Ensurepass

QUESTION 111

You have a server named Server1 that runs Windows Server 2012. Windows Server 2012 is installed on volume C.

You need to ensure that Safe Mode with Networking loads the next time Server1 restarts. Which tool should you use?

A. The Msconfig command

B. The Restart-Server cmdlet

C. The Restart-Computer cmdlet

D. The Bootcfg command

Answer: A


QUESTION 112

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012. DC1 has the DNS Server server role installed. The network contains client computers that run either Linux, Windows 7, or Windows 8. You have a standard primary zone named adatum.com as shown in the exhibit. (Click the Exhibit button.)

You plan to configure Name Protection on all of the DHCP servers.

You need to configure the adatum.com zone to support Name Protection.

Which two configurations should you perform from DNS Manager? (Each correct answer presents part of the solution. Choose two.)

Exhibit:

clip_image001

A. Sign the zone.

B. Store the zone in Active Directory.

C. Modify the Security settings of the zone.
D. Configure Dynamic updates.

Answer: BD


QUESTION 113

Your network contains two servers named Server1 and Server2 that run Windows Server 2012. Server1 and Server2 have the Hyper-V server role installed. Server1 and Server2 are configured as Hyper-V replicas of each other. Server1 hosts a virtual machine named VM1. VM1 is replicated to Server2.

You need to verify whether the replica of VM1 on Server2 is functional. The solution must ensure that VM1 remains accessible to clients.

What should you do from Hyper-V Manager?

A. On Server1, execute a Planned Failover.
B. On Server1, execute a Test Failover.

C. On Server2, execute a Planned Failover.
D. On Server2, execute a Test Failover.

Answer: D


QUESTION 114

You have a failover cluster named Cluster1 that contains four nodes. All of the nodes run Windows Server

2012. You need to force every node in Cluster1 to contact immediately the Windows Server Update

Services (WSUS) server on your network for updates.

Which tool should you use?

A. The Add-CauClusterRole cmdlet

B. The Wuauclt command

C. The Wusa command

D. The Invoke-CauScan cmdlet

Answer: D


QUESTION 115

Your network contains an Active Directory domain named contoso.com. The network contains a file server named Server1 that runs Windows Server 2012. You are configuring a central access policy for temporary employees.

You enable the Department resource property and assign the property a suggested value of Temp.

You need to configure a target resource condition for the central access rule that is scoped to resources assigned to Temp only.

Which condition should you use?

A. (Temp.Resource Equals "Department")
B. (Resource.Temp Equals "Department")
C. (Resource.Department Equals "Temp")
D. (Department.Value Equals "Temp")

Answer: C


QUESTION 116

Your network contains a server named Server1 that runs Windows Server 2012. Server1 has the Active Directory Certificate Services server role installed and is configured as a standalone certification authority (CA).

You install a second server named Server2.

You install the Online Responder role service on Server2.

You need to ensure that Server1 can issue an Online Certificate Status Protocol (OCSP) Response

Signing certificate to Server2.

What should you do?

A. On Server1, run the certutil.exe command and specify the -setreg parameter.
B. On Server2, run the certutil.exe command and specify the -policy parameter.

C. On Server1, configure Security for the OCSP Response Signing certificate template.

D. On Server2, configure Issuance Requirements for the OCSP Response Signing certificate template.

Answer: C


QUESTION 117

Your network contains an Active Directory domain named adatum.com. The domain contains a server named CA1 that runs Windows Server 2012. CA1 has the Active Directory Certificate Services server role installed and is configured to support key archival and recovery.

You need to ensure that a user named User1 can decrypt private keys archived in the Active Directory Certificate Services (AD CS) database. The solution must prevent User1 from retrieving the private keys from the AD CS database.

What should you do?

A. Assign User1 the Issue and Manage Certificates permission to Server1.

B. Assign User1 the Read permission and the Write permission to all certificate templates.

C. Provide User1 with access to a Key Recovery Agent certificate and a private key.
D. Assign User1 the Manage CA permission to Server1.

Answer: C


QUESTION 118

Your network contains an Active Directory domain named contoso.com. The domain contains two sites named Site1 and Site2 and two domain controllers named DC1 and DC2. Both domain controllers are located in Site1. You install an additional domain controller named DC3 in Site1 and you ship DC3 to Site2. A technician connects DC3 to Site2.

You discover that users in Site2 are authenticated by all three domain controllers.

You need to ensure that the users in Site2 are authenticated by DC1 or DC2 only if DC3 is unavailable.

What should you do?

A. From Network Connections, modify the IP address of DC3.

B. In Active Directory Sites and Services, modify the Query Policy of DC3.
C. From Active Directory Sites and Services, move DC3.

D. In Active Directory Users and Computers, configure the insDS-PrimaryComputer attribute for the users in Site2.

Answer: C


QUESTION 119

Your network contains two Active Directory forests named contoso.com and adatum.com. Contoso.com contains one domain. Adatum.com contains a child domain named child.adatum.com. Contoso.com has a one-way forest trust to adatum.com. Selective authentication is enabled on the forest trust. Several user accounts are migrated from child.adatum.com to adatum.com. Users report that after the migration, they fail to access resources in contoso.com. The users successfully accessed the resources in contoso.com before the accounts were migrated.

You need to ensure that the migrated users can access the resources in contoso.com. What should you do?

A. Replace the existing forest trust with an external trust.
B. Run netdom and specify the /quarantine attribute.

C. Disable SID filtering on the existing forest trust.

D. Disable selective authentication on the existing forest trust.

Answer: C


QUESTION 120

You have four servers that run Windows Server 2012. The servers have the Failover Clustering feature installed. You deploy a new cluster named Cluster1. Cluster1 is configured as shown in the following table.

clip_image002

Site2 is a disaster recovery site. Server1, Server2, and Server3 are configured as the preferred owners of the cluster roles. Dynamic quorum management is disabled.

You plan to perform hardware maintenance on Server3.

You need to ensure that if the WAN link between Site1 and Site2 fails while you are performing

maintenance on Server3, the cluster resource will remain available in Site1. What should you do?

A. Enable dynamic quorum management.
B. Remove the node vote for Server3.

C. Add a file share witness in Site1.

D. Remove the node vote for Server4 and Server5.

Answer: D

 

Download Latest 70-412 Real Free Tests , help you to pass exam 100%.

Comments are closed.