Latest Real 70-412 Tests Dumps and VCE Exam Questions 211-220

Ensurepass

QUESTION 211

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. The domain contains two domain controllers. The domain controllers are configured as shown in the following table.

 

clip_image002

 

The Branch site contains a perimeter network. For security reasons, client computers in the perimeter network can communicate with client computers in the Branch site only. You plan to deploy a new RODC to the perimeter network in the Branch site. You need to ensure that the new RODC will be able to replicate from DC10. What should you do first on DC10?

 

A.      Run dcpromo and specify the /createdcaccount parameter.

B.      Run the Active Directory Domain Services Configuration Wizard.

C.      Run the Add-ADDSReadOnlyDomainControllerAccount cmdlet.

D.      Enable the Bridge all site links setting.

 

Correct Answer: C

 

 

QUESTION 212

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The forest contains three Active Directory sites named SiteA, SiteB, and SiteC. The sites contain four domain controllers. The domain controllers are configured as shown in the following table.

 

clip_image004

 

An IP site link exits between each site. You discover that the users in SiteC are authenticated by the domain controllers in SiteA and SiteB. You need to ensure that the SiteC users are authenticated by the domain controllers in SiteB, unless all of the domain controllers in SiteB are unavailable. What should you do?

 

A.      Create an SMTP site link between SiteB and SiteC.

B.      Decrease the cost of the site link between SiteB and SiteC.

C.      Disable site link bridging.

D.      Create additional connection objects for DC1 and DC2.

 

Correct Answer: B

 

 

QUESTION 213

Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012. The domain contains a domain controller named DC1 that is configured as an enterprise root certification authority (CA). All users in the domain are issued a smart card and are required to log on to their domain-joined client computer by using their smart card. A user named User1 resigned and started to work for a competing company. You need to prevent User1 immediately from logging on to any computer in the domain. The solution must not prevent other users from logging on to the domain. Which tool should you use?

 

A.      The Security Configuration Wizard

B.      The Certification Authority console

C.      Active Directory Administrative Center

D.      Certificate Templates

 

Correct Answer: C

 

 

QUESTION 214

You have a server named Server1 that runs Windows Server 2012. Server1 has the DNS Server server role installed. You need to store the contents of all the DNS queries received by Server1. What should you configure?

 

A.      Logging from Windows Firewall with Advanced Security

B.      Debug logging from DNS Manager

C.      A Data Collector Set (DCS) from Performance Monitor

D.      Monitoring from DNS Manager

 

Correct Answer: D

 

 

QUESTION 215

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. The domain contains two domain controllers. The domain controllers are configured as shown in the following table.

 

clip_image006

 

You configure a user named User1 as a delegated administrator of DC10. You need to ensure that User1 can log on to DC10 if the network link between the Main site and the Branch site fails. What should you do?

 

A.      On DC10, run ntdsutil and configure the settings in the Roles context.

B.      On DC10, run ntdsutil and configure the settings in the Local Roles context.

C.      Modify the properties of the DCIO computer account.

D.      Run repadmin and specify /replsingleobject parameter.

 

Correct Answer: B

 

 

QUESTION 216

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The forest contains three Active Directory sites named SiteA, SiteB, and SiteC. The sites contain four domain controllers. The domain controllers are configured as shown in the following table.

 

clip_image008

 

An IP site link exits between each site. You discover that the users in SiteC are authenticated by the domain controllers in SiteA and SiteB. You need to ensure that the SiteC users are authenticated by the domain controllers in SiteB, unless all of the domain controllers in SiteB are unavailable. What should you do?

 

A.      Create an SMTP site link between SiteB and SiteC.

B.      Crate additional connection objects for DC1 and DC2.

C.      Decrease the cost of the site link between SiteB and SiteC.

D.      Create additional connection objects for DC3 and DC4.

 

Correct Answer: C

 

 

QUESTION 217

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012. The domain contains two domain controllers. The domain controllers are configured as shown in the following table.

 

clip_image010

 

The Branch site contains a perimeter network. For security reasons, client computers in the perimeter network can communicate with client computers in the Branch site only. You plan to deploy a new RODC to the perimeter network in the Branch site. You need to ensure that the new RODC will be able to replicate from DC10. What should you do first on DC10?

 

A.      Enable the Bridge all site links setting.

B.      Create an Active Directory subnet.

C.      Run the Add-ADDSReadOnlyDomainControllerAccount cmdlet.

D.      Run the Uninstall-ADDSDomainController cmdlet.

 

Correct Answer: C

 

 

QUESTION 218

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The domain contains three domain controllers. The domain controllers are configured as shown in the following table.

 

clip_image011

 

You plan to test an Application on a server named Server1. Server1 is currently located in Site1. After the test, Server1 will be moved to Site2. You need to ensure that Server1 attempts to authenticate to DC3 first, while you test the Application. What should you do?

 

A.      Modify the priority of site-specific service location (SRV) DNS records for Site2.

B.      Modify the weight of site-specific service location (SRV) DNS records Site1.

C.      Modify the registry on Server1.

D.      Create a new site and associate the site to an existing site link object.

 

Correct Answer: A

 

 

 

QUESTION 219

Your network contains an Active Directory domain named contoso.com. The domain contains a main office and a branch office. An Active Directory site exists for each office. All domain controllers run Windows Server 2012. The domain contains two domain controllers. The domain controllers are configured as shown in the following table.

 

clip_image013

 

DC1 hosts an Active Directory-integrated zone for contoso.com. You add the DNS Server server role to DC2. You discover that the contoso.com DNS zone fails to replicate to DC2. You verify that the domain, schema, and configuration naming contexts replicate from DC1 to DC2. You need to ensure that DC2 replicates the contoso.com zone by using Active Directory replication. Which tool should you use?

 

A.      Active Directory Users and Computers

B.      Active Directory Sites and Services

C.      Dnscmd

D.      DNS Manager

 

Correct Answer: B

 

 

QUESTION 220

Your network contains an Active Directory forest. The forest contains two domains named contoso.com and fabrikam.com. The functional level of the forest is Windows Server 2003. You have a domain outside the forest named adatum.com.

 

You need to configure an access solution to meet the following requirements:

 

Ÿ   Users in fabrikam.com must be able to access resources in adatum.com.

Ÿ   Users in contoso.com must be prevented from accessing resources in adatum.com.

Ÿ   Users in adatum.com must be prevented from accessing resources in both fabrikam.com and contoso.com.

 

What should you create?

 

A.      a one-way realm trust from fabrikam.com to adatum.com

B.      a one-way external trust from adatum.com to fabrikam.com

C.      a one-way external trust from fabrikam.com to adatum.com

D.      a one-way realm trust from adatum.com to fabrikam.com

 

Correct Answer: B