70-412 Guide

cbt 70-412 (91 to 105)

High quality of 70-412 dumps materials and preparation for Microsoft certification for client, Real Success Guaranteed with Updated 70-412 pdf dumps vce Materials. 100% PASS Configuring Advanced Windows Server 2012 Services exam Today!

2021 May 70-412 Study Guide Questions:

Q91. Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC2 that runs Windows Server 2012 R2. DC2 has the DHCP Server server role installed. 

DHCP is configured as shown in the exhibit. (Click the Exhibit button.) 


You discover that client computers cannot obtain IPv4 addresses from DC2. 

You need to ensure that the client computers can obtain IPv4 addresses from DC2. 

What should you do? 

A. Disable the Deny filters. 

B. Enable the Allow filters. 

C. Authorize DC2. 

D. Restart the DHCP Server service 

Answer: C 

Explanation: 

From the exhibit we see a red marker on the IPv4 server icon. The DHCP server is not 

authorized. 

Authorize DHCP Server 

The final step is to authorize the server. 

Right-click your FQDN and select Authorize. 

Refresh the view by right-clicking your FQDN and selecting Refresh. 

You should now see green check mark next to IPv4. 

Example: 


Reference: Server 2012 DHCP Server Role 


Q92. Your network contains two Active Directory forests named contoso.com and litwareinc.com. A two-way forest trusts exists between the forest. Selective authentication is enabled on 

the trust. 

The contoso.com forest contains a server named Server1. 

You need to ensure that users in litwareinc.com can access resources on Server1. 

What should you do? 

A. Install Active Directory Rights Management Services on a domain controller in contoso.com. 

B. Modify the permission on the Server1 computer account. 

C. Install Active Directory Rights Management Services on a domain controller in litwareinc.com. 

D. Configure SID filtering on the trust. 

Answer: B 

Explanation: 

Selective authentication between forests If you decide to set selective authentication on an incoming forest trust, you need to manually assign permissions on each computer in the domain as well as the resources to which you want users in the second forest to have access. To do this, set a control access right Allowed to authenticate on the computer object that hosts the resource in Active Directory Users and Computers in the second forest. Then, allow user or group access to the particular resources you want to share. 

Reference: Accessing resources across forests 


Q93. You have a server named Server1 that runs Windows Server 2012 R2. 

From Server Manager, you install the Active Directory Certificate Services server role on Server1. 

A domain administrator named Admin1 logs on to Server1. 

When Admin1 runs the Certification Authority console, Admin1 receive the following error message. 


You need to ensure that when Admin1 opens the Certification Authority console on Server1, the error message does not appear. 

What should you do? 

A. Install the Active Directory Certificate Services (AD CS) tools. 

B. Run the regsvr32.exe command. 

C. Modify the PATH system variable. 

D. Configure the Active Directory Certificate Services server role from Server Manager. 

Answer: D 

Explanation: 

The error message is related to missing role configuration. 

* Cannot Manage Active Directory Certificate Services Resolution: configure the two Certification Authority and Certification Authority Web Enrollment Roles: 


image 

Reference: Cannot manage Active Directory Certificate Services in Server 2012 Error 0x800070002 


Q94. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. 

You install the IP Address Management (IPAM) Server feature on a server named Server1 

and select Manual as the provisioning method. 

The IPAM database is located on a server named SQL1. 

You need to configure IPAM to use Group Policy Based provisioning. 

What command should you run first? 

To answer, select the appropriate options in the answer area. 



Answer: 



Q95. You have a file server named Server1 that runs a Server Core Installation of Windows Server 2012 R2. 

Server1 has a volume named D that contains user data. Server1 has a volume named E that is empty. 

Server1 is configured to create a shadow copy of volume D every hour. You need to configure the shadow copies of volume D to be stored on volume E. 

What should you run? 

A. The Set-Volume cmdlet with the -driveletter parameter 

B. The Set-Volume cmdlet with the -path parameter 

C. The vssadmin.exe add shadowstorage command 

D. The vssadmin.exe create shadow command 

Answer: C 

Explanation: 

Add ShadowStorage 

Adds a shadow copy storage association for a specified volume. 

Incorrect: 

Not A. Sets or changes the file system label of an existing volume. -DriveLetter Specifies a 

letter used to identify a drive or volume in the system. 

Not B. Create Shadow 

Creates a new shadow copy of a specified volume. 

Not C. Sets or changes the file system label of an existing volume -Path Contains valid 

path information. 

Reference: Vssadmin; Set-Volume 

http://technet.microsoft.com/en-us/library/cc754968(v=ws.10).aspx 

http://technet.microsoft.com/en-us/library/hh848673(v=wps.620).aspx 


70-412 free exam questions

Far out study material 70-412:

Q96. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Active Directory Certificate Services server role installed and configured. 

For all users, you are deploying smart cards for logon. You are using an enrollment agent to enroll the smart card certificates for the users. 

You need to configure the Contoso Smartcard Logon certificate template to support the use of the enrollment agent. 

Which setting should you modify? To answer, select the appropriate setting in the answer area. 


Answer: 



Q97. Your network contains three servers named HV1, HV2, and Server1 that run Windows Server 2012 R2. HV1 and HV2 have the Hyper-V server role installed. Server1 is a file server that contains 3 TB of free disk space. 

HV1 hosts a virtual machine named VM1. The virtual machine configuration file for VM1 is stored in D:VM and the virtual hard disk file is stored in E:VHD. 

You plan to replace drive E with a larger volume. 

You need to ensure that VM1 remains available from HV1 while drive E is being replaced. You want to achieve this goal by using the minimum amount of administrative effort. 

What should you do? 

A. Perform a live migration to HV2. 

B. Add HV1 and HV2 as nodes in a failover cluster. Perform a storage migration to HV2. 

C. Add HV1 and HV2 as nodes in a failover cluster. Perform a live migration to HV2. 

D. Perform a storage migration to Server1. 

Answer: D 

Explanation: 

One of the great new features coming in Windows Server 2012 is Storage Migration for Hyper-V. Storage Migration allows an administrator to relocate the source files that make up a virtual machine to another location without any downtime. 

Storage Migration creates a copy of the file or files at the new location. Once that is finished, Server 2012 does a final replication of changes and then the virtual machine uses the files in the new location. 

Reference: Windows Server 2012 Hyper-V – Part 3: Storage Migration 


Q98. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 and a server named Server1. Both servers run Windows Server 2012 R2. 

You configure the classification of a share on Server1 as shown in the Share1 Properties exhibit. (Click the Exhibit button.) 


You configure the resource properties in Active Directory as shown in the Resource Properties exhibit. (Click the Exhibit button.) 


You need to ensure that the Impact classification can be assigned to Share1 immediately. 

Which cmdlet should you run on each server? 

To answer, select the appropriate cmdlet for each server in the answer area. 



Answer: 



Q99. Your network contains an Active Directory domain named contoso.com. 

A previous administrator implemented a Proof of Concept installation of Active Directory Rights Management Services (AD RMS) on a server named Server1. 

After the proof of concept was complete, the Active Directory Rights Management Services server role was removed. 

You attempt to deploy AD RMS. 

During the configuration of AD RMS, you receive an error message indicating that an existing AD RMS Service Connection Point (SCP) was found. 

You need to ensure that clients will only attempt to establish connections to the new AD RMS deployment. 

Which should you do? 

A. From DNS, remove the records for Server1. 

B. From DNS, increase the priority of the DNS records for the new deployment of AD RMS. 

C. From Active Directory, remove the computer object for Server1. 

D. From Active Directory, remove the SCP. 

Answer: D 

Explanation: The Active Directory Rights Management Services (AD RMS) Service Connection Point (SCP) is an object in Active Directory that holds the web address of the AD RMS certification cluster. AD RMS-enabled applications use the SCP to discover the AD RMS service; it is the first connection point for users to discover the AD RMS web services. 

Only one SCP can exist in your Active Directory forest. If you try to install AD RMS and an SCP already exists in your forest from a previous AD RMS installation that was not properly deprovisioned, the new SCP will not install properly. It must be removed before you can establish the new SCP. 

Reference: The AD RMS Service Connection Point 

http://social.technet.microsoft.com/wiki/contents/articles/710.the-ad-rms-service-connection-point.aspx 


Q100. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. 

You have a Dynamic Access Control policy named Policy1. 

You create a new Central Access Rule named Rule1. 

You need to add Rule1 to Policy1. 

What command should you run? 

To answer, select the appropriate options in the answer area. 



Answer: 



70-412 practice test

Pinpoint microsoft 70-412:

Q101. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2. Both servers have the IP Address Management (IPAM) Server feature installed. 

You have a support technician named Tech1. Tech1 is a member of the IPAM Administrators group on Server1 and Server2. You need to ensure that Tech1 can use Server Manager on Server1 to manage IPAM on Server2. To which group on Server2 should you add Tech1? To answer, select the appropriate group in the answer area. 


Answer: 



Q102. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. 

Server1 is an enterprise root certification authority (CA) for contoso.com. 

You need to ensure that the members of a group named Group1 can request code signing certificates. The certificates must be issued automatically to the members. 

Which two actions should you perform? (Each correct answer presents part of the solution. 

Choose two.) 

A. From Certificate Templates, modify the certificate template. 

B. From Certification Authority, add a certificate template to be issued. 

C. From Certificate Authority, modify the CA properties. 

D. From Certificate Templates, duplicate a certificate template. 

E. From Certificate Authority, stop and start the Active Directory Certificate Services (AD CS) service. 

Answer: A,D 

Explanation: 

Explanation/Reference: 

Best Practices include: Duplicate new templates from existing templates closest in function 

to the intended template. 

New certificate templates are duplicated from existing templates. Many settings are copied 

from the original template. Because of this, duplicating one template to another of a totally 

different type may carry over some unintended settings. When duplicating a template, 

examine the subject type of the original template and ensure that you duplicate one that 

has a similar function to that of the intended template. Although most settings for certificate 

templates can be edited once the template is duplicated, the subject type cannot be 

changed. 

Reference: Deploying Certificate Templates 

https://technet.microsoft.com/en-us/library/cc770794%28v=ws.10%29.aspx 


Q103. DRAG DROP 

Your network contains an Active Directory domain named contoso.com. The domain contains four member servers named Server1, Server2, Servers, and Server4. All servers run Windows Server 2012 R2. 

Server1 and Server2 are located in a site named Site1. Server3 and Server4 are located in a site named Site2. The servers are configured as nodes in a failover cluster named Cluster1. 

Cluster1 is configured to use the Node Majority quorum configuration. 

You need to ensure that Server1 is the only server in Site1 that can vote to maintain quorum. 

What should you run from Windows PowerShell? 

To answer, drag the appropriate commands to the correct location. Each command may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. 


Answer: 



Q104. Your network contains an Active Directory forest. The forest contains one domain named contoso.com. The domain contains three domain controllers. The domain controllers are configured as shown in the following table. 


DC1 has all of the operations master roles installed. 

You transfer all of the operations master roles to DC2, and then you uninstall Active Directory from DC1. 

You need to ensure that you can use Password Settings objects (PSOs) in the domain. 

What should you do? 

A. Change the domain functional level. 

B. Upgrade DC2. 

C. Run the dcgpofix.exe command. 

D. Transfer the schema master role. 

Answer: A 

Explanation: 

The domain functional level must be Windows Server 2008 to use PSO's 

Requirements and special considerations for fine-grained password and account lockout policies: 

* Domain functional level: The domain functional level must be set to Windows Server 2008 

or higher. 

Etc. 

Incorrect: 

Not B. DC2 is also Windows Server 2008. 

Not C. Recreates the default Group Policy Objects (GPOs) for a domain 

Not D. Schema isn't up to right level 

Reference: AD DS: Fine-Grained Password Policies 

http://technet.microsoft.com/en-us/library/cc770394(v=ws.10).aspx 


Q105. You have a server named Server1 that runs Windows Server 2012 R2. 

You install the File and Storage Services server role on Server1. 

From Windows Explorer, you view the properties of a folder named Folder1 and you discover that the Classification tab is missing. 

You need to ensure that you can assign classifications to Folder1 from Windows Explorer manually. 

What should you do? 

A. From Folder Options, clear Hide protected operating system files (Recommended). 

B. Install the File Server Resource Manager role service. 

C. From Folder Options, select the Always show menus. 

D. Install the Share and Storage Management Tools. 

Answer: B 

Explanation: 

On the Classification tab of the file properties in Windows Server 2012, File Classification Infra-structure adds the ability to manually classify files. You can also classify folders so that any file added to the classified folder will inherit the classifications of the parent folder. 

Reference: What's New in File Server Resource Manager in Windows Server. 


To know more about the 70-412, click here.

Tagged as : Microsoft 70-412 Dumps, Download 70-412 pdf, 70-412 VCE, 70-412 pass4sure, examcollection 70-412