New Updated Microsoft MCSA 70-412 Real Exam Questions and Answers Download 1-10

Ensurepass

QUESTION 1

You have a DHCP server named Server1. Server1 has one network adapter. Server1 is located on a

subnet named Subnet1. Server1 has scope named Scope1. Scope1 contains IP addresses for the

192.168.1.0/24 network. Your company is migrating the IP addresses on Subnet1 to use a

network ID of 10.10.0.0/16. On Server1, you create a scope named Scope2. Scope2 contains IP

addresses for the 10.10.0.0/16 network. You need to ensure that clients on Subnet1 can receive

IP addresses from either scope. What should you create on Server1?

 

  1. A multicast scope

  2. A scope

  3. A superscope

  4. A split-scope

 

Correct Answer: C

 

 

QUESTION 2

Your network contains an Active Directory domain named adatum.com. The domain contains a

domain controller named DC1 that runs Windows Server 2012 R2. On Dc1, you open DNS

Manager as shown in the exhibit.

 

70-412-demo-2

 

You need to change the zone type of the contoso.com zone from an Active Directory-integrated

zone to a standard primary zone. What should you do before you change the zone type?

 

  1. Unsign the zone.

  2. Modify the Zone Signing Key (ZSK).

  3. Modify the Key Signing Key (KSK).

  4. Change the Key Master.

 

Correct Answer: A

 

 

QUESTION 3

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the DNS Server

server role installed. You need to configure Server1 to resolve queries for single-label DNS names.

Which two actions should you perform? (Each correct answer presents part of the solution.

Choose two.)

 

  1. Run the Set-DNSServerGlobalNameZone cmdlet.

  2. Modify the DNS suffix search list setting.

  3. Modify the Primary DNS Suffix Devolution setting.

  4. Create a zone named “.”.

  5. Create a zone named GlobalNames.

  6. Run the Set-DNSServerRootHint cmdlet.

 

Correct Answer: AE

 

 

QUESTION 4

Your network contains an Active Directory domain named contoso.com. The domain contains two

servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 has the IP Address

Management (IPAM) Server feature installed. Server2 has the DHCP Server server role installed.

A user named User1 is a member of the IPAM Users group on Server1. You need to ensure that

User1 can use IPAM to modify the DHCP scopes on Server2. The solution must minimize the

number of permissions assigned to User1. To which group should you add User1?

 

  1. DHCP Administrators on Server2.

  2. IPAM ASM Administrators on Server1.

  3. IPAMUG in Active Directory.

  4. IPAM MSM Administrators on Server1.

 

Correct Answer: A

 

 

QUESTION 5

You have a server named DC2 that runs Windows Server 2012 R2. DC2 contains a DNS zone

named adatum.com. The adatum.com zone is shown in the exhibit.

 

70-412-demo-3

 

You need to configure DNS clients to perform DNSSEC validation for the adatum.com DNS domain. What should you configure?

 

  1. The Network Location settings.

  2. A Name Resolution Policy.

  3. The DNS Client settings.

  4. The Network Connection settings.

 

Correct Answer: B

 

 

QUESTION 6

Your network contains an Active Directory domain named contoso.com. The domain contains two

servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 has the DHCP

Server server role installed. Server2 has the Hyper-V server role installed. Server2 has an IP

address of 192.168.10.50. Server1 has a scope named Scope1 for the 192.168.10.0/24 network.

You plan to deploy 20 virtual machines on Server2 that will be connected to the external network. The MAC addresses for the virtual machines will begin with 00-15-SD-83-03. You need to

configure Server1 to offer the virtual machines IP addresses from 192.168.10.200 to

192.168.10.21g. Physical computers on the network must be offered IP addresses outside this

range. You want to achieve this goal by using the minimum amount of administrative effort. What

should you do from the DHCP console?

 

  1. Create reservations.

  2. Create a policy.

  3. Delete Scope1 and create two new scopes.

  4. Configure Allow filters and Deny filters.

 

Correct Answer: B

 

 

QUESTION 7

Your network contains an Active Directory domain named contoso.com. The domain contains two

servers named Server1 and Server2. Both servers have the IP Address Management (IPAM)

Server feature installed. You have a support technician named Tech1. Tech1 is a member of the

IPAM Administrators group on Server1 and Server2. You need to ensure that Tech 1 can use

Server Manager on Server1 to manage IPAM on Server2. To which group on Server2 should you

add Tech1?

 

  1. Remote Management Users

  2. IPAM MSM Administrators

  3. IPAM Administrators

  4. WinRM Remote WM1 Users

 

Correct Answer: D

 

 

QUESTION 8

Your network contains two Active Directory forests named contoso.com and adatum.com. All of

the domain controllers in both of the forests run Windows Server 2012 R2. The adatum.com

domain contains a file server named Servers. Adatum.com has a one-way forest trust to

contoso.com. A contoso.com user name User10 attempts to access a shared folder on Servers

and receives the error message shown in the exhibit.

 

70-412-demo-4

 

You verify that the Authenticated Users group has Read permissions to the Data folder. You need

to ensure that User10 can read the contents of the Data folder on Server5 in the adatum.com

domain. What should you do?

 

  1. Grant the Other Organization group Read permissions to the Data folder.

  2. Modify the list of logon workstations of the contosoUser10 user account.

  3. Enable the Netlogon Service (NP-In) firewall rule on Server5.

  4. Modify the permissions on the Server5 computer object in Active Directory.

 

Correct Answer: D

 

 

QUESTION 9

HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains two

Active Directory sites named Site1 and Site2. You discover that when the account of a user in

Site1 is locked out, the user can still log on to the servers in Site2 for up to 15 minutes by using

Remote Desktop Services (RDS). You need to reduce the amount of time it takes to synchronize

account lockout information across the domain. Which attribute should you modify?

 

To answer, select the appropriate attribute in the answer area.

 

Hot Area:

70-412-demo-5

 

Correct Answer:

70-412-demo-6

 

 

QUESTION 10

Your network contains an Active Directory forest. The forest contains two domains named

contoso.com and fabrikam.com. The functional level of the forest is Windows Server 2003. You

have a domain outside the forest named adatum.com. You need to configure an access solution

to meet the following requirements:

 

  • Users in adatum.com must be able to access resources in contoso.com.

  • Users in adatum.com must be prevented from accessing resources in fabrikam.com.

  • Users in both contoso.com and fabrikam.com must be prevented from accessing resources

in adatum.com.

 

What should you create?

 

  1. a one-way external trust from adatum.com to fabrikam.com

  2. a one-way realm trust from fabrikam.com to adatum.com

  3. a one-way realm trust from adatum.com to fabrikam.com

  4. a one-way external trust from fabrikam.com to adatum.com

 

Correct Answer: A

 

Instant Access to Download Latest Complete Collection of Microsoft MCSA 70-412 Real Exam

Try Microsoft MCSA 70-412 Free Demo