getcertified4sure.com

Amazing 70 412 study guide To Try




The Microsoft Microsoft practice questions and answers are the most current 70-412 exam study resources for Microsoft 70-412 exam. Each of our IT Microsoft exam writers are keeping the Microsoft 70-412 up-to-date. The actual Microsoft 70-412 exam, study manual and test engine can detect your database administration expertise. Exambible provides a new quiz for you ahead of buying the Microsoft products. It will help you to locate out the general knowledge with the Microsoft Microsoft 70-412 exam and assess you skills of expertise. You can take advantage of the actual quiz to test yourself along with our precise answers.

2021 Oct cbt nuggets 70-412:

Q61. Your network contains a perimeter network and an internal network. The internal network contains an Active Directory Federation Services (AD FS) 2.1 infrastructure. The infrastructure uses Active Directory as the attribute store. 

You plan to deploy a federation server proxy to a server named Server2 in the perimeter network. 

You need to identify which value must be included in the certificate that is deployed to Server2. 

What should you identify? 

A. The FQDN of the AD FS server 

B. The name of the Federation Service 

C. The name of the Active Directory domain 

D. The public IP address of Server2 

Answer:

Explanation: 

To add a host (A) record to corporate DNS for a federation server On a DNS server for the corporate network, open the DNS snap-in. 

1. In the console tree, right-click the applicable forward lookup zone, and then click New Host (A). 

2. In Name, type only the computer name of the federation server or federation server cluster (for example, type fs for the fully qualified domain name (FQDN) fs.adatum.com). 

3. In IP address, type the IP address for the federation server or federation server cluster (for example, 192.168.1.4). 

4. Click Add Host. 

Reference: Add a host (A) record to corporate DNS for a federation server 

http://technet.microsoft.com/en-us/library/cc776786(v=ws.10).aspx 


Q62. HOTSPOT 

Your network contains two Web servers named Server1 and Server2. Both servers run Windows Server 2012 R2. 

Server1 and Server2 are nodes in a Network Load Balancing (NLB) cluster. The NLB cluster contains an application named App1 that is accessed by using the name appl.contoso.com. 

The NLB cluster has the port rules configured as shown in the exhibit. (Click the Exhibit button.) 

To answer, complete each statement according to the information presented in the exhibit. Each correct selection is worth one point. 

Answer: 


Q63. Your network contains an Active Directory domain named contoso.com. The domain contains a file server named Server1. The File Server Resource Manager role service is installed on Server1. All servers run Windows Server 2012 R2. 

A Group Policy object (GPO) named GPO1 is linked to the organizational unit (OU) that contains Server1. The following graphic shows the configured settings in GPO1. 

Server1 contains a folder named Folder1. Folder1 is shared as Share1. 

You attempt to configure access-denied assistance on Server1, but the Enable access-denied assistance option cannot be selected from File Server Resource Manager. 

You need to ensure that you can configure access-denied assistance on Server1 manually by using File Server Resource Manager. 

Which two actions should you perform? 

A. Set the Enable access-denied assistance on client for all file types policy setting to Disabled for GPO1. 

B. Set the Customize message for Access Denied errors policy setting to Not Configured for GPO1. 

C. Set the Enable access-denied assistance on client for all file types policy setting to Enabled for GPO1. 

D. Set the Customize message for Access Denied errors policy setting to Enabled for GPO1. 

Answer: C,D 

Explanation: 

C. To configure access-denied assistance for all file types by using Group Policy . Open Group Policy Management. In Server Manager, click Tools, and then click 

Group Policy Management. . Right-click the appropriate Group Policy, and then click Edit. . Click Computer Configuration, click Policies, click Administrative Templates, click 

System, and then click Access-Denied Assistance. 

Right-click Enable access-denied assistance on client for all file types, and then 

click Edit. 

Click Enabled, and then click OK. 

D. To configure access-denied assistance by using Group Policy (see step 5) 

Open Group Policy Management. In Server Manager, click Tools, and then click 

Group Policy Management. 

Right-click the appropriate Group Policy, and then click Edit. 

Click Computer Configuration, click Policies, click Administrative Templates, click 

System, and then click Access-Denied Assistance. 

Right-click Customize message for Access Denied errors, and then click Edit. 

Select the Enabled option. 

Etc Reference: Deploy Access-Denied Assistance (Demonstration Steps) http://technet.microsoft.com/en-us/library/hh831402.aspx 


Q64. HOTSPOT 

You have a file server named Server1 that runs Windows Server 2012 R2. 

Server1 contains a file share that must be accessed by only a limited number of users. 

You need to ensure that if an unauthorized user attempts to access the file share, a custom access-denied message appears, which contains a link to request access to the share. The message must not appear when the unauthorized user attempts to access other shares. 

Which two nodes should you configure in File Server Resource Manager? To answer, select the appropriate two nodes in the answer area. 

Answer: 


Q65. Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2. 

The domain contains a domain controller named DC1 that is configured as an enterprise root certification authority (CA). 

All users in the domain are issued a smart card and are required to log on to their domain-joined client computer by using their smart card. 

A user named User1 resigned and started to work for a competing company. 

You need to prevent User1 immediately from logging on to any computer in the domain. The solution must not prevent other users from logging on to the domain. 

Which tool should you use? 

A. Active Directory Users and Computers 

B. Server Manager 

C. The Certificates snap-in 

D. Active Directory Administrative Center 

Answer:

Explanation: 

To disable or enable a user account using Active Directory Administrative Center 

1. To open Active Directory Administrative Center, click Start , click Administrative Tools , 

and then click Active Directory Administrative Center . 

To open Active Directory Users and Computers in Windows Server 2012, click Start , type 

dsac.exe. 

2. In the navigation pane, select the node that contains the user account whose status you 

want to change. 

3. In the management list, right-click the user whose status you want to change. 

4. Depending on the status of the user account, do one of the following: . uk.co.certification.simulator.questionpool.PList@ef38f20 

Reference: Disable or Enable a User Account 


Most recent 70-412 configuring advanced windows server 2012 services:

Q66. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. The relevant servers in the domain are configured as shown in the following table. 

You plan to create a shared folder on Server1 named Share1. Share1 must only be accessed by users who are using computers that are joined to the domain. 

You need to identify which servers must be upgraded to support the requirements of Share1. 

In the table below, identify which computers require an upgrade and which computers do not require an upgrade. Make only one selection in each row. Each correct selection is worth one point. 

Answer: 


Q67. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. The system properties of Server1 are shown in the exhibit. (Click the Exhibit button.) 

You need to configure Server1 as an enterprise subordinate certification authority (CA). 

What should you do first? 

A. Add RAM to the server. 

B. Set the Startup Type of the Certificate Propagation service to Automatic. 

C. Install the Certification Authority Web Enrollment role service. 

D. Join Server1 to the contoso.com domain. 

Answer:

Explanation: 

Enterprise CAs must be domain members. From the exhibit we see that it is only a 

Workgroup member. 

Note: 

A new CA can be the root CA of a new PKI or subordinate to another in an existing PKI. 

Enterprise subordinate certification authority. 

An enterprise subordinate CA must get a CA certificate from an enterprise root CA but can 

then issue certificates to all users and computers in the enterprise. These types of CAs are 

often used for load balancing of an enterprise root CA. 

Reference: Install a Subordinate Certification Authority 


Q68. You have a server named Server1 that runs Windows Server 2012 R2. 

You have a subscription to Windows Azure. 

You need to register the Microsoft Azure Backup Agent on Server1. 

What should you do first? 

A. Install the Microsoft System Center 2012 Data Protection Manager (DPM) agent. 

B. Create a backup vault. 

C. Create Site Recovery vault. 

D. Configure a passphrase for the Azure Backup Agent. 

Answer:

Explanation: To back up files and data from your Windows Server to Azure, you must create a backup vault in the geographic region where you want to store the data. The main steps include: 

* the creation of the vault you will use to store backups 

* downloading a vault credential 

* the installation of a backup agent 

Reference: Configure Azure Backup to quickly and easily back up Windows Server 

https://azure.microsoft.com/sv-se/documentation/articles/backup-configure-vault/ 


Q69. Your network contains an Active Directory forest. The forest contains one domain named contoso.com. The domain contains three domain controllers. The domain controllers are configured as shown in the following table. 

DC1 has all of the operations master roles installed. 

You transfer all of the operations master roles to DC2, and then you uninstall Active Directory from DC1. 

You need to ensure that you can use Password Settings objects (PSOs) in the domain. 

What should you do? 

A. Change the domain functional level. 

B. Upgrade DC2. 

C. Run the dcgpofix.exe command. 

D. Transfer the schema master role. 

Answer:

Explanation: 

The domain functional level must be Windows Server 2008 to use PSO's 

Requirements and special considerations for fine-grained password and account lockout policies: 

* Domain functional level: The domain functional level must be set to Windows Server 2008 

or higher. 

Etc. 

Incorrect: 

Not B. DC2 is also Windows Server 2008. 

Not C. Recreates the default Group Policy Objects (GPOs) for a domain 

Not D. Schema isn't up to right level 

Reference: AD DS: Fine-Grained Password Policies 

http://technet.microsoft.com/en-us/library/cc770394(v=ws.10).aspx 


Q70. You have a failover cluster named Cluster1 that contains four nodes. All of the nodes run Windows Server 2012 R2. 

You need to force every node in Cluster1 to contact immediately the Windows Server Update Services (WSUS) server on your network for updates. 

Which tool should you use? 

A. The Add-CauClusterRole cmdlet 

B. The Wuauclt command 

C. The Wusa command 

D. The Invoke-CauScan cmdlet 

Answer:

Explanation: 

The Add-CauClusterRole cmdlet adds the Cluster-Aware Updating (CAU) clustered role 

that provides the self-updating functionality to the specified cluster. When the CAU 

clustered role has been added to a cluster, the failover cluster can update itself on the 

schedule that is specified by the user, without requiring an external computer to coordinate 

the cluster updating process. 

Incorrect: 

Not B. The wuauclt utility allows you some control over the functioning of the Windows 

Update Agent. It is updated as part of Windows Update. 

The following are the command line for wuauclt. 

OptionDescription 

/a /ResetAuthorization 

Initiates an asynchronous background search for applicable updates. If Automatic Updates 

is disabled, this option has no effect. 

/r /ReportNow 

Sends all queued reporting events to the server asynchronously. 

/? /h /help 

Shows this help information. 

Not D. 

The Invoke-CauScan cmdlet performs a scan of cluster nodes for applicable updates and 

returns a list of the initial set of updates that would be applied to each node in a specified 

cluster. 

Note: The Invoke-CauRun cmdlet performs a scan of cluster nodes for applicable updates 

and installs those updates via an Updating Run on the specified cluster. 

Reference: Add-CauClusterRole 

http://technet.microsoft.com/en-us/library/hh847235(v=wps.620).aspx