Warning: preg_replace_callback(): Requires argument 2, 'Array', to be a valid callback in /home/dump4cer/public_html/guide4certs/Core/Common/Funs.php on line 181
 70-412 Exam | 70-412 PDF | 70-412 VCE | 70-412 - Study Guide | 70-412 Braindumps | Microsoft Exam Dumps - Guide4Certs

70-412 Exam

Configuring Advanced Windows Server 2012 Services

  • Exam Number/Code : 70-412
  • Exam Name : Configuring Advanced Windows Server 2012 Services
  • Questions and Answers : 274 Q&As
  • Update Time: 2017-09-17
  • Price: $ 99.00 $ 39.00

What Guide4Certs Offer for Microsoft 70-412

We provide 70-412 questions with answers for passing your Microsoft Microsoft Windows Server 70-412 exam (Configuring Advanced Windows Server 2012 Services ) quickly with 90 days free updates and money back guarantee if you fail in exam unfortunately. Please see the guarantee page on top manu for more details.

 

Exam Description or Exam Demo

QUESTION NO: 1

You have a DHCP server named Server1. Server1 has one network adapter. Server1 is located

on a subnet named Subnet1. Server1 has scope named Scope1. Scope1 contains IP addresses

for the 192.168.1.0/24 network.

Your company is migrating the IP addresses on Subnet1 to use a network ID of 10.10.0.0/16.

On Server1, you create a scope named Scope2. Scope2 contains IP addresses for the

10.10.0.0/16 network.

You need to ensure that clients on Subnet1 can receive IP addresses from either scope.

What should you create on Server1?

A. A multicast scope

B. A scope

C. A superscope

D. A split-scope

Answer: C

Explanation:

http://technet.microsoft.com/en-us/library/dd759168.aspx

QUESTION NO: 2

Your network contains an Active Directory domain named adatum.com. The domain contains a

domain controller named DC1 that runs Windows Server 2012.

On Dc1, you open DNS Manager as shown in the exhibit. (Click the Exhibit button.)

You need to change the zone type of the contoso.com zone from an Active Directory-integrated

zone to a standard primary zone.

What should you do before you change the zone type?

A. Unsign the zone.

B. Modify the Zone Signing Key (ZSK).

C. Modify the Key Signing Key (KSK).

D. Change the Key Master.

Answer: A

Explanation:

QUESTION NO: 3

You have a server named Server1 that runs Windows Server 2012. Server1 has the DNS Server

server role installed.

You need to configure Server1 to resolve queries for single-label DNS names.

Which two actions should you perform? (Each correct answer presents part of the solution.

Choose two.)

A. Run the Set-DNSServerGlobalNameZone cmdlet.

B. Modify the DNS suffix search list setting.

C. Modify the Primary DNS Suffix Devolution setting.

D. Create a zone named “.”.

E. Create a zone named GlobalNames.

F. Run the Set-DNSServerRootHint cmdlet.

Answer: E,F

Explanation:

Open DNS Manager from Administrative Tools. Expend the DNS server, right-click “Forward

Lookup Zones”, and choose “New Zone”

Click Next

Choose “Primary zone” (Store zone in Active Directory), click Next

Choose the Active Directory Zone Replication Scope. Click Next

On Zone Name, screen, enter “GlobalNames”, click Next

On Dynamic Update screen, choose “Do not allow dynamic updates”, click Next

Click Finish

QUESTION NO: 4

Your network contains an Active Directory domain named contoso.com. The domain contains two

servers named Server1 and Server2 that run Windows Server 2012. Server1 has the IP Address

Management (IPAM) Server feature installed. Server2 has the DHCP Server server role installed.

A user named User1 is a member of the IPAM Users group on Server1.

You need to ensure that User1 can use IPAM to modify the DHCP scopes on Server2. The

solution must minimize the number of permissions assigned to User1.

To which group should you add User1?

A. DHCP Administrators on Server2

B. IPAM ASM Administrators on Server1

C. IPAMUG in Active Directory

D. IPAM MSM Administrators on Server1

Answer: A

Explanation:

QUESTION NO: 5

You have a server named DC2 that runs Windows Server 2012. DC2 contains a DNS zone named

adatum.com.

The adatum.com zone is shown in the exhibit. (Click the Exhibit button.)

You need to configure DNS clients to perform DNSSEC validation for the adatum.com DNS

domain.

What should you configure?

A. The Network Location settings

B. A Name Resolution Policy

C. The DNS Client settings

D. The Network Connection settings

Answer: B

Explanation:

http://technet.microsoft.com/en-us/library/hh831411.aspx#config_client1

QUESTION NO: 6

Your network contains an Active Directory domain named contoso.com. The domain contains two

servers named Server1 and Server2 that run Windows Server 2012. Server1 has the DHCP

Server server role installed. Server2 has the Hyper-V server role installed. Server2 has an IP

address of 192.168.10.50.

Server1 has a scope named Scope1 for the 192.168.10.0/24 network.

You plan to deploy 20 virtual machines on Server2 that will be connected to the external network.

The MAC addresses for the virtual machines will begin with 00-15-SD-83-03.

You need to configure Server1 to offer the virtual machines IP addresses from 192.168.10.200 to

192.168.10.21g. Physical computers on the network must be offered IP addresses outside this

range. You want to achieve this goal by using the minimum amount of administrative effort.

What should you do from the DHCP console?

A. Create reservations.

B. Create a policy.

C. Delete Scope1 and create two new scopes.

D. Configure Allow filters and Deny filters.

Answer: B

Explanation:

http://blogs.technet.com/b/teamdhcp/archive/2012/08/22/granular-dhcp-server-administrationusing-

dhcppolicies-in-windows-server-2012.aspx

QUESTION NO: 7

Your network contains an Active Directory domain named contoso.com. The domain contains two

servers named Server1 and Server2. Both servers have the IP Address Management (IPAM)

Server feature installed.

You have a support technician named Tech1. Tech1 is a member of the IPAM Administrators

group on Server1 and Server2.

You need to ensure that Tech 1 can use Server Manager on Server1 to manage IPAM on Server2.

To which group on Server2 should you add Tech1.

A. Remote Management Users

B. IPAM MSM Administrators

C. IPAM Administrators

D. WinRM Remote WM1 Users

Answer: D

Explanation:

QUESTION NO: 8

Your network contains two Active Directory forests named contoso.com and adatum.com. All of

the domain controllers in both of the forests run Windows Server 2012. The adatum.com domain

contains a file server named Servers.

Adatum.com has a one-way forest trust to contoso.com.

A contoso.com user name User10 attempts to access a shared folder on Servers and receives the

error message shown in the exhibit. (Click the Exhibit button.)

You verify that the Authenticated Users group has Read permissions to the Data folder.

You need to ensure that User10 can read the contents of the Data folder on Server5 in the

adatum.com domain.

What should you do?

A. Grant the Other Organization group Read permissions to the Data folder.

B. Modify the list of logon workstations of the contosoUser10 user account.

C. Enable the Netlogon Service (NP-In) firewall rule on Server5.

D. Modify the permissions on the Server5 computer object in Active Directory.

Answer: D

Explanation:

To resolve the issue, I had to open up AD Users and Computers --> enable Advanced Features --

> Select the Computer Object --> Properties --> Security --> Add the Group I want to allow access

to the computer (in this case, DomainADomain users) and allow "Allowed to Authenticate". Once I

did that, everything worked:

QUESTION NO: 9 HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains two

Active Directory sites named Site1 and Site2.

You discover that when the account of a user in Site1 is locked out, the user can still log on to the

servers in Site2 for up to 15 minutes by using Remote Desktop Services (RDS).

You need to reduce the amount of time it takes to synchronize account lockout information across

the domain.

Which attribute should you modify?

To answer, select the appropriate attribute in the answer area.

Answer:

Explanation:

QUESTION NO: 10

Your network contains an Active Directory forest. The forest contains two domains named

contoso.com and fabrikam.com. The functional level of the forest is Windows Server 2003.

You have a domain outside the forest named adatum.com.

You need to configure an access solution to meet the following requirements:

-

-

-

Users in adatum.com must be able to access resources in contoso.com.

Users in adatum.com must be prevented from accessing resources in fabrikam.com.

Users in both contoso.com and fabrikam.com must be prevented from accessing resources in

adatum.com.

What should you create?

A. a one-way external trust from adatum.com to fabrikam.com

B. a one-way realm trust from fabrikam.com to adatum.com

C. a one-way realm trust from adatum.com to fabrikam.com

D. a one-way external trust from fabrikam.com to adatum.com

Answer: A

Explanation:

QUESTION NO: 11

Your network contains an Active Directory domain named contoso.com. The domain contains a

main office and a branch office. An Active Directory site exists for each office.

All domain controllers run Windows Server 2012. The domain contains two domain controllers.

The domain controllers are configured as shown in the following table.

DC1 hosts an Active Directory-integrated zone for contoso.com.

You add the DNS Server server role to DC2.

You discover that the contoso.com DNS zone fails to replicate to DC2.

You verify that the domain, schema, and configuration naming contexts replicate from DC1 to

DC2.

You need to ensure that DC2 replicates the contoso.com zone by using Active Directory

replication.

Which tool should you use?

A. Active Directory Sites and Services

B. Ntdsutil

C. DNS Manager

D. Active Directory Domains and Trusts

Answer: A

Explanation:

QUESTION NO: 12

Your network contains an Active Directory forest. The forest contains two domains named

contoso.com and fabrikam.com. The functional level of the forest is Windows Server 2003.

The contoso.com domain contains domain controllers that run either Windows Server 2008 or

Windows Server 2008 R2. The functional level of the domain is Windows Server 2008.

The fabrikam.com domain contains domain controllers that run either Windows Server 2003 or

Windows Server 2008. The functional level of the domain is Windows Server 2003.

The contoso.com domain contains a member server named Server1 that runs Windows Server

2012.

You install the Active Directory Domain Services server role on Server1.

You need to add Server1 as a new domain controller in the contoso.com domain.

What should you do?

A. Run the Active Directory Domain Services Configuration Wizard.

B. Run adprep.exe /domainprep, and then run dcpromo.exe.

C. Raise the functional level of the forest, and then run dcprorno.exe.

D. Modify the Computer Name/Domain Changes properties.

Answer: A

Explanation:

Windows Server 2012 requires a Windows Server 2003 forest functional level. That is, before you

can add a domain controller that runs Windows Server 2012 to an existing Active Directory forest,

the forest functional level must be Windows Server 2003 or higher.

QUESTION NO: 13

Your network contains an Active Directory forest. The forest contains two domains named

contoso.com and fabrikam.com. The forest functional level is Windows 2000.

The contoso.com domain contains domain controllers that run either Windows Server 2008 or

Windows Server 2008 R2. The domain functional level is Windows Server 2008.

The fabrikam.com domain contains domain controllers that run either Windows 2000 Server or

Windows Server 2003. The domain functional level is Windows 2000 native.

The contoso.com domain contains a member server named Server1 that runs Windows Server

2012.

You need to add Server1 as a new domain controller in the contoso.com domain.

What should you do first?

A. Raise the functional level of the contoso.com domain to Windows Server 2008 R2.

B. Upgrade the domain controllers that run Windows Server 2008 to Windows Server 2008 R2.

C. Raise the functional level of the fabrikam.com domain to Windows Server 2003.

D. Decommission the domain controllers that run Windows 2000.

E. Raise the forest functional level to Windows Server 2003.

Answer: D

Explanation:

QUESTION NO: 14

Your network contains an Active Directory domain named adatum.com. The domain contains two

domain controllers that run Windows Server 2012. The domain controllers are configured as

shown in the following table.

You log on to DC1 by using a user account that is a member of the Domain Admins group, and

then you create a new user account named User1.

You need to prepopulate the password for User1 on DC2.

What should you do first?

What should you do first?

A. Connect to DC2 from Active Directory Users and Computers.

B. Add DC2 to the Allowed RODC Password Replication Policy group.

C. Add the User1 account to the Allowed RODC Password Replication Policy group.

D. Run Active Directory Users and Computers as a member of the Enterprise Admins group.

Answer: C

Explanation:

http://technet.microsoft.com/en-us/library/cc730883(v=ws.10).aspx

QUESTION NO: 15

Your company has offices in Montreal, New York, and Amsterdam.

The network contains an Active Directory forest named contoso.com. An Active Directory site

exists for each office. All of the sites connect to each other by using the DEFAULTIPSITELINK site

link.

You need to ensure that only between 20:00 and 08:00, the domain controllers in the Montreal

office replicate the Active Directory changes to the domain controllers in the Amsterdam office.

The solution must ensure that the domain controllers in the Montreal and the New York offices can

replicate the Active Directory changes any time of day.

What should you do?

A. Create a new site link that contains Montreal and Amsterdam. Remove Amsterdam from

DEFAULTIPSITELINK. Modify the schedule of DEFAULTIPSITELINK.

B. Create a new site link that contains Montreal and Amsterdam. Create a new site link bridge.

Modify the schedule of DEFAU LTIPSITELINK.

C. Create a new site link that contains Montreal and Amsterdam. Remove Amsterdam from

DEFAULTIPSITELINK. Modify the schedule of the new site link.

D. Create a new site link that contains Montreal and Amsterdam. Create a new site link bridge.

Modify the schedule of the new site link.

Answer: A

Explanation:

QUESTION NO: 16

Your network contains two Active Directory forests named contoso.com and adatum.com. A twoway

forest trust exists between the forests.

The contoso.com forest contains an enterprise certification authority (CA) named Server1.

You implement cross-forest certificate enrollment between the contoso.com forest and the

adatum.com forest.

On Server1, you create a new certificate template named Template1.

You need to ensure that users in the adatum.com forest can request certificates that are based on

Template1.

Which tool should you use?

A. DumpADO.ps1

B. Repadmin

C. Add-CATemplate

D. Certutil

E. PKISync.ps1

Answer: E

Explanation:

http://technet.microsoft.com/en-us/library/ff955845(v=ws.10).aspx#BKMK_Consolidating

QUESTION NO: 17

Your network contains an Active Directory domain named adatum.com. The domain contains four

servers. The servers are configured as shown in the following table.

You plan to deploy an enterprise certification authority (CA) on a server named Server5. Server5

will be used to issue certificates to domain-joined computers and workgroup computers.

You need to identify which server you must use as the certificate revocation list (CRL) distribution

point for Server5.

Which server should you identify?

A. Server3

B. Server2

C. Server4

D. Server1

Answer: A

Explanation:

CRL is published to a web site

QUESTION NO: 18

You have a server named Server1 that has the Active Directory Certificate Services server role

installed.

Server1 uses a hardware security module (HSM) to protect the private key of Server1.

You need to ensure that the Active Directory Certificate Services (AD CS) database, log files, and

private key are backed up.

You perform regular backups of the HSM module by using a backup utility provided by the HSM

manufacturer.

What else should you do?

A. Run the certutil.exe command and specify the -backupkey parameter.

B. Run the certutil.exe command and specify the -backupdb parameter.

C. Run the certutil.exe command and specify the -backup parameter.

D. Run the certutil.exe command and specify the -dump parameter.

Answer: B

Explanation:

http://technet.microsoft.com/en-us/library/cc732443(v=ws.10).aspx#BKMK_backupDB

QUESTION NO: 19 HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains a

server named Server1 that runs Windows Server 2012. Server1 has the Active Directory

Federation Services (AD FS) server role installed.

Adatum.com is a partner organization.

You are helping the administrator of adatum.com set up a federated trust between adatum.com

and contoso.com. The administrator of adatum.com asks you to provide a file containing the

federation metadata of contoso.com.

You need to identify the location of the federation metadata file.

Which node in the AD FS console should you select?

To answer, select the appropriate node in the answer area.

Answer:

Explanation:

QUESTION NO: 20

Your network contains three Active Directory forests. Each forest contains an Active Directory

Rights Management Services (AD RMS) root cluster.

All of the users in all of the forests must be able to access protected content from any of the

forests.

You need to identify the minimum number of AD RMS trusts required.

How many trusts should you identify?

A. 2

B. 3

C. 4

D. 6

Answer: D

Explanation:

QUESTION NO: 21

Your network contains an Active Directory domain named contoso.com. All servers run Windows

Server 2012.

The domain contains a domain controller named DC1 that is configured as an enterprise root

certification authority (CA).

All users in the domain are issued a smart card and are required to log on to their domain-joined

client computer by using their smart card.

A user named User1 resigned and started to work for a competing company.

You need to prevent User1 immediately from logging on to any computer in the domain. The

solution must not prevent other users from logging on to the domain.

Which tool should you use?

A. Active Directory Sites and Services

B. Active Directory Administrative Center

C. Server Manager

D. Certificate Templates

Answer: B

Explanation:

QUESTION NO: 22

Your network contains a server named Server1 that runs Windows Server 2012. Server1 has the

Hyper-V server role installed. Server1 hosts 10 virtual machines that run Windows Server 2012.

You add a new server named Server2. Server2 has faster hard disk drives, more RAM, and a

different processor manufacturer than Server1.

You need to move all of the virtual machines from Server1 to Server2. The solution must minimize

downtime.

What should you do for each virtual machine?

A. Perform a quick migration.

B. Perform a storage migration.

C. Export the virtual machines from Server1 and import the virtual machines to Server2.

D. Perform a live migration.

Answer: C

Explanation:


Why Should you Buy Guide4Certs 70-412 Product

Quality and Value for the 70-412 Exam
70-412 Exam Free Demo Avaialble for you to check Exam Qestions and Pattern before you Purchase
100% Guarantee to Pass Your 70-412 Exam
70-412 90 Days Updates (FREE)
70-412 PDF Questions with Answers
70-412 Instant Download Right After Purchased
70-412 Drag and Drop questions as experienced in the Actual Exams
Guide4Certs Live Chat Support Available (7 Days a Week)

Guide4Certs 70-412 Exam Features

Quality and Value for the 70-412 Exam

Guide4Certs Practice Exams for Microsoft 70-412 are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development.

100% Guarantee to Pass Your 70-412 Exam

If you preparing for the exam using our Guide4Certs study Guide, we guarantee that you will succeed in the very first attempt. If you do not pass the Microsoft Windows Server 70-412 exam (Configuring Advanced Windows Server 2012 Services ) on your first attempt we will give you a FULL REFUND of your purchasing fee AND send you another same value product for free.

Microsoft 70-412 Downloadable, Printable Exams (in PDF format)

Our Exam 70-412 Study Guides provides you everything you will need to take your 70-412 Exam. The 70-412 Exam details are researched and produced by Professional Certification Experts who are constantly using industry experience to produce precise, logical and up to date exam study guides for you. You may get questions from different web sites or books, but concept is the key.Guide4Certs Product will help you not only pass in the first try, but also save your valuable time.

Our Microsoft 70-412 Exam will provide you with latest 70-412 dumps questions with verified answers that reflect the actual exam. These Questions and Answers will certainly help you in real exam and will boost your confidence before taking the actual test. High quality and Value for the 70-412 Exam:100% Guarantee to Pass Your Microsoft Windows Server exam and get your Microsoft Windows Server Certification.

http://www.Guide4Certs.com The Latest IT Certifications Guides to make it easier to get Microsoft Windows Server Exams.

>