New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 11-20

Ensurepass

QUESTION 11

Your network contains an Active Directory domain named contoso.com. The domain contains a

main office and a branch office. An Active Directory site exists for each office. All domain

controllers run Windows Server 2012 R2. The domain contains two domain controllers. The

domain controllers are configured as shown in the following table.

 

70-412-demo-7

 

DC1 hosts an Active Directory-integrated zone for contoso.com. You add the DNS Server server

role to DC2. You discover that the contoso.com DNS zone fails to replicate to DC2. You verify that

the domain, schema, and configuration naming contexts replicate from DC1 to DC2. You need to

ensure that DC2 replicates the contoso.com zone by using Active Directory replication. Which

tool should you use?

 

  1. Active Directory Sites and Services

  2. Ntdsutil

  3. DNS Manager

  4. Active Directory Domains and Trusts

 

Correct Answer: A

 

 

QUESTION 12

Your network contains an Active Directory forest. The forest contains two domains named

contoso.com and fabrikam.com. The functional level of the forest is Windows Server 2003. The

contoso.com domain contains domain controllers that run either Windows Server 2008 or

Windows Server 2008 R2. The functional level of the domain is Windows Server 2008. The

fabrikam.com domain contains domain controllers that run either Windows Server 2003 or

Windows Server 2008. The functional level of the domain is Windows Server 2003. The

contoso.com domain contains a member server named Server1 that runs Windows Server 2012

R2. You install the Active Directory Domain Services server role on Server1. You need to add

Server1 as a new domain controller in the contoso.com domain. What should you do?

 

  1. Run the Active Directory Domain Services Configuration Wizard.

  2. Run adprep.exe /domainprep, and then run dcpromo.exe.

  3. Raise the functional level of the forest, and then run dcprorno.exe.

  4. Modify the Computer Name/Domain Changes properties.

 

Correct Answer: A

 

 

QUESTION 13

Your network contains an Active Directory forest. The forest contains two domains named

contoso.com and fabrikam.com. The forest functional level is Windows 2000. The contoso.com

domain contains domain controllers that run either Windows Server 2008 or Windows Server

2008 R2. The domain functional level is Windows Server 2008. The fabrikam.com domain

contains domain controllers that run either Windows 2000 Server or Windows Server 2003. The

domain functional level is Windows 2000 native. The contoso.com domain contains a member

server named Server1 that runs Windows Server 2012 R2. You need to add Server1 as a new

domain controller in the contoso.com domain. What should you do first?

 

  1. Raise the functional level of the contoso.com domain to Windows Server 2008 R2.

  2. Upgrade the domain controllers that run Windows Server 2008 to Windows Server 2008 R2.

  3. Raise the functional level of the fabrikam.com domain to Windows Server 2003.

  4. Decommission the domain controllers that run Windows 2000.

  5. Raise the forest functional level to Windows Server 2003.

 

Correct Answer: D

 

 

 

QUESTION 14

Your network contains an Active Directory domain named adatum.com. The domain contains two

domain controllers that run Windows Server 2012 R2. The domain controllers are configured as

shown in the following table.

 

70-412-demo-8

 

You log on to DC1 by using a user account that is a member of the Domain Admins group, and

then you create a new user account named User1. You need to prepopulate the password for

User1 on DC2. What should you do first?

 

  1. Connect to DC2 from Active Directory Users and Computers.

  2. Add DC2 to the Allowed RODC Password Replication Policy group.

  3. Add the User1 account to the Allowed RODC Password Replication Policy group.

  4. Run Active Directory Users and Computers as a member of the Enterprise Admins group.

 

Correct Answer: C

 

 

QUESTION 15

Your company has offices in Montreal, New York, and Amsterdam. The network contains an

Active Directory forest named contoso.com. An Active Directory site exists for each office. All of

the sites connect to each other by using the DEFAULTIPSITE1INK site link. You need to ensure that

only between 20:00 and 08:00, the domain controllers in the Montreal office replicate the Active

Directory changes to the domain controllers in the Amsterdam office. The solution must ensure

that the domain controllers in the Montreal and the New York offices can replicate the Active

Directory changes any time of day. What should you do?

 

  1. Create a new site link that contains Montreal and Amsterdam. Remove Amsterdam from

DEFAULTIPSITE1INK. Modify the schedule of DEFAULTIPSITE1INK.

  1. Create a new site link that contains Montreal and Amsterdam. Create a new site link bridge.

Modify the schedule of DEFAU LTIPSITE1INK.

  1. Create a new site link that contains Montreal and Amsterdam. Remove Amsterdam from

DEFAULTIPSITE1INK. Modify the schedule of the new site link.

  1. Create a new site link that contains Montreal and Amsterdam. Create a new site link bridge.

Modify the schedule of the new site link.

 

Correct Answer: C

 

 

 

QUESTION 16

Your network contains two Active Directory forests named contoso.com and adatum.com. A

two-way forest trust exists between the forests. The contoso.com forest contains an enterprise

certification authority (CA) named Server1. You implement cross-forest certificate enrollment

between the contoso.com forest and the adatum.com forest. On Server1, you create a new

certificate template named Template1. You need to ensure that users in the adatum.com forest

can request certificates that are based on Template1. Which tool should you use?

 

  1. DumpADO.ps1

  2. Repadmin

  3. Add-CATemplate

  4. Certutil

  5. PKISync.ps1

 

Correct Answer: E

 

 

QUESTION 17

Your network contains an Active Directory domain named adatum.com. The domain contains

four servers. The servers are configured as shown in the following table.

 

70-412-demo-9

 

You plan to deploy an enterprise certification authority (CA) on a server named Server5. Server5

will be used to issue certificates to domain-joined computers and workgroup computers. You

need to identify which server you must use as the certificate revocation list (CRL) distribution

point for Server5. Which server should you identify?

 

  1. Server3

  2. Server2

  3. Server4

  4. Server1

 

Correct Answer: C

 

 

 

QUESTION 18

You have a server named Server1 that has the Active Directory Certificate Services server role

installed. Server1 uses a hardware security module (HSM) to protect the private key of Server1.

You need to ensure that the Active Directory Certificate Services (AD CS) database, log files, and

private key are backed up. You perform regular backups of the HSM module by using a backup

utility provided by the HSM manufacturer. What else should you do?

 

  1. Run the certutil.exe command and specify the -backupkey parameter.

  2. Run the certutil.exe command and specify the -backupdb parameter.

  3. Run the certutil.exe command and specify the -backup parameter.

  4. Run the certutil.exe command and specify the -dump parameter.

 

Correct Answer: B

 

 

QUESTION 19

HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs Windows Server 2012 R2. Server1 has the Active Directory

Federation Services (AD FS) server role installed. Adatum.com is a partner organization. You are

helping the administrator of adatum.com set up a federated trust between adatum.com and

contoso.com. The administrator of adatum.com asks you to provide a file containing the

federation metadata of contoso.com. You need to identify the location of the federation

metadata file. Which node in the AD FS console should you select?

 

To answer, select the appropriate node in the answer area.

 

Hot Area:

70-412-demo-10

 

Correct Answer:

70-412-demo-11

 

 

QUESTION 20

Your network contains three Active Directory forests. Each forest contains an Active Directory

Rights Management Services (AD RMS) root cluster. All of the users in all of the forests must be

able to access protected content from any of the forests. You need to identify the minimum

number of AD RMS trusts required. How many trusts should you identify?

 

  1. 2

  2. 3

  3. 4

  4. 6

 

Correct Answer: D

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo