Latest Real 70-412 Tests Dumps and VCE Exam Questions 101-110

Ensurepass

QUESTION 101

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012. DC1 has the DNS Server role installed. The network contains client computers that run either Linux, Windows 7, or Windows 8. You have a standard primary zone named adatum.com as shown in the exhibit.

clip_image001

You plan to configure Name Protection on all of the DHCP servers. You need to configure the adatum.com zone to support Name Protection. Which two configurations should you perform from DNS Manager? (Each correct answer presents part of the solution. Choose two.)

 

A.      Sign the zone.

B.      Store the zone in Active Directory.

C.      Modify the Security settings of the zone.

D.      Configure Dynamic updates.

 

Correct Answer: BD

 

 

QUESTION 102

Your network contains two servers named Server1 and Server2 that run Windows Server 2012. Server1 and Server2 have the Hyper-V server role installed. Server1 and Server2 are configured as Hyper-V replicas of each other. Server1 hosts a virtual machine named VM1. VM1 is replicated to Server2. You need to verify whether the replica of VM1 on Server2 is functional. The solution must ensure that VM1 remains accessible to clients. What should you do from Hyper-V Manager?

 

A.      On Server1, execute a Planned Failover.

B.      On Server1, execute a Test Failover.

C.      On Server2, execute a Planned Failover.

D.      On Server2, execute a Test Failover.

 

Correct Answer: D

 

 

QUESTION 103

You have a failover cluster named Cluster1 that contains four nodes. All of the nodes run Windows Server 2012. You need to force every node in Cluster1 to contact immediately the Windows Server Update Services (WSUS) server on your network for updates. Which tool should you use?

 

A.      The Add-CauClusterRole cmdlet

B.      The Wuauclt command

C.      The Wusa command

D.      The Invoke-CauScan cmdlet

 

Correct Answer: D

 

 

QUESTION 104

Your network contains an Active Directory domain named contoso.com. The network contains a file server named Server1 that runs Windows Server 2012. You are configuring a central access policy for temporary employees. You enable the Department resource property and assign the property a suggested value of Temp. You need to configure a target resource condition for the central access rule that is scoped to resources assigned to Temp only. Which condition should you use?

 

A.      (Temp.Resource Equals “Department”)

B.      (Resource.Temp Equals “Department”)

C.      (Resource.Department Equals “Temp”)

D.      (Department.Value Equals “Temp”)

 

Correct Answer: C

 

 

QUESTION 105

Your network contains a server named Server1 that runs Windows Server 2012. Server1 has the Active Directory Certificate Services server role installed and is configured as a standalone certification authority (CA). You install a second server named Server2. You install the Online Responder role service on Server2. You need to ensure that Server1 can issue an Online Certificate Status Protocol (OCSP) Response Signing certificate to Server2. What should you do?

 

A.        On Server1, run the certutil.exe command and specify the -setreg parameter.

B.        On Server2, run the certutil.exe command and specify the -policy parameter.

C.        On Server1, configure Security for the OCSP Response Signing certificate template.

D.        On Server2, configure Issuance Requirements for the OCSP Response Signing certificate template.

 

Correct Answer: C

 

 

QUESTION 106

Your network contains an Active Directory domain named adatum.com. The domain contains a server named CA1 that runs Windows Server 2012. CA1 has the Active Directory Certificate Services server role installed and is configured to support key archival and recovery. You need to ensure that a user named User1 can decrypt private keys archived in the Active Directory Certificate Services (AD CS) database. The solution must prevent User1 from retrieving the private keys from the AD CS database. What should you do?

 

A.      Assign User1 the Issue and Manage Certificates permission to Server1.

B.      Assign User1 the Read permission and the Write permission to all certificate templates.

C.      Provide User1 with access to a Key Recovery Agent certificate and a private key.

D.      Assign User1 the Manage CA permission to Server1.

Correct Answer: C

 

 

QUESTION 107

Your network contains an Active Directory domain named contoso.com. The domain contains two sites named Site1 and Site2 and two domain controllers named DC1 and DC2. Both domain controllers are located in Site1. You install an additional domain controller named DC3 in Site1 and you ship DC3 to Site2. A technician connects DC3 to Site2. You discover that users in Site2 are authenticated by all three domain controllers. You need to ensure that the users in Site2 are authenticated by DC1 or DC2 only if DC3 is unavailable. What should you do?

 

A.      From Network Connections, modify the IP address of DC3.

B.      In Active Directory Sites and Services, modify the Query Policy of DC3.

C.      From Active Directory Sites and Services, move DC3.

D.      In Active Directory Users and Computers, configure the msDS-PrimaryComputer attribute for the users in Site2.

 

Correct Answer: C

 

 

QUESTION 108

Your network contains two Active Directory forests named contoso.com and adatum.com. Contoso.com contains one domain.

 

Adatum.com contains a child domain named child.adatum.com.

 

Contoso.com has a one-way forest trust to adatum.com. Selective authentication is enabled on the forest trust. Several user accounts are migrated from child.adatum.com to adatum.com. Users report that after the migration, they fail to access resources in contoso.com. The users successfully accessed the resources in contoso.com before the accounts were migrated. You need to ensure that the migrated users can access the resources in contoso.com. What should you do?

 

A.      Replace the existing forest trust with an external trust.

B.      Run netdom and specify the /quarantine attribute.

C.      Disable SID filtering on the existing forest trust.

D.      Disable selective authentication on the existing forest trust.

 

Correct Answer: C

 

 

QUESTION 109

You have four servers that run Windows Server 2012. The servers have the Failover Clustering feature installed. You deploy a new cluster named Cluster1. Cluster1 is configured as shown in the following table.

 

clip_image002

 

Site2 is a disaster recovery site. Server1, Server2, and Server3 are configured as the preferred owners of the cluster roles. Dynamic quorum management is disabled. You plan to perform hardware maintenance on Server3. You need to ensure that if the WAN link between Site1 and Site2 fails while you are performing maintenance on Server3, the cluster resource will remain available in Site1. What should you do?

 

A.      Enable dynamic quorum management.

B.      Remove the node vote for Server3.

C.      Add a file share witness in Site1.

D.      Remove the node vote for Server4 and Server5.

 

Correct Answer: D

 

 

QUESTION 110

You have a test server named Server1 that is configured to dual-boot between Windows Server 2008 R2 and Windows Server 2012. You start Server1 and you discover that the boot entry for Windows Server 2008 R2 no longer appears on the boot menu. You start Windows Server 2012 on Server1 and you discover the disk configurations shown in the following table.

 

clip_image003

 

You need to restore the Windows Server 2008 R2 boot entry on Server1. What should you do?

 

A.      Run bcdedit.exe and specify the /createstore parameter.

B.      Run bootrec.exe and specify the /scanos parameter.

C.      Run bcdboot.exe d:windows.

D.      Run bootrec.exe and specify the /rebuildbcd parameter.

 

Correct Answer: D