Tag Archives: 70-412 Dumps

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 301-310

Ensurepass

QUESTION 301

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs Windows Server 2012 R2 and has the DHCP Server server role

installed. Server1 has an IPv6 scope named Scope1. You implement an additional DHCP server

named Server2 that runs Windows Server 2012 R2. You need to provide high availability for

Scope1. The solution must minimize administrative effort. What should you do?

 

  1. Install and configure Network Load Balancing (NLB) on Server1 and Server2.

  2. Create a scope on Server2.

  3. Configure DHCP failover on Server1.

  4. Install and configure Failover Clustering on Server1 and Server2.

 

Correct Answer: B

 

 

QUESTION 302

Your company has two offices. The offices are located in Seattle and Montreal. The network

contains an Active Directory domain named contoso.com. The domain contains two DHCP servers

named Server1 and Server2. Server1 is located in the Seattle office. Server2 is located in the

Montreal office. All servers run Windows Server 2012 R2. You need to create a DHCP scope for

video conferencing in the Montreal office. The scope must be configured as shown in the

following table.

 

70-412-demo-239

 

Which Windows PowerShell cmdlet should you run?

 

  1. Add-DchpServerv4SuperScope

  2. Add-DchpServerv4MulticastScope

  3. Add-DHCPServerv4Policy

  4. Add-DchpServerv4Scope

 

Correct Answer: B

 

 

QUESTION 303

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server3 that runs Windows Server 2012 R2 and has the DHCP Server server role

installed. DHCP is configured as shown in the exhibit.

 

70-412-demo-240

 

Scope1, Scope2, and Scope3 are configured to assign the IP addresses of two DNS servers to

DHCP cli
ents. The remaining scopes are NOT configured to assign IP addresses of DNS servers to

DHCP clients. You need to ensure that only Scope1, Scope3, and Scopes assign the IP addresses of

the DNS servers to the DHCP clients. The solution must minimize administrative effort. What

should you do?

 

  1. Create a superscope and a filter.

  2. Create a superscope and scope-level policies.

  3. Configure the Server Options.

  4. Configure the Scope Options.

 

Correct Answer: C

 

 

QUESTION 304

You have an Active Directory Rights Management Services (AD RMS) cluster. You need to prevent

users from encrypting new content. The solution must ensure that the users can continue to

decrypt content that was encrypted already. Which two actions should you perform? (Each

correct answer presents part of the solution. Choose two.)

 

  1. From the Active Directory Rights Management Services console, enable decommissioning.

  2. From the Active Directory Rights Management Services console, create a user exclusion

policy.

  1. Modify the NTFS permissions of %systemdrive%inetpubwwwroot_wmcslicensing.

  2. Modify the NTFS permissions of %systemdrive%inetpubwwwroot_wmcsdecommission.

  3. From the Active Directory Rights Management Services console, modify the rights policy

templates.

 

Correct Answer: BE

 

 

QUESTION 305

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs Windows Server 2012. Server1 is the enterprise root certification

authority (CA) for contoso.com. You need to enable CA role separation on Server1. Which tool

should you use?

 

  1. The Certutil command.

  2. The Authorization Manager console.

  3. The Certsrv command.

  4. The Certificates snap-in.

 

Correct Answer: A

 

 

QUESTION 306

DRAG DROP

Your network contains an
Active Directory domain named contoso.com. The domain contains two

servers named Server1 and Server3. The network contains a standalone server named Server2.

All servers run Windows Server 2012 R2. The servers are configured as shown in the following

table.

 

70-412-demo-241

 

Server3 hosts an App1ication named App1. App1 is accessible internally by using the URL

https://App1.contoso.com. App1 only supports Integrated Windows authentication.

You need to ensure that all users from the Internet are pre-authenticated before they can access

App1. What should you do?

 

To answer, drag the appropriate servers to the correct actions. Each server may be used once,

more than once, or not at all. You may need to drag the split bar between panes or scroll to view

content.

 

Select and Place:

70-412-demo-242

 

Correct Answer:

70-412-demo-243

 

QUESTION 307

You have five servers that run Windows Server 2012 R2. The servers have the Failover Clustering

feature installed. You deploy a new cluster named Cluster1. Cluster1 is configured as shown in

the following table.

 

70-412-demo-244

 

Server1, Server2, and Server3 are configured as the preferred owners of the cluster roles.

Dynamic quorum management is disabled. You plan to perform hardware maintenance on

Server3. You need to ensure that if the WAN link between Site1 and Site2 fails while you are

performing maintenance on Server3, the cluster resource will remain available in Site1. What

should you do?

 

  1. Add a file share witness in Site1.

  2. Enable DrainOnShutdown on Cluster1.

  3. Remove the node vote for Server4 and Servers.

  4. Remove the node vote for Server3.

 

Correct Answer: C

 

 

QUESTION 308

Your network contains an Active Directory domain named contoso.com. You deploy a server

named Server1 that runs Windows Server 2012 R2. A local administrator installs the Active

Directory Rights Management Services server role on Server1. You need to ensure that AD RMS

clients can discover the AD RMS cluster automatically. What should you do?

 

  1. Run the Active Directory Rights Management Services console by using an account that is a

member of the Schema Admins group, and then configure the proxy settings.

  1. Run the Active Directory Rights Management Services console by using an account that is a

member of the Schema Admins group, and then register the Service Connection Point (SCP).

  1. Run the Active Directory Rights Management Services console by using an account that is a

member of the Enterprise Admins group, and then register the Service Connection Point

(SCP).

  1. Run the Active Directory Rights Management Services console by using an account that is a

member of the Enterprise Admins group, and then configure the proxy settings.

 

Correct Answer: C

 

 

QUESTION 309

HOTSPOT

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has access to disks

that connect to a RAID controller, iSCSI disks, and disks connected to a SCSI controller. You plan to

use a tiered storage space on Server1. You need to identify which storage controller and volume

type you must use for the tiered storage space. Which storage components should you use?

 

To answer, select the appropriate options in the answer area.

 

Hot Area:

70-412-demo-245

 

Correct Answer:

70-412-demo-246

 

 

 

 

 

 

QUESTION 310

DRAG DROP

Your network contains an Active Directory domain named adatum.com. The domain contains

three servers. The servers are configured as shown in the following table.

 

70-412-demo-247

 

Server1 is configured as shown in the exhibit.

 

70-412-demo-248

 

Template1 contains custom cryptography settings that are required by the corporate security

team. On Server2, an administrator successfully installs a certificate based on Template1. The

administrator reports that Template1 is not listed in the Certificate Enrollment wizard on Server3,

even after selecting the Show all templates check box. You need to ensure that you can install a

server authentication certificate on Server3. The certificate must comply with the cryptography

requirements. Which three actions should you perform in sequence?

 

To answer, move the appropriate three actions from the list of actions to the answer area and

arrange them in the correct order.

 

Select and Place:

70-412-demo-249

 

Correct Answer:

70-412-demo-250

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo

 

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 291-300

Ensurepass

QUESTION 291

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs Windows Server 2012 R2. Server1 has the Active Directory Rights

Management Services server role installed. The domain contains a domain local group named

Group1. You create a rights policy template named Template1. You assign Group1 the rights to

Template1. You need to ensure that all the members of Group1 can use Template1. What should

you do?

 

  1. Configure the email address attribute of Group1.

  2. Convert the scope of Group1 to global.

  3. Convert the scope of Group1 to universal.

  4. Configure the email address attribute of all the users who are members of Group1.

 

Correct Answer: D

 

 

QUESTION 292

You have a server named Server1 that runs Windows Server 2012 R2. From Server Manager, you

install the Active Directory Certificate Services server role on Server1. A domain administrator

named Admin1 logs on to Server1. When Admin1 runs the Certification Authority console,

Admin1 receive the following error message.

 

70-412-demo-224

 

You need to ensure that when Admin1 opens the Certification Authority console on Server1, the

error message does not appear. What should you do?

 

  1. Run the Install-AdcsCertificationAuthority cmdlet.

  2. Install the Active Directory Certificate Services (AD CS) tools.

  3. Modify the PATH system variable.

  4. Add Admin1 to the Cert Publishers group.

 

Correct Answer: B

 

 

QUESTION 293

Your network contains an Active Directory forest named contoso.com. The forest contains four

domains. All servers run Windows Server 2012 R2. Each domain has a user named User1. You

have a file server named Server1 that is used to synchronize user folders by using the Work

Folders role service. Server1 has a work folder named Sync1. You need to ensure that each user

has a separate folder in Sync1. What should you do?

 

  1. From Windows Explorer, modify the Sharing properties of Sync1.

  2. Run the Set-SyncServerSetting cmdlet.

  3. From File and Storage Services in Server Manager, modify the properties of Sync1.

  4. Run the Set-SyncShare cmdlet.

 

Correct Answer: D

 

 

QUESTION 294

HOTSPOT

Your network contains an Active Directory domain named contoso.com. The relevant servers in

the domain are configured as shown in the following table.

 

70-412-demo-225

 

You plan to create a shared folder on Server1 named Share1. Share1 must only be accessed by

users who are using computers that are joined to the domain. You need to identify which servers

must be upgraded to support the requirements of Share1.

 

In the table below, identify which computers require an upgrade and which computers do not

require an upgrade. Make only one selection in each row. Each correct selection is worth one

point.

 

Hot Area:

70-412-demo-226

 

Correct Answer:

70-412-demo-227

 

 

QUESTION 295

You have five servers that run Windows Server 2012 R2. The servers have the Failover Clustering

feature installed. You deploy a new cluster named Cluster1. Cluster1 is configured as shown in

the following table.

 

70-412-demo-228

 

Server1, Server2, and Server3 are configured as the preferred owners of the cluster roles.

Dynamic quorum management is disabled. You plan to perform hardware maintenance on

Server3. You need to ensure that if the WAN link between Site1 and Site2 fails while you are

performing maintenance on Servers, the cluster resource will remain available in Site1. What

should you do?

 

  1. Add a file share witness in Site1.

  2. Enable DrainOnShutdown on Cluster1.

  3. Remove the node vote for Server4 and Servers.

  4. Remove the node vote for Server3.

 

Correct Answer: C

 

 

 

QUESTION 296

HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains a

DNS server named Server1. Server1 is configured to resolve single-label names for DNS clients.

You need to view the number of queries for single-label names that are resolved by Server1.

What command should you run?

 

To answer, select the appropriate options in the answer area.

 

Hot Area:

70-412-demo-229

 

Correct Answer:

70-412-demo-230

 

 

 

QUESTION 297

Your network contains an Active Directory domain named contoso.com. The domain contains a

member server named Server1. Server1 has the IP Address Management (IPAM) Server feature

installed. A technician performs maintenance on Server1. After the maintenance is complete, you

discover that you cannot connect to the IPAM server on Server1. You open the Services console

as shown in the exhibit.

 

70-412-demo-231

 

You need to ensure that you can connect to the IPAM server. Which service should you start?

 

  1. Windows Process Activation Service

  2. windows Event Collector

  3. Windows Internal Database

  4. Windows Store Service (WSService)

 

Correct Answer: C

 

 

QUESTION 298

HOTSPOT

Your network contains an Active Directory domain named contoso.com. You have a Dynamic

Access Control policy named Policy1. You create a new Central Access Rule named Rule1. You

need to add Rule1 to Policy1. What command should you run?

 

To answer, select the appropriate options in the answer area.

 

Hot Area:

70-412-demo-232

 

Correct Answer:

70-412-demo-233

 

 

 

QUESTION 299

HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains a

domain controller named DC1 and a server named Server1. Both servers run Windows Server

2012 R2. You configure the classification of a share on Server1 as shown in the Share1 Properties

exhibit.

 

70-412-demo-234

 

You configure the resource properties in Active Directory as shown in the Resource Properties

exhibit.

 

70-412-demo-235

 

You need to ensure that the Impact classification can be assigned to Share1 immediately. Which

cmdlet should you run on each server?

 

To answer, select the appropriate cmdlet for each server in the answer area.

 

Hot Area:

70-412-demo-236

 

Correct Answer:

70-412-demo-237

 

 

QUESTION 300

Your network contains an Active Directory forest named contoso.com. The forest contains two

domains named contoso.com and childl.contoso.com. The domains contain three domain

controllers. The domain controllers are configured as shown in the following table.

 

70-412-demo-238

 

You need to ensure that the KDC support for claims, compound authentication, and kerberos

armoring setting is enforced in both domains. Which two actions should you perform? (Each

correct answer presents part of the solution. Choose two.)

 

  1. Raise the domain functional level of contoso.com.

  2. Raise the domain functional level ofchildl.contoso.com.

  3. Raise the forest functional level of contoso.com.

  4. Upgrade DC11 to Windows Server 2012 R2.

  5. Upgrade DC1 to Windows Server 2012 R2.

 

Correct Answer: BE

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 281-290

Ensurepass

QUESTION 281

Your network contains two Active Directory forests named contoso.com and adatum.com. Each

forest contains one domain. Contoso.com has a two-way forest trust to adatum.com. Selective

authentication is enabled on the forest trust. Contoso contains 10 servers that have the File

Server role service installed. Users successfully access shared folders on the file servers by using

permissions granted to the Authenticated Users group. You migrate the file servers to

adatum.com. Contoso users report that after the migration, they are unable to access shared

folders on the file servers. You need to ensure that the Contoso users can access the shared

folders on the file servers. What should you do?

 

  1. Disable selective authentication on the existing forest trust.

  2. Disable SID filtering on the existing forest trust.

  3. Run netdom and specify the /quarantine attribute.

  4. Replace the existing forest trust with an external trust.

 

Correct Answer: A

 

 

QUESTION 282

You have a server named FS1 that runs Windows Server 2012 R2. You install the File and Storage

Services server role on FS1. From Windows Explorer, you view the properties of a shared folder

named Share1 and you discover that the Classification tab is missing. You need to ensure that you

can assign classifications to Share1 from Windows Explorer manually. What should you do?

 

  1. From Folder Options, select Show hidden files, folders, and drives.

  2. From Folder Options, clear Use Sharing Wizard (Recommend).

  3. Install the File Server Resource Manager role service.

  4. Install the Enhanced Storage feature.

 

Correct Answer: C

 

 

 

QUESTION 283

Your network contains two servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 and Server2 are configured as shown in the following table.

 

70-412-demo-214

 

You need to ensure that when new targets are added to Server1, the targets are registered on

Server2 automatically. What should you do on Server1?

 

  1. Configure the Discovery settings of the iSCSI initiator.

  2. Configure the security settings of the iSCSI target.

  3. Run the Set-Wmilnstance cmdlet.

  4. Run the Set-IscsiServerTarget cmdlet.

 

Correct Answer: C

 

 

QUESTION 284

HOTSPOT

You have a file server named Server1 that runs Windows Server 2012 R2. Server1 contains a file

share that must be accessed by only a limited number of users. You need to ensure that if an

unauthorized user attempts to access the file share, a custom access-denied message appears,

which contains a link to request access to the share. The message must not appear when the

unauthorized user attempts to access other shares. Which two nodes should you configure in File

Server Resource Manager?

 

To answer, select the appropriate two nodes in the answer area.

 

Hot Area:

70-412-demo-215

 

Correct Answer:

70-412-demo-216

 

 

 

QUESTION 285

HOTSPOT

You have a server named Server1 that runs Windows Server 2012 R2. You are configuring a

storage space on Server1. You need to ensure that the storage space supports tiered storage.

Which settings should you configure?

 

To answer, select the appropriate options in the answer area.

 

Hot Area:

70-412-demo-217

 

Correct Answer:

70-412-demo-218

 

 

QUESTION 286

HOTSPOT

You have a server that runs Windows Server 2012 R2 and has the iSCSI Target Server role ser
vice

installed. You run the New-IscsiVirtualDisk cmdlet as shown in the New-IscsiVirtualDisk exhibit.

 

70-412-demo-219

 

To answer, complete each statement according to the information presented in the exhibits. Each

correct selection is worth one point.

 

Hot Area:

70-412-demo-220

 

Correct Answer:

70-412-demo-221

 

 

QUESTION 287

Your network contains a server named Server1 that runs Windows Server 2012 R2. Server1 has

the Active Directory Certificate Services server role installed and is configured as a standalone

certification authority (CA). You install a second server named Server2. You install the Online

Responder role service on Server2. You need to ensure that Server1 can issue an Online

Certificate Status Protocol (OCSP) Response Signing certificate to Server2. What should you run

on Server1?

 

  1. The certreq.exe command and specify the -policy parameter.

  2. The certutil.exe command and specify the -getkey parameter.

  3. The certutil.exe command and specify the -setreg parameter.

  4. The certreq.exe command and specify the -retrieve parameter.

 

Correct Answer: C

 

 

QUESTION 288

DRAG DROP

Your network contains two Active Directory forests named contoso.com and adatum.com. Each

forest contains an Active Directory Rights Management Services (AD RMS) root cluster. All servers

run Windows Server 2012 R2. You need to ensure that the rights account certificates issued in

adatum.com are accepted by the AD RMS root cluster in contoso.com. What should you do in

each forest?

 

To answer, drag the appropriate actions to the correct forests. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

 

Select and Place:

70-412-demo-222

 

Correct Answer:

70-412-demo-223

 

 

QUESTION 289

Your network contains an Active Directory domain named contoso.com. All servers run Windows

Server 2012 R2. The domain contains a domain controller named DC1 that is configured as an

enterprise root certification authority (CA). All users in the domain are issued a smart card and

are required to log on to their domain-joined client computer by using their smart card. A user

named User1 resigned and started to work for a competing company. You need to prevent User1

immediately from logging on to any computer in the domain. The solution must not prevent

other users from logging on to the domain. Which tool should you use?

 

  1. Active Directory Users and Computers.

  2. Active Directory Sites and Services.

  3. The Certificates snap-in.

  4. Server Manager.

 

Correct Answer: A

 

 

QUESTION 290

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs a Server Core installation of Windows Server 2012 R2. You need

to deploy a certification authority (CA) to Server1. The CA must support the auto-enrollment of

certificates. Which two cmdlets should you run? (Each correct answer presents part of the

solution. Choose two.)

 

  1. Add-CAAuthoritylnformationAccess

  2. Install-AdcsCertificationAuthority

  3. Add-WindowsFeature

  4. Install-AdcsOnlineResponder

  5. Install-AdcsWebEnrollment

 

Correct Answer: BD

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo

 

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 271-280

Ensurepass

QUESTION 271

You create a new virtual disk in a storage pool by using the New Virtual Disk Wizard. You discover

that the new virtual disk has a write-back cache of 1 GB. You need to ensure that the virtual disk

has a write-back cache of 5 GB. What should you do?

 

  1. Detach the virtual disk, and then run the Resize-VirtualDisk cmdlet.

  2. Detach the virtual disk, and then run the Set-VirtualDisk cmdlet.

  3. Delete the virtual disk, and then run the New-StorageSubSystemVirtualDisk cmdlet.

  4. Delete the virtual disk, and then run the New-VirtualDisk cmdlet.

 

Correct Answer: D

 

 

QUESTION 272

DRAG DROP

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs Windows Server 2012 R2. You plan to install the Active Directory Federation Services server role on Server1 to allow for Workplace Join.

 

You run nslookup enterpriseregistration and you receive the following results:

 

70-412-demo-198

 

You need to create a certificate request for Server1 to support the Active Directory Federation

Services (AD FS) installation. How should you configure the certificate request?

 

To answer, drag the appropriate names to the correct locations. Each name may be used once,

more than once, or not at all. You may need to drag the split bar between panes or scroll to view

content.

 

Select and Place:

70-412-demo-199

 

Correct Answer:

70-412-demo-200

 

 

QUESTION 273

Your network contains an Active Directory domain named contoso.com. The domain contains

servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 has the Active

Directory Federation Services server role installed. Server2 is a file server. Your company

introduces a Bring Your Own Device (BYOD) policy. You need to ensure that users can use a

personal device to access domain resources by using Single Sign-On (SSO) while they are

connected to the internal network. Which two actions should you perform? (Each correct answer

presents part of the solution. Choose two.)

 

  1. Enable the Device Registration Service in Active Directory.

  2. Publish the Device Registration Service by using a Web App1ication Proxy.

  3. Configure Active Directory Federation Services (AD FS) for the Device Registration Service.

  4. Create and configure a sync share on Server2.

  5. Install the Work Folders role service on Server2.

 

Correct Answer: AC

 

 

QUESTION 274

You have a server named Server1. You install the IP Address Management (IPAM) Server feature

on Server1. You need to provide a user named User1 with the ability to set the access scope of all

the DHCP servers that are managed by IPAM. The solution must use the principle of least

privilege. Which user role should you assign to User1?

 

  1. IPAM Administrator Role

  2. IPAM DHCP Scope Administrator Role

  3. IPAM MSM Administrator Role

  4. IP Address Record Administrator Role

 

Correct Answer: C

 

 

 

 

 

 

 

QUESTION 275

DRAG DROP

You have two failover clusters named Cluster1 and Cluster2. All of the nodes in both of the

clusters run Windows Server 2012 R2. Cluster1 hosts two virtual machines named VM1 and VM2.

You plan to configure VM1 and VM2 as nodes in a new failover cluster named Cluster3. You need

to configure the witness disk for Cluster3 to be hosted on Cluster2. Which three actions should

you perform in sequence?

 

To answer, move the appropriate three actions from the list of actions to the answer area and

arrange them in the correct order.

 

Select and Place:

70-412-demo-201

 

Correct Answer:

70-412-demo-202

 

 

 

 

 

 

QUESTION 276

HOTSPOT

Your network contains two Web servers named Server1 and Server2. Both servers run Windows

Server 2012 R2. Server1 and 5erver2 are nodes in a Network Load Balancing (NLB) cluster. The

NLB cluster contains an App1ication named App1 that is accessed by using the URL

http://App1.contoso.com. You deploy a new server named Server3 that runs Windows Server

2012 R2. The contoso.com DNS zone contains the records shown in the following table.

 

70-412-demo-203

 

You need to add Server3 to the NLB cluster. What command should you run?

 

To answer, select the appropriate options in the answer area.

 

Hot Area:

70-412-demo-204

 

Correct Answer:

70-412-demo-205

 

 

QUESTION 277

DRAG DROP

Your network contains an Active Directory domain named contoso.com. The domain contains

four member servers named Server1, Server2, Server3, and Server4. All servers run Windows

Server 2012 R2. Server1 and Server3 are located in a site named Site1. Server2 and Server4 are

located in a site named Site2. The servers are configured as nodes in a failover cluster named

Cluster1. Dynamic quorum management is disabled. Cluster1 is configured to use the Node

Majority quorum configuration. You need to ensure that users in Site2 can access Cluster1 if the

network connection between the two sites becomes unavailable. What should you run from

Windows PowerShell?

 

To answer, drag the appropriate commands to the correct location. Each command may be used

once, more than once, or not at all. You may need to drag the split bar between panes or scroll to

view content.

 

Select and Place:

70-412-demo-206

 

Correct Answer:

70-412-demo-207

 

 

 

QUESTION 278

HOTSPOT

Your network contains an Active Directory domain named contoso.com. All domain controllers

run Windows Server 2012 R2. The network has the physical sites and TCP/IP subnets configured

as shown in the following table.

 

70-412-demo-208

 

You have a web App1ication named App1 that is host
ed on six separate Web servers. DNS has the

host names and IP addresses registered as shown in the following table.

 

70-412-demo-209

 

You discover that when users connect to App1.contoso.com, they are connected frequently to a

server that is not on their local subnet. You need to ensure that when the users connect to

app1.contoso.com, they connect to a server on their local subnet. The connections must be

distributed across the servers that host app1.contoso.com on their subnet. Which two settings

should you configure?

 

To answer, select the appropriate two settings in the answer area.

 

Hot Area:

70-412-demo-210

 

Correct Answer:

70-412-demo-211

 

 

QUESTION 279

Your network contains an Active Directory domain named contoso.com. The domain contains two

member servers named Server1 and Server2. You install the DHCP Server server role on Server1

and Server2. You install the IP Address Management (IPAM) Server feature on Server1. You notice

that you cannot discover Server1 or Server2 in IPAM. You need to ensure that you can use IPAM

to discover the DHCP infrastructure. Which two actions should you perform? (Each correct

answer presents part of the solution. Choose two.)

 

  1. On Server2, create an IPv4 scope.

  2. On Server1, run the Add-IpamServerInventory cmdlet.

  3. On Server2, run the Add-DhcpServerInDc cmdlet

  4. On both Server1 and Server2, run the Add-DhcpServerv4Policy cmdlet.

  5. On Server1, uninstall the DHCP Server server role.

 

Correct Answer: AC

 

 

QUESTION 280

Your network contains two Active Directory forests named contoso.com and corp.contoso.com.

 

70-412-demo-212

 

User1 is a member of the DnsAdmins domain local group in contoso.com. User1 attempts to

create a conditional forwarder to corp.contoso.com but receive an error message shown in the

exhibit.

 

70-412-demo-213

 

You need to configure bi-directional name resolution between the two forests. What should you

do first?

 

  1. Add User1 to the DnsUpdateProxy group.

  2. Configure the zone to be Active Directory-integrated.

  3. Enable the Advanced view from DNS Manager.

  4. Run the New Delegation Wizard.

 

Correct Answer: A

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 261-270

Ensurepass

QUESTION 261

DRAG DROP

Your network contains an Active Directory domain named contoso.com. You need to ensure that

third-party devices can use Workplace Join to access domain resources on the Internet. Which

four actions should you perform in sequence?

 

To answer, move the appropriate four actions from the list of actions to the answer area and

arrange them in the correct order.

 

Select and Place:

70-412-demo-187

 

Correct Answer:

70-412-demo-188

 

 

QUESTION 262

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs Windows Server 2012 R2 and has the DHCP Server server role

installed. You need to create an IPv6 scope on Server1. The scope must use an address space that

is reserved for private networks. The addresses must be routable. Which IPV6 scope prefix should

you use?

 

  1. 2001:123:4567:890A::

  2. FE80:123:4567::

  3. FF00:123:4567:890A::

  4. FD00:123:4567::

 

Correct Answer: D

 

 

QUESTION 263

You have a virtual machine named VM1 that runs on a host named Host1. You configure VM1 to

replicate to another host named Host2. Host2 is located in the same physical location as Host1.

You need to add an additional replica of VM1. The replica will be located in a different physical

site. What should you do?

 

  1. From VM1 on Host2, click Extend Replication.

  2. On Host1, configure the Hyper-V settings.

  3. From VM1 on Host1, click Extend Replication.

  4. On Host2, configure the Hyper-V settings.

 

Correct Answer: A

 

 

QUESTION 264

HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains two

servers named Server1 and Server2. All servers run Windows Server 2012 R2. You install the

DHCP Server server role on both servers. On Server1, you have the DHCP scope configured as

shown in the exhibit.

 

70-412-demo-189

 

You need to configure the scope to be load-balanced across Server1 and Server2. What Windows

PowerShell cmdlet should you run on Server1?

 

To answer, select the appropriate options in the answer area.

 

Hot Area:

70-412-demo-190

Correct Answer:

70-412-demo-191

 

 

QUESTION 265

HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains two

DHCP servers named Server1 and Server2. Both servers have multiple IPv4 scopes. Server1 and

Server2 are used to assign IP addresses for the network IDs of 172.20.0.0/16 and 131.107.0.0/16.

You install the IP Address Management (IPAM) Server feature on a server named IPAM1 and

configure IPAM1 to manage Server1 and Server2. Some users from the 172.20.0.0 network report

that they occasionally receive an IP address conflict error message. You need to identify whether

any scopes in the 172.20.0.0 network ID conflict with one another. What Windows PowerShell

cmdlet should you run?

 

To answer, select the appropriate options in the answer area.

 

Hot Area:

70-412-demo-192

 

Correct Answer:

70-412-demo-193

 

 

QUESTION 266

Your network contains an Active Directory forest named contoso.com. Users frequently access

the website of an external partner company. The URL of the website is

http://partners.adatum.com. The partner company informs you that it will perform maintenance

on its Web server and that the IP addresses of the Web server will change. After the change is

complete, the users on your internal network report that they fail to access the website. However, some users who work from home report that they can access the website. You need to ensure

that your DNS servers can resolve partners.adatum.com to the correct IP address immediately.

What should you do?

 

  1. Run dnscmd and specify the CacheLockingPercent parameter.

  2. Run Set-DnsServerGlobalQueryBlockList.

  3. Run ipconfig and specify the Renew parameter.

  4. Run Set-DnsServerCache.

 

Correct Answer: A

 

 

QUESTION 267

You have a server named Server1. You install the IP Address Management (IPAM) Server feature

on Server1. You need to provide a user named User1 with the ability to set the access scope of all

the DHCP servers that are managed by IPAM. The solution must use the principle of least

privilege. Wh
ich user role should you assign to User1?

 

  1. DNS Record Administrator Role

  2. IPAM DHCP Reservations Administrator Role

  3. IPAM MSM Administrator Role

  4. IPAM DHCP Administrator Role

 

Correct Answer: C

 

 

QUESTION 268

HOTSPOT

You have a file server named Server1 that runs Windows Server 2012 R2. You need to ensure that

you can use the NFS Share – Advanced option from the New Share Wizard in Server Manager.

Which two role services should you install?

 

To answer, select the appropriate two role services in the answer area.

 

Hot Area:

70-412-demo-194

 

Correct Answer:

70-412-demo-195

 

 

QUESTION 269

Your network contains 20 iSCSI storage App1iances that will provide storage for 50 Hyper-V hosts

running Windows Server 2012 R2. You need to configure the storage for the Hyper-V hosts. The

solution must minimize administrative effort. What should you do first?

 

  1. Install the iSCSI Target Server role service and configure iSCSI targets.

  2. Install the iSNS Server service feature and create a Discovery Domain.

  3. Start the Microsoft iSCSI Initiator Service and configure the iSCSI Initiator Properties.

  4. Install the Multipath I/O (MPIO) feature and configure the MPIO Properties.

 

Correct Answer: C

 

 

QUESTION 270

DRAG DROP

You have a server that runs Windows Server 2012 R2. You create a new work folder named

Share1. You need to configure Share1 to meet the following requirements:

 

  • Ensure that all synchronized copies of Share1 are encrypted.

  • Ensure that clients synchronize to Share1 every 30 minutes.

  • Ensure that Share1 inherits the NTFS permissions of the parent folder.

 

Which cmdlet should you use to achieve each requirement?

 

To answer, drag the appropriate cmdlets to the correct requirements. Each cmdlet may be used

once, more than once, or not at all. You may need to drag the split bar between panes or scroll to

view content.

 

Select and Place:

70-412-demo-196

 

Correct Answer:

70-412-demo-197

 

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 251-260

Ensurepass

QUESTION 251

Your network contains an Active Directory domain named contoso.com. The domain contains two

member servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 has

Microsoft SQL Server 2012 installed. You install the Active Directory Federation Services server

role on Server2. You need to configure Server2 as the first Active Directory Federation Services

(AD FS) server in the domain. The solution must ensure that the AD FS database is stored in a SQL

Server database on Server1. What should you do on Server2?

 

  1. From the AD FS console, run the AD FS Federation Server Configuration Wizard and select the

Stand-alone federation server option.

  1. From Server Manager, install the Federation Service Proxy.

  2. From Windows PowerShell, run Install-ADFSFarm.

  3. From Server Manager, install the AD FS Web Agents.

 

Correct Answer: A

 

 

QUESTION 252

Your network contains two servers that run Windows Server 2012 R2 named Server1 and Server2. Both servers have the File Server role service installed. On Server2, you create a share named

Backups. From Windows Server Backup on Server1, you schedule a full backup to run every night.

You set the backup destination to \Server2 Backups. After several weeks, you discover that

\Server2Backups only contains the last backup that completed on Server1. You need to ensure

that multiple backups of Server1 are maintained. What should you do?

 

  1. Modify the Volume Shadow Copy Service (VSS) settings.

  2. Modify the properties of the Windows Store Service (WSService) service.

  3. Change the backup destination,

  4. Configure the permission of the Backups share.

 

Correct Answer: C

 

 

QUESTION 253

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs Windows Server 2012 R2. Server1 has an enterprise root

certification authority (CA) for contoso.com. You deploy another member server named Server2

that runs Windows Server 2012 R2 and has the Web Server (IIS) server role installed. You need to

designate a website on Server1 as the certificate revocation list (CRL) distribution point for the CA. The solution must ensure that CRLs are published automatically to Server2. Which two actions

should you perform? (Each correct answer presents part of the solution. Choose two.)

 

  1. Create an http:// CRL distribution point (CDP) entry.

  2. Configure a CA exit module.

  3. Create a file:// CRL distribution point (CDP) entry

  4. Configure an enrollment agent.

  5. Configure a CA policy module.

 

Correct Answer: AE

 

 

QUESTION 254

Your network contains an Active Directory domain named adatum.com. You create a new Group

Policy object (GPO) named GPO1. You need to verify that GPO1 was replicated to all of the

domain controllers. Which tool should you use?

 

  1. Gpupdate

  2. Gpresult

  3. Group Policy Management

  4. Active Directory Sites and Services

 

Correct Answer: C

 

 

QUESTION 255

HOTSPOT

Your network contains three Active Directory forests. The forests are configured as shown in the

following table.

 

70-412-demo-181

 

A two-way forest trust exists between contoso.com and divisionl.contoso.com. A two-way forest

trust also exists between contoso.com and division2.contoso.com. You plan to create a one-way

forest trust from divisionl.contoso.com to division2.contoso.com. You need to ensure that any

cross-forest authentication requests are sent to the domain controllers in the appropriate forest

after the trust is created. How should you configure the existing forest trust settings?

 

In the table below, identify which configuration must be performed in each forest. Make only one

selection in each column. Each correct selection is worth one point.

 

Hot Area:

70-412-demo-182

 

Correct Answer:

70-412-demo-183

 

 

QUESTION 256

Your network contains two Web servers named Server1 and Server2. Both servers run Windows

Server 2012 R2. Server1 and Server2 are nodes in a Network Load Balancing (NLB) cluster. The

NLB cluster contains an App1ication named App1 that is accessed by using the URL

http://app1.contoso.com. You plan to perform maintenance on Server1. You need to ensure that

all new connections to App1 are directed to Server2. The solution must not disconnect the

existing connections to Server1. What should you run?

 

  1. The Set-NlbCluster cmdlet.

  2. The Set-NlbClusterNode cmdlet.

  3. The Stop-NlbCluster cmdlet.

  4. The Stop-NlbClusterNode cmdlet.

 

Correct Answer: B

 

 

QUESTION 257

HOTSPOT

Your network contains an Active Directory domain named contoso.com. You have a failover cluster named Cluster1 that contains two nodes named Server1 and Server2. Both servers run Windows Server 2012 R2 and have the Hyper-V server role installed. You plan to create two virtual machines that will run an App1ication named App1. App1 will store data on a virtual hard drive named App1data.vhdx. App1data.vhdx will be shared by both virtual machines.

 

The network contains the following shared folders:

 

  • An SMB file share named Share1 that is hosted on a Scale-Out File Server.

  • An SMB file share named Share2 that is hosted on a standalone file server.

  • An NFS share named Share3 that is hosted on a standalone file server.

 

You need to ensure that both virtual machines can use App1data.vhdx simultaneously. What

should you do?

 

To answer, select the appropriate configurations in the answer area.

 

Hot Area:

70-412-demo-184

 

Correct Answer:

70-412-demo-185

 

 

QUESTION 258

Your network contains an Active directory forest named contoso.com. The forest contains two

child domains named east.contoso.com and west.contoso.com. You install an Active Directory

Rights Management Services (AD RMS) cluster in each child domain. You discover that all of the

users in the contoso.com forest are directed to the AD RMS cluster in east.contoso.com. You

need to ensure that the users in west.contoso.com are directed to the AD RMS cluster in

west.contoso.com and that the users in east.contoso.com are directed to the AD RMS cluster in

east.contoso.com. What should you do?

 

  1. Modify the Service Connection Point (SCP).

  2. Configure the Group Policy object (GPO) settings of the users in the west.contoso.com

domain.

  1. Configure the Group Policy object (GPO) settings of the users in the east.contoso.com

domain.

  1. Modify the properties of the AD RMS cluster in west.contoso.com.

 

Correct Answer: B

 

 

QUESTION 259

You have a server named Server1 that runs Windows Server 2012 R2. From Server Manager, you

install the Active Directory Certificate Services server role on Server1. A domain administrator

named Admin1 logs on to Server1. When Admin1 runs the Certification Authority console,

Admin1 receive the following error message.

 

70-412-demo-186

 

You need to ensure that when Admin1 opens the Certification Authority console on Server1, the

error message does not appear. What should you do?

 

  1. Install the Active Directory Certificate Services (AD CS) tools.

  2. Run the regsvr32.exe command.

  3. Modify the PATH system variable.

  4. Configure the Active Directory Certificate Services server role from Server Manager.

Correct Answer: D

 

 

QUESTION 260

Your network contains an Active Directory domain named contoso.com. The domain contains a

member server named Server1 that has the Active Directory Federation Services server role

installed. All servers run Windows Server 2012. You complete the Active Directory Federation

Services Configuration Wizard on Server1. You need to ensure that client devices on the internal

network can use Workplace Join. Which two actions should you perform on Server1? (Each

correct answer presents part of the solution. Choose two.)

 

  1. Run Enable-AdfsDeviceRegistration -PrepareActiveDirectory.

  2. Edit the multi-factor authentication global authentication policy settings.

  3. Run Enable-AdfsDeviceRegistration.

  4. Run Set-AdfsProxyProperties HttpPort 80.

  5. Edit the primary authentication global authentication policy settings.

 

Correct Answer: AB

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 241-250

Ensurepass

QUESTION 241

Your network contains an Active Directory domain named adatum.com. The domain contains a

file server named FS1 that runs Windows Server 2012 R2 and has the File Server Resource

Manager role service installed. All client computers run Windows 8. File classification and

Access-Denied Assistance are enabled on FS1. You need to ensure that if users receive an Access

Denied message, they can request assistance by email from the Access Denied dialog box. What

should you configure?

 

  1. A file management task.

  2. A classification property.

  3. The File Server Resource Manager Options.

  4. A report task.

 

Correct Answer: C

 

 

QUESTION 242

You have a server named LON-DC1 that runs Windows Server 2012 R2. An iSCSI virtual disk named VirtuahSCSIl.vhd exists on LON-DC1 as shown in the exhibit.

 

70-412-demo-178

 

You create a new iSCSI virtual disk named Virtua
liSCSI2.vhd by using the existing itgt iSCSI target.

VirtuahSCSI1.vhd is removed from LON-DC1. You need to assign VirtualiSCSI2.vhd a logical unit

value of 0. What should you do?

 

  1. Run the Set-IscsiVirtualDisk cmdlet and specify the -DevicePath parameter.

  2. Run the iscsicpl command and specify the virtualdisklun parameter.

  3. Modify the properties of the itgt ISCSI target.

  4. Run the Set-VirtualDisk cmdlet and specify the -Uniqueld parameter.

 

Correct Answer: D

 

 

QUESTION 243

Your network contains three servers named Server1, Server2, and Server3. All servers run

Windows Server 2012 R2. You need to ensure that Server1 can provide iSCSI storage for Server2

and Server3. What should you do on Server1?

 

  1. Start the Microsoft iSCSI Initiator Service and configure the iSCSI Initiator Properties.

  2. Install the iSNS Server service feature and create a Discovery Domain.

  3. Install the Multipath I/O (MPIO) feature and configure the MPIO Properties.

  4. Install the iSCSI Target Server role service and configure iSCSI targets.

 

Correct Answer: D

 

 

QUESTION 244

Your network contains two servers named Server1 and Server2 that run Windows Server 2008 R2. Server1 and Server2 are nodes in a failover cluster named Cluster1. The network contains two

servers named Server3 and Server4 that run Windows Server 2012 R2. Server3 and Server4 are

nodes in a failover cluster named Cluster2. You need to move all of the App1ications and the

services from Cluster1 to Cluster2. What should you do first from Failover Cluster Manager?

 

  1. On a server in Cluster2, configure Cluster-Aware Updating.

  2. On a server in Cluster2, click Move Core Cluster Resources, and then click Best Possible Node.

  3. On a server in Cluster1, click Move Core Cluster Resources, and then click Best Possible Node.

  4. On a server in Cluster1, click Migrate Roles.

 

Correct Answer: B

 

 

QUESTION 245

You have a server named LON-DC1 that runs Windows Server 2012 R2. An iSCSI virtual disk

named VirtualiSCSI1.vhd exists on LON-DC1 as shown in the exhibit.

 

70-412-demo-179

 

You create a new iSCSI virtual disk named VirtualiSCSI2.vhd by using the existing itgt iSCSI target.

VirtualiSCSIl.vhd is removed from LON-DC1. You need to assign VirtualiSCSI2.vhd a logical unit

value of 0. What should you do?

 

  1. Modify the properties of the itgt ISCSI target.

  2. Modify the properties of the VirtualiSCSI2.vhd iSCSI virtual disk.

  3. Run the Set-VirtualDisk cmdlet and specify the -Uniqueld parameter.

  4. Run the iscsicli command and specify the reportluns parameter.

 

Correct Answer: B

QUESTION 246

You have a Hyper-V host named Server1 that runs Windows Server 2012 R2. Server1 contains a

virtual machine named VM1 that runs Windows Server 2012 R2. You fail to start VM1 and you

suspect that the boot files on VM1 are corrupt. On Server1, you attach the virtual hard disk (VHD)

of VM1 and you assign the VHD a drive letter of F. You need to repair the corrupt boot files on

VM1. What should you run?

 

  1. bootrec.exe /rebuildbcd

  2. bootrec.exe /scanos

  3. bcdboot.exe f:windows /s c:

  4. bcdboot.exe c:windows /s f:

 

Correct Answer: D

 

 

QUESTION 247

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs Windows Server 2012 R2 and has the DNS Server server role

installed. Server1 has a zone named contoso.com. The zone is configured as shown in the exhibit.

 

70-412-demo-180

 

You need to assign a user named User1 permission to add and delete records from the

contoso.com zone only. What should you do first?

  1. Enable the Advanced view from DNS Manager.

  2. Add User1 to the DnsUpdateProxy group.

  3. Run the New Delegation Wizard.

  4. Configure the zone to be Active Directory-integrated.

 

Correct Answer: D

 

 

QUESTION 248

Your network contains two servers named Server1 and Server2 that run Windows Server 2008 R2. Server1 and Server2 are nodes in a failover cluster named Cluster1. The network contains two

servers named Server3 and Server4 that run Windows Server 2012 R2. Server3 and Server4 are

nodes in a failover cluster named Cluster2. You need to move all of the App1ications and the

services from Cluster1 to Cluster2. What should you do first from Failover Cluster Manager?

 

  1. On a server in Cluster1, click Move Core Cluster Resources, and then click Select Node.

  2. On a server in Cluster2, configure Cluster-Aware Updating.

  3. On a server in Cluster1, configure Cluster-Aware Updating.

  4. On a server in Cluster2, click Migrate Roles.

  5. On a server in Cluster2, click Move Core Cluster Resources, and then click Best Possible Node.

 

Correct Answer: E

 

 

QUESTION 249

Your network contains two servers named HV1 and HV2. Both servers run Windows Server 2012

R2 and have the Hyper-V server role installed. HV1 hosts 25 virtual machines. The virtual machine

configuration files and the virtual hard disks are stored in D:VM. You shut down all of the virtual

machines on HV1. You copy D:VM to D:VM on HV2. You need to start all of the virtual machines

on HV2. You want to achieve this goal by using the minimum amount of administrative effort.

What should you do?

 

  1. Run the Import-VMInitialReplication cmdlet.

  2. From HV1, export all virtual machines to D:VM. Copy D:VM to D:VM on HV2 and overwrite

the existing files. On HV2, run the Import Virtual Machine wizard.

  1. From HV1, export all virtual machines to D:VM. Copy D:VM to D:VM on HV2 and overwrite

the existing files. On HV2, run the New Virtual Machine wizard.

  1. Run the Import-VM cmdlet.

 

Correct Answer: D

 

 

QUESTION 250

Your company recently deployed a new Active Directory forest named contoso.com. The first

domain controller in the forest runs Windows Server 2012 R2. You need to identify the

time-to-live (TTL) value for domain referrals to the NETLOGON and SYSVOL shared folders.

Which tool should you use?

 

  1. Ultrasound

  2. Replmon

  3. Dfsdiag

  4. Frsutil

 

Correct Answer: C

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo

< strong> 

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 231-240

Ensurepass

QUESTION 231

You are employed as a network administrator at consoto.com. Contoso.com has in an Active

Directory domain named contoso.com. All Servers on the contoso.com network have Windows

Server 2012 R2 installed. A contoso.com server, named Server1, hosts the Active Directory

Certificate Services Server role and utilizes a hardware security module (HSM) to safeguard its

private key. You have been instructed to backup the Active Directory Certificate Services (ADCS)

database, log files, and private key regularly. You should not use a utility supplied by the

hardware security module (HSM) creator. Which of the following actions should you take?

 

  1. You should consider scheduling an incremental backup.

  2. You Should consider making use of the certutil.exe command.

  3. You should consider schedulling a differential backup.

  4. You should consider schedulling a copy backup.

 

Correct Answer: B

 

 

QUESTION 232

You are employed as a senior network administrator at contoso.com contoso.com has an active

directory domain named contoso.com. All servers on the contoso.com network have Windows

Server 2012 R2 installed. You are currently running at training exercise for junior network

administrators. You are discussing the DNSSEC NRPT rule properly. Which of the following

describes the purpose of this rule property?

 

  1. It is used to indicate the namespace to which the policy App1ies.

  2. It is used to indicate whether the DNS client should check for DNSSEC validation in the

response.

  1. It is used to indicate DNSSEC must be used to protect DNS traffic for queries belonging to the

namespace.

  1. It is used to indicate whether DNS connections over DNSSEC will use encryption.

 

Correct Answer: B

 

 

QUESTION 233

You are employed as a network administrator at contoso.com. Contoso.com has an active

directory domain named contoso.com. All servers on the contoso.com network have Windows

Server 2012 R2 installed. Contoso.com has a server named server1, which is configured as a file

server. You have been instructed to enable a feature that discovers and eradicates duplication

within data without compromising its reliability or accuracy. Which of the following actions

should you take?

 

  1. You should consider having the Data Deduplication feature enabled.

  2. You should consider having the Storage Spaces feature enabled.

  3. You should consider having the Storage Management feature enabled.

  4. You should consider having the folder redirection feature enabled.

 

Correct Answer: A

 

 

QUESTION 234

You are employed as a network administrator at contoso.com. contoso.com has a single Active

Directory domain named contoso.com. All servers on the Contoso.com network have Windows

Server 2012 R2 installed. Contoso.com has two servers, named server1 and server2 which are

configured in a two-node fail over cluster. You are currently configuration the quorum settings for

the cluster. You want to make use of a quorum mode that allows each node to vote if it is

available and in communication. Which of the following is the mode you should use?

 

  1. Node Majority

  2. Node and Disk Majority

  3. Node and File Share Majority

  4. No Majority: Disk Only

 

Correct Answer: A

 

 

QUESTION 235

You are employed as a network administrator at contoso.com. Contoso.com has a single Active

Directory domain named contoso.com. All servers on the contoso.com network have Windows

Server 2012 R2 installed. You are preparing to install a third-party App1ication on a contoso.com

server, named SERVER1. You find that the App1ication is unable to install completely due to its

driver not being digitally signed. You want to make sure that the App1ication can be installed

successfully. Which of the following actions should you take?

 

  1. You should consider downloading a signed driver.

  2. You should consider having SERVER1 is restored to an earlier date.

  3. You should consider making use of the Disable Driver Signature Enforcement option from the

Advanced Boot Option.

  1. You should consider restarting SERVER1 in safe Mode.

 

Correct Answer: C

 

 

QUESTION 236

You are employed as a senior network administrator at contoso.com.Contoso.com has a single

Active Directory Domain named contoso.com. All servers on the contoso.com network have

Windows Server 2012 R2 installed. You are running a training exercise for junior network

administrator. You are currently discussing the Dnslint.exe tool. W
hich of the following should

this tool be used for? (Choose all that App1y)

 

  1. To help diagnose common DNS name resolution issues.

  2. For developing scripts for configuring a DNS server.

  3. To administer the DNS server Service.

  4. To look for specific DNS record set and sure that they are consistent across multiple DNS

servers.

  1. To verify that DNS records used specifially for Active Directory replication are correct.

  2. To Create and delete zones and resource records.

 

Correct Answer: ADE

 

 

QUESTION 237

You work as an administrator at contoso.com. Contoso.com network consists of a single domain

named contoso.com. All servers on the contoso.com network have Windows Server 2012 R2

installed. Contoso.com has a server, named SERVER1, which has the AD DS, DHCP and DNS server

roles installed. Contoso.com also has a server named SERVER2, which has the DHCP and Remote

Access Server Role installed. You have configured SERVER3, which has the File and Storage

Services Server role installed to automatically acquire an IP address. You then create a filter on

SERVER1. Which of the following is a reason for this configuration?

 

  1. To make sure that SERVER1 issues Server3 an IP address.

  2. To make sure that SERVER1 does not issue SERVER3 an IP address.

  3. To make sure that SERVER3 acquires a constant IP address from SERVER2 only.

  4. To make sure that SERVER3 is configured with a static IP address.

 

Correct Answer: B

 

 

QUESTION 238

You are employed as a senior network administrator at ABC.com. ABC.com has an Active

Directory domain named ABC.com. All servers on the ABC.com network have Windows Server

2012 R2 installed. The ABC.com domain has an Active Directory site configured in London, and an

Active Directory site in New York. You have been instructed to make sure that the synchronization

of account lockout data happens quicker.

 

  1. You should consider editing the options attribute from WANLINK properties.

  2. You should consider editing the options attribute from LANLIK properties.

  3. You should consider editing the options attribute from the DEFAULTSITE1INK properties.

  4. You should consider editing the proxyAddressess attribute from the DEFAULTIPSITE1INK

properties.

 

Correct Answer: C

 

 

QUESTION 239

You are employed as a senior network administrator at ABC.com. ABC.com has an Active

Directory domain named ABC.com. All servers on the ABC.com network have Windows Server

2012 R2 installed. ABC.com has two servers, named SERVER1 and SERVER2 which are configured

in a two-node failover cluster. Server1 includes a folder, named ABCAppData, which is configured

as a Distributed File System (DFS) name space folder target. After configuring another two nodes

in the failover cluster, you are instructed to make sure that access to ABCAppData is highly

available. You also have to make sure that App1ication data is replicated to ABCAppData via DFS

replication. Which following actions should you take?

 

  1. You should consider configuring a scale-out File Server.

  2. You should consider configuring the replication settings for the cluster.

  3. You should consider configuring a file server for general use.

  4. You should consider configuring the Quorum settings.

 

Correct Answer: A

 

 

QUESTION 240

Your network contains an Active Directory domain named contoso.com. All servers run Windows

Server 2012 R2. The domain contains a domain controller named DC1 that is configured as an

enterprise root certification authority (CA). All users in the domain are issued a smart card and

are required to log on to their domain joined client computer by using their smart card. A user

named User1 resigned and started to work for a competing company. You need to prevent User1

immediately from logging on to any computer in the domain. The solution must not prevent

other users from logging on to the domain. Which tool should you use?

 

  1. Active Directory Administrative Center

  2. Active Directory Sites and Services

  3. Active Directory Users and Computers

  4. the Certification Authority console

  5. the Certificates snap-in

  6. Certificate Templates

  7. Server Manager

  8. the Security Configuration Wizard

 

Correct Answer: ACD

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 221-230

Ensurepass

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 211-220

Ensurepass

QUESTION 211

Your network contains an Active Directory domain named contoso.com. All domain controllers

run Windows Server 2012 R2. The domain contains two domain controllers. The domain

controllers are configured as shown in the following table.

 

70-412-demo-165

 

The Branch site contains a perimeter network. For security reasons, client computers in the

perimeter network can communicate with client computers in the Branch site only. You plan to

deploy a new RODC to the perimeter network in the Branch site. You need to ensure that the

new RODC will be able to replicate from DC10. What should you do first on DC10?

 

  1. Create an Active Directory site link bridge.

  2. Create an Active Directory site.

  3. Run the Uninstall-ADDSDomainController cmdlet.

  4. Run the Add-ADDSReadOnlyDomainControllerAccount cmdlet.

Correct Answer: D

 

 

QUESTION 212

Your network contains an Active Directory forest named contoso.com. The forest contains a

single domain. The forest contains three Active Directory sites named SiteA, SiteB, and SiteC. The

sites contain four domain controllers. The domain controllers are configured as shown in the

following table.

 

70-412-demo-166

 

An IP site link exits between each site. You discover that the users in SiteC are authenticated by

the domain controllers in SiteA and SiteB. You need to ensure that the SiteC users are

authenticated by the domain controllers in SiteB, unless all of the domain controllers in SiteB are

unavailable. What should you do?

 

  1. Create an SMTP site link between SiteB and SiteC.

  2. Create additional connection objects for DC3 and DC4.

  3. Decrease the cost of the site link between SiteB and SiteC.

  4. Create additional connection objects for DC1 and DC2.

 

Correct Answer: C

 

 

QUESTION 213

Your network contains an Active Directory forest named contoso.com. The forest contains a

single domain. The domain contains three domain controllers. The domain controllers are

configured as shown in the following table.

 

70-412-demo-167

 

You plan to test an App1ication on a server named Server1. Server1 is currently located in Site1.

After the test, Server1 will be moved to Site2. You need to ensure that Server1 attempts to

authenticate to DC3 first, while you test the App1ication. What should you do?

 

  1. Create a new site and associate the site to an existing site link object.

  2. Modify the registry on DC3.

  3. Modify the weight of site-specific service location (SRV) DNS records Site1.

  4. Modify the registry on Server1.

  5. Modify the priority of site-specific service location (SRV) DNS records for Site2.

 

Correct Answer: E

 

 

QUESTION 214

Your network contains two servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 and Server2 have the Hyper-V server role installed. Server1 and Server2 are configured

as Hyper-V replicas of each other. Server2 hosts a virtual machine named VM5. VM5 is replicated

to Server1. You need to verify whether the replica of VM5 on Server1 is functional. The solution

must ensure that VM5 remains accessible to clients. What should
you do from Hyper-V Manager?

 

  1. On a server in Cluster2, click Migrate Roles.

  2. On a server in Cluster2, configure Cluster-Aware Updating.

  3. On a server in Cluster1, click Move Core Cluster Resources, and then click Select Node.

  4. On a server in Cluster1, configure Cluster-Aware Updating.

 

Correct Answer: B

 

 

QUESTION 215

Your network contains an Active Directory domain named contoso.com. The domain contains two

member servers named Server1 and Server2. All servers run Windows Server 2012 R2. Server1

and Server2 have the Failover Clustering feature installed. The servers are configured as nodes in

a failover cluster named Cluster1. Cluster1 has access to four physical disks. The disks are

configured as shown in the following table.

 

70-412-demo-168

 

You need to ensure that all of the disks can be added to a Cluster Shared Volume (CSV). Which

two actions should you perform? (Each correct answer presents part of the solution. Choose

two.)

 

  1. Enable BitLocker on Disk4.

  2. Format Disk3 to use NTFS.

  3. Format Disk2 to use NTFS.

  4. Disable BitLocker on Disk1.

 

Correct Answer: BC

 

 

QUESTION 216

Your network contains an Active Directory forest named contoso.com. The contoso.com domain

only contains domain controllers that run Windows Server 2012 R2. The forest contains a child

domain named child.contoso.com. The child.contoso.com domain only contains domain

controllers that run Windows Server 2008 R2. The child.contoso.com domain contains a member

server named Server1 that runs Windows Server 2012 R2. You have access to four administrative

user accounts in the forest. The administrative user accounts are configured as shown in the

following table.

 

70-412-demo-169

 

You need to ensure that you can add a domain controller that runs Windows Server 2012 R2 to

the child.contoso.com domain. Which account should you use to run adprep.exe?

 

  1. Admin1

  2. Admin2

  3. Admin3

  4. Admin4

 

Correct Answer: C

 

 

QUESTION 217

Your network contains two servers named Server1 and Server 2. Both servers run Windows

Server 2012 R2 and have the Hyper-V server role installed. Server1 hosts a virtual machine

named VM1. The virtual machine configuration files and the virtual hard disks for VM1 are stored

in D: VM1. You shut down VM1 on Server1. You copy D:VM1 to D:VM1 on Server2. You need

to start VM1 on Server2. You want to achieve this goal by using the minimum amount of

administrative effort. What should you do?

 

  1. Run the Import-VMIntialReplication cmdlet.

  2. Create a new virtual machine on Server2 and attach the VHD from VM1 to the new virtual

machine.

  1. From Hyper-V Manager, run the Import Virtual Machine wizard.

  2. Run the Import-IscsiVirtualDisk cmdlet.

 

Correct Answer: C

 

 

QUESTION 218

Your network contains an Active Directory domain named contoso.com. The domain contains two

servers named Node1 and Node2. Node1 and Node2 run Windows Server 2012 R2. Node1 and

Node2 are configured as a two-node failover cluster named Cluster2. The computer accounts for

all of the servers reside in an organizational unit (OU) named Servers. A user named User1 is a

member of the local Administrators group on Node1 and Node2. User1 creates a new clustered

File Server role named File1 by using the File Server for general use option. A report is generated

during the creation of File1 as shown in the exhibit.

 

70-412-demo-170

File1 fails to start. You need to ensure that you can start File1. What should you do?

 

  1. Log on to the domain by using the built-in Administrator for the domain, and then recreate

the clustered File Server role by using the File Server for general use option.

  1. Recreate the clustered File Server role by using the File Server for scale-out App1ication data

option.

  1. Assign the computer account permissions of Cluster2 to the Servers OU.

  2. Assign the user account permissions of User1 to the Servers OU.

  3. Increase the value of the ms-DS-MachineAccountQuota attribute of the domain.

 

Correct Answer: B

 

 

QUESTION 219

Your network contains an Active Directory forest. The forest contains one domain named

adatum.com. The domain contains three domain controllers. The domain controllers are

configured as shown in the following table.

 

70-412-demo-171

 

DC2 has all of the domain-wide operations master roles. DC3 has all of the forest-wide operation

master roles. You need to ensure that you can use Password Settings objects (PSOs) in the

domain. What should you do first?

 

  1. Uninstall Active Directory from DC1.

  2. Change the domain functional level.

  3. Transfer the domain-wide operations master roles.

  4. Transfer the forest-wide operations master roles.

 

Correct Answer: A

 

 

QUESTION 220

Your network contains an Active Directory forest named contoso.com. The forest contains three

domains. All domain controllers run Windows Server 2012 R2. The forest has a two-way realm

trust to a Kerberos realm named adatum.com. You discover that users in adatum.com can only

access resources in the root domain of contoso.com. You need to ensure that the adatum.com

users can access the resources in all of the domains in the forest. What should you do in the

forest?

 

  1. Delete the realm trust and create a forest trust.

  2. Delete the realm trust and create three external trusts.

  3. Modify the incoming realm trust.

  4. Modify the outgoing realm trust.

 

Correct Answer: D

 

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 191-200

Ensurepass

QUESTION 201

Your network contains an Active Directory forest named contoso.com. The forest contains a

single domain. The domain contains three domain controllers. The domain controllers are

configured as shown in the following table.

 

70-412-demo-156

 

You plan to test an App1ication on a server named Server1. Server1 is currently located in Site1.

After the test, Server1 will be moved to Site2. You need to ensure that Server1 attempts to

authenticate to DC3 first, while you test the App1ication. What should you do?

  1. Modify the priority of site-specific service location (SRV) DNS records for Site2.

  2. Modify the weight of site-specific service location (SRV) DNS records Site1.

  3. Modify the registry on Server1.

  4. Create a new site and associate the site to an existing site link object.

 

Correct Answer: A

 

 

QUESTION 202

Your network contains an Active Directory domain named contoso.com. The domain contains a

main office and a branch office. An Active Directory site exists for each office. All domain

controllers run Windows Server 2012 R2. The domain contains two domain controllers. The

domain controllers are configured as shown in the following table.

 

70-412-demo-157

 

DC1 hosts an Active Directory-integrated zone for contoso.com. You add the DNS Server server

role to DC2. You discover that the contoso.com DNS zone fails to replicate to DC2. You verify that

the domain, schema, and configuration naming contexts replicate from DC1 to DC2. You need to

ensure that DC2 replicates the contoso.com zone by using Active Directory replication. Which

tool should you use?

 

  1. Active Directory Users and Computers

  2. Active Directory Sites and Services

  3. Dnscmd

  4. DNS Manager

 

Correct Answer: D

 

 

QUESTION 203

Your network contains an Active Directory forest. The forest contains two domains named

contoso.com and fabrikam.com. The functional level of the forest is Windows Server 2003.

You have a domain outside the forest named adatum.com.

 

You need to configure an access solution to meet the following requirements:

 

  • Users in fabrikam.com must be able to access resources in adatum.com.

  • Users in contoso.com must be prevented from accessing resources in adatum.com.

  • Users in adatum.com must be prevented from accessing resources in both fabrikam.com

and contoso.com.

 

What should you create?

 

  1. a one-way realm trust from fabrikam.com to adatum.com

  2. a one-way external trust from adatum.com to fabrikam.com

  3. a one-way external trust from fabrikam.com to adatum.com

  4. a one-way realm trust from adatum.com to fabrikam.com

 

Correct Answer: B

 

 

QUESTION 204

You deploy an Active Directory Federation Services (AD FS) 2.1 infrastructure. The infrastructure

uses Active Directory as the attribute store. Some users report that they fail to authenticate to

the AD FS infrastructure. You discover that only users who run third-party web browsers

experience issues. You need to ensure that all of the users can authenticate to the AD FS

infrastructure successfully. Which Windows PowerShell command should you run?

 

  1. Set-ADFSProperties -ProxyTrustTokenLifetime 1:00:00

  2. Set-ADFSProperties -AddProxyAuthenticationRules None

  3. Set-ADFSProperties -SSOLifetime 1:00:00

  4. Set-ADFSProperties -ExtendedProtectionTokenCheck None

 

Correct Answer: A

 

 

QUESTION 205

Your network contains an Active Directory domain named contoso.com. All servers run Windows

Server 2012 R2. The domain contains a file server named Server1. The domain contains a domain

controller named DC1. Server1 contains three shared folders. The folders are configured as

shown in the following table.

 

70-412-demo-158

 

Folder2 has a conditional expression of User.Department= = MMarketing”.

You discover that a user named User1 cannot access \Server1folder2. User1 can access

\Server1folderl and \Server1folder3.

 

You verify the group membership of User1 as shown in the Member of exhibit.

70-412-demo-159

 

You verify the organization information of User1 as shown in the Organization exhibit.

 

70-412-demo-160

 

You verify the general properties of User1 as shown in the General exhibit.

 

70-412-demo-161

 

You need to ensure that User1 can access the contents of \Server1folder2. What should you

do?

 

  1. From a Group Policy object (GPO), set the Support for Dynamic Access Control and Kerberos

armoring setting to Always provide claims.

  1. Change the department attribute of User1.

  2. Grant the Full Control NTFS permissions on Folder2 to
    User1.

  3. Remove User11from the Accounting global group.

 

Correct Answer: B

 

 

QUESTION 206

You have a server named Server1 that runs Windows Server 2012 R2. You install the File and

Storage Services server role on Server1. From Windows Explorer, you view the properties of a

folder named Folder1 and you discover that the Classification tab is missing. You need to ensure

that you can assign classifications to Folder1 from Windows Explorer manually. What should you

do?

 

  1. From Folder Options, clear Hide protected operating system files (Recommended).

  2. Install the File Server Resource Manager role service.

  3. From Folder Options, select the Always show menus.

  4. Install the Share and Storage Management Tools.

 

Correct Answer: B

 

 

QUESTION 207

Your network contains an Active Directory domain named contoso.com. All domain controllers

run Windows Server 2012 R2. The domain contains two domain controllers. The domain

controllers are configured as shown in the following table.

 

70-412-demo-162

 

The Branch site contains a perimeter network. For security reasons, client computers in the

perimeter network can communicate with client computers in the Branch site only. You plan to

deploy a new RODC to the perimeter network in the Branch site. You need to ensure that the

new RODC will be able to replicate from DC10. What should you do first on DC10?

 

  1. Enable the Bridge all site links setting.

  2. Run the Active Directory Domain Services Configuration Wizard.

  3. Create an Active Directory site link bridge.

  4. Create an Active Directory site.

 

Correct Answer: C

 

 

QUESTION 208

Your network contains an Active Directory forest named contoso.com. The forest contains a

single domain. The domain contains three domain controllers. The domain controllers are

configured as shown in the following table.

 

70-412-demo-163

 

You plan to test an App1ication on a server named Server1. Server1 is currently located in Site1.

After the test, Server1 will be moved to Site2. You need to ensure that Server1 attempts to

authenticate to DC3 first, while you test the App1ication. What should you do?

 

  1. Modify the weight of site-specific service location (SRV) DNS records Site1.

  2. Create a new subnet object and associate the subnet object to an existing site.

  3. Modify the registry on DC3.

  4. Modify the priority of site-specific service location (SRV) DNS records for Site2.

 

Correct Answer: D

 

 

QUESTION 209

Your network contains an Active Directory domain named contoso.com. The domain contains two

member servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 has

Microsoft SQL Server 2012 installed. You install the Active Directory Federation Services server

role on Server2. You need to configure Server2 as the first Active Directory Federation Services

(AD FS) server in the domain. The solution must ensure that the AD FS database is stored in a SQL

Server database on Server1. What should you do on Server2?

 

  1. From a command prompt, run fsutil.exe.

  2. From Windows PowerShell, run Install-ADFSFarm.

  3. From Server Manager, install the Federation Service Proxy.

  4. From Server Manager, install the AD FS Web Agents.

 

Correct Answer: B

 

 

QUESTION 210

Your network contains an Active Directory domain named contoso.com. All domain controllers

run Windows Server 2012 R2. The domain contains two domain controllers. The domain

controllers are configured as shown in the following table.

 

70-412-demo-164

 

The Branch site contains a perimeter network. For security reasons, client computers in the

perimeter network can communicate with client computers in the Branch site only. You plan to

deploy a new RODC to the perimeter network in the Branch site. You need to ensure that the

new RODC will be able to replicate from DC10. What should you do first on DC10?

 

  1. Create an Active Directory subnet.

  2. Run the Active Directory Domain Services Configuration Wizard.

  3. Run dcpromo and specify the fcreatedcaccount parameter.

  4. Run the Add-ADDSReadOnlyDomainControllerAccount cmdlet.

 

Correct Answer: D

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 191-200

Ensurepass

QUESTION 191

Your network contains an Active Directory domain named contoso.com. All domain controllers

run Windows Server 2012 R2. The domain contains two domain controllers. The domain

controllers are configured as shown in the following table.

 

70-412-demo-148

 

The Branch site contains a perimeter network. For security reasons, client computers in the

perimeter network can communicate with client computers in the Branch site only. You plan to

deploy a new RODC to the perimeter network in the Branch site. You need to ensure that the

new RODC will be able to replicate from DC10. What should you do first on DC10?

 

  1. Run dcpromo and specify the /createdcaccount parameter.

  2. Run the Active Directory Domain Services Configuration Wizard.

  3. Run the Add-ADDSReadOnlyDomainControllerAccount cmdlet.

  4. Enable the Bridge all site links setting.

 

Correct Answer: C

 

 

QUESTION 192

Your network contains an Active Directory forest named contoso.com. The forest contains a

single domain. The forest contains three Active Directory sites named SiteA, SiteB, and SiteC. The

sites contain four domain controllers. The domain controllers are configured as shown in the

following table.

 

70-412-demo-149

 

An IP site link exits between each site. You discover that the users in SiteC are authenticated by

the domain controllers in SiteA and SiteB You need to ensure that the SiteC users are

authenticated by the domain controllers in SiteB, unless all of the domain controllers in SiteB are

unavailable. What should you do?

 

  1. Create an SMTP site link between SiteB and SiteC

  2. Decrease the cost of the site link between SiteB and SiteC

  3. Disable site link bridging.

  4. Create additional connection objects for DC1 and DC2.

 

Correct Answer: B

 

 

QUESTION 193

Your network contains an Active Directory domain named contoso.com. All servers run Windows

Server 2012 R2. The domain contains a domain controller named DC1 that is configured as an

enterprise root certification authority (CA). All users in the domain are issued a smart card and

are required to log on to their domain-joined client computer by using their smart card. A user

named User1 resigned and started to work for a competing company. You need to prevent User1

immediately from logging on to any computer in the domain. The solution must not prevent

other users from logging on to the domain. Which tool should you use?

 

  1. The Security Configuration Wizard.

  2. The Certification Authority console.

  3. Active Directory Administrative Center.

  4. Certificate Templates.

 

Correct Answer: B

 

 

QUESTION 194

You perform a full installation of Windows Server 2012 R2 on a virtual machine named Server1.

You plan to use Server1 as a reference image. You need to minimize the amount of storage space

used by the Windows Server 2012 R2 installation. Which cmdlet should you use?

 

  1. Remove-Module

  2. Optimize-VHD

  3. Optimize-Volume

  4. Uninstall-WindowsFeature

 

Correct Answer: B

 

 

QUESTION 195

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs Windows Server 2012 R2 and has the DHCP Server server role

installed. Server1 has a scope named Scope1. A policy named Policy1 is configured for Scope1.

Policy1 is configured to provide Hyper-V virtual machines a one-day lease. All other computers

receive an eight-day lease. You implement an additional DHCP server named Server2 that runs

Windows Server 2012 R2. On Server1, you configure Scope1 for DHCP failover. You discover that

virtual machines that receive IP addresses from Server2 have a lease duration of eight days. You

need to ensure that when Server2 assigns IP addresses to the Hyper-V virtual machines, the lease

duration is one day. The solution must ensure that other computers that receive IP addresses

from Server2 have a lease duration of eight days. What should you do?

 

  1. On Server2, right-click Scope1, and then click Reconcile.

  2. On Server1, right-click Scope1, and then click Replicate Scope.

  3. On Server2, create a new DHCP policy.

  4. On Server1, delete Policy1, and then recreate the policy.

 

Correct Answer: B

 

 

QUESTION 196

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the DNS Server

server role installed. You need to store the contents of all the DNS queries received by Server1.

What should you configure?

 

  1. Logging from Windows Firewall with Advanced Security.

  2. Debug logging from DNS Manager.

  3. A Data Collector Set (DCS) from Performance Monitor.

  4. Monitoring from DNS Manager.

 

Correct Answer: D

 

 

QUESTION 197

HOTSPOT

Your network contains two Hyper-V hosts that are configured as shown in the following table.

 

70-412-demo-150

 

You create a virtual machine on Server1 named VM1. You plan to export VM1 from Server1 and


import VM1 to Server2. You need to ensure that you can start the imported copy of VM1 from

snapshots. What should you configure on VM1?

 

To answer, select the appropriate node in the answer area.

 

Hot Area:

70-412-demo-151

 

Correct Answer:

70-412-demo-152

 

 

QUESTION 198

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2. The domain contains two domain controllers. The domain controllers are configured as shown in the following table.

 

70-412-demo-153

 

You configure a user named User1 as a delegated administrator of DC10. You need to ensure that

User1 can log on to DC10 if the network link between the Main site and the Branch site fails.

What should you do?

 

  1. On DC10, run ntdsutil and configure the settings in the Roles context.

  2. On DC10, run ntdsutil and configure the settings in the Local Roles context.

  3. Modify the properties of the DC10 computer account.

  4. Run repadmin and specify /replsingleobject parameter.

  5. On DC10, modify the User Rights Assignment in Local Policies.

 

Correct Answer: E

 

 

QUESTION 199

Your network contains an Active Directory forest named contoso.com. The forest contains a

single domain. The forest contains three Active Directory sites named SiteA, SiteB, and SiteC. The

sites contain four domain controllers. The domain controllers are configured as shown in the

following table.

 

70-412-demo-154

 

An IP site link exits between each site. You discover that the users in SiteC are authenticated by

the domain controllers in SiteA and SiteB. You need to ensure that the SiteC users are

authenticated by the domain controllers in SiteB, unless all of the domain controllers in SiteB are

unavailable. What should you do?

 

  1. Create an SMTP site link between SiteB and SiteC.

  2. Crate additional connection objects for DC1 and DC2.

  3. Decrease the cost of the site link between SiteB and SiteC.

  4. Create additional connection objects for DC3 and DC4.

 

Correct Answer: C

 

 

QUESTION 200

Your network contains an Active Directory domain named contoso.com. All domain controllers

run Windows Server 2012 R2. The domain contains two domain controllers. The domain

controllers are configured as shown in the following table.

 

70-412-demo-155

 

The Branch site contains a perimeter network. For security reasons, client computers in the

perimeter network can communicate with client computers in the Branch site only. You plan to

deploy a new RODC to the perimeter network in the Branch site. You need to ensure that the

new RODC will be able to replicate from DC10. What should you do first on DC10?

 

  1. Enable the Bridge all site links setting.

  2. Create an Active Directory subnet.

  3. Run the Add-ADDSReadOnlyDomainControllerAccount cmdlet.

  4. Run the Uninstall-ADDSDomainController cmdlet.

 

Correct Answer: C

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 181-190

Ensurepass

QUESTION 181

Your network contains two DNS servers named DN51 and DNS2 that run Windows Server 2012

R2. DNS1 has a primary zone named contoso.com. DNS2 has a secondary copy of the

contoso.com zone. You need to log the zone transfer packets sent between DNS1 and DNS2.

What should you configure?

 

  1. Monitoring from DNS Manager.

  2. Logging from Windows Firewall with Advanced Security.

  3. A Data Collector Set (DCS) from Performance Monitor.

  4. Debug logging from DNS Manager.

 

Correct Answer: D

 

 

QUESTION 182

Your network contains an Active Directory forest. The forest contains one domain named

contoso.com. The domain contains three domain controllers. The domain controllers are

configured as shown in the following table.

 

70-412-demo-136

 

DC1 has all of the operations master roles installed. You transfer all of the operations master

roles to DC2, and then you uninstall Active Directory from DC1. You need to ensure that you can

use Password Settings objects (PSOs) in the domain. What should you do?

 

  1. Change the domain functional level.

  2. Upgrade DC2.

  3. Run the dcgpofix.exe command.

  4. Transfer the schema master role.

 

Correct Answer: A

 

 

QUESTION 183

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server3 that runs Windows Server 2012 R2 and has the DHCP Server server role

installed. DHCP is configured as shown in the exhibit.

 

70-412-demo-137

 

You need to ensure that only Scope1, Scope3, and Scope5 assign the same DNS servers to DHCP

clients. The solution must minimize administrative effort. What should you do?

 

  1. Create a superscope and scope-level policies.

  2. Configure the Scope Options.

  3. Create a superscope and a filter.

  4. Configure the Server Options.

 

Correct Answer: B

 

 

QUESTION 184

You have a server named Server1 that runs Windows Server 2012 R2. When you install a custom App1ication on Server1 and restart the server, you receive the following error message:

 

“The Boot Configuration Data file is missing some required information.

File: BootBCD

Error code: 0x0000034.”

 

You start Server1 by using Windows PE. You need to ensure that you can start Windows Server

2012 R2 on Server1. Which tool should you use?

 

  1. Bootsect

  2. Bootim

  3. Bootrec

  4. Bootcfg

 

Correct Answer: C

 

 

QUESTION 185

You have a server named Server1 that runs Windows Server 2012 R2. Server1 fails. You identify

that the master boot record (MBR) is corrupt. You need to repair the MBR. Which tool should you

use?

 

  1. Bcdedit

  2. Bcdboot

  3. Bootrec

  4. Fixmbr

 

Correct Answer: C

 

 

QUESTION 186

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs Windows Server 2012 R2. Server1 has the Active Directory Rights

Management Services server role installed. Your company works with a partner organization that

does not have its own Active Directory Rights Management Services (AD RMS) implementation.

You need to create a trust policy for the partner organization.

 

The solution must meet the following requirements:

 

  • Grant users in the partner organization access to protected content.

  • Provide users in the partner organization with the ability to create protected content.

 

Which type of trust policy should you create?

 

  1. A federated trust.

  2. Windows Live ID.

  3. A trusted publishing domain.

  4. A trusted user domain.

 

Correct Answer: A

 

 

QUESTION 187

HOTSPOT

Your network contains an Active Directory domain named contoso.com. All servers run Windows

Server 2012 R2. The domain contains two domain controllers. The domain controllers are

configured as shown in the following table.

 

70-412-demo-138

 

On DC1, you create an Active Directory-integrated zone named Zone1. You verify that Zone1

replicates to DC2. You use DNSSEC to sign Zone1. You discover that the updates to Zone1 fail to

replicate to DC2. You need to ensure that Zone1 replicates to DC2. What should you configure on

DC1?

 

To answer, select the appropriate tab in the answer area.

 

Hot Area:

70-412-demo-139

 

Correct Answer:

70-412-demo-140

 

 

QUESTION 188

DRAG DROP

Your network contains four servers that run Windows Server 2012 R2. Each server has the

Failover Clustering feature installed. Each server has three network adapters installed. An iSCSI

SAN is available on the network. You create a failover cluster named Cluster1. You add the servers

to the cluster. You plan to configure the network settings of each server node as shown in the

following table.

 

70-412-demo-141

 

You need to configure the network settings for Cluster1. What should you do?

 

To answer, drag the appropriate network communication setting to the correct cluster network.

Each network communication setting may be used once, more than once, or not at all. You may

need to drag the split bar between panes or scroll to view content.

 

Select and Place:

70-412-demo-142

 

Correct Answer:

70-412-demo-143

 

 

 

QUESTION 189

HOTSPOT

You have a server named Server1 that runs Windows Server 2012 R2. The volumes on Server1 are

configured as shown in the following table.

 

70-412-demo-144

 

A new corporate policy states that backups must use Windows Azure Online Backup whenever

possible. You need to identify which backup methods you must use to back up Server1. The

solution must use Windows Azure Online Backup whenever possible. Which backup type should

you identify for each volume?

 

To answer, select the appropriate backup type for each volume in the answer area.

 

Hot Area:

70-412-demo-145

 

Correct Answer:

70-412-demo-146

 

 

QUESTION 190

Your network contains an Active Directory domain named contoso.com. All domain controllers

run Windows Server 2012 R2. The domain contains two domain controllers. The domain

controllers are configured as shown in the following table.

 

70-412-demo-147

 

You configure a user named User1 as a delegated administrator of DC10. You need to ensure that

User1 can log on to DC10 if the network link between the Main site and the Branch site fails.

What should you do?

 

  1. Add User1 to the Domain Admins group.

  2. On DC10, run ntdsutil and configure the settings in the Roles context.

  3. Run repadmin and specify the /prp parameter.

  4. On DC1, modify the User Rights Assignment in Default Domain Controllers Group Policy

object (GPO).

 

Correct Answer: D

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 171-180

Ensurepass

QUESTION 171

HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs Windows Server 2012 R2. Server1 has the Active Directory

Certificate Services server role installed and configured. For all users, you are deploying smart

cards for logon. You are using an enrollment agent to enroll the smart card certificates for the

users. You need to configure the Contoso Smartcard Logon certificate template to support the

use of the enrollment agent. Which setting should you modify?

 

To answer, select the appropriate setting in the answer area.

 

Hot Area:

70-412-demo-123

 

Correct Answer:

70-412-demo-124

 

 

QUESTION 172

HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains the

two servers. The servers are configured as shown in the following table.

 

70-412-demo-125

 

You investigate a report about the potential compromise of a private key for a certificate issued

to Server2. You need to revoke the certificate issued to Server2. The solution must ensure that

the revocation can be reverted. Which reason code should you select?

 

To answer, select the appropriate reason code in the answer area.

 

Hot Area:

70-412-demo-126

 

Correct Answer:

70-412-demo-127

QUESTION 173

DRAG DROP

Your network contains two Active Directory forests named contoso.com and adatum.com. All

domain controllers run Windows Server 2012 R2. A federated trust exists between adatum.com

and contoso.com. The trust provides adatum.com users with access to contoso.com resources.

You need to configure Active Directory Federation Services (AD FS) claim rules for the federated

trust. The solution must meet the following requirements:

 

  • In contoso.com, replace an incoming claim type named Group with an outgoing claim type

named Role.

  • In adatum.com, allow users to receive their tokens for the relying party by using their Active

Directory group membership as the claim type.

 

The AD FS claim rules must use predefined templates. Which rule types should you configure on

each side of the federated trust?

 

To answer, drag the appropriate rule types to the correct location or locations. Each rule type may

be used once, more than once, or not at all. You may need to drag the split bar between panes or

scroll to view content.

 

Select and Place:

70-412-demo-128

 

Correct Answer:

70-412-demo-129

 

 

 

QUESTION 174

Your network contains an Active Directory domain named contoso.com. The domain contains a

main office and a branch office. An Active Directory site exists for each office. All domain

controllers run Windows Server 2012 R2. The domain contains two domain controllers.

The domain controllers are configured as shown in the following table.

 

70-412-demo-130

 

DC1 hosts an Active Directory-integrated zone for contoso.com. You add the DNS Server server

role to DC2. You discover that the contoso.com DNS zone fails to replicate to DC2. You verify that

the domain, schema, and configuration naming contexts replicate from DC1 to DC2. You need to

ensure that DC2 replicates the contoso.com zone by using Active Directory replication. Which

tool should you use?

 

  1. Active Directory Domains and Trusts

  2. Active Directory Users and Computers

  3. Repadmin

  4. Ntdsutil

 

Correct Answer: C

 

 

QUESTION 175

Your network contains an Active Directory domain named contoso.com. All servers run Windows

Server 2012 R2. The domain contains a domain controller named DC1 that is configured as an

enterprise root certification authority (CA). All users in the domain are issued a smart card and

are required to log on to their domain-joined client computer by using their smart card. A user

named User1 resigned and started to work for a competing company. You need to prevent User1

immediately from logging on to any computer in the domain. The solution must not prevent

other users from logging on to the domain. Which tool should you use?

 

  1. Active Directory Users and Computers.

  2. Server Manager.

  3. The Certificates snap-in.

  4. The Certification Authority console.

 

Correct Answer: A

 

 

QUESTION 176

DRAG DROP

You plan to deploy a failover cluster that will contain two nodes that run Windows Server 2012

R2. You need to configure a witness disk for the failover cluster. How should you configure the

witness disk?

 

To answer, drag the appropriate configurations to the correct location or locations. Each

configuration may be used once, more than once, or not at all. You may need to drag the split bar

between panes or scroll to view content.

 

Select and Place:

70-412-demo-131

 

Correct Answer:

70-412-demo-132

 

QUESTION 177

Your network contains an Active Directory domain named contoso.com. All domain controllers

run Windows Server 2012 R2. The domain contains two domain controllers. The domain

controllers are configured as shown in the following table.

 

70-412-demo-133

 

You configure a user named User1 as a delegated administrator of DC10. You need to ensure that

User1 can log on to DC10 if the network link between the Main site and the Branch site fails.

What should you do?

 

  1. On DC10, run ntdsutil and configure the settings in the Local Roles context.

  2. Run repadmin and specify /replsingleobject parameter.

  3. Modify the properties of the DC10 computer account.

  4. On DC10, modify the User Rights Assignment in Local Policies.

 

Correct Answer: D

 

 

QUESTION 178

Your network contains an Active Directory forest named contoso.com. The forest contains a

single domain. The domain contains three domain controllers. The domain controllers are

configured as shown in the following table.

 

70-412-demo-134

 

You plan to test an App1ication on a server named Server 1. Server1 is currently located in Site1.

After the test, Server1 will be moved to Site2. You need to ensure that Server1 attempts to

authenticate to DC3 first, while you test the App1ication. What should you do?

 

  1. Modify the priority of site-specific service location (SRV) DNS records for Site2.

  2. Create a new subnet object and associate the subnet object to an existing site.

  3. Create a new site and associate the site to an existing site link object.

  4. Modify the registry on DC3.

 

Correct Answer: A

 

 

QUESTION 179

Your network contains an Active Directory domain named contoso.com. The domain contains a

main office and a branch office. An Active Directory site exists for each office. All domain

controllers run Windows Server 2012 R2. The domain contains two domain controllers. The

domain controllers are configured as shown in the following table.

 

70-412-demo-135

 

DC1 hosts an Active Directory-integrated zone for contoso.com. You add the DNS Server server

role to DC2. You discover that the contoso.com DNS zone fails to replicate to DC2. You verify that

the domain, schema, and configuration naming contexts replicate from DC1 to DC2. You need to

ensure that DC2 replicates the contoso.com zone by using Active Directory replication. Which

tool should you use?

 

  1. Active Directory Users and Computers

  2. Ntdsutil

  3. DNS Manager

  4. Active Directory Domains and Trusts

 

Correct Answer: C

 

 

QUESTION 180

Your network contains an Active Directory forest named contoso.com. The forest contains a

single domain. The forest functional level is Windows Server 2012 R2. You have a domain

controller named DC1. On DC1, you create a new Group Policy object (GPO) named GPO1. You

need to verify that GPO1 was replicated to all of the domain controllers. Which tool should you

use?

 

  1. Group Policy Management

  2. Active Directory Sites and Services

  3. DFS Management

  4. Active Directory Administrative Center

 

Correct Answer: A

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo

New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 161-170

Ensurepass

QUESTION 161

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs Windows Server 2012 R2. You need to ensure that a WIM file

that is located on a network share is used as the installation source when installing server roles

and features on Server1. Which two actions should you perform? (Each correct answer presents

part of the solution. Choose two.)

 

  1. Run the dism.exe command and specify the /remove-package parameter.

  2. Run the Remove-WindowsFeature cmdlet.

  3. Enable and configure the Specify settings for optional component installation and

component repair policy setting by using a Group Policy object (GPO).

  1. Enable the Enforce upgrade component rules policy setting by using a Group Policy object

(GPO).

  1. Run the Remove-WindowsPackage cmdlet.

 

Correct Answer: AC