Which rule types should you configure on each side of t…
DRAG DROP
Your network contains two Active Directory forests named contoso.com and adatum.com. All domain
controllers run Windows Server 2012 R2.
A federated trust exists between adatum.com and contoso.com. The trust provides adatum.com users with
access to contoso.com resources.
You need to configure Active Directory Federation Services (AD FS) claim rules for the federated trust.
The solution must meet the following requirements:
In contoso.com, replace an incoming claim type named Group with an outgoing claim type named Role.
In adatum.com, allow users to receive their tokens for the relying party by using their Active Directory group
membership as the claim type.
The AD FS claim rules must use predefined templates.
Which rule types should you configure on each side of the federated trust?
To answer, drag the appropriate rule types to the correct location or locations. Each rule type may be used
once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Select and Place:
which method should you move VM1?
You have a datacenter that contains six servers. Each server has the Hyper-V server role installed and runs
Windows Server 2012 R2. The servers are configured as shown in the following table.
Host4 and Host5 are part of a cluster named Cluster1. Cluster1 hosts a virtual machine named VM1.
You need to move VM1 to another Hyper-V host. The solution must minimize the downtime of VM1.
To which server and by which method should you move VM1?
Which tool should you use?
Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012
R2.
The domain contains a domain controller named DC1 that is configured as an enterprise root certification
authority (CA).
All users in the domain are issued a smart card and are required to log on to their domain-joined client
computer by using their smart card.
A user named User1 resigned and started to work for a competing company.
You need to prevent User1 immediately from logging on to any computer in the domain. The solution must notprevent other users from logging on to the domain.
Which tool should you use?
Which two actions should you perform?
Your network contains an Active Directory domain named contoso.com. The domain contains servers named
Server1 and Server2 that run Windows Server 2012 R2. Server1 has the Active Directory Federation Services
server role installed. Server2 is a file server.
Your company introduces a Bring Your Own Device (BYOD) policy.
You need to ensure that users can use a personal device to access domain resources by using Single Sign-On
(SSO) while they are connected to the internal network.
Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)
How should you configure the certificate request?
DRAG DROP
Your network contains an Active Directory domain named contoso.com. The domain contains a server named
Server1 that runs Windows Server 2012 R2.
You plan to install the Active Directory Federation Services server role on Server1 to allow for Workplace Join.
You run nslookup enterprise registration and you receive the following results:
You need to create a certificate request for Server1 to support the Active Directory Federation Services (AD
FS) installation.
How should you configure the certificate request?
To answer, drag the appropriate names to the correct locations. Each name may be used once, more than
once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Select and Place:
You need to ensure that you can manage the certificates…
Your network contains an Active Directory domain named contoso.com. The domain contains a server named
Server1 that runs Windows Server 2012 R2. Server1 is an enterprise root certification authority (CA) for
contoso.com.
Your user account is assigned the certificate manager role and the auditor role on the contoso.com CA. Your
account is a member of the local Administrators group on Server1.
You enable CA role separation on Server1.
You need to ensure that you can manage the certificates on the CA.
What should you do?
Which common name should you use for the certificates o…
HOTSPOT
Your network contains an Active Directory domain named contoso.com. The domain contains two servers
named Server1 and Server2 that run Windows Server 2012 R2. The servers have the Hyper-V server role
installed.
A certification authority (CA) is available on the network.
A virtual machine named vml.contoso.com is replicated from Server1 to Server2. A virtual machine named
vm2.contoso.com is replicated from Server2 to Server1.
You need to configure Hyper-V to encrypt the replication of the virtual machines.
Which common name should you use for the certificates on each server?
To answer, configure the appropriate common name for the certificate on each server in the answer area.
Hot Area:
You need to verify whether the replica of VM5 on Server…
Your network contains two servers named Server1 and Server2 that run Windows Server 2012 R2. Server1
and Server2 have the Hyper-V server role installed. Server1 and Server2 are configured as Hyper-V replicas of
each other.
Server2 hosts a virtual machine named VM5. VM5 is replicated to Server1.
You need to verify whether the replica of VM5 on Server1 is functional. The solution must ensure that VM5
remains accessible to clients.
What should you do from Hyper-V Manager?
You need to ensure that multiple backups of Server1 are…
Your network contains two servers that run Windows Server 2012 R2 named Server1 and Server2. Both
servers have the File Server role service installed.
On Server2, you create a share named Backups.
From Windows Server Backup on Server1, you schedule a full backup to run every night. You set the backup
destination to \\\\Server2 \\Backups.After several weeks, you discover that \\\\Server2\\Backups only contains the last backup that completed on
Server1.
You need to ensure that multiple backups of Server1 are maintained.
What should you do?
You need to start the operating system on Server1 as so…
You have a server named Server1 that runs Windows Server 2012 R2. Server1 has a single volume that is
encrypted by using BitLocker Drive Encryption (BitLocker).
BitLocker is configured to save encryption keys to a Trusted Platform Module (TPM). Server1 is configured to
perform a daily system image backup.
The motherboard on Server1 is upgraded.
After the upgrade, Windows Server 2012 R2 on Server1 fails to start.
You need to start the operating system on Server1 as soon as possible.
What should you do?
 
                




