Your company recently deployed a new Active Directory forest named contoso.com. The first
domain controller in the forest runs Windows Server 2012 R2.
You need to identify the time-to-live (TTL) value for domain referrals to the NETLOGON and
SYSVOL shared folders.
Which tool should you use?

A.
Ultrasound
B.
Replmon
C.
Dfsdiag
D.
Frsutil
these just look like the same questions from the 412(v2)
0
0
C.
Dfsdiag
0
0
Today Pass Exam studing 412 V2 and 412 V3, much questions are confirm and correction by my.
0
0
i taught as much too
0
0
Here is a complete list of the new questions including some of fabolous’
I edited and formatted it. Answered some of the questions I know. Please post them so we can get the answers..
Q1: You have an enterprise certification authority (CA) named CA1.
You have a certificate template named UserAutoEnroll that is based on the User certificate template. Domain users are configured to autoenroll for UserAutoEnroll.
A user named User1 has an email address defined in Active Directory. A user named User2 does not have an email address defined in Active Directory.
You discover that User1 was issued a certificate based on UserAutoEnroll template automatically. A request by user2 for a certificate based on the UserAutoEnroll template fails.
You need to ensure that all users can autoenroll for certificated based on the UserAutoEnroll template.
Which setting should you configure from the properties on the UserAutoEnroll certificate template?
A. Issuance Requirements
B. Request Handling
C. Cryptography
D. Subject Name
Answer: (D) Subject Name
Explanation:
————
Q2: Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.
Name Domain Site
DC1 Contoso.com Main Office
DC2 Contoso.com Main Office
DC3 Contoso.com Europe Office
DC4 Contoso.com Asia Office
DC5 Sales.contoso.com Main Office
DC6 Manufacturiung.contoso.com Main Office
You create a trust between contoso.com and a domain in another forest at a partner company.
You need to prevent the sales.contoso.com and the manufacturing.contoso.com names from being used in authentication requests across the forest trust.
What should you use?
A. Set-ADSite
B. Set-ADReplicationSite
C. Set-ADDomain
D. Set-ADReplicationSiteLink
E. Set-ADGroup
F. Set-ADForest
G. Netdom
Answer: (G) Netdom
Explanation: The question seems to be describing “Selective Authentication.” I was able to find a Server 2008 article but not 2012 (https://technet.microsoft.com/en-us/library/cc794747(v=ws.10).aspx)
————–
Q3: Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.
Name Domain Site
DC1 Contoso.com Main Office
DC2 Contoso.com Main Office
DC3 Contoso.com Europe Office
DC4 Contoso.com Asia Office
DC5 Sales.contoso.com Main Office
DC6 Manufacturiung.contoso.com Main Office
You need to prevent administrators from accidently deleting any of the site in the forest.
What should you use?
A. Set-ADSite
B. Set-ADReplicationSite
C. Set-ADDomain
D. Set-ADReplicationSiteLink
E. Set-ADGroup
F. Set-ADForest
G. Netdom
Answer: (B) Set-ADReplicationSite
Explanation: Use the ‘-ProtectedFromAccidentalDeletion” switch (https://technet.microsoft.com/en-us/library/hh852305(v=wps.630).aspx)
————–
Q4: Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.
Name Domain Site
DC1 Contoso.com Main Office
DC2 Contoso.com Main Office
DC3 Contoso.com Europe Office
DC4 Contoso.com Asia Office
DC5 Sales.contoso.com Main Office
DC6 Manufacturiung.contoso.com Main Office
You need ensure that all Active Directory changes are replicated to all of the domain controllers in the forest within 30 minutes.
What should you use?
A. Set-ADSite
B. Set-ADReplicationSite
C. Set-ADDomain
D. Set-ADReplicationSiteLink
E. Set-ADGroup
F. Set-ADForest
G. Netdom
Answer: (D) Set-ADSiteReplicationLink
Explanation: Use the “-ReplicationFrequencyInMinuites” switch (https://technet.microsoft.com/en-us/library/hh852257(v=wps.630).aspx)
————
Q 5: Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.
Name Domain Site
DC1 Contoso.com Main Office
DC2 Contoso.com Main Office
DC3 Contoso.com Europe Office
DC4 Contoso.com Asia Office
DC5 Sales.contoso.com Main Office
DC6 Manufacturiung.contoso.com Main Office
You have a trust from contoo.com to another forest named fabrikam.com.
You plan to migrate users from contodo.com to fabrikam.com.
You need to ensure that the users who migrated to fabrikam.com can continue to access shared resources in contoso.com. the solution must not require administrators to modify permissions to shared resources.
What should you use?
A. Set-ADSite
B. Set-ADReplicationSite
C. Set-ADDomain
D. Set-ADReplicationSiteLink
E. Set-ADGroup
F. Set-ADForest
G. Netdom
Answer: (G) Netdom
Explanation: It should be Netdom, you need and enable “sidhistory” (https://technet.microsoft.com/en-us/library/cc794801(v=ws.10).aspx)
————
Q6: your network contains one Active Directory forest named adatum.com. The forest contains a single domain.
The site topology for the forest is shown in the exhibit.
Each site contain s one domain controller.
You need to ensure that replication between site2 and site4 occurs in 15 minutes or less.
What command should you run? To answer select the appropriate options in the answer area.
Answer Area
New-AdReplicationSiteLink
New-ADReplicationLinkBridge
Set-ADReplicationConnection
Set-ADReplicationSiteLink
Set-ADReplicationSiteLinkBridge
-name
SiteLink3
SiteLink6
SiteLink1, SiteLink2
-SitesIncluded Site2, Site4
–ReplicationFrequencyinMinutes 15
–Cost
70
110
400
Answer: New-AdReplicationSiteLink (Select Name (SiteLink3?)) -SitesIncluded Site1,Site4 -Cost 70
Explanation: See Example 2: Create a replication site link and set properties for it (https://technet.microsoft.com/en-us/library/hh852320(v=wps.630).aspx)
Lower the cost should be higher priority. Notice I put (Select Name.) I am not sure if this is written incorrectly or we need to actually refer to the site topolgy exhibit which would appear int he exam. I would assume the name would be SiteLink2-SiteLink4 but that option is not there. So this is something you will have to pay attention to when you do the exam.
————
Q7: Your network contains one Active Directory forest named contoso.com. The forest contains a single domain. The domain contains the domain controllers is configured as shown in the following table.
Name Site
DC1 Site1
DC2 Site2
DC3 Site3
DC4 Site4
The replication topology is configured as shown in the following output.
Cost : 100
DistinguishedName : CN=SiteLink1, CN=IP, CN=Inter-Site Transports, CN=Sites, CN=Configuration, Dc=Adatum, DC=com
Name : SiteLink1
ObjectClass : SiteLink
ObjectGUID : e1c8c335-b75f-4612-8a9e-58a0edead21f
ReplInterval : 60
SiteList : {CN=Site4, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com,
CN=Site2, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com}
Cost : 100
DistinguishedName : CN=SiteLink1, CN=IP, CN=Inter-Site Transports, CN=Sites, CN=Configuration, Dc=Adatum, DC=com
Name : SiteLink2
ObjectClass :SiteLink
ObjectGUID : 9516948e-cd56-4a9b-b6ba-cdf3dd7fe0d1
ReplInterval : 60
SiteList : {CN=Site4, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com,
CN=Site2, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com}
Cost : 100
DistinguishedName : CN=SiteLink3, CN=IP, CN=Inter-Site Transports, CN=Sites, CN=Configuration, Dc=Adatum, DC=com
Name : SiteLink3
ObjectClass : SiteLink
ObjectGUID : 07a7a37e-a12c-40c4-8042-f5d2e737b8a9
ReplInterval : 60
SiteList : {CN=Site4, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com,
CN=Site3, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com}
Cost : 400
DistinguishedName : CN=SiteLink4, CN=IP, CN=Inter-Site Transports, CN=Sites, CN=Configuration, Dc=Adatum, DC=com
Name : SiteLink4
ObjectClass : SiteLink
ObjectGUID : 508810dc-30fd-4845-982a-d4552fba2e04
ReplInterval : 45
SiteList : {CN=Site4, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com,
CN=Site2, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum, DC=com}
You discover that replication between DC1 and DC3 takes a few hours.
You need to reduce the amount of time it takes to replicate Active Directory changes between DC1 and DC3.
What should you do?
A. Create a site link that connects Site1 and Site3, has a cost of 350, and replicates every 15 minutes.
B. Modify SiteLink4 to replicate every 15 minute.
C. Disable Site Link bridging.
D. Set the cost of SiteLink4 to 100.
Answer: (D) Set the cost of SiteLink4 to 100.
Explanation: No explanation, found answer on internet
————
Q8: your network contains one Active Directory forest named contoso.com. The forest contains a single domain. The domain contains the domain controllers is configured as shown in the following table.
Name Site
DC1 Site1
DC2 Site2
DC3 Site3
DC4 Site4
The forest contains a member server named Server1. Server1 has an IP address of 172.16.10.66.
The forest has the following Active Directory subnet configuration.
DistinguishedName : CN=172.16.10.0/26, CN=subnets, CN=Sites, CN=Configuration,
Location Dc=Adatum, DC=com
Name : 172.16.10.0/26
ObjectClass : subnet
ObjectGUID : db362a6c-c0a9-4703-aaee-191083ab9ea5
Site : CN=Site1, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum,
DC=com,
DistinguishedName : CN=172.16.10.64/26, CN=subnets, CN=Sites, CN=Configuration,
Location Dc=Adatum, DC=com
Name : 172.16.10.64/26
ObjectClass : subnet
ObjectGUID : ef101558-3afa-41f1-9c5a-717453436fc1
Site : CN=Site2, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum,
DC=com,
DistinguishedName : CN=172.16.10.192/26, CN=subnets, CN=Sites, CN=Configuration,
Location Dc=Adatum, DC=com
Name : 172.16.10.192/26
ObjectClass : subnet
ObjectGUID : 33137047-6711-4195-940f-a463bbdab8fb
Site : CN=Site4, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum,
DC=com,
DistinguishedName : CN=172.16.10.128/26, CN=subnets, CN=Sites, CN=Configuration,
Location Dc=Adatum, DC=com
Name : 172.16.10.128/26
ObjectClass : subnet
ObjectGUID : ef5235ab-759b-4dc8-992a-c5ec1dae97a8
Site : CN=Site3, CN=Sites, CN=Configuration, DC=Adatum, DC=Adatum,
DC=com,
Use the drop down menus to select the answer choice that complete each statement.
Answer Area
If you promote Server1 to a domain controller, its server object will be created in [answer area]
Site1
Site2
Site3
Site4
If you perform an Active Directory search from a domain member that has an IP address of 172.16.10.116, you will attempt to connect [answer area]
DC1
DC2
DC3
DC4
Answer: Site 2
Answer: DC2
Explanation: No explanation, found on internet
————
Q9: You have a server named Server1 that runs Windows Server 2012 R2 and uses Windows Server Backup.
You need to identify whether the backups performed on Server1 support bare metal recovery.
Which cmdlet should you run?
A. Get-OBMachineSetting
B. GetWBVSSBackupOption
C. Get-WBPolicy
D. Get-OBPolicy
Answer: (C) Get-WBPolicy
Explanation:
Get-OBMachineSetting is for Azure Backup, question asks about Windows Backup
GetWBVSSBackupOption cmdlet doesn’t exist
Get-WBPolicy is for Windows Backup
Get-OBPolicy is for Azure Backup, question asks Windows Backup
————
Q10: You have a cluster named Cluster1 that contains two nodes. Both nodes run Windows Server 2012 R2. Cluster1 hosts a virtual machine named VM1 that runs Windows Server 2012 R2.
You notice that VM1 is marked as being in a critical state in the cluster.
You verify that VM1 is functioning correctly.
You need to ensure that VM1 is no longer marked as being in a critical state.
Which cmdlet should you run?
A. Remove-ClusterVmMonitoredItem
B. Remove-ClusterResourceDependency
C. Reset-ClusterVMMonitoredState
D. Clear-ClusterNode
Answer: (C) Reset-ClusterVMMonitoredState
Explanation:
Remove-ClusterVmMonitoredItem actually removes the monitoring so nothing will happen
Remove-ClusterResourceDependency – self explanatory has to do with dependencies, not critical state
Reset-ClusterVMMonitoredState – This cmdlet resets the Application Critical state of a virtual machine, so that the virtual machine is no longer marked as being in a critical state in the cluster (https://technet.microsoft.com/en-us/library/hh847312(v=wps.630).aspx)
Clear-ClusterNode – This cmdlet helps ensure that the failover cluster configuration has been completely removed from a node that was evicted.
————
Q10: You run Get-FSRMClassificationule and you receive the following output
ClassificationMechanism : Content Classfier
ContentRegularExpression : {\d{2,}}
ContentString :
ContentStringCaseSensitive :
Description :
Disabled : False
Flags :
Lastmodified : 4/18/2015 12:59:47 AM
Name : Rule2
Namespace : {D:\}
Parameters : {FSRMClearPropertyInternal = 0}
Property : Property2
PropertyValue : Value2
ReevaluateProperty : Overwrite
PSComputerName :
ClassficationMechanism : FolderClassifier
ContentRegularExpression :
ContentString :
ContentStringCaseSensitive :
Description :
Disabled : False
Flags :
Lastmodified : 4/15/2015 9:17:16 PM
Name : Rule1
Namespace : {D:\}
Parameters : {FSRMClearPropertyInternal = 0}
Property : Property1
PropertyValue : Value1
ReevaluateProperty : Aggregate
PSComputerName :
You have a file named file1 that is stored on drive D and has the following content
“111000000000111111”
You run the classification with all of the rules
Use the drop-down menus top select the answer choice that completes each statement.
File1 has [answer choice]
Only Property1 set to value1
Only Property2 set to value2
Property1 set to value1 and property2 set to value2
Neither Property1 nor Property2 set
If you modify File1 [answer choice]
Only the value of Property1 is
Only the value of Property2 is
the value of Property1 and Property2 are
Neither the value of Property1 nor the value of Property2 is
Answer:
Explanation:
————
Q11: You network contains one Active Directory domain. The domain contains two Hyper-V Hosts named Host1 and Host2 that run Windows Server 2012 R2. Host1 contains a virtual machine named DC5. DC5 is a domain controller that run Windows Server 2012 R2.
You configure Active Directory to support domain controller cloning for DC5, and then you shut down DC5.
You need to create a clone of DC5 on Host2
What should you run on each Hyper-V Host.? To answer Drag the appropriate commands or cmdlets to the correct Hyper-V hosts. Each command or cmdlet may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Command and cmdlets
Export-VM
Import-VM
Move-VM
New-ADDCCloneConfigFile
Answer Area
Host1: Command or cmdlet
Host2: Command or cmdlet
Answer:
Host 1: New-ADDCCloneConfigFile
Host 2: Import-VM
Explanation: http://blogs.technet.com/b/canitpro/archive/2013/06/12/step-by-step-domain-controller-cloning.aspx
– Create the cloneconfig file by running ADDCCloneConfig on the source first (Step 2)
– Export the source VM (Step 4-2)
– Import the source VM into the new host (Step 4-3)
————
Q12: You network contains one Active Directory domain named adatum.com. The domain contains a DNS server named Server1 that runs Windows Server 2012 R2. All domain computers use Server1 for DNS.
You sign adatum.com by using DNSSEC.
You need to configure the domain computers to validate DNS responses for adatum.com records.
What should you configure in Group Policy?
A. Network List Manager Policies
B. Network Access Protection (NAP)
C. Name Resolution Policy
D. Public Key Policy
Answer: (C) Name Resolution Policy
Explanation: Name resolution policy needs to be configured in group policy.
“In both example 1 and example 2, validation is not required for the secure.contoso.com zone because the Name Resolution Policy Table (NRPT) is not configured to require validation.” (https://technet.microsoft.com/en-us/library/jj200221.aspx)
————
Q13) Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.
Name Domain Site
DC1 Contoso.com Main Office
DC2 Contoso.com Main Office
DC3 Contoso.com Europe Office
DC4 Contoso.com Asia Office
DC5 Sales.contoso.com Main Office
DC6 Manufacturiung.contoso.com Main Office
You need to add an additional UPN Suffix.
What should you use?
A. Set-ADSite
B. Set-ADReplicationSite
C. Set-ADDomain
D. Set-ADReplicationSiteLink
E. Set-ADGroup
F. Set-ADForest
G. Netdom
Answer: (F) Set-ADForest
Explanation: https://technet.microsoft.com/en-us/library/dd391925(v=ws.10).aspx
————
Q14: Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.
Name Domain Site
DC1 Contoso.com Main Office
DC2 Contoso.com Main Office
DC3 Contoso.com Europe Office
DC4 Contoso.com Asia Office
DC5 Sales.contoso.com Main Office
DC6 Manufacturiung.contoso.com Main Office
You need to replicate users who haven’t authenticated against any domain controllers for the last 7 days.
What should you use?
A. Set-ADSite
B. Set-ADReplicationSite
C. Set-ADDomain
D. Set-ADReplicationSiteLink
E. Set-ADGroup
F. Set-ADForest
G. Netdom
Answer: (C) Set-ADDomain
Explanation: Not really sure on this, but perhaps its the -LastLogonReplication interval? (https://technet.microsoft.com/en-us/library/ee617212.aspx)
————
Q15: You have a cluster named cluster1 that contains two nodes.
Both nodes run windows server 2012 R2.
cluster1 hosts a virtual machine named VM1 that runs Windows Server 2012 R2.
You configure a custom service on VM1 named service1.
You need to ensure that VM1 will be moved to a different node3 if service1 fails.
which comdlet should you run on cluster1?
options:
a. set-clusterresiurcedependency
b. add-clustergenericservicerole
c. enable-vmresourcemetering
d. add-clustervmmonitoreditem
Answer: (D) Add-ClusterVMMonitoredItem
Explanation: It is not B because question specifically asks to monitor an event that is running through a VM which is on the cluster.
“Configures monitoring for a service or an Event Tracing for Windows (ETW) event so that it is monitored on a virtual machine.”
(https://technet.microsoft.com/en-us/library/hh847288(v=wps.630).aspx)
————
Q16: You have the following microsoft azure backup policy
backup schedule : 9:00am, 12:00 pm,11:00 pm
every day
every 1 week(s)
dslist : {datasource
datasourceid:1576400609127590137
name:c:\
filespec:filespec
filespec:c:\
isexclude:false
isrecursive:true
}
policyname : f77828d2-69b6-4c4b-b98a-e5e20d9ab7e9
retentionpolicy : retention days : 30
week1yltrsschedule :
days: monday
times: 12:00:00,
retentention weeks: 60
month1yltrschedule :
days of month : [last,monday]
times: 23:00:00
retentention weeks: 90
year1yltrschedule :
yearly schedule is not set
state : existing
policystate : valid
Answer Area:
Of the backups that are created daily at 9:00, a maximum of recovery points will be available for restore _____
– 30
– 60
– 90
– 122
– 366
– 512
if a backup is performed on monday,january 31, at 9:00,the backup will be retained for _____
– 30 days
– 60 weeks
– 90 month
Answer:
Explanation:
—————-
Q17: Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.
Name Domain Site
DC1 Contoso.com Main Office
DC2 Contoso.com Main Office
DC3 Contoso.com Europe Office
DC4 Contoso.com Asia Office
DC5 Sales.contoso.com Main Office
DC6 Manufacturiung.contoso.com Main Office
for the contoso.com doamin, a company policy states that administrators must be able to retrive a list of all the users who have not logged on to the network in the last seven days from any domain controllers
What should you use?
A. Set-ADSite
B. Set-ADReplicationSite
C. Set-ADDomain
D. Set-ADReplicationSiteLink
E. Set-ADGroup
F. Set-ADForest
G. Netdom
Answer:
Explanation:
————–
Q18: You havea dns server named server1 that runs windows server 2012 r2.
you need to disable recursion on server1
whatare three possible ways to achive the goal?each correct answer presents a complete solution
A. create a reverse lookup zone named 0.in-addr.arpa.
B. create a forward lookup zone named globalnames
C. from dns manager,modify the advanced properties of server1
D. from dns manager,modify the forwarders properties of server1
E. create a forward lookup zones named “”
F. run dnscmd.exe and specify the /config parameter
Answer:
Explanation:
————–
Q19: your network uses the 192.168.2.0/23 address space.
you are configuring video conferencing infrastructure.
you need to configure the dhcp server to lease ip address for multicast address for video conferencing.
what command should you run on the dhcp server?to answer,select the apprperiate options in the answer area
add-dhcpserverv4multicastscope -name “vc scope” -startscope
[Start Range] [End Range]
192.168.2.10 192.168.2.255
225.0.0.10 225.0.0.250
239.0.0.1 240.0.0.0
fd80:: fe80:
ff00:: ff02:
Answer:
Explanation:
———-
Q20: your network contans one active directory domain named contoso.com.the domain contains two servers named server1` and server2 that run windows server 2012 r2 .
you perform daily backups of the data on server1 to microsoft azure.
you need to restore the data from the lst backup of server1 to server2.
what should you do first?
A. on server2,install the azure backup agent.
B. in the domain, add server1 to the backup operators group.
C. from the azure management portal, modify the configuration of the backup vault.
D. on server2,install the windows server backup feature.
Answer:
Explanation:
———-
Q21: Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.
Name Domain Site
DC1 Contoso.com Main Office
DC2 Contoso.com Main Office
DC3 Contoso.com Europe Office
DC4 Contoso.com Asia Office
DC5 Sales.contoso.com Main Office
DC6 Manufacturiung.contoso.com Main Office
you need to enable universal group membership caching for the europe office and asia office sites.
What should you use?
A. Set-ADSite
B. Set-ADReplicationSite
C. Set-ADDomain
D. Set-ADReplicationSiteLink
E. Set-ADGroup
F. Set-ADForest
G. Netdom
Answer:
Explanation:
———-
Q22: you have dhcp server named server1 that runs windows server 2012r2.
server1 has two scope production and development.
currebntly,all dhcp clients register their host name in a dns zone named contoso.com.
you need to ensure that only the clients that obtain an ip address from the development scope,register their host name in a dns zone named dev.contoso.com.
what should you do?
A. modify the advanced settings of the dhcp server.
B. run the set-dhcpserver4scope cmdlet.
C. modify the dns settings of the development scope.
D. run the add-dhcpserver4policy cmdlet.
Answer:
Explanation:
———-
Q23: your network contains one active directory domain.the domain contains the servers configured as shown in the following table.
server1 domain controllers
dns server
server2 domain controllers
dns server
server3 dns server
server1 hasthe zones shown in the following table:
zone name zone type Isautocreated Isdsintegrated Isreverselookupzone Issigned
adatum.com primary false false false false
contoso.com primary false true false false
litwareinc.com secondary false true false false
server3 has the following output:
zone name zone type Isautocreated Isdsintegrated Isreverselookupzone Issigned
contoso.com secondary false true false false
litwareinc.com primary false true false false
use the drop down list must select trhe answer choice that completes each assignment.
—you can protect [answer choice] by using dnssec:
only adatum.com
only contoso.com
only litwareinc.com
only contoso.com and adatum.com
contoso.com,adatum.com and litwareinc.com
—on server1,you configure permissions for the contoso.com zone.the permission will be efficitive on [answer choice]:
server1 only
server1 and server2 only
server1 and server3 only
server1,server2 and server3.
Answer:
Explanation:
———-
Q24: your network contains an active directory domain anmed contoso.com.
the domain contains the server named server1 that runs windows server 2012r2.
server1 has the active directory rights management services server role installed.
the domain contains a domain local group named group1
you create a rights policy template named template1.
you need to ensure that all the members of group1 can use template1.
What should you do?
A. Convert the scope of group1 to universal and assign group1 the rights to template1
B. Convert the scope of group1 to global and configure the email address attribute of group1.
C. Configure the email address attribute of group1 and configure the email address attribute of all the users are members of group1.
D. Configure the email address of all the users who are members of group1 and assign group1 the rights to template1.
Answer:
Explanation:
———-
Q25:
you have a server that runs windows server 2012r2.
you create a new work folder named share1.
you need to configure share1 to meet the follwoing requirements:
*ensure that all synchronized copies of share1 are encrypted.
*ensure that clients synchronize to share1 every 30 minutes.
*ensure that share1 inherits the ntfs permissions of the parent folder.
Which command should you use to achive each requirements?
to answer,drag the appropriate cmdlets to the correct requirements.each cmdlet may be used once.more than once,or not at all.
you may need to drag ther splitbacr between panes or scroll to view cmdlet?
Availible cmdlets:
enable-synshare
new-syncdevicepolicy
new-syncshare
set-syncdevicepolicy
set-syncserversetting
set-synshare
answer area:
ensure that all synchronized copies of share1 area encrypted _______________
ensure that clients synchronize to share1 every 30 minutes _______________
ensure that share1 inherits the ntfs permissions of the percentage _______________
Answer:
Explanation:
0
0
Q10:
Answer:
Only Property1 set to value1
Only the value of Property1 is
0
0
Q17 Answer: C. Set-ADDomain
0
0
Q18 Answer: CEF
0
0
Q19 Answer: 225.0.0.10 225.0.0.250
0
0
Global Catalog
DC1 |contoso.com | Site1 | Yes
DC2 |constoso.com | Site2 | No
DC3 |adatum.com | Site2 | Yes
DC4 |adatum.com | Site1 | No
1. Create and place File1.txt inside SYSVOL folder on DC1
2. Create User account User1 on DC3
3. Create Group Policy GPO1 and link GPO1 to site 2
Q. Mark whether the item is replicated to the appropriate DC
File1.txt User1 GPO1
DC1 ___________|_________|________
DC2 ___________|_________|________
DC3 ___________|_________|________
DC4 ___________|_________|________
0
0
+ 1 to this! My thoughts…
File1.txt is on DC1 and if located in the SYSVOL folder, I think it would replicate much like a GPO would, to all the servers regardless of site, based on my interpretation of this article. DC1 DC2 DC3 and DC4
http://social.technet.microsoft.com/wiki/contents/articles/8548.sysvol-and-netlogon-share-importance-in-active-directory.aspx
User1 I believe would replicate to servers with the Global Catalog so DC1 and DC3. (Global Catalogs hold a copy of all user info from all the domains in the forest. By that assumption, the servers that don’t hold the GC won’t have users)
The GPO although linked to site 2 would replicate to all servers via the SYSVOL/policies folder. So My guess would be DC1 DC2 DC3 and DC4?
0
0
Anyone figure out the answer to this one yet? I’ve seen this one on a previous attempt. I’m assuming Column 1 is all checked, column two is just DC1 and DC3 (the gloabl catalogs) and column 3 is also all checked because GPOs are replicated via sysvol?
Can anyone confirm or refute?
0
0
This question states that they are 2 separate forests so my take is top 2, bottom 2, top 2 as replication does not cross forests.
If they were 2 domains in the same forest i would say:
1,2/1,3,4/1,2,3
0
0
I agree Aaron that if in a separate forest top 2 bottom 2 and top 2 is right. SYSVOL replication is per domain anyway. As is user replication and GPO’s. I disagree if they’re separate domains in the same forest. I still say the same thing will happen as before. GC’s contain a subset of information of AD objects. As far as I know the user object is not replicated – just enough attribute information to enable searches to come back with the correct results (I could be wrong there but I haven’t seen anything that indicates that). GPO’s get created in the SYSVOL folder so they have the same replication scope as your file. I’ve never heard of a GPO from a parent domain being applied to a child domain or another AD tree – stand to be corrected there but I don’t know how you could do it?
0
0
Not sure about the wording of the last one there too – there’s two site 2’s! I expect in the real question the question is either more specific or the sites are labelled differently. In either case I’d only mark the replication to occur within the same domain.
0
0
You need to configure Stateless DHCP IPv6, Which cmdlet should you use?
Add-DHCPv6Scope
Set-DHCPv6OptionValue
Set-DHCPv6Class
Add-DHCPv6OptionDefinition
0
0
To configure something that is already there use Set- PS_Command [not Add-].
Out of 2 Set- commands offered. Set-DHCPv6Class does not seem to exist.
That leaves use with …
The Answer: Set-DHCPv6OptionValue -InfoRefreshTime
Specifies the value for the information refresh option. This parameter is used with stateless DHCPv6 as there are no addresses or other entities with lifetimes that can tell the client when to contact the DHCPv6 server to refresh its configuration.
Source: https://technet.microsoft.com/en-us/%5Clibrary/JJ590694%28v=WPS.630%29.aspx
0
0
Certificate Server
Question | Exhibit 1 (Server1) (CA) | Exhibit 2 (Server2) (CA-1) | Exhibit 3
Exhibit 1: Picture of a certsrv folder structure (without a Certificate Templates Folder)
Exhibit 2: Picture of a certsrv folder structure (With a Certificate Templates Folder)
Exhibit 3: A certificate with “Issued to: CA-1” and “Issued BY: CA”
Yes | No
1. Server 1 is an enterprise CA?
2. Server 2 is an enterprise CA?
3. Server 1 is a subordinate server to server 2?
0
0
Answers:
1) No (see explanation)
2) Yes (see explanation)
3) No (because the certificate is issued by CA to CA-1. Means that server2 must be a subordinate server to server 1)
Explanation
Stand Alone CA
* No Certificate templates available (specific requests are required)
* No autoenrollment available (approval needed)
* Supported by AD environments and non-AD environments
* Most of the times used for root and policy CAs that are offline)
Enterprise CA
* Certificate templates available
* Autoenrollment is possible
* Supported by AD environments
* Most of the times used for issuing certs to end-entities
http://www.experts-exchange.com/Networking/Protocols/SSL/Q_24993799.html
0
0
Even the “new” questions posted here are now outdated. Looks like we have to pay $100 and give away anonymity to get anywhere in these tests. Sorry, I can’t read a million TechNet articles and have perfect recall as applied to various new scenarios. Doesn’t look like I’ll get an MCSA anytime soon.
0
0
Sorry but I do not accept your winging as valid. If you are relying on these dumps to get your MCSA you should never get one. You should use these dumps to confirm your knowledge gained from text books and real life use of Server 2012. Not memorize the answers…
0
0
That logic fails consistently, Aaron. The fact is that Microsoft is now finding every obscure example of the subject matter and people are failing consistently. Microsoft knows it. $100 Dump sites know it. And a lot of people are making money from it. I’ve seen first hand 15% pass rates in high traffic testing centers from people with 3-years+ experience in the field. This isn’t a matter for personal opinion about who should be certified. Certifications are no better than college degrees. It’s always up to the individual to prove themselves. There are so many practical day-to-day applications that aren’t even covered in these tests. The capitalizing of this information that should be freely accessible is just one more example of the internet becoming less free. People can still get what is in ‘your’ opinion a false certificate. The only difference with the failing of information sites like this used to be is that it now costs $100. So talented poor people don’t have the same opportunity as someone with $100 cash available to them.
0
0
I disagree completely. I started studying for MCSE since 1998 Windows V3.51. 18 Years certified now but I have to agree with grande. I’m a very experienced self employed IT Pro. The exams from Microsoft are a bunch crap. The only reason you need the certificate is because customers ask proof of certification.
Loads of questions aren’t from the books or real life use. If that was the case this site didn’t have so many visitors. It’s easier to study from a book compared to visiting this site and dig through 600 questions (and checking them). Believe me I read all the books but that’s not enough to certify. Maybe I have to conclude that I’m to stupid for the IT business after 18 years?
0
0
I sat for the 70-412 test yesterday and passed (second shot). I know for sure that if I had NOT seen the new questions posted by bopbop that I would have failed again. As far as I’m concerned, yes, having answers is great, having discussions it also helpful, but go out and research the questions that you don’t know. I’m sure MS does more than just change the names of the companies/domains up on the test.
I would guess that for every 100 hours I spend studying, a good 40 – 50% of that time is spent researching. The problem with researching is that no matter how hard you try, you can’t seem to get a definite answer for each question – Technet is not always forthcoming with concise and understandable information.
I’ll go back later and see if I can find the ones I missed. Now, it’s time to get back to the 70-411 – it’s the last one I need to pass – I’ve failed it four times already.
0
0
I sat for the 70-412 test yesterday and passed (second shot – 740). I know for sure that if I had NOT seen the new questions posted by bopbop that I would have failed again. As far as I’m concerned, yes, having answers is great, having discussions it also helpful, but go out and research the questions that you don’t know. I’m sure MS does more than just change the names of the companies/domains up on the test.
I would guess that for every 100 hours I spend studying, a good 40 – 50% of that time is spent researching. The problem with researching is that no matter how hard you try, you can’t seem to get a definite answer for each question – Technet is not always forthcoming with concise and understandable information.
I’ll go back later and see if I can find the ones I missed. Now, it’s time to get back to the 70-411 – it’s the last one I need to pass – I’ve failed it four times already.
0
0
Congrats on 412, Bruce. Good luck on 411. You got this, man!
0
0
C. Dfsdiag
0
0
Took the 412 today. Failed with a 640. 51 questions about 25 are not even listed here!
0
0
Hi, Which is the answer? Thank you
Your network contains one Active Directory forest named contoso.com. the forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table.
Name Domain Site
DC1 Contoso.com Main Office
DC2 Contoso.com Main Office
DC3 Contoso.com Europe Office
DC4 Contoso.com Asia Office
DC5 Sales.contoso.com Main Office
DC6 Manufacturiung.contoso.com Main Office
you need to enable universal group membership caching for the europe office and asia office sites.
What should you use?
A. Set-ADSite
B. Set-ADReplicationSite
C. Set-ADDomain
D. Set-ADReplicationSiteLink
E. Set-ADGroup
F. Set-ADForest
G. Netdom
0
0
Set AD-ReplicationSite
0
0
It is Set-ADSiteReplication
https://technet.microsoft.com/en-us/library/hh852286(v=wps.630).aspx
0
0
HI, Help, which are the answers? Thank you
Q1–You have the following microsoft azure backup policy
backup schedule : 9:00am, 12:00 pm,11:00 pm
every day
every 1 week(s)
dslist : {datasource
datasourceid:1576400609127590137
name:c:\
filespec:filespec
filespec:c:\
isexclude:false
isrecursive:true
}
policyname : f77828d2-69b6-4c4b-b98a-e5e20d9ab7e9
retentionpolicy : retention days : 30
week1yltrsschedule :
days: monday
times: 12:00:00,
retentention weeks: 60
month1yltrschedule :
days of month : [last,monday]
times: 23:00:00
retentention weeks: 90
year1yltrschedule :
yearly schedule is not set
state : existing
policystate : valid
Answer Area:
Of the backups that are created daily at 9:00, a maximum of recovery points will be available for restore _____
– 30
– 60
– 90
– 122
– 366
– 512
if a backup is performed on monday,january 31, at 9:00,the backup will be retained for _____
– 30 days
– 60 weeks
– 90 month
Q2–You have dhcp server named server1 that runs windows server 2012r2.
server1 has two scope production and development.
currently, all dhcp clients register their host name in a dns zone named contoso.com.
you need to ensure that only the clients that obtain an ip address from the development scope, register their host name in a dns zone named dev.contoso.com.
what should you do?
A. modify the advanced settings of the dhcp server.
B. run the set-dhcpserver4scope cmdlet.
C. modify the dns settings of the development scope.
D. run the add-dhcpserver4policy cmdlet.
0
0
Add-DHCPserver5Policy
Only a scope or server policy allows you to specify domain suffix for registration with DNS
0
0
Q1 Answer: – 30 – 30 days
0
0
Q 18:
C, D:
There are various situations where you would want to prevent your DNS server from performing a recursive query. Depending on what you are trying to accomplish, there are two settings that have caused confusion amongst DNS administrators. These two settings are “Do not use recursion for this domain” found in the Forwarders tab and “Disable Recursion” found in the Advanced tab. Let’ s take a look at these settings in more detail.
http://www.itgeared.com/articles/1050-do-not-use-recursion-for-this-domain-vs/
F:
dnscmd /Config /NoRecursion {1|0}
0
0
Q 19:
Since multicast adresses can be in range: 224.0.0.0–239.255.255.255
We can see than in “End Range” only adress we can use is 225.0.0.250 So from the first column (Start Range) we must chose 225.0.0.10.
0
0
Q 20:
A
https://azure.microsoft.com/en-us/documentation/articles/backup-azure-restore-windows-server/
0
0
Q 21:
B
-UniversalGroupCachingEnabled
Indicates whether the cmdlet enables universal group caching. If this parameter is true, it indicates this site caches universal groups, which are those groups cached on global catalog (GC) servers. It can be useful in sites with no GC servers available locally.
https://technet.microsoft.com/en-us/library/hh852305%28v=wps.630%29.aspx
0
0
Q 22
I belive C.
You can set what DNS will users use for scope, so i belive that sould also alow them to register with that DNS.
0
0
I passed the exam so i would like to give you some advice:
1.) The most important thing is that you shouldn’t memorize answers. Microsoft tends to change questions slightly, or offer different answers for same question. What you should do is learn the subject based on question at hand. Following this advice, you will be able to answer even new questions that u haven’t seen before.
2.) In these dumps there is a lot of wrong answers, even the ones where most people agree about answers could be wrong. Don’t believe dumps, even the premium ones, because they just copy from each other. My advice would be to research every question and research every offered answer.
3.) And pliz get your hand on server. It doesn’t even have to be server, install Win 8 on your personal computer and use Hyper V to install Win server 2012 R2 evaluation version (seems the simplest solution in my opinion).
Good luck everyone!
0
0
FI, 70-412(v4) is published with a lot of new questions.
0
0
p.s.
Free 391q dumps from Google Drive:
https://drive.google.com/open?id=0B-ob6L_QjGLpfm94alk1eU9xWjFYRkVoNkl0cjRiOXZRRjVkUXNXTklicDdKZDJwRGJCM1k
0
0