PrepAway - Latest Free Exam Questions & Answers

Which tool should you use?

Your company recently deployed a new Active Directory forest named contoso.com. The first
domain controller in the forest runs Windows Server 2012 R2.
You need to identify the time-to-live (TTL) value for domain referrals to the NETLOGON and
SYSVOL shared folders.
Which tool should you use?

PrepAway - Latest Free Exam Questions & Answers

A.
Ultrasound

B.
Replmon

C.
Dfsdiag

D.
Frsutil

42 Comments on “Which tool should you use?

    1. bopbop says:

      Here is a complete list of the new questions including some of fabolous’

      I edited and formatted it. Answered some of the questions I know. Please post them so we can get the answers..

      Q1: You have an enterprise certification authority (CA) named CA1.
      You have a certificate template named UserAutoEnroll that is based on the User certificate template. Domain users are configured to autoenroll for UserAutoEnroll.
      A user named User1 has an email address defined in Active Directory. A user named User2 does not have an email address defined in Active Directory.
      You discover that User1 was issued a certificate based on UserAutoEnroll template automatically. A request by user2 for a certificate based on the UserAutoEnroll template fails.
      You need to ensure that all users can autoenroll for certificated based on the UserAutoEnroll template.
      Which setting should you configure from the properties on the UserAutoEnroll certificate template?
      A. Issuance Requirements
      B. Request Handling
      C. Cryptography
      D. Subject Name

      Answer: (D) Subject Name
      Explanation:

      ————

      Q2: Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.

      Name Domain Site
      DC1 Contoso.com Main Office
      DC2 Contoso.com Main Office
      DC3 Contoso.com Europe Office
      DC4 Contoso.com Asia Office
      DC5 Sales.contoso.com Main Office
      DC6 Manufacturiung.contoso.com Main Office

      You create a trust between contoso.com and a domain in another forest at a partner company.
      You need to prevent the sales.contoso.com and the manufacturing.contoso.com names from being used in authentication requests across the forest trust.

      What should you use?

      A. Set-ADSite
      B. Set-ADReplicationSite
      C. Set-ADDomain
      D. Set-ADReplicationSiteLink
      E. Set-ADGroup
      F. Set-ADForest
      G. Netdom

      Answer: (G) Netdom
      Explanation: The question seems to be describing “Selective Authentication.” I was able to find a Server 2008 article but not 2012 (https://technet.microsoft.com/en-us/library/cc794747(v=ws.10).aspx)

      ————–

      Q3: Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.

      Name Domain Site
      DC1 Contoso.com Main Office
      DC2 Contoso.com Main Office
      DC3 Contoso.com Europe Office
      DC4 Contoso.com Asia Office
      DC5 Sales.contoso.com Main Office
      DC6 Manufacturiung.contoso.com Main Office

      You need to prevent administrators from accidently deleting any of the site in the forest.
      What should you use?

      A. Set-ADSite
      B. Set-ADReplicationSite
      C. Set-ADDomain
      D. Set-ADReplicationSiteLink
      E. Set-ADGroup
      F. Set-ADForest
      G. Netdom

      Answer: (B) Set-ADReplicationSite
      Explanation: Use the ‘-ProtectedFromAccidentalDeletion” switch (https://technet.microsoft.com/en-us/library/hh852305(v=wps.630).aspx)

      ————–

      Q4: Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.

      Name Domain Site
      DC1 Contoso.com Main Office
      DC2 Contoso.com Main Office
      DC3 Contoso.com Europe Office
      DC4 Contoso.com Asia Office
      DC5 Sales.contoso.com Main Office
      DC6 Manufacturiung.contoso.com Main Office

      You need ensure that all Active Directory changes are replicated to all of the domain controllers in the forest within 30 minutes.
      What should you use?

      A. Set-ADSite
      B. Set-ADReplicationSite
      C. Set-ADDomain
      D. Set-ADReplicationSiteLink
      E. Set-ADGroup
      F. Set-ADForest
      G. Netdom

      Answer: (D) Set-ADSiteReplicationLink
      Explanation: Use the “-ReplicationFrequencyInMinuites” switch (https://technet.microsoft.com/en-us/library/hh852257(v=wps.630).aspx)

      ————

      Q 5: Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.

      Name Domain Site
      DC1 Contoso.com Main Office
      DC2 Contoso.com Main Office
      DC3 Contoso.com Europe Office
      DC4 Contoso.com Asia Office
      DC5 Sales.contoso.com Main Office
      DC6 Manufacturiung.contoso.com Main Office

      You have a trust from contoo.com to another forest named fabrikam.com.
      You plan to migrate users from contodo.com to fabrikam.com.
      You need to ensure that the users who migrated to fabrikam.com can continue to access shared resources in contoso.com. the solution must not require administrators to modify permissions to shared resources.

      What should you use?

      A. Set-ADSite
      B. Set-ADReplicationSite
      C. Set-ADDomain
      D. Set-ADReplicationSiteLink
      E. Set-ADGroup
      F. Set-ADForest
      G. Netdom

      Answer: (G) Netdom
      Explanation: It should be Netdom, you need and enable “sidhistory” (https://technet.microsoft.com/en-us/library/cc794801(v=ws.10).aspx)

      ————

      Q6: your network contains one Active Directory forest named adatum.com. The forest contains a single domain.
      The site topology for the forest is shown in the exhibit.

      Each site contain s one domain controller.
      You need to ensure that replication between site2 and site4 occurs in 15 minutes or less.
      What command should you run? To answer select the appropriate options in the answer area.

      Answer Area
      New-AdReplicationSiteLink
      New-ADReplicationLinkBridge
      Set-ADReplicationConnection
      Set-ADReplicationSiteLink
      Set-ADReplicationSiteLinkBridge

      -name

      SiteLink3
      SiteLink6
      SiteLink1, SiteLink2

      -SitesIncluded Site2, Site4

      –ReplicationFrequencyinMinutes 15

      –Cost

      70
      110
      400

      Answer: New-AdReplicationSiteLink (Select Name (SiteLink3?)) -SitesIncluded Site1,Site4 -Cost 70
      Explanation: See Example 2: Create a replication site link and set properties for it (https://technet.microsoft.com/en-us/library/hh852320(v=wps.630).aspx)
      Lower the cost should be higher priority. Notice I put (Select Name.) I am not sure if this is written incorrectly or we need to actually refer to the site topolgy exhibit which would appear int he exam. I would assume the name would be SiteLink2-SiteLink4 but that option is not there. So this is something you will have to pay attention to when you do the exam.

      ————

      Q7: Your network contains one Active Directory forest named contoso.com. The forest contains a single domain. The domain contains the domain controllers is configured as shown in the following table.
      Name Site
      DC1 Site1
      DC2 Site2
      DC3 Site3
      DC4 Site4

      The replication topology is configured as shown in the following output.

      Cost : 100
      DistinguishedName : CN=SiteLink1, CN=IP, CN=Inter-Site Transports, CN=Sites, CN=Configuration, Dc=Adatum, DC=com
      Name : SiteLink1
      ObjectClass : SiteLink
      ObjectGUID : e1c8c335-b75f-4612-8a9e-58a0edead21f
      ReplInterval : 60
      SiteList : {CN=Site4, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com,
      CN=Site2, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com}

      Cost : 100
      DistinguishedName : CN=SiteLink1, CN=IP, CN=Inter-Site Transports, CN=Sites, CN=Configuration, Dc=Adatum, DC=com
      Name : SiteLink2
      ObjectClass :SiteLink
      ObjectGUID : 9516948e-cd56-4a9b-b6ba-cdf3dd7fe0d1
      ReplInterval : 60
      SiteList : {CN=Site4, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com,
      CN=Site2, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com}

      Cost : 100
      DistinguishedName : CN=SiteLink3, CN=IP, CN=Inter-Site Transports, CN=Sites, CN=Configuration, Dc=Adatum, DC=com
      Name : SiteLink3
      ObjectClass : SiteLink
      ObjectGUID : 07a7a37e-a12c-40c4-8042-f5d2e737b8a9
      ReplInterval : 60
      SiteList : {CN=Site4, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com,
      CN=Site3, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com}

      Cost : 400
      DistinguishedName : CN=SiteLink4, CN=IP, CN=Inter-Site Transports, CN=Sites, CN=Configuration, Dc=Adatum, DC=com
      Name : SiteLink4
      ObjectClass : SiteLink
      ObjectGUID : 508810dc-30fd-4845-982a-d4552fba2e04
      ReplInterval : 45
      SiteList : {CN=Site4, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com,
      CN=Site2, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com}

      You discover that replication between DC1 and DC3 takes a few hours.
      You need to reduce the amount of time it takes to replicate Active Directory changes between DC1 and DC3.

      What should you do?
      A. Create a site link that connects Site1 and Site3, has a cost of 350, and replicates every 15 minutes.
      B. Modify SiteLink4 to replicate every 15 minute.
      C. Disable Site Link bridging.
      D. Set the cost of SiteLink4 to 100.

      Answer: (D) Set the cost of SiteLink4 to 100.
      Explanation: No explanation, found answer on internet

      ————

      Q8: your network contains one Active Directory forest named contoso.com. The forest contains a single domain. The domain contains the domain controllers is configured as shown in the following table.
      Name Site
      DC1 Site1
      DC2 Site2
      DC3 Site3
      DC4 Site4

      The forest contains a member server named Server1. Server1 has an IP address of 172.16.10.66.
      The forest has the following Active Directory subnet configuration.

      DistinguishedName : CN=172.16.10.0/26, CN=subnets, CN=Sites, CN=Configuration,
      Location Dc=Adatum, DC=com
      Name : 172.16.10.0/26
      ObjectClass : subnet
      ObjectGUID : db362a6c-c0a9-4703-aaee-191083ab9ea5
      Site : CN=Site1, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum,
      DC=com,

      DistinguishedName : CN=172.16.10.64/26, CN=subnets, CN=Sites, CN=Configuration,
      Location Dc=Adatum, DC=com
      Name : 172.16.10.64/26
      ObjectClass : subnet
      ObjectGUID : ef101558-3afa-41f1-9c5a-717453436fc1
      Site : CN=Site2, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum,
      DC=com,

      DistinguishedName : CN=172.16.10.192/26, CN=subnets, CN=Sites, CN=Configuration,
      Location Dc=Adatum, DC=com
      Name : 172.16.10.192/26
      ObjectClass : subnet
      ObjectGUID : 33137047-6711-4195-940f-a463bbdab8fb
      Site : CN=Site4, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum,
      DC=com,

      DistinguishedName : CN=172.16.10.128/26, CN=subnets, CN=Sites, CN=Configuration,
      Location Dc=Adatum, DC=com
      Name : 172.16.10.128/26
      ObjectClass : subnet
      ObjectGUID : ef5235ab-759b-4dc8-992a-c5ec1dae97a8
      Site : CN=Site3, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum,
      DC=com,

      Use the drop down menus to select the answer choice that complete each statement.

      Answer Area

      If you promote Server1 to a domain controller, its server object will be created in [answer area]
      Site1
      Site2
      Site3
      Site4

      If you perform an Active Directory search from a domain member that has an IP address of 172.16.10.116, you will attempt to connect [answer area]
      DC1
      DC2
      DC3
      DC4

      Answer: Site 2
      Answer: DC2
      Explanation: No explanation, found on internet

      ————

      Q9: You have a server named Server1 that runs Windows Server 2012 R2 and uses Windows Server Backup.
      You need to identify whether the backups performed on Server1 support bare metal recovery.

      Which cmdlet should you run?

      A. Get-OBMachineSetting
      B. GetWBVSSBackupOption
      C. Get-WBPolicy
      D. Get-OBPolicy

      Answer: (C) Get-WBPolicy

      Explanation:
      Get-OBMachineSetting is for Azure Backup, question asks about Windows Backup
      GetWBVSSBackupOption cmdlet doesn’t exist
      Get-WBPolicy is for Windows Backup
      Get-OBPolicy is for Azure Backup, question asks Windows Backup

      ————

      Q10: You have a cluster named Cluster1 that contains two nodes. Both nodes run Windows Server 2012 R2. Cluster1 hosts a virtual machine named VM1 that runs Windows Server 2012 R2.
      You notice that VM1 is marked as being in a critical state in the cluster.
      You verify that VM1 is functioning correctly.
      You need to ensure that VM1 is no longer marked as being in a critical state.

      Which cmdlet should you run?

      A. Remove-ClusterVmMonitoredItem
      B. Remove-ClusterResourceDependency
      C. Reset-ClusterVMMonitoredState
      D. Clear-ClusterNode

      Answer: (C) Reset-ClusterVMMonitoredState

      Explanation:
      Remove-ClusterVmMonitoredItem actually removes the monitoring so nothing will happen

      Remove-ClusterResourceDependency – self explanatory has to do with dependencies, not critical state

      Reset-ClusterVMMonitoredState – This cmdlet resets the Application Critical state of a virtual machine, so that the virtual machine is no longer marked as being in a critical state in the cluster (https://technet.microsoft.com/en-us/library/hh847312(v=wps.630).aspx)

      Clear-ClusterNode – This cmdlet helps ensure that the failover cluster configuration has been completely removed from a node that was evicted.

      ————

      Q10: You run Get-FSRMClassificationule and you receive the following output

      ClassificationMechanism : Content Classfier
      ContentRegularExpression : {\d{2,}}
      ContentString :
      ContentStringCaseSensitive :
      Description :
      Disabled : False
      Flags :
      Lastmodified : 4/18/2015 12:59:47 AM

      Name : Rule2
      Namespace : {D:\}
      Parameters : {FSRMClearPropertyInternal = 0}
      Property : Property2
      PropertyValue : Value2
      ReevaluateProperty : Overwrite
      PSComputerName :

      ClassficationMechanism : FolderClassifier
      ContentRegularExpression :
      ContentString :
      ContentStringCaseSensitive :
      Description :
      Disabled : False
      Flags :
      Lastmodified : 4/15/2015 9:17:16 PM
      Name : Rule1
      Namespace : {D:\}
      Parameters : {FSRMClearPropertyInternal = 0}
      Property : Property1
      PropertyValue : Value1
      ReevaluateProperty : Aggregate
      PSComputerName :

      You have a file named file1 that is stored on drive D and has the following content
      “111000000000111111”
      You run the classification with all of the rules

      Use the drop-down menus top select the answer choice that completes each statement.

      File1 has [answer choice]

      Only Property1 set to value1
      Only Property2 set to value2
      Property1 set to value1 and property2 set to value2
      Neither Property1 nor Property2 set

      If you modify File1 [answer choice]

      Only the value of Property1 is
      Only the value of Property2 is
      the value of Property1 and Property2 are
      Neither the value of Property1 nor the value of Property2 is

      Answer:
      Explanation:

      ————

      Q11: You network contains one Active Directory domain. The domain contains two Hyper-V Hosts named Host1 and Host2 that run Windows Server 2012 R2. Host1 contains a virtual machine named DC5. DC5 is a domain controller that run Windows Server 2012 R2.
      You configure Active Directory to support domain controller cloning for DC5, and then you shut down DC5.
      You need to create a clone of DC5 on Host2
      What should you run on each Hyper-V Host.? To answer Drag the appropriate commands or cmdlets to the correct Hyper-V hosts. Each command or cmdlet may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

      Command and cmdlets

      Export-VM
      Import-VM
      Move-VM
      New-ADDCCloneConfigFile

      Answer Area

      Host1: Command or cmdlet
      Host2: Command or cmdlet

      Answer:
      Host 1: New-ADDCCloneConfigFile
      Host 2: Import-VM

      Explanation: http://blogs.technet.com/b/canitpro/archive/2013/06/12/step-by-step-domain-controller-cloning.aspx
      – Create the cloneconfig file by running ADDCCloneConfig on the source first (Step 2)
      – Export the source VM (Step 4-2)
      – Import the source VM into the new host (Step 4-3)

      ————

      Q12: You network contains one Active Directory domain named adatum.com. The domain contains a DNS server named Server1 that runs Windows Server 2012 R2. All domain computers use Server1 for DNS.
      You sign adatum.com by using DNSSEC.
      You need to configure the domain computers to validate DNS responses for adatum.com records.
      What should you configure in Group Policy?

      A. Network List Manager Policies
      B. Network Access Protection (NAP)
      C. Name Resolution Policy
      D. Public Key Policy

      Answer: (C) Name Resolution Policy
      Explanation: Name resolution policy needs to be configured in group policy.
      “In both example 1 and example 2, validation is not required for the secure.contoso.com zone because the Name Resolution Policy Table (NRPT) is not configured to require validation.” (https://technet.microsoft.com/en-us/library/jj200221.aspx)

      ————

      Q13) Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.

      Name Domain Site
      DC1 Contoso.com Main Office
      DC2 Contoso.com Main Office
      DC3 Contoso.com Europe Office
      DC4 Contoso.com Asia Office
      DC5 Sales.contoso.com Main Office
      DC6 Manufacturiung.contoso.com Main Office

      You need to add an additional UPN Suffix.
      What should you use?

      A. Set-ADSite
      B. Set-ADReplicationSite
      C. Set-ADDomain
      D. Set-ADReplicationSiteLink
      E. Set-ADGroup
      F. Set-ADForest
      G. Netdom

      Answer: (F) Set-ADForest
      Explanation: https://technet.microsoft.com/en-us/library/dd391925(v=ws.10).aspx

      ————

      Q14: Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.

      Name Domain Site
      DC1 Contoso.com Main Office
      DC2 Contoso.com Main Office
      DC3 Contoso.com Europe Office
      DC4 Contoso.com Asia Office
      DC5 Sales.contoso.com Main Office
      DC6 Manufacturiung.contoso.com Main Office

      You need to replicate users who haven’t authenticated against any domain controllers for the last 7 days.
      What should you use?

      A. Set-ADSite
      B. Set-ADReplicationSite
      C. Set-ADDomain
      D. Set-ADReplicationSiteLink
      E. Set-ADGroup
      F. Set-ADForest
      G. Netdom

      Answer: (C) Set-ADDomain
      Explanation: Not really sure on this, but perhaps its the -LastLogonReplication interval? (https://technet.microsoft.com/en-us/library/ee617212.aspx)

      ————

      Q15: You have a cluster named cluster1 that contains two nodes.
      Both nodes run windows server 2012 R2.
      cluster1 hosts a virtual machine named VM1 that runs Windows Server 2012 R2.
      You configure a custom service on VM1 named service1.
      You need to ensure that VM1 will be moved to a different node3 if service1 fails.
      which comdlet should you run on cluster1?

      options:
      a. set-clusterresiurcedependency
      b. add-clustergenericservicerole
      c. enable-vmresourcemetering
      d. add-clustervmmonitoreditem

      Answer: (D) Add-ClusterVMMonitoredItem
      Explanation: It is not B because question specifically asks to monitor an event that is running through a VM which is on the cluster.
      “Configures monitoring for a service or an Event Tracing for Windows (ETW) event so that it is monitored on a virtual machine.”
      (https://technet.microsoft.com/en-us/library/hh847288(v=wps.630).aspx)

      ————

      Q16: You have the following microsoft azure backup policy

      backup schedule : 9:00am, 12:00 pm,11:00 pm
      every day
      every 1 week(s)

      dslist : {datasource
      datasourceid:1576400609127590137
      name:c:\
      filespec:filespec
      filespec:c:\
      isexclude:false
      isrecursive:true

      }

      policyname : f77828d2-69b6-4c4b-b98a-e5e20d9ab7e9
      retentionpolicy : retention days : 30

      week1yltrsschedule :
      days: monday
      times: 12:00:00,
      retentention weeks: 60

      month1yltrschedule :
      days of month : [last,monday]
      times: 23:00:00
      retentention weeks: 90

      year1yltrschedule :
      yearly schedule is not set

      state : existing
      policystate : valid

      Answer Area:

      Of the backups that are created daily at 9:00, a maximum of recovery points will be available for restore _____
      – 30
      – 60
      – 90
      – 122
      – 366
      – 512

      if a backup is performed on monday,january 31, at 9:00,the backup will be retained for _____
      – 30 days
      – 60 weeks
      – 90 month

      Answer:
      Explanation:

      —————-

      Q17: Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.

      Name Domain Site
      DC1 Contoso.com Main Office
      DC2 Contoso.com Main Office
      DC3 Contoso.com Europe Office
      DC4 Contoso.com Asia Office
      DC5 Sales.contoso.com Main Office
      DC6 Manufacturiung.contoso.com Main Office

      for the contoso.com doamin, a company policy states that administrators must be able to retrive a list of all the users who have not logged on to the network in the last seven days from any domain controllers

      What should you use?

      A. Set-ADSite
      B. Set-ADReplicationSite
      C. Set-ADDomain
      D. Set-ADReplicationSiteLink
      E. Set-ADGroup
      F. Set-ADForest
      G. Netdom

      Answer:
      Explanation:

      ————–

      Q18: You havea dns server named server1 that runs windows server 2012 r2.
      you need to disable recursion on server1
      whatare three possible ways to achive the goal?each correct answer presents a complete solution

      A. create a reverse lookup zone named 0.in-addr.arpa.
      B. create a forward lookup zone named globalnames
      C. from dns manager,modify the advanced properties of server1
      D. from dns manager,modify the forwarders properties of server1
      E. create a forward lookup zones named “”
      F. run dnscmd.exe and specify the /config parameter

      Answer:
      Explanation:

      ————–

      Q19: your network uses the 192.168.2.0/23 address space.
      you are configuring video conferencing infrastructure.
      you need to configure the dhcp server to lease ip address for multicast address for video conferencing.
      what command should you run on the dhcp server?to answer,select the apprperiate options in the answer area

      add-dhcpserverv4multicastscope -name “vc scope” -startscope

      [Start Range] [End Range]
      192.168.2.10 192.168.2.255
      225.0.0.10 225.0.0.250
      239.0.0.1 240.0.0.0
      fd80:: fe80:
      ff00:: ff02:

      Answer:
      Explanation:

      ———-

      Q20: your network contans one active directory domain named contoso.com.the domain contains two servers named server1` and server2 that run windows server 2012 r2 .
      you perform daily backups of the data on server1 to microsoft azure.
      you need to restore the data from the lst backup of server1 to server2.
      what should you do first?

      A. on server2,install the azure backup agent.
      B. in the domain, add server1 to the backup operators group.
      C. from the azure management portal, modify the configuration of the backup vault.
      D. on server2,install the windows server backup feature.

      Answer:
      Explanation:

      ———-

      Q21: Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.

      Name Domain Site
      DC1 Contoso.com Main Office
      DC2 Contoso.com Main Office
      DC3 Contoso.com Europe Office
      DC4 Contoso.com Asia Office
      DC5 Sales.contoso.com Main Office
      DC6 Manufacturiung.contoso.com Main Office

      you need to enable universal group membership caching for the europe office and asia office sites.

      What should you use?

      A. Set-ADSite
      B. Set-ADReplicationSite
      C. Set-ADDomain
      D. Set-ADReplicationSiteLink
      E. Set-ADGroup
      F. Set-ADForest
      G. Netdom

      Answer:
      Explanation:

      ———-

      Q22: you have dhcp server named server1 that runs windows server 2012r2.
      server1 has two scope production and development.
      currebntly,all dhcp clients register their host name in a dns zone named contoso.com.
      you need to ensure that only the clients that obtain an ip address from the development scope,register their host name in a dns zone named dev.contoso.com.
      what should you do?

      A. modify the advanced settings of the dhcp server.
      B. run the set-dhcpserver4scope cmdlet.
      C. modify the dns settings of the development scope.
      D. run the add-dhcpserver4policy cmdlet.

      Answer:
      Explanation:

      ———-

      Q23: your network contains one active directory domain.the domain contains the servers configured as shown in the following table.

      server1 domain controllers
      dns server

      server2 domain controllers
      dns server

      server3 dns server

      server1 hasthe zones shown in the following table:

      zone name zone type Isautocreated Isdsintegrated Isreverselookupzone Issigned

      adatum.com primary false false false false
      contoso.com primary false true false false
      litwareinc.com secondary false true false false

      server3 has the following output:

      zone name zone type Isautocreated Isdsintegrated Isreverselookupzone Issigned

      contoso.com secondary false true false false
      litwareinc.com primary false true false false

      use the drop down list must select trhe answer choice that completes each assignment.

      —you can protect [answer choice] by using dnssec:

      only adatum.com
      only contoso.com
      only litwareinc.com
      only contoso.com and adatum.com
      contoso.com,adatum.com and litwareinc.com

      —on server1,you configure permissions for the contoso.com zone.the permission will be efficitive on [answer choice]:

      server1 only
      server1 and server2 only
      server1 and server3 only
      server1,server2 and server3.

      Answer:
      Explanation:

      ———-

      Q24: your network contains an active directory domain anmed contoso.com.
      the domain contains the server named server1 that runs windows server 2012r2.
      server1 has the active directory rights management services server role installed.

      the domain contains a domain local group named group1
      you create a rights policy template named template1.
      you need to ensure that all the members of group1 can use template1.

      What should you do?

      A. Convert the scope of group1 to universal and assign group1 the rights to template1
      B. Convert the scope of group1 to global and configure the email address attribute of group1.
      C. Configure the email address attribute of group1 and configure the email address attribute of all the users are members of group1.
      D. Configure the email address of all the users who are members of group1 and assign group1 the rights to template1.

      Answer:
      Explanation:

      ———-

      Q25:

      you have a server that runs windows server 2012r2.
      you create a new work folder named share1.
      you need to configure share1 to meet the follwoing requirements:

      *ensure that all synchronized copies of share1 are encrypted.
      *ensure that clients synchronize to share1 every 30 minutes.
      *ensure that share1 inherits the ntfs permissions of the parent folder.

      Which command should you use to achive each requirements?

      to answer,drag the appropriate cmdlets to the correct requirements.each cmdlet may be used once.more than once,or not at all.
      you may need to drag ther splitbacr between panes or scroll to view cmdlet?

      Availible cmdlets:

      enable-synshare
      new-syncdevicepolicy
      new-syncshare
      set-syncdevicepolicy
      set-syncserversetting
      set-synshare

      answer area:

      ensure that all synchronized copies of share1 area encrypted _______________
      ensure that clients synchronize to share1 every 30 minutes _______________
      ensure that share1 inherits the ntfs permissions of the percentage _______________

      Answer:
      Explanation:




      0



      0
  1. Jason says:

    Global Catalog
    DC1 |contoso.com | Site1 | Yes
    DC2 |constoso.com | Site2 | No
    DC3 |adatum.com | Site2 | Yes
    DC4 |adatum.com | Site1 | No

    1. Create and place File1.txt inside SYSVOL folder on DC1
    2. Create User account User1 on DC3
    3. Create Group Policy GPO1 and link GPO1 to site 2

    Q. Mark whether the item is replicated to the appropriate DC

    File1.txt User1 GPO1
    DC1 ___________|_________|________
    DC2 ___________|_________|________
    DC3 ___________|_________|________
    DC4 ___________|_________|________




    0



    0
    1. bob says:

      + 1 to this! My thoughts…

      File1.txt is on DC1 and if located in the SYSVOL folder, I think it would replicate much like a GPO would, to all the servers regardless of site, based on my interpretation of this article. DC1 DC2 DC3 and DC4
      http://social.technet.microsoft.com/wiki/contents/articles/8548.sysvol-and-netlogon-share-importance-in-active-directory.aspx

      User1 I believe would replicate to servers with the Global Catalog so DC1 and DC3. (Global Catalogs hold a copy of all user info from all the domains in the forest. By that assumption, the servers that don’t hold the GC won’t have users)

      The GPO although linked to site 2 would replicate to all servers via the SYSVOL/policies folder. So My guess would be DC1 DC2 DC3 and DC4?




      0



      0
    2. bob says:

      Anyone figure out the answer to this one yet? I’ve seen this one on a previous attempt. I’m assuming Column 1 is all checked, column two is just DC1 and DC3 (the gloabl catalogs) and column 3 is also all checked because GPOs are replicated via sysvol?

      Can anyone confirm or refute?




      0



      0
      1. Aaron says:

        This question states that they are 2 separate forests so my take is top 2, bottom 2, top 2 as replication does not cross forests.

        If they were 2 domains in the same forest i would say:

        1,2/1,3,4/1,2,3




        0



        0
        1. Watcher says:

          I agree Aaron that if in a separate forest top 2 bottom 2 and top 2 is right. SYSVOL replication is per domain anyway. As is user replication and GPO’s. I disagree if they’re separate domains in the same forest. I still say the same thing will happen as before. GC’s contain a subset of information of AD objects. As far as I know the user object is not replicated – just enough attribute information to enable searches to come back with the correct results (I could be wrong there but I haven’t seen anything that indicates that). GPO’s get created in the SYSVOL folder so they have the same replication scope as your file. I’ve never heard of a GPO from a parent domain being applied to a child domain or another AD tree – stand to be corrected there but I don’t know how you could do it?




          0



          0
          1. Watcher says:

            Not sure about the wording of the last one there too – there’s two site 2’s! I expect in the real question the question is either more specific or the sites are labelled differently. In either case I’d only mark the replication to occur within the same domain.




            0



            0
    1. Peter says:

      To configure something that is already there use Set- PS_Command [not Add-].
      Out of 2 Set- commands offered. Set-DHCPv6Class does not seem to exist.
      That leaves use with …
      The Answer: Set-DHCPv6OptionValue -InfoRefreshTime
      Specifies the value for the information refresh option. This parameter is used with stateless DHCPv6 as there are no addresses or other entities with lifetimes that can tell the client when to contact the DHCPv6 server to refresh its configuration.
      Source: https://technet.microsoft.com/en-us/%5Clibrary/JJ590694%28v=WPS.630%29.aspx




      0



      0
  2. bob says:

    Certificate Server

    Question | Exhibit 1 (Server1) (CA) | Exhibit 2 (Server2) (CA-1) | Exhibit 3

    Exhibit 1: Picture of a certsrv folder structure (without a Certificate Templates Folder)
    Exhibit 2: Picture of a certsrv folder structure (With a Certificate Templates Folder)
    Exhibit 3: A certificate with “Issued to: CA-1” and “Issued BY: CA”

    Yes | No
    1. Server 1 is an enterprise CA?
    2. Server 2 is an enterprise CA?
    3. Server 1 is a subordinate server to server 2?




    0



    0
    1. Annihilator says:

      Answers:
      1) No (see explanation)
      2) Yes (see explanation)
      3) No (because the certificate is issued by CA to CA-1. Means that server2 must be a subordinate server to server 1)

      Explanation

      Stand Alone CA
      * No Certificate templates available (specific requests are required)
      * No autoenrollment available (approval needed)
      * Supported by AD environments and non-AD environments
      * Most of the times used for root and policy CAs that are offline)

      Enterprise CA
      * Certificate templates available
      * Autoenrollment is possible
      * Supported by AD environments
      * Most of the times used for issuing certs to end-entities

      http://www.experts-exchange.com/Networking/Protocols/SSL/Q_24993799.html




      0



      0
  3. grande says:

    Even the “new” questions posted here are now outdated. Looks like we have to pay $100 and give away anonymity to get anywhere in these tests. Sorry, I can’t read a million TechNet articles and have perfect recall as applied to various new scenarios. Doesn’t look like I’ll get an MCSA anytime soon.




    0



    0
    1. Aaron says:

      Sorry but I do not accept your winging as valid. If you are relying on these dumps to get your MCSA you should never get one. You should use these dumps to confirm your knowledge gained from text books and real life use of Server 2012. Not memorize the answers…




      0



      0
      1. grande says:

        That logic fails consistently, Aaron. The fact is that Microsoft is now finding every obscure example of the subject matter and people are failing consistently. Microsoft knows it. $100 Dump sites know it. And a lot of people are making money from it. I’ve seen first hand 15% pass rates in high traffic testing centers from people with 3-years+ experience in the field. This isn’t a matter for personal opinion about who should be certified. Certifications are no better than college degrees. It’s always up to the individual to prove themselves. There are so many practical day-to-day applications that aren’t even covered in these tests. The capitalizing of this information that should be freely accessible is just one more example of the internet becoming less free. People can still get what is in ‘your’ opinion a false certificate. The only difference with the failing of information sites like this used to be is that it now costs $100. So talented poor people don’t have the same opportunity as someone with $100 cash available to them.




        0



        0
      2. Annihilator says:

        I disagree completely. I started studying for MCSE since 1998 Windows V3.51. 18 Years certified now but I have to agree with grande. I’m a very experienced self employed IT Pro. The exams from Microsoft are a bunch crap. The only reason you need the certificate is because customers ask proof of certification.

        Loads of questions aren’t from the books or real life use. If that was the case this site didn’t have so many visitors. It’s easier to study from a book compared to visiting this site and dig through 600 questions (and checking them). Believe me I read all the books but that’s not enough to certify. Maybe I have to conclude that I’m to stupid for the IT business after 18 years?




        0



        0
  4. Bruce941 says:

    I sat for the 70-412 test yesterday and passed (second shot). I know for sure that if I had NOT seen the new questions posted by bopbop that I would have failed again. As far as I’m concerned, yes, having answers is great, having discussions it also helpful, but go out and research the questions that you don’t know. I’m sure MS does more than just change the names of the companies/domains up on the test.

    I would guess that for every 100 hours I spend studying, a good 40 – 50% of that time is spent researching. The problem with researching is that no matter how hard you try, you can’t seem to get a definite answer for each question – Technet is not always forthcoming with concise and understandable information.

    I’ll go back later and see if I can find the ones I missed. Now, it’s time to get back to the 70-411 – it’s the last one I need to pass – I’ve failed it four times already.




    0



    0
  5. Bruce941 says:

    I sat for the 70-412 test yesterday and passed (second shot – 740). I know for sure that if I had NOT seen the new questions posted by bopbop that I would have failed again. As far as I’m concerned, yes, having answers is great, having discussions it also helpful, but go out and research the questions that you don’t know. I’m sure MS does more than just change the names of the companies/domains up on the test.

    I would guess that for every 100 hours I spend studying, a good 40 – 50% of that time is spent researching. The problem with researching is that no matter how hard you try, you can’t seem to get a definite answer for each question – Technet is not always forthcoming with concise and understandable information.

    I’ll go back later and see if I can find the ones I missed. Now, it’s time to get back to the 70-411 – it’s the last one I need to pass – I’ve failed it four times already.




    0



    0
  6. jealheca says:

    Hi, Which is the answer? Thank you

    Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.
    Name Domain Site
    DC1 Contoso.com Main Office
    DC2 Contoso.com Main Office
    DC3 Contoso.com Europe Office
    DC4 Contoso.com Asia Office
    DC5 Sales.contoso.com Main Office
    DC6 Manufacturiung.contoso.com Main Office
    you need to enable universal group membership caching for the europe office and asia office sites.
    What should you use?
    A. Set-ADSite
    B. Set-ADReplicationSite
    C. Set-ADDomain
    D. Set-ADReplicationSiteLink
    E. Set-ADGroup
    F. Set-ADForest
    G. Netdom




    0



    0
  7. jealheca says:

    HI, Help, which are the answers? Thank you

    Q1–You have the following microsoft azure backup policy
    backup schedule : 9:00am, 12:00 pm,11:00 pm
    every day
    every 1 week(s)
    dslist : {datasource
    datasourceid:1576400609127590137
    name:c:\
    filespec:filespec
    filespec:c:\
    isexclude:false
    isrecursive:true
    }
    policyname : f77828d2-69b6-4c4b-b98a-e5e20d9ab7e9
    retentionpolicy : retention days : 30
    week1yltrsschedule :
    days: monday
    times: 12:00:00,
    retentention weeks: 60
    month1yltrschedule :
    days of month : [last,monday]
    times: 23:00:00
    retentention weeks: 90
    year1yltrschedule :
    yearly schedule is not set
    state : existing
    policystate : valid
    Answer Area:
    Of the backups that are created daily at 9:00, a maximum of recovery points will be available for restore _____
    – 30
    – 60
    – 90
    – 122
    – 366
    – 512
    if a backup is performed on monday,january 31, at 9:00,the backup will be retained for _____
    – 30 days
    – 60 weeks
    – 90 month

    Q2–You have dhcp server named server1 that runs windows server 2012r2.
    server1 has two scope production and development.
    currently, all dhcp clients register their host name in a dns zone named contoso.com.
    you need to ensure that only the clients that obtain an ip address from the development scope, register their host name in a dns zone named dev.contoso.com.
    what should you do?
    A. modify the advanced settings of the dhcp server.
    B. run the set-dhcpserver4scope cmdlet.
    C. modify the dns settings of the development scope.
    D. run the add-dhcpserver4policy cmdlet.




    0



    0
  8. MadMilkman says:

    Q 18:

    C, D:

    There are various situations where you would want to prevent your DNS server from performing a recursive query. Depending on what you are trying to accomplish, there are two settings that have caused confusion amongst DNS administrators. These two settings are “Do not use recursion for this domain” found in the Forwarders tab and “Disable Recursion” found in the Advanced tab. Let’ s take a look at these settings in more detail.
    http://www.itgeared.com/articles/1050-do-not-use-recursion-for-this-domain-vs/

    F:
    dnscmd /Config /NoRecursion {1|0}




    0



    0
  9. MadMilkman says:

    Q 19:

    Since multicast adresses can be in range: 224.0.0.0–239.255.255.255

    We can see than in “End Range” only adress we can use is 225.0.0.250 So from the first column (Start Range) we must chose 225.0.0.10.




    0



    0
  10. MadMilkman says:

    I passed the exam so i would like to give you some advice:

    1.) The most important thing is that you shouldn’t memorize answers. Microsoft tends to change questions slightly, or offer different answers for same question. What you should do is learn the subject based on question at hand. Following this advice, you will be able to answer even new questions that u haven’t seen before.

    2.) In these dumps there is a lot of wrong answers, even the ones where most people agree about answers could be wrong. Don’t believe dumps, even the premium ones, because they just copy from each other. My advice would be to research every question and research every offered answer.

    3.) And pliz get your hand on server. It doesn’t even have to be server, install Win 8 on your personal computer and use Hyper V to install Win server 2012 R2 evaluation version (seems the simplest solution in my opinion).

    Good luck everyone!




    0



    0

Leave a Reply