412 Exam prep set 3

  1. Your network contains an Active Directory domain named contoso.com. The domain contains four member servers named Server1, Server2, Server3, and Server4.

    Server1 and 5erver2 run Windows Server 2008 R2. Server1 and Server2 have the Hyper-V server role and the Failover Clustering feature installed.

    Failover Clustering is configured to provide highly available virtual machines by using a cluster named Cluster1. Cluster1 hosts 10 virtual machines. Server3 and Server4 run Windows Server 2012 R2.

    You install the Hyper-V server role and the Failover Clustering feature on Server3 and Server4. You create a cluster named Cluster2.

    You need to migrate cluster resources from Cluster1 to Cluster2. The solution must minimize downtime on the virtual machines.

    Which five actions should you perform?

    Image Upload 2
    Image Upload 4


    Shut down all the VMs in Cluster 1

    Unmask the shared storage to present the storage to Cluster 2

    Mask the shared storage to prevent the storage from being accessed by Cluster 1

    Start the VMs in Cluster 2

    From Failover Cluster Manager in Cluster 1, run the Migrate a Cluster Wizard.
  2. Your network contains an Active Directory domain named contoso.com. The domain contains amain office and a branch office. An Active Directory site exists for each office. All domaincontrollers run Windows Server 2012 R2. The domain contains two domain controllers. The domain controllers are configured as shown in the following table.

    Image Upload 6

    DC1 hosts an Active Directory-integrated zone for contoso.com. You add the DNS Server server role to DC2. You discover that the contoso.com DNS zone fails to replicate to DC2. You verify that the domain, schema, and configuration naming contexts replicate from DC1 to DC2.

    You need to ensure that DC2 replicates the contoso.com zone by using Active Directory replication. Which tool should you use?

    A. Ntdsutil

    B. Repadmin

    C. Dnslint

    D. Active Directory Domains and Trusts
    Repadmin.

    (Repadmin.exe is a command line tool that is designed to assist administrators in diagnosing, monitoring, andtroubleshooting Active Directory replication problems.)
  3. You have a server named Server1 that runs Windows Server 2012 R2. Windows Server 2012 R2 is installed on volume C.

    You need to ensure that Safe Mode with Networking loads the next time Server1 restarts.

    Which tool should you use?

    A. The Msconfig command.

    B. The Restart-Server cmdlet.

    C. The Restart-Computer cmdlet.

    D. The Bootcfg command.
    A. The Msconfig command.
  4. Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012 R2. DC1 has the DNS Server server role installed.

    The network contains client computers that run either Linux, Windows 7, or Windows 8. You have a standard primary zone named adatum.com as shown in the exhibit.

    Image Upload 8

    You plan to configure Name Protection on all of the DHCP servers. You need to configure the adatum.com zone to support Name Protection.

    Which two configurations should you perform from DNS Manager? (Each correct answer presents part of the solution. Choose two.)

    A. Sign the zone.

    B. Store the zone in Active Directory.

    C. Modify the Security settings of the zone.

    D. Configure Dynamic updates.
    B. Store the zone in Active Directory.

    D. Configure Dynamic updates.
  5. Your network contains two servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 and Server2 have the Hyper-V server role installed.

    Server1 and Server2 are configured as Hyper-V replicas of each other. Server1 hosts a virtual machine named VM1. VM1 is replicated to Server2.

    You need to verify whether the replica of VM1 on Server2 is functional. The solution must ensure that VM1 remains accessible to clients.

    What should you do from Hyper-V Manager?

    A. On Server1, execute a Planned Failover.

    B. On Server1, execute a Test Failover.

    C. On Server2, execute a Planned Failover.

    D. On Server2, execute a Test Failover.
    D. On Server2, execute a Test Failover.
  6. You have a failover cluster named Cluster1 that contains four nodes. All of the nodes run Windows Server 2012 R2.

    You need to force every node in Cluster1 to contact immediately the Windows Server Update Services (WSUS) server on your network for updates.

    Which tool should you use?

    A. The Add-CauClusterRole cmdlet

    B. The Wuauclt command

    C. The Wusa command

    D. The Invoke-CauScan cmdlet
    D. The Invoke-CauScan cmdlet
  7. Your network contains an Active Directory domain named contoso.com. The network contains a file server named Server1 that runs Windows Server 2012 R2.

    You are configuring a central access policy for temporary employees. You enable the Department resource property and assign the property a suggested value of Temp.

    You need to configure a target resource condition for the central access rule that is scoped to resources assigned to Temp only. Which condition should you use?

    A. (Temp.Resource Equals "Department")

    B. (Resource.Temp Equals "Department")

    C. (Resource.Department Equals "Temp")

    D. (Department.Value Equals "Temp")
    C. (Resource.Department Equals "Temp")
  8. Your network contains a server named Server1 that runs Windows Server 2012 R2. Server1 hasthe Active Directory Certificate Services server role installed and is configured as a stand alone certification authority (CA). You install a second server named Server2. You install the Online Responder role service on Server2.

    You need to ensure that Server1 can issue an Online Certificate Status Protocol (OCSP) Response Signing certificate to Server2.

    What should you do?

    A. On Server1, run the certutil.exe command and specify the -setreg parameter.

    B. On Server2, run the certutil.exe command and specify the -policy parameter.

    C. On Server1, configure Security for the OCSP Response Signing certificate template.

    D. On Server2, configure Issuance Requirements for the OCSP Response Signing certificatetemplate.
    C. On Server1, configure Security for the OCSP Response Signing certificate template.
  9. Your network contains an Active Directory domain named adatum.com. The domain contains a server named CA1 that runs Windows Server 2012 R2. CA1 has the Active Directory Certificate Services server role installed and is configured to support key archival and recovery.

    You need tonsure that a user named User1 can decrypt private keys archived in the Active Directory Certificate Services (AD CS) database.

    The solution must prevent User1 from retrieving the private keys from the AD CS database.

    What should you do?

    A. Assign User1 the Issue and Manage Certificates permission to Server1.

    B. Assign User1 the Read permission and the Write permission to all certificate templates.

    C. Provide User1 with access to a Key Recovery Agent certificate and a private key.

    D. Assign User1 the Manage CA permission to Server1.
    C. Provide User1 with access to a Key Recovery Agent certificate and a private key.
  10. Your network contains an Active Directory domain named contoso.com. The domain contains two sites named Site1 and Site2 and two domain controllers named DC1 and DC2. Both domain controllers are located in Site1.

    You install an additional domain controller named DC3 in Site1 and you ship DC3 to Site2. A technician connects DC3 to Site2. You discover that users in Site2 are authenticated by all three domain controllers.

    You need to ensure that the users in Site2 are authenticated by DC1 or DC2 only if DC3 is unavailable.

    What should you do?

    A. From Network Connections, modify the IP address of DC3.

    B. In Active Directory Sites and Services, modify the Query Policy of DC3.

    C. From Active Directory Sites and Services, move DC3.

    D. In Active Directory Users and Computers, configure the insDS-PrimaryComputer attribute for the users in Site2.
    C. From Active Directory Sites and Services, move DC3.
  11. Your network contains two Active Directory forests named contoso.com and adatum.com.Contoso.com contains one domain. Adatum.com contains a child domain namedchild.adatum.com. Contoso.com has a one-way forest trust to adatum.com. Selective authentication is enabled on the forest trust.

    Several user accounts are migrated from child.adatum.com to adatum.com. Users report that after the migration, they fail to access resources in contoso.com. The users successfully accessed the resources in contoso.com before the accounts were migrated.

    You need to ensure that the migrated users can access the resource sin contoso.com.

    What should you do?

    A. Replace the existing forest trust with an external trust.

    B. Run netdom and specify the /quarantine attribute.

    C. Disable SID filtering on the existing forest trust.

    D. Disable selective authentication on the existing forest trust.
    C. Disable SID filtering on the existing forest trust.
  12. You have four servers that run Windows Server 2012 R2. The servers have the Failover Clustering feature installed. You deploy a new cluster named Cluster1. Cluster1 is configured as shown in the following table.

    Image Upload 10

    Site2 is a disaster recovery site. Server1, Server2, and Server3 are configured as the preferred owners of the cluster roles. Dynamic quorum management is disabled.

    You plan to perform hardware maintenance on Server3.

    You need to ensure that if the WAN link between Site1 and Site2 fails while you are performing maintenance on Server3, the cluster resource will remain available in Site1.

    What should you do?

    A. Enable dynamic quorum management.

    B. Remove the node vote for Server3. 

    C. Add a file share witness in Site1.

    D. Remove the node vote for Server4 and Server5.
    D. Remove the node vote for Server4 and Server5.
  13. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server2 that runs Windows Server 2012 R2.

    You are a member of the local Administrators group on Server2. You install an Active Directory Rights Management Services (ADRMS) root cluster on Server2.

    You need to ensure that the AD RMS cluster is discoverable automatically by the AD RMS client computers and the users in contoso.com.

    Which additional configuration settings should you configure?

    To answer, select the appropriate tab in the answer area.

    Image Upload 12
    • Image Upload 14
    • scp
  14. Your network contains an Active Directory domain named contoso.com. The domain contains two member servers named Server1 and Server2. All servers run Windows Server 2012 R2.

    Server1 and Server2 have the Network Load Balancing (NLB) feature installed. The servers are configured as nodes in an NLB cluster named Cluster1. Both servers connect to the same switch. Cluster1 hosts a secure web App1ication named WebApp1. WebApp1 saves user state information in a central database.

    You need to ensure that the connections to WebApp1 are distributed evenly between the nodes. The solution must minimize port flooding.

    What should you configure?

    To answer, configure the appropriate affinity and the appropriate mode for Cluster1 in the answer area.

    Image Upload 16
    Image Upload 18
  15. You have 3 server named Server1 that runs Windows Server 2012 R2. You are asked to test Windows Azure Online Backup to back up Server1.

    You need to back up Server1 by using Windows Azure Online Backup. Which four actions should you perform in sequence?

    To answer, move the appropriate four actions from the list of actions to the answer area and-arrange them in the correct order.

    Image Upload 20
    • Image Upload 22
    • Sign up for a MS online Services Account
    • Download the Win Azure Online backup agent
    • Install the Win Server Backup feature
    • Run the register Server Wizard.
  16. Your network contains an Active Directory domain named adatum.com. All servers run Windows Server 2012 R2. All domain controllers have the DNS Server server role installed.

    You have a domain controller named DC1. On DC1, you create an Active Directory-integrated zone named adatum.com and you sign the zone by using DNSSEC. You deploy a new read-only domain controller (RODC) named RODC1.

    You need to ensure that the contoso.com zone replicates to RODC1. What should you configure on DC1?

    To answer, select the appropriate tab in the answer area.

    Image Upload 24
    Image Upload 26
  17. Your network contains an Active Directory domain named contoso.com. The domain contains four member servers named Server1, Server2, Servers, and Server4. All servers run WindowsServer 2012 R2.

    Server1 and Server2 are located in a site named Site1. Server3 and Server4 are located in a site named Site2. The servers are configured as nodes in a failover cluster named Cluster1. Cluster1 is configured to use the Node Majority quorum configuration.

    You need to ensure that Server1 is the only server in Site1 that can vote to maintain quorum. What should you run from Windows PowerShell?

    To answer, drag the appropriate commands to the correct location.

    Image Upload 28
    • Image Upload 30
    • Cluster node Server 2
    • NodeWeight 0
  18. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2 and has the DHCP Server server role installed.

    You need to create an IPv6 scope on Server1. The scope must use an address space that is reserved for private networks. The addresses must be routable.

    Which IPV6 scope prefix should you use?

    A. FF00::

    B. 2001::

    C. FD00:123:4567::

    D. FE80::
    C. FD00:123:4567::
  19. Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The domain contains three domain controllers. The domain controllers are configured as shown in the following table.

    Image Upload 32

    You discover that when you run Group Policy Results from Group Policy Management, the settings from site-linked Group Policy objects (GPOs) fail to appear in the results.

    You need to ensure that the settings from site-linked GPOs appear in the results.

    What should you do first?

    A. Run adprep on DC3 by using Windows Server 2012 R2 installation media.

    B. Transfer the infrastructure master role to DC3.

    C. Upgrade DC2 to Windows Server 2012 R2.

    D. Run adprep on DC1 by using Windows Server 2003 installation media.
    A. Run adprep on DC3 by using Windows Server 2012 R2 installation media.
  20. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2 and has the DNS Server server role installed.

    Server1 is configured to use a DNS server from an Internet Service Provider (ISP) as a forwarder. Corporate management requires that client computers only resolve names of contoso.com computers.

    You need to configure Server1 to resolve names in the contoso.com zone only.

    What should you do on Server1?

    A. From DNS Manager, modify the root hints of Server1.

    B. From Windows PowerShell, run the Remove-DnsServerForwarder cmdlet.

    C. From Windows PowerShell, run the Set-NetDnsTransitionConfiguration cmdlet.

    D. From DNS Manager, modify the Advanced properties of Server1.
    A. From DNS Manager, modify the root hints of Server1.
  21. You have a server named Server1 that runs Windows Server 2012 R2. Each day, Server1 is backed up fully to an external disk.

    On Server1, the disk that contains the operating system fails. You replace the failed disk.

    You need to perform a bare-metal recovery of Server1 by using the Windows Recovery Environment (Windows RE).

    What should you use?

    A. The Wbadmin.exe command.

    B. The Repair-bde.exe command.

    C. The Get-WBBareMetalRecovery cmdlet.

    D. The Start-WBVolumeRecovery cmdlet.
    A. The Wbadmin.exe command.
  22. Your company has a main office and a remote office. The remote office is used for disaster recovery. The network contains an Active Directory domain named contoso.com. The domain contains member servers named Server1, Server2, Server3, and Server4. All servers run WindowsServer 2012 R2.

    Server1 and Server2 are located in the main office. Server3 and Server4 are located in the remote office. All servers have the Failover Clustering feature installed. The servers are configured as nodes in a failover cluster named Cluster1. Storage is replicated between the main office and the remote site.

    You need to ensure that Cluster1 is available if two nodes in the same office fail.

    What are two possible quorum configurations that achieve the goal? (Each correct answer presents a complete solution. Choose two.)

    A. Node Majority

    B. No Majority: Disk Only

    C. Node and File Share Majority 

    D. Node and Disk Majority
    A. Node Majority

    B. No Majority: Disk Only
  23. Your network contains an Active Directory domain named contoso.com. The domain contains four servers named Server1, Server2, Server3, and Server4 that run Windows Server 2012 R2. All servers have the Hyper-V server role and the Failover Clustering feature installed.

    The servers are configured as shown in the following table.

    Image Upload 34

    Which three actions should you perform? (Each correct answer presents part of the solution.Choose three.)

    A. From Hyper-V Manager on a node in Cluster2, create three virtual machines.

    B. From Hyper-V Manager on a node in Cluster2, modify the Hyper-V settings.

    C. From Failover Cluster Manager on Cluster1, configure each virtual machine for replication.

    D. From Cluster1, add and configure the Hyper-V Replica Broker role.

    E. From Cluster2, add and configure the Hyper-V Replica Broker role.
    A. From Hyper-V Manager on a node in Cluster2, create three virtual machines.

    C. From Failover Cluster Manager on Cluster1, configure each virtual machine for replication.

    E. From Cluster2, add and configure the Hyper-V Replica Broker role.

    Explanation:

    A: Need to have same number of replicated VMs in the replicated site. 

    C: Once the hosting server is configured for Replica, you can enable replication for each virtual machine that you want to be replicated. 

    E: The Hyper-V Replica Broker is placed in the replicated cluster

    Note: * Each node of the failover cluster that is involved in Replica must have the Hyper-V server role installed. 

    * Windows Server 2012 R2 Hyper-V Replica is a built-in mechanism for replicating Virtual Machines (VMs). It can replicate selected VMs in real-time or asynchronously from a primary site to a designated replica site across LAN/WAN. Here a replica site hosts a replicated VM while an associated primary site is where the source VM runs.

    And either a replica site or a primary site can be a Windows Server 2012 R2 Hyper-V host or a Windows Server 2012 R2 Failover Cluster.
  24. You have a server named Server1 that runs Windows Server 2012 R2. You download and install the Windows Azure Online Backup Service Agent on Server1.

    You need to ensure that you can configure an online backup from Windows Server Backup.

    What should you do first?

    A. From Windows Server Backup, run the Register Server Wizard.

    B. From Computer Management, add the Server1 computer account to the Backup Operators group.

    C. From a command prompt, run wbadmin.exe enable backup.

    D. From the Services console, modify the Log On settings of the Windows Azure Online BackupService Agent
    A. From Windows Server Backup, run the Register Server Wizard.
  25. Your network contains an Active Directory domain named contoso.com. The domain contains a file server named Server1. The File Server Resource Manager role service is installed on Server1. All servers run Windows Server 2012 R2. A Group Policy object (GPO) named GPO1 is linked to the organizational unit (OU) that contains Server1. The following graphic shows the configured settings in GPO1.

    Image Upload 36

    Server1 contains a folder named Folder1. Folder1 is shared as Share1. You attempt to configure access-denied assistance on Server1, but the Enable access-denied assistance option cannot be selected from File Server Resource Manager.

    You need to ensure that you can configure access-denied assistance on Server1 manually by using File Server Resource Manager.

    Which two actions should you perform?

    A. Set the Enable access-denied assistance on client for all file types policy setting to Disabled for GPO1.

    B. Set the Customize message for Access Denied errors policy setting to Not Configured for GPO1.

    C. Set the Enable access-denied assistance on client for all file types policy setting to Enabled for GPO1.

    D. Set the Customize message for Access Denied errors policy setting to Enabled for GPO1.
    D. Set the Customize message for Access Denied errors policy setting to Enabled for GPO1.
  26. Your network contains an Active Directory forest named contoso.com. The forest contains two domains named contoso.com and childl.contoso.com. The domains contain three domain controllers. The domain controllers are configured as shown in the following table.

    Image Upload 38

    You need to ensure that the KDC support for claims, compound authentication, and kerberos armoring setting is enforced in the child1.contoso.com domain.

    Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

    A. Upgrade DC1 to Windows Server 2012 R2.

    B. Upgrade DC11 to Windows Server 2012 R2.

    C. Raise the domain functional level of childl.contoso.com.

    D. Raise the domain functional level of contoso.com.

    E. Raise the forest functional level of contoso.com.
    B. Upgrade DC11 to Windows Server 2012 R2.

    D. Raise the domain functional level of contoso.com.
  27. Your network contains an Active Directory domain named contoso.com. The domain contains a main office and a branch office. An Active Directory site exists for each office. All domain controllers run Windows Server 2012 R2. The domain contains two domain controllers. The domain controllers are configured as shown in the following table.

    Image Upload 40

    You add the DNS Server server role to DC2. You discover that the contoso.com DNS zone fails to replicate to DC2. You verify that the domain, schema, and configuration naming contexts replicate from DC1 to DC2.

    You need to ensure that DC2 replicates the contoso.com zone by using Active Directory replication.

    Which tool should you use?

    A. Ntdsutil

    B. DNS Manager

    C. Active Directory Users and Computers

    D. Active Directory Sites and Services
    D. Active Directory Sites and Services

    The other choice is DNS manager.
  28. Your network contains an Active Directory domain named contoso.com. The domain contains four servers named Server1, Server2, Server3, and Server4 that run Windows Server 2012 R2. All servers have the Hyper-V server role and the Failover Clustering feature installed.

    Image Upload 42

    You need to replicate virtual machines from Cluster1 to Cluster2. Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

    A. From Hyper-V Manager on a node in Cluster2, create three virtual machines.

    B. From Cluster2, add and configure the Hyper-V Replica Broker role.

    C. From Failover Cluster Manager on Cluster1, configure each virtual machine for replication.

    D. From Cluster1, add and configure the Hyper-V Replica Broker role.

    E. From Hyper-V Manager on a node in Cluster2/ modify the Hyper-V settings.
    A. From Hyper-V Manager on a node in Cluster2, create three virtual machines.

    B. From Cluster2, add and configure the Hyper-V Replica Broker role.

    C. From Failover Cluster Manager on Cluster1, configure each virtual machine for replication.
  29. Your company has a primary data center and a disaster recovery data center. The network contains an Active Directory domain named contoso.com. The domain contains a server named Server 1 that runs Windows Server 2012 R2.

    Server1 is located in the primary data center. Server1 has an enterprise root certification authority (CA) for contoso.com. You deploy another server named Server2 to the disaster recovery data center. You plan to configure Server2 as a secondary certificate revocation list (CRL) distribution point.

    You need to configure Server2 as a CRL distribution point (CDP). Which tab should you use to configure the required CDP entry?

    Image Upload 44
    Image Upload 46
  30. Your network contains two servers named Server1 and Server2 that run Windows Server 2012 R2.

    Server1 and Server2 have the Hyper-V server role installed. Server1 and Server2 are configured as Hyper-V replicas of each other. Server2 hosts a virtual machine named VM5. VM5 is replicated to Server1.

    You need to verify whether the replica of VM5 on Server1 is functional. The solution must ensure that VM5 remains accessible to clients.

    What should you do from Hyper-V Manager?

    A. On Server1, execute a Planned Failover.

    B. On Server1, execute a Test Failover.

    C. On Server2, execute a Planned Failover.

    D. On Server2, execute a Test Failover.
    B. On Server1, execute a Test Failover.
  31. Your network contains an Active Directory domain named adatum.com. The domain contains two sites named Site1 and Site2 and two domain controllers named DC1 and DC2.

    DC1 is located in Site1 and DC2 is located in Site2.

    You install an additional domain controller named DC3 in Site1 and you ship DC3 to Site2. A technician connects DC3 to Site2. You discover that users in Site2 are authenticated only by DC2.

    You need to ensure that the users in Site2 are authenticated by both DC2 and DC3.

    What should you do?

    A. In Active Directory Users and Computers, configure the msDS-PrimaryComputer attribute forDC3.

    B. In Active Directory Users and Computers, configure the msDS-Site-Affinity attribute for DC3.

    C. From Active Directory Sites and Services, move DC3.

    D. From Active Directory Sites and Services, modify the site link between Site1 and Site2

    .
    C. From Active Directory Sites and Services, move DC3.
  32. Your network contains an Active Directory domain named contoso.com. The domain contains a file server named Server1 that runs Windows Server 2012 R2. All client computers run Windows 8.

    You need to configure a custom Access Denied message that will be displayed to users when they are denied access to folders or files on Server1.

    What should you configure?

    A. A classification property.

    B. The File Server Resource Manager Options.

    C. A file management task.

    D. A file screen template.
    B. The File Server Resource Manager Options.
  33. You have a file server named Server1 that runs a Server Core Installation of Windows Server 2012R2.

    Server1 has a volume named D that contains user data. Server1 has a volume named E that is empty. Server1 is configured to create a shadow copy of volume D every hour.

    You need to configure the shadow copies of volume D to be stored on volume E.

    What should you run?

    A. The Set-Volume cmdlet with the -driveletter parameter.

    B. The Set-Volume cmdlet with the -path parameter.

    C. The vssadmin.exe add shadowstorage command.

    D. The vssadmin.exe create shadow command.
    C. The vssadmin.exe add shadowstorage command.
  34. You have a server named Server1 that runs Windows Server 2012 R2. Server1 is backed up by using Windows Server Backup. The backup configuration is shown in the exhibit.

    Image Upload 48

    You discover that only the last copy of the backup is maintained.

    You need to ensure that multiple backup copies are maintained. What should you do?

    A. Modify the backup destination.

    B. Configure the Optimize Backup Performance settings.

    C. Modify the Volume Shadow Copy Service (VSS) settings.

    D. Modify the backup times.
    A. Modify the backup destination.
  35. Your network contains an Active Directory forest named contoso.com. All servers run WindowsServer 2012 R2. The domain contains four servers. The servers are configured as shown in the following table.

    Image Upload 50

    You need to deploy IP Address Management (IPAM) to manage DNS and DHCP. On which server should you install IPAM?

    A. DC1

    B. DC2

    C. DC3

    D. Server1
    D. Server1
  36. You have a server named Server1 that runs Windows Server 2012 R2. The storage on Server1 is configured as shown in the following table.

    Image Upload 52

    You plan to implement Data Deduplication on Server1.

    You need to identify on which drives you can enable Data Deduplication.

    Which three drives should you identify? (Each correct answer presents part of the solution. Choose two.)

    A. C

    B. D

    C. E

    D. F

    E. G
    B. D

    D. F

    E. G
  37. You have a server named Server1 that runs Windows Server 2012 R2. Server1 is located in the perimeter network and has the DNS Server server role installed. Server1 has a zone named contoso.com.

    You App1y a security template to Server1. After you App1y the template, users report that they can no longer resolve names from contoso.com. On Server1, you open DNSManager as shown in the DNS exhibit.

    Image Upload 54

    On Server1, you open Windows Firewall with Advanced Security as shown in the Firewall exhibit.

    Image Upload 56

    You need to ensure that users can resolve contoso.com names. What should you do?

    A. From Windows Firewall with Advanced Security, disable the DNS (TCP, Incoming) rule and theDNS (UDP, Incoming) rule.

    B. From DNS Manager, modify the Zone Transfers settings of the contoso.com zone.

    C. From DNS Manager, unsign the contoso.com zone.

    D. From DNS Manager, modify the Start of Authority (SOA) of the contoso.com zone.

    E. From Windows Firewall with Advanced Security, modify the profiles of the DNS (TCP,Incoming) rule and the DNS (UDP, Incoming) rule.
    E. From Windows Firewall with Advanced Security, modify the profiles of the DNS (TCP,Incoming) rule and the DNS (UDP, Incoming) rule
  38. Your network contains an Active Directory domain named corp.contoso.com. You deploy Active Directory Rights Management Services (AD RMS).

    You have a rights policy template named Template1. Revocation is disabled for the template. A user named User1 can open content that is protected by Template1 while the user is connected to the corporate network. When User1 is disconnected from the corporate network, the user cannot open the protected content even if the user previously opened the content.

    You need to ensure that the content protected by Template1 can be opened by users who are disconnected from the corporate network.

    What should you modify?

    A. The User Rights settings of Template1.

    B. The templates file location of the AD RMS cluster.

    C. The Extended Policy settings of Template1.

    D. The exclusion policies of the AD RMS cluster.
    C. The Extended Policy settings of Template1.
  39. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2 and has the DHCP Server server role installed.

    You need to create an IPv6 scope on Server1. The scope must use an address space that is reserved for private networks. The addresses must be routable.

    Which IPV6 scope prefix should you use?

    A. FF00::

    B. FE80:123:4567::

    C. FD00:123:4567::

    D. FF00:123:4567:890A::
    C. FD00:123:4567::
  40. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Active Directory Federation Services server role installed.

    You need to make configuration changes to the Windows Token-based Agent role service.

    Which tool should you use? To answer, select the appropriate tool in the answer area

    Image Upload 58
    Image Upload 60
  41. Your network contains an Active Directory domain named contoso.com. The domain contains two member servers named Server1 and Server2. All servers run Windows Server 2012 R2. Server1 and Server2 have the Hyper-V server role installed. The servers are configured as shown in the following table.

    Image Upload 62

    You add a third server named Server3 to the network. Server3 has Intel processors.

    You need to move VM3 and VM6 to Server3. The solution must minimize downtime on the virtual machines.

    Which method should you use to move each virtual machine? To answer, select the appropriate method for each virtual machine in the answer area.

    Image Upload 64
    Image Upload 66
  42. Your network contains an Active Directory domain named contoso.com. The domain contains two DHCP servers named DHCP1 and DHCP2 that run Windows Server 2012 R2. You install the IP Address Management (IPAM) Server feature on a member server named Server1 and you run theRun Invoke-IpamGpoProvisioning cmdlet.

    You need to manage the DHCP servers by using IPAM on Server1.

    Which three actions should you perform?

    Image Upload 68
    • Image Upload 70
    • Provision the IPAM server
    • Set the manageability status of the server
    • Configure server discovery
  43. Your network contains an Active Directory domain named contoso.com. The domain contains two member servers named Server1 and Server2. All servers run Windows Server 2012 R2. Server1 and Server2 have the Hyper-V server role and the Failover Clustering feature installed.

    Server1 and Server2 are members of a cluster named Cluster1. Cluster1 hosts 10 virtual machines. When you try to migrate a running virtual machine from one server to another, you receive the following error message:

    "There was an error checking for virtual machine compatibility on the target node."

    You need to ensure that the virtual machines can be migrated from one node to another.

    From which node should you perform the configuration?

    Image Upload 72
    Image Upload 74
  44. You have 20 servers that run Windows Server 2012 R2.

    You need to create a Windows PowerShell script that registers each server in Windows Azure Online Backup and sets an encryption pass phrase.

    Which two PowerShell cmdlets should you run in the script? (Each correct answer presents part of the solution. Choose two.)

    A. New-OBPolicy

    B. New-OBRetentionPolicy

    C. Add-OBFileSpec

    D. Start-OBRegistration

    E. Set OBMachineSetting
    D. Start-OBRegistration

    E. Set OBMachineSetting
  45. Your network contains an Active Directory domain named contoso.com. The domain contains a main office and a branch office. An Active Directory site exists for each office. All domain controllers run Windows Server 2012 R2. The domain contains two domain controllers. The domain controllers are configured as shown in the following table.

    Image Upload 76

    DC1 hosts an Active Directory-integrated zone for contoso.com. You add the DNS Server server role to DC2. You discover that the contoso.com DNS zone fails to replicate to DC2. You verify that the domain, schema, and configuration naming contexts replicate from DC1 to DC2.

    You need to ensure that DC2 replicates the contoso.com zone by using Active Directory replication.

    Which tool should you use?

    A. Repadmin

    B. Dnscmd

    C. Dnslint

    D. DNS Manager
    A. Repadmin

    NOTE: If you see question about AD Replication,

    First preference is AD Sites and Services,

    then Repadmin

    and then DNSLINT.
  46. Your company recently deployed a new Active Directory forest named contoso.com. The forest contains two Active Directory sites named Site1 and Site2. The first domain controller in the forest runs Windows Server 2012 R2.

    You need to force the replication of the SYSVOL folder from Site1 to Site2. Which tool should you use?

    A. Active Directory Sites and Services

    B. DFS Management

    C. Repadmin

    D. Dfsrdiag
    D. Dfsrdiag
Author
BlackWidow
ID
288774
Card Set
412 Exam prep set 3
Description
412 Exam prep set 3
Updated