Tips for pdf 70-412

Proper study guides for Improve Microsoft Configuring Advanced Windows Server 2012 Services certified begins with Microsoft 70-412 preparation products which designed to deliver the Simulation 70-412 questions by making you pass the 70-412 test at your first time. Try the free 70-412 demo right now.

2016 Aug cbt nuggets 70-412:

Q166. Your network contains an Active Directory domain named contoso.com. The domain contains a file server named Server1 that runs Windows Server 2012 R2. 

You create a user account named User1 in the domain. 

You need to ensure that User1 can use Windows Server Backup to back up Server1. The solution must minimize the number of administrative rights assigned to User1. 

What should you do? 

A. Add User1 to the Backup Operators group. 

B. Add User1 to the Power Users group. 

C. Assign User1 the Backup files and directories user right and the Restore files and directories user right. 

D. Assign User1 the Backup files and directories user right. 

Answer: D 

Explanation: 

Backup Operators have these permissions by default: 


However the question explicitly says we need to minimize administrative rights. Since the requirement is for backing up the data only--no requirement to restore or shutdown--then assigning the "Back up files and directories user right" would be the correct answer. 


Reference: Default local groups 

http://technet.microsoft.com/en-us/library/cc787956(v=ws.10).aspx http://technet.microsoft.com/en-us/library/cc756898(v=ws.10).aspx http://technet.microsoft.com/en-us/library/cc771990.aspx 


Q167. HOTSPOT 

Your network contains one Active Directory forest named contoso.com. The forest contains the domain controllers configured as shown in the following table. 


You perform the following actions: 

. Create a file named File1.txt in the SYSVOL folder on DC1. 

. Create a user named User1 on DC4. You need to identify on which domain controller or controllers a copy of each object is stored. 

What should you identify? To answer, select the appropriate options in the answer area. 


Answer: 



Q168. Your network contains an Active Directory domain named contoso.com. The domain contains a file server named Server1 that runs Windows Server 2012 R2. All client computers run Windows 8. 

You need to configure a custom Access Denied message that will be displayed to users when they are denied access to folders or files on Server1. 

What should you configure? 

A. A classification property 

B. The File Server Resource Manager Options 

C. A file management task 

D. A file screen template 

Answer: B 

Explanation: 

Access-denied assistance can be configured by using the File Server Resource Manager console on the file server. 

Note: Access-denied assistance is a new feature in Windows Server 2012, which provides the following ways to troubleshoot issues that are related to access to files and folders: 

* Self-assistance. If a user can determine the issue and remediate the problem so that they can get the requested access, the impact to the business is low, and no special exceptions are needed in the central access policy. Access-denied assistance provides an access-denied message that file server administrators can customize with information specific to their organizations. For example, an administrator could set the message so that users can request access from a data owner without involving the file server administrator. 

Reference: Scenario: Access-Denied Assistance 


Q169. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. The domain contains two member servers named Server1 and Server2. All servers run Windows Server 2012 R2. 

Server1 and Server2 have the Network Load Balancing (NLB) feature installed. The servers are configured as nodes in an NLB cluster named Cluster1. Both servers connect to the same switch. 

Cluster1 hosts a secure web Application named WebApp1. WebApp1 saves user state information in a central database. 

You need to ensure that the connections to WebApp1 are distributed evenly between the nodes. The solution must minimize port flooding. 

What should you configure? To answer, configure the appropriate affinity and the appropriate mode for Cluster1 in the answer area. 


Answer: 



Q170. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. The domain contains an enterprise certification authority (CA). 

The domain contains a server named Server1 that runs Windows Server 2012 R2. You install the Active Directory Federation Services server role on Server1. 

You plan to configure Server1 as an Active Directory Federation Services (AD FS) server. The Federation Service name will be set to adfs1.contoso.com. 

You need to identify which type of certificate template you must use to request a certificate for AD FS. 


Answer: 



Q171. Your network contains an Active Directory forest named adatum.com. The forest contains an Active Directory Rights Management Services (AD RMS) cluster. 

A partner company has an Active Directory forest named litwareinc.com. The partner company does not have AD RMS deployed. 

You need to ensure that users in litwareinc.com can consume rights-protected content from adatum.com. 

Which type of trust policy should you create? 

A. At federated trust 

B. A trusted user domain 

C. A trusted publishing domain 

D. Windows Live ID 

Answer: A 

Explanation: 

In AD RMS rights can be assigned to users who have a federated trust with Active Directory Federation Services (AD FS). This enables an organization to share access to rights-protected content with another organization without having to establish a separate Active Directory trust or Active Directory Rights Management Services (AD RMS) infrastructure. 

Reference: AD RMS and AD FS Considerations 

http://technet.microsoft.com/en-us/library/dd772651(v=WS.10).aspx 


Q172. DRAG DROP 

Your network contains an Active Directory domain named adatum.com. The domain contains three servers. The servers are configured as shown in the following table. 


Server1 is configured as shown in the exhibit. (Click the Exhibit button.) 


Template1 contains custom cryptography settings that are required by the corporate security team. 

On Server2, an administrator successfully installs a certificate based on Template1. 

The administrator reports that Template1 is not listed in the Certificate Enrollment wizard on Server3, even after selecting the Show all templates check box. 

You need to ensure that you can install a server authentication certificate on Server3. The certificate must comply with the cryptography requirements. 

Which three actions should you perform in sequence? 

To answer, move the appropriate three actions from the list of actions to the answer area 

and arrange them in the correct order. 


Answer: 



70-412 pdf exam

Far out 70-412 configuring advanced windows server 2012:

Q173. Your network contains an Active Directory forest named adatum.com. The forest contains a single domain. The domain contains four servers. The servers are configured as shown in the following table. 


You need to update the schema to support a domain controller that will run Windows Server 2012 R2. 

On which server should you run adprep.exe? 

A. Server1 

B. DC3 

C. DC2 

D. DC1 

Answer: B 

Explanation: 

We must use the Windows Server 2008 R2 Server. 

Upgrade Domain Controllers to Windows Server 2012 R2 and Windows Server 2012 

You can use adprep.exe on domain controllers that run 64-bit versions of Windows Server 2008 or Windows Server 2008 R2 to upgrade to Windows Server 2012. You cannot upgrade domain controllers that run Windows Server 2003 or 32-bit versions of Windows Server 2008. To replace them, install domain controllers that run a later version of Windows Server in the domain, and then remove the domain controllers that Windows Server 2003. 

Reference: Upgrade Domain Controllers to Windows Server 2012 R2 and Windows Server 2012, Supported in-place upgrade paths. 

http://technet.microsoft.com/en-us/library/hh994618.aspx#BKMK_UpgradePaths 


Q174. HOTSPOT 

You have a server named Server1 that runs Windows Server 2012 R2. The volumes on Server1 are configured as shown in the following table. 


A new corporate policy states that backups must use Windows Azure Online Backup whenever possible. 

You need to identify which backup methods you must use to back up Server1. The solution must use Windows Azure Online Backup whenever possible. 

Which backup type should you identify for each volume? 

To answer, select the appropriate backup type for each volume in the answer area. 



Answer: 



Q175. HOTSPOT 

Your network contains two servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 and Server2 have the Hyper-V server role installed. 

Server1 and Server2 have different processor models from the same manufacturer. 

On Server1, you plan to create a virtual machine named VM1. Eventually, VM1 will be 

exported to Server2. 

You need to ensure that when you import VM1 to Server2, you can start VM1 from saved 

snapshots. 

What should you configure on VM1? 

To answer, select the appropriate node in the answer area. 


Answer: 



Q176. You have a server named Server1 that runs Windows Server 2012 R2. 

You start Server1 by using Windows RE. 

You need to repair the Boot Configuration Data (BCD) store on Server1. 

Which tool should you use? 

A. Bootim 

B. Bootsect 

C. Bootrec 

D. Bootcfg 

Answer: C


Q177. Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 is a file server that has the Hyper-V server role installed. 

Server1 hosts several virtual machines. The virtual machine configuration files are stored on drive D and the VHD files are stored on drive E. 

You plan to replace drive E with a larger volume. 

You need to ensure that the virtual machines on Server1 remain available while drive E is being replaced. 

What should you do? 

A. Perform a quick migration. 

B. Add Server1 and Server2 as nodes in a failover cluster. 

C. Perform a live migration. 

D. Perform a storage migration. 

Answer: D 

Explanation: 

Hyper-V in Windows Server 2012 R2 introduces support for moving virtual machine storage without downtime by making it possible to move the storage while the virtual machine remains running. 

Reference: Virtual Machine Storage Migration Overview 

http://technet.microsoft.com/en-us/library/hh831656.aspx 


Q178. Your network contains an Active Directory forest. The forest contains one domain named adatum.com. The domain contains three domain controllers. The domain controllers are configured as shown in the following table. 


DC2 has all of the domain-wide operations master roles. DC3 has all of the forest-wide operation master roles. 

You need to ensure that you can use Password Settings objects (PSOs) in the domain. 

What should you do first? 

A. Uninstall Active Directory from DC1. 

B. Change the domain functional level. 

C. Transfer the domain-wide operations master roles. 

D. Transfer the forest-wide operations master roles. 

Answer: A 

Explanation: 

In Windows Server 2008 and later, you can use fine-grained password policies to specify multiple password policies and apply different password restrictions and account lockout policies to different sets of users within a single domain. 

Note: In Microsoft Windows 2000 and Windows Server 2003 Active Directory domains, you could apply only one password and account lockout policy, which is specified in the domain's Default Domain Policy, to all users in the domain. As a result, if you wanted different password and account lockout settings for different sets of users, you had to either create a password filter or deploy multiple domains. Both options were costly for different reasons. 

Reference: AD DS Fine-Grained Password and Account Lockout Policy Step-by-Step Guide 


Q179. You have a DNS server named Server1 that runs Windows Server 2012 R2. Server1 has the zones shown in the following output. 


You need to delegate permissions to modify the records in the adatum.com zone to a group named Group1. 

What should you do first? 

A. Enable the distribution of the trust anchors for adatum.com. 

B. Unsign adatum.com. 

C. Store adatum.com in Active Directory. 

D. Update the server data file for adatum.com. 

Answer: A 

Explanation: From the exhibit we see that the adatum.com zone is signed. 

A trust anchor (or trust “point”) is a public cryptographic key for a signed zone. Trust 

anchors must be configured on every non-authoritative DNS server that will attempt to 

validate DNS data. You cannot distribute trust anchors until after a zone is signed. 

Reference: Trust Anchors 

https://technet.microsoft.com/en-us/library/dn593672.aspx 


Q180. Your network contains an Active directory forest named contoso.com. The forest contains two child domains named east.contoso.com and west.contoso.com. 

You install an Active Directory Rights Management Services (AD RMS) cluster in each child domain. 

You discover that all of the users in the contoso.com forest are directed to the AD RMS cluster in east.contoso.com. 

You need to ensure that the users in west.contoso.com are directed to the AD RMS cluster in west.contoso.com and that the users in east.contoso.com are directed to the AD RMS cluster in east.contoso.com. 

What should you do? 

A. Modify the Service Connection Point (SCP). 

B. Configure the Group Policy object (GPO) settings of the users in the west.contoso.com domain. 

C. Configure the Group Policy object (GPO) settings of the users in the east.contoso.com domain. 

D. Modify the properties of the AD RMS cluster in west.contoso.com. 

Answer: B 

Explanation: 

The west.contoso.com are the ones in trouble that need to be redirected to the west.contoso.com not the east.contoso.com. 

Note: It is recommended that you use GPO to deploy AD RMS client settings and that you only deploy settings as needed. 

Reference: AD RMS Best Practices Guide 



see more 70-412 dumps