPO named GP2 is linked to the AppServers OU.

You install Windows Defender on Nano1.

End of repeated scenario

You need to ensure that you can deploy a shielded virtual machine to Server4. Which server role should you deploy?

  1. Hyper-V

  2. Device Health Attestation

  3. Network Controller

  4. Host Guardian Service

Answer: A

Question No: 15

Note: This question b part of a series of questions that use the same or simitar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.

Your network contains an Active Directory domain named contoso.com The domain contains a server named Server1 that runs Windows Server 2016.

Server1 has a shared folder named Share1.

You need to ensure that all access to Share1 uses SMB Encryption. Which tool should you use?

  1. File Explorer

  2. Shared Folders

  3. Server Manager

  4. Disk Management

  5. Storage Explorer

  6. Computer Management

  7. System Configuration

  8. File Server Resource Manager (FSRM)gt;

Answer: H

Question No: 16

Your network contains an Active Directory domain named contoio.com. The domain

contains a server named Server1 that runs Windows Server 2016.

You have an organizational unit (OU) named Administration that contains the computer account of Server1.

You import the Active Directory module to Served1.

You create a Group Policy object (GPO) named GPO1 You link GPO1 to the Administration OU.

You need to log an event each time an Active Directory cmdlet is executed succesfully from Served.

What should you do?

  1. From Advanced Audit Policy in GPO1 configure auditing for directory service changes.

  2. Run the (Get-Module ActiveDirectory).LogPipelineExecutionDetails – $false command.

  3. Run the (Get-Module ArtivcDirectory).LogPipelineExecutionDetails = $true command.

  4. From Advanced Audit Policy in GPO1 configure auditing for other privilege use events.

Answer: C

Question No: 17

Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server 2016.

Server1 is configured as a domain controller.

You configure Server1 as a Just Enough Administration (JEA) endpoint You configure the required JEA rights for a user named User1.

You need to tell User1 how to manage Active Directory objects from Server2. What should you tell User1 to do first on Server2?

  1. From a command prompt, run ntdsutil.exe.

  2. From Windows PowerShell, run the Import-Module cmdlet.

  3. From Windows PowerShell run the Enter-PSSession cmdlet.

  4. Install the management consoles for Active Directory, and then launch Active Directory Users and Computer.

Answer: A

Question No: 18

Your network contains an Active Directory forest named conloso.com. The network is connected to the Internet.

You have 100 point-of-sale (POS) devices that run Windows 10. The devices cannot access the Internet.

You deploy Microsoft Operations Management Suite (OMS).

You need to use OMS to collect and analyze data from the POS devices. What should you do first?

  1. Deploy Windows Server Gateway to the network.

  2. Install the OMS Log Analytics Forwarder on the network.

  3. Install Microsoft Data Management Gateway on the network.

  4. Install the Simple Network Management Protocol (SNMP) feature on the devices.

  5. Add the Microsoft NDJS Capture service to the network adapter of the devices.

Answer: E

Question No: 19

Note: This question It part of a series of questions that present the same scenario. Each question In the series contains a unique solution that might meet the stated goats. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to It. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain named contoso.com. The domain contains a computer named Computer1 that runs Windows 10. Computer1 connects to a home network and a corporate network.

The corporate network uses the 17216.0.0/24 address space internally. Computerl runs an application named App1 that listens to port 8080.

You need to prevent connections to App1 when Computer1 is connected to the home network.

Solution: From Group Policy Management you create a software restriction policy.

Does this meet the goal?

  1. Yes

  2. No

Answer: A

Question No: 20

Note: This question Is part of a series of questions that present the same scenario. Each question In the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to It, As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain named contoso.com. The domain contains multiple Hyper-V hosts.

You need to deploy several critical line-to-business applications to the network to meet the following requirements:

*The resources of the applications must be isolated (rom the physical host.

*Each application must be prevented from accessing the resources of the other applications.

*The configurations of the applications must be accessible only from the operating system that hosts the application.

Solution: You deploy a separate Hyper-V container for each application. Does this meet the goal?

  1. Yes

  2. No

Answer: A

100% Free Download!
Download Free Demo:70-744 Demo PDF
100% Pass Guaranteed!
Download 2017 EnsurePass 70-744 Full Exam PDF and VCE

EnsurePass ExamCollection Testking
Lowest Price Guarantee Yes No No
Up-to-Dated Yes No No
Real Questions Yes No No
Explanation Yes No No
PDF VCE Yes No No
Free VCE Simulator Yes No No
Instant Download Yes No No

2017 EnsurePass IT Certification PDF and VCE

[Free] 2017(Sep) EnsurePass Pass4sure Microsoft 70-744 Dumps with VCE and PDF 1-10

EnsurePass
2017 Sep Microsoft Official New Released 70-744
100% Free Download! 100% Pass Guaranteed!
http://www.EnsurePass.com/70-744.html

Securing Windows Server 2016

Question No: 1

Note: This question ts part of a series of questions that present the same scenario. Each question In the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question In this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory forest named contoso.com. All servers run Windows Server 2016. The forest contains 2,000 client computers that run Windows 10. All client computers are deployed from a customized Windows image.

You need to deploy 10 Privileged Access Workstations (PAWs). The solution must ensure that administrators can access several client applications used by all users.

Solution: You deploy one physical computer and configure it as a Hyper-V host that runs Windows Server 2016. You create 10 virtual machines and configure each one as a PAW.

Does this meet the goal?

  1. Yes

  2. No

Answer: A

Question No: 2

Your network contains an Active Directory domain named contoso.com The domain contains five file servers that run Windows Server 2016.

You have an organizational unit (OU) named Finance that contains all of the servers. You create a Group Policy object (GPO) and link the GPO to the Finance OU.

You need to ensure that when a user in the finance department deletes a file from a file server, the event is logged. The solution must log only users who have a manager attribute of Ben Smith.

Which audit policy setting should you configure in the GPO?

  1. File system in Global Object Access Auditing

  2. Audit Detailed File Share

  3. Audit Other Account Logon Events

  4. Audit File System in Object Access

Answer: C

Question No: 3 HOTSPOT

Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.

Start of repeated scenario

Your network contains an Active Directory domain named contoso.com. The functional level of the forest and the domain is Windows Server 2008 R2.

The domain contains the servers configured as shown in the following table.

Ensurepass 2017 PDF and VCE

All servers run Windows Server 2016. All client computers run Windows 10.

You have an organizational unit (OU) named Marketing that contains the computers in the marketing department. You have an OU named Finance that contains the computers in the finance department. You have an OU named AppServers that contains application servers. A Group Policy object (GPO) named GP1 is linked to the Marketing OU. A GPO named GP2 is linked to the AppServers OU.

You install Windows Defender on Nano1.

End of repeated scenario

You need to ensure that you can implement the Local Administrator Password Solution (LAPS) (or the finance department computers.

What should you do in the contoso.com forest? To answer, select the appropriate options in the answer area.

Ensurepass 2017 PDF and VCE

Answer:

Ensurepass 2017 PDF and VCE

Question No: 4

Note: Thb question Is part of a series of questions that present the same scenario. Each question In the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you willNOTbeabletorrturntoit.Asa result, these questions will not appear in the review screen.

Your network contains an Active Directory domain named contoso.com. The domain contains multiple Hyper-V hosts.

You need to deploy several critical line-of-business applications to the network to meet the following requirements:

*The resources of the applications must be isolated from the physical host

*Each application must be prevented from accessing the resources of the other applications.

*The configurations of the applications must be accessible only from the operating system that hosts the application.

Solution: You deploy one Windows container to host all of the applications. Does this meet the goal?

  1. Yes

  2. No

Answer: A

Question No: 5

Your network contains two single-domain Active Directory forests named contoso.com and contosoadmin.com. Contosoadmin.com contains all of the user accounts used to manage the servers in contoso.com.

You need to recommend a workstation solution that provides the highest level of protection from vulnerabilities and attacks.

What should you include in the recommendation?

  1. Provide a Privileged Access Workstation (PAW) for each user account in both forests. Join each PAW to the contoso.com domain.

  2. Provide a Pnvileged Access Workstation (PAW) for each user in the contoso.com forest Join each PAW to the contoso.com domain.

  3. Provide a Pnvileged Access Workstation (PAW) for each administrator. Join each PAW to the contoso.com domain.

  4. Provide a Pnvileged Access Workstation (PAW) for each administrator. Join each PAW to the contosoadmin.com domain.

Answer: B

Question No: 6 HOTSPOT

Your network contains an Active Directory domain named adatum.com. The domain contains a file server named Server1 that runs Windows Server 2016.

You have an organizational unit (OU) named OU1 that contains Server1.

You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1.

A user named User1 is a member of group named Group1. The properties of User1 are shown in the User1 exhibit (Click the Exhibit button.)

Ensurepass 2017 PDF and VCE

User1 has permissions to two files on Server1 configured as shown in the following table.

Ensurepass 2017 PDF and VCE

From Auditing Entry for Global File SACL, you configure the advanced audit policy settings in GPO1 as shown in the SACL exhibit (Click the Exhibit button.)

Ensurepass 2017 PDF and VCE

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Ensurepass 2017 PDF and VCE

Answer:

Ensurepass 2017 PDF and VCE

Question No: 7 HOTSPOT

You plan to deploy three encrypted virtual machines that use Secure Boot. The virtual machines will be configured as shown in the following table.

Ensurepass 2017 PDF and VCE

How should you protect each virtual machine? To answer, select the appropriate options in the answer area.

Ensurepass 2017 PDF and VCE

Answer:

Ensurepass 2017 PDF and VCE

Question No: 8

Your network contains an Active Directory forest named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2016.

You create a new bastion forest named admin.contoso.com. The forest functional level of admin.contoso.com is Windows Server 2012 R2.

You need to implement a Privileged Access Management (PAM) solution.

Which two actions should you perform? Each correct answer presents part of the solution.

  1. Raise the forest functional level of admm.contoso.com.

  2. Deploy Microsoft Identify Management (MIM) 2016 to admin.contoso.com.

  3. Configure contoso.com to trust admin.contoso.com.

  4. Deploy Microsoft Identity Management (MIM) 2016 to contoso.com.

  5. Raise the forest functional level of contoso.com.

  6. Configure admin.contoso.com to trust contoso.com.

Answer: C,F

Question No: 9

Note: This question Is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question In this section, you will NOT be able to return to It. As a result, these questions will not appear In the review screen.

Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2016. All client computers run Windows 10.

The relevant objects in the domain are configured as shown in the following table.

Ensurepass 2017 PDF and VCE

You need to assign User1 the right to restore files and folders on Server1 and Server2.

Solution: You create a Group Policy object (GPO), you link the GPO to the Servers OU, and then you modify the Users Rights Assignment in the GPO.

Does this meet the goat?

  1. Yes

  2. No

Answer: A

Question No: 10

Your network contains an Active Directory domain named contoso.com. The domain contains four servers. The servers are configured as shown in the following table.

Ensurepass 2017 PDF and VCE

You need to manage FS1 and FS2 by using Just Enough Administration (JEA). What should you do before you can implement JEA?

  1. Install Microsoft .NET Framework 4.6.2 on FS2.

  2. Install Microsoft .NET Framework 4.6.2 on FS1.

  3. Install Windows Management Framework 5.0 on FS2.

  4. Upgrade DC1 to Windows Server 2016.

Answer: D

100% Free Download!
Download Free Demo:70-744 Demo PDF
100% Pass Guaranteed!
Download 2017 EnsurePass 70-744 Full Exam PDF and VCE

EnsurePass ExamCollection Testking
Lowest Price Guarantee Yes No No
Up-to-Dated Yes No No
Real Questions Yes No No
Explanation Yes No No
PDF VCE Yes No No
Free VCE Simulator Yes No No
Instant Download Yes No No

2017 EnsurePass IT Certification PDF and VCE