getcertified4sure.com

Beginners Guide: configuring advanced windows server 2012 services




Its moment to put your Actualtests Microsoft 70-412 practice questions and answers directly into use. You just need to spend just a little money and a short span of your energy to practise your Microsoft 70-412 exam dumps. Its worthwhile to create great initiatives on the Microsoft 70-412 exam preparation. Actualtests 70-412 analyze engine urge your candidates to crack your Microsoft 70-412 exam. We provide the most recent and also accurate Microsoft 70-412 simulated questions and also answers.

2021 Oct cbt nuggets 70-412:

Q141. Your network contains an Active Directory domain named contoso.com. The domain contains a file server named Server1 that runs Windows Server 2012 R2. 

You create a user account named User1 in the domain. 

You need to ensure that User1 can use Windows Server Backup to back up Server1. The solution must minimize the number of administrative rights assigned to User1. 

What should you do? 

A. Add User1 to the Backup Operators group. 

B. Add User1 to the Power Users group. 

C. Assign User1 the Backup files and directories user right and the Restore files and directories user right. 

D. Assign User1 the Backup files and directories user right. 

Answer:

Explanation: 

Backup Operators have these permissions by default: 

However the question explicitly says we need to minimize administrative rights. Since the requirement is for backing up the data only--no requirement to restore or shutdown--then assigning the "Back up files and directories user right" would be the correct answer. 

Reference: Default local groups 

http://technet.microsoft.com/en-us/library/cc787956(v=ws.10).aspx http://technet.microsoft.com/en-us/library/cc756898(v=ws.10).aspx http://technet.microsoft.com/en-us/library/cc771990.aspx 


Q142. Your network contains an Active Directory domain named contoso.com. The domain contains two member servers named Server1 and Server2. All servers run Windows Server 2012 R2. 

Server1 and Server2 have the Failover Clustering feature installed. The servers are configured as nodes in a failover cluster named Cluster1. Cluster1 contains a cluster disk resource. 

A developer creates an application named App1. App1 is NOT a cluster-aware application. App1 runs as a service. App1 stores date on the cluster disk resource. 

You need to ensure that App1 runs in Cluster1. The solution must minimize development effort. 

Which cmdlet should you run? 

A. Add-ClusterGenericServiceRole 

B. Add-ClusterGenericApplicationRole 

C. Add-ClusterScaleOutFileServerRole 

D. Add-ClusterServerRole 

Answer:

Explanation: 

Add-ClusterGenericApplicationRole 

Configure high availability for an application that was not originally designed to run in a 

failover cluster. 

If you run an application as a Generic Application, the cluster software will start the 

application, then periodically query the operating system to see whether the application 

appears to be running. If so, it is presumed to be online, and will not be restarted or failed 

over. 

EXAMPLE 1. 

Command Prompt: C:\PS> 

Add-ClusterGenericApplicationRole -CommandLine NewApplication.exe 

Name OwnerNode State 

cluster1GenApp node2 Online Description 

This command configures NewApplication.exe as a generic clustered application. A default name will be used for client access and this application requires no storage. 

Reference: Add-ClusterGenericApplicationRole 

http://technet.microsoft.com/en-us/library/ee460976.aspx 


Q143. Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012 R2. DC1 has the DNS Server server role installed. 

The network contains client computers that run either Linux, Windows 7, or Windows 8. 

You have a standard primary zone named adatum.com as shown in the exhibit. (Click the Exhibit button.) 

You plan to configure Name Protection on all of the DHCP servers. 

You need to configure the adatum.com zone to support Name Protection. 

Which two configurations should you perform from DNS Manager? (Each correct answer presents part of the solution. Choose two.) 

A. Sign the zone. 

B. Store the zone in Active Directory. 

C. Modify the Security settings of the zone. 

D. Configure Dynamic updates. 

E. Add a DNS key record 

Answer: B,D 

Explanation:

Name protection requires secure update to work. Without name protection DNS names may be hijacked.

You can use the following procedures to allow only secure dynamic updates for a zone.

Secure dynamic update is supported only for Active Directory–integrated zones. If the zone type is configured differently, you must change the zone type and directory-integrate the zone before securing it for Domain Name System (DNS) dynamic updates.

1. (B) Convert primary DNS server to Active Directory integrated primary

2. (D) Enable secure dynamic updates

Reference: DHCP: Secure DNS updates should be configured if Name Protection is enabled on any IPv4 scope

http://technet.microsoft.com/en-us/library/ee941152(v=ws.10).aspx


Q144. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 is an enterprise root certification authority (CA) for contoso.com. 

Your user account is assigned the certificate manager role and the auditor role on the contoso.com CA. Your account is a member of the local Administrators group on Server1. 

You enable CA role separation on Server1. 

You need to ensure that you can manage the certificates on the CA. 

What should you do? 

A. Remove your user account from the local Administrators group. 

B. Assign the CA administrator role to your user account. 

C. Assign your user account the Bypass traverse checking user right. 

D. Remove your user account from the Manage auditing and security log user right. 

Answer:

Explanation: 

The separation of CA roles can be enforced using role separation. Once enforced, role separation only allows a user to be assigned a single role. If a user is assigned to more than one role and attempts to perform an operation on the CA, the operation is denied. For this reason, before role separation is enabled, a user should be assigned only one CA role. 

Reference: Role Separation 


Q145. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2. Both servers have the IP Address Management (IPAM) Server feature installed. 

You have a support technician named Tech1. Tech1 is a member of the IPAM Administrators group on Server1 and Server2. You need to ensure that Tech1 can use Server Manager on Server1 to manage IPAM on Server2. To which group on Server2 should you add Tech1? To answer, select the appropriate group in the answer area. 

Answer: 


Up to date pdf 70-412:

Q146. You have a server named Server1 that runs Windows Server 2012 R2. 

Server1 is backed up by using Windows Server Backup. The backup configuration is shown in the exhibit. (Click the Exhibit button.) 

You discover that only the last copy of the backup is maintained. You need to ensure that multiple backup copies are maintained. What should you do? 

A. Modify the backup destination. 

B. Configure the Optimize Backup Performance settings. 

C. Modify the Volume Shadow Copy Service (VSS) settings. 

D. Modify the backup times. 

Answer:

Explanation: 

The destination in the exhibit shows a network share is used. If a network share is being used only the latest copy will be saved 

Reference: Where should I save my backup? http://windows.microsoft.com/en-us/windows7/where-should-i-save-my-backup 


Q147. DRAG DROP 

You have a file server named Server1 that runs Windows Server 2012 R2. The folders on Server1 are configured as shown in the following table. 

A new corporate policy states that backups must use Windows Azure Online Backup whenever possible. 

You need to identify which technology you must use to back up Server1. The solution must use Windows Azure Online Backup whenever possible. 

What should you identify? 

To answer, drag the appropriate backup type to the correct location or locations. Each backup type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. 

Answer: 


Q148. You have a server named Server1 that runs Windows Server 2012 R2. 

Server1 has a single volume that is encrypted by using BitLocker Drive Encryption 

(BitLocker). 

BitLocker is configured to save encryption keys to a Trusted Platform Module (TPM). 

Server1 is configured to perform a daily system image backup. 

The motherboard on Server1 is upgraded. 

After the upgrade, Windows Server 2012 R2 on Server1 fails to start. 

You need to start the operating system on Server1 as soon as possible. 

What should you do? 

A. Start Server1 from the installation media. Run startrec.exe. 

B. Move the disk to a server that has a model of the old motherboard. Start the server from the installation media. Run bcdboot.exe. 

C. Move the disk to a server that has a model of the old motherboard. Start the server. Run tpm.msc. 

D. Start Server1 from the installation media. Perform a system image recovery. 

Answer:

Explanation: 

By moving the hard drive to server with that has a model of the old motherboard the system 

would be able to start. As BitLocker was configured to save encryption keys to a Trusted 

Platform Module (TPM), we can use tpm.msc to access the TPM settings. 

Note: After you replaced the motherboard, you need to repopulate the TPM with new 

information regarding the encryption of the hard disk. 

We use these commands to repopulate the information in the TPM (without PIN): 

manage-bde –delete -protectors C: -type TPM 

manage-bde –protectors –add C: -tpm 

Incorrect: 

Not D. After the system image recovery you would still have the new motherboard installed. 

The problem would return. 

Reference: BitLocker - New motherboard replacement 


Q149. DRAG DROP 

You plan to deploy a failover cluster that will contain two nodes that run Windows Server 

2012 R2. 

You need to configure a witness disk for the failover cluster. 

How should you configure the witness disk? 

To answer, drag the appropriate configurations to the correct location or locations. Each configuration may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. 

Answer: 


Q150. You have a server named DNS1 that runs Windows Server 2012 R2. 

You discover that the DNS resolution is slow when users try to access the company intranet home page by using the URL http://companyhome. 

You need to provide single-label name resolution for CompanyHome that is not dependent on the suffix search order. 

Which three cmdlets should you run? (Each correct answer presents part of the solution. Choose three.) 

A. Add-DnsServerPrimaryZone 

B. Add-DnsServerResourceRecordCName 

C. Set-DnsServerDsSetting 

D. Set-DnsServerGlobalNameZone 

E. Set-DnsServerEDns 

F. Add-DnsServerDirectory Partition 

Answer: A,B,D 

Explanation: 

You can use this task to create a GlobalNames zone to maintain a set of single-label, Domain Name System (DNS) names that Windows Server 2008 DNS servers can resolve on behalf of DNS clients throughout a single forest in Active Directory Domain Services 

(AD DS). 

Deploying a GlobalNames zone in a single forest requires that you perform the following 

steps: 

. (A) Create a zone named GlobalNames that replicates to all domain controllers in the forest. 

. (B) Add an alias (CNAME) record to the zone for each host for which you want to provide single-label name resolution. For example, if you want DNS clients to be able to access a server whose fully qualified domain name (FQDN) is cweb.itgroup.contoso.com, add an alias (CNAME) resource record that maps the name cweb to cweb.igroup.contoso.com. 

Note: 

A. The Add-DnsServerPrimaryZone cmdlet adds a specified primary zone on a Domain Name System (DNS) server. 

B. The Add-DnsServerResourceRecordCName cmdlet adds a canonical name (CNAME) resource record to a specified Domain Name System (DNS) zone. A CNAME record allows you to use more than one resource record to refer to a single host 

D. The Set-DnsServerGlobalNameZone cmdlet enables or disables single-label Domain Name System (DNS) queries. It also changes configuration settings for a GlobalNames zone. The GlobalNames zone supports short, easy-to-use names instead of fully qualified domain names (FQDNs) without using Windows Internet Name Service (WINS) technology. For instance, DNS can query SarahJonesDesktop instead of SarahJonesDesktop.contoso.com. 

Reference: Adding a GlobalNames zone to a forest 

https://technet.microsoft.com/en-us/library/cc816717(v=ws.10).aspx