New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 201-210

Ensurepass

QUESTION 201

Your network contains an Active Directory forest named contoso.com. The forest contains a

single domain. The domain contains three domain controllers. The domain controllers are

configured as shown in the following table.

 

70-412-demo-156

 

You plan to test an App1ication on a server named Server1. Server1 is currently located in Site1.

After the test, Server1 will be moved to Site2. You need to ensure that Server1 attempts to

authenticate to DC3 first, while you test the App1ication. What should you do?

  1. Modify the priority of site-specific service location (SRV) DNS records for Site2.

  2. Modify the weight of site-specific service location (SRV) DNS records Site1.

  3. Modify the registry on Server1.

  4. Create a new site and associate the site to an existing site link object.

 

Correct Answer: A

 

 

QUESTION 202

Your network contains an Active Directory domain named contoso.com. The domain contains a

main office and a branch office. An Active Directory site exists for each office. All domain

controllers run Windows Server 2012 R2. The domain contains two domain controllers. The

domain controllers are configured as shown in the following table.

 

70-412-demo-157

 

DC1 hosts an Active Directory-integrated zone for contoso.com. You add the DNS Server server

role to DC2. You discover that the contoso.com DNS zone fails to replicate to DC2. You verify that

the domain, schema, and configuration naming contexts replicate from DC1 to DC2. You need to

ensure that DC2 replicates the contoso.com zone by using Active Directory replication. Which

tool should you use?

 

  1. Active Directory Users and Computers

  2. Active Directory Sites and Services

  3. Dnscmd

  4. DNS Manager

 

Correct Answer: D

 

QUESTION 203

Your network contains an Active Directory forest. The forest contains two domains named

contoso.com and fabrikam.com. The functional level of the forest is Windows Server 2003.

You have a domain outside the forest named adatum.com.

 

You need to configure an access solution to meet the following requirements:

 

  • Users in fabrikam.com must be able to access resources in adatum.com.

  • Users in contoso.com must be prevented from accessing resources in adatum.com.

  • Users in adatum.com must be prevented from accessing resources in both fabrikam.com

and contoso.com.

 

What should you create?

 

  1. a one-way realm trust from fabrikam.com to adatum.com

  2. a one-way external trust from adatum.com to fabrikam.com

  3. a one-way external trust from fabrikam.com to adatum.com

  4. a one-way realm trust from adatum.com to fabrikam.com

 

Correct Answer: B

 

 

QUESTION 204

You deploy an Active Directory Federation Services (AD FS) 2.1 infrastructure. The infrastructure

uses Active Directory as the attribute store. Some users report that they fail to authenticate to

the AD FS infrastructure. You discover that only users who run third-party web browsers

experience issues. You need to ensure that all of the users can authenticate to the AD FS

infrastructure successfully. Which Windows PowerShell command should you run?

 

  1. Set-ADFSProperties -ProxyTrustTokenLifetime 1:00:00

  2. Set-ADFSProperties -AddProxyAuthenticationRules None

  3. Set-ADFSProperties -SSOLifetime 1:00:00

  4. Set-ADFSProperties -ExtendedProtectionTokenCheck None

 

Correct Answer: A

 

 

QUESTION 205

Your network contains an Active Directory domain named contoso.com. All servers run Windows

Server 2012 R2. The domain contains a file server named Server1. The domain contains a domain

controller named DC1. Server1 contains three shared folders. The folders are configured as

shown in the following table.

 

70-412-demo-158

 

Folder2 has a conditional expression of User.Department= = MMarketing”.

You discover that a user named User1 cannot access \Server1folder2. User1 can access

\Server1folderl and \Server1folder3.

 

You verify the group membership of User1 as shown in the Member of exhibit.

70-412-demo-159

 

You verify the organization information of User1 as shown in the Organization exhibit.

 

70-412-demo-160

 

You verify the general properties of User1 as shown in the General exhibit.

 

70-412-demo-161

 

You need to ensure that User1 can access the contents of \Server1folder2. What should you

do?

 

  1. From a Group Policy object (GPO), set the Support for Dynamic Access Control and Kerberos

armoring setting to Always provide claims.

  1. Change the department attribute of User1.

  2. Grant the Full Control NTFS permissions on Folder2 to
    User1.

  3. Remove User11from the Accounting global group.

 

Correct Answer: B

 

QUESTION 206

You have a server named Server1 that runs Windows Server 2012 R2. You install the File and

Storage Services server role on Server1. From Windows Explorer, you view the properties of a

folder named Folder1 and you discover that the Classification tab is missing. You need to ensure

that you can assign classifications to Folder1 from Windows Explorer manually. What should you

do?

 

  1. From Folder Options, clear Hide protected operating system files (Recommended).

  2. Install the File Server Resource Manager role service.

  3. From Folder Options, select the Always show menus.

  4. Install the Share and Storage Management Tools.

 

Correct Answer: B

 

 

QUESTION 207

Your network contains an Active Directory domain named contoso.com. All domain controllers

run Windows Server 2012 R2. The domain contains two domain controllers. The domain

controllers are configured as shown in the following table.

 

70-412-demo-162

 

The Branch site contains a perimeter network. For security reasons, client computers in the

perimeter network can communicate with client computers in the Branch site only. You plan to

deploy a new RODC to the perimeter network in the Branch site. You need to ensure that the

new RODC will be able to replicate from DC10. What should you do first on DC10?

 

  1. Enable the Bridge all site links setting.

  2. Run the Active Directory Domain Services Configuration Wizard.

  3. Create an Active Directory site link bridge.

  4. Create an Active Directory site.

 

Correct Answer: C

 

QUESTION 208

Your network contains an Active Directory forest named contoso.com. The forest contains a

single domain. The domain contains three domain controllers. The domain controllers are

configured as shown in the following table.

 

70-412-demo-163

 

You plan to test an App1ication on a server named Server1. Server1 is currently located in Site1.

After the test, Server1 will be moved to Site2. You need to ensure that Server1 attempts to

authenticate to DC3 first, while you test the App1ication. What should you do?

 

  1. Modify the weight of site-specific service location (SRV) DNS records Site1.

  2. Create a new subnet object and associate the subnet object to an existing site.

  3. Modify the registry on DC3.

  4. Modify the priority of site-specific service location (SRV) DNS records for Site2.

 

Correct Answer: D

 

 

QUESTION 209

Your network contains an Active Directory domain named contoso.com. The domain contains two

member servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 has

Microsoft SQL Server 2012 installed. You install the Active Directory Federation Services server

role on Server2. You need to configure Server2 as the first Active Directory Federation Services

(AD FS) server in the domain. The solution must ensure that the AD FS database is stored in a SQL

Server database on Server1. What should you do on Server2?

 

  1. From a command prompt, run fsutil.exe.

  2. From Windows PowerShell, run Install-ADFSFarm.

  3. From Server Manager, install the Federation Service Proxy.

  4. From Server Manager, install the AD FS Web Agents.

 

Correct Answer: B

 

QUESTION 210

Your network contains an Active Directory domain named contoso.com. All domain controllers

run Windows Server 2012 R2. The domain contains two domain controllers. The domain

controllers are configured as shown in the following table.

 

70-412-demo-164

 

The Branch site contains a perimeter network. For security reasons, client computers in the

perimeter network can communicate with client computers in the Branch site only. You plan to

deploy a new RODC to the perimeter network in the Branch site. You need to ensure that the

new RODC will be able to replicate from DC10. What should you do first on DC10?

 

  1. Create an Active Directory subnet.

    i>

  2. Run the Active Directory Domain Services Configuration Wizard.

  3. Run dcpromo and specify the fcreatedcaccount parameter.

  4. Run the Add-ADDSReadOnlyDomainControllerAccount cmdlet.

 

Correct Answer: D

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo