QUESTION 1

How can you manage an newly installed Windows Server 2012 R2 core from a another Windows Server 2012 R2 with computer manager?

 

70-410-demo-2

 

Correct Answer:

 

70-410-demo-3

 

 

QUESTION 2

Your network contain an active directory domain named Contoso.com. The domain contains two servers named server1 and server2 that run Windows Server 2012 R2.

You create a security template named template1 by using the security template snap-in.

You need to apply template1 to server2. Which tool should you use?

 

A.

Security Templates

B.

Computer Management

C.

Security Configuration and Analysis

D.

System Configuration

 

Correct Answer: C

 

QUESTION 3

Your network contains an active directory domain named Contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2.

You create a group Managed Service Account named gservice1.

You need to configure a service named service1 to run as the gservice1 account.

How should you configure service1?

 

A.

From Services Console configure the recovery settings

B.

From a command prompt ,run sc.exe and specify the config parameter

C.

From Windows PowerShell,run Set-Service and specify the -PassThrough parameter

D.

From a command prompt ,run sc.exe and specify the sdset parameter

 

Correct Answer: B 

 

QUESTION 4

Your network contains an active directory domain named Contoso.com. The domain contains 100 user accounts that reside in an organizational unit (OU) named OU1.

You need to ensure that user named user1 can link and unlink Group Policy Objects(GPOs) to OU1. The solution must minimize the number of permissions assigned to user1.

What should you do?

 

A.

Run the Delegation of Control Wizard on the Policies containers

B.

Run the Set-GPPermission cmdlet

C.

Run the Delegation of Control Wizard on OU1

D.

Modify the permission on the user1 account

 

Correct Answer: C

 

QUESTION 5

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has 2 dual-core processors and 16 GB of RAM.

You install the Hyper-V server role in Server1.

You plan to create two virtual machines on Server1.

You need to ensure that both virtual machines can use up to 8 GB of memory. The solution must ensure that both virtual machines can be started simultaneously.

What should you configure on each virtual machine?

 

A.

Dynamic Memory

B.

NUMA topology

C.

Memory weight

D.

Ressource Control

 

Correct Answer: A

 

QUESTION 6

You have a server named Server1 that runs Windows Server 2012 R2. You promote Server1 to domain controller. You need to view the service location (SVR) records that Server1 registers on DNS. What should you do on Server1?

A.

Open the Srv.sys file

B.

Open the Netlogon.dns file

C.

Run ipconfig/displaydns

D.

Run Get-DnsServerDiagnostics

 Correct Answer: B

 

QUESTION 7

Your network contains an active directory domain named Contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2 and has the Hyper-V server role installed. You have a virtual machine named VM1. VM1 has a snapshot. You need to modify the Snapshot File Location of VM1.

What should you do First?

 

A.

Copy the snapshot file

B.

Pause VM1

C.

Shut down VM1

D.

Delete the snapshot

 

Correct Answer: D

 

QUESTION 8

You have a server named Server1 that runs Windows Server 2012 R2. Several users are members of the local Administrators group. You need to ensure that all local administrators receive User Account Control (UAC) prompts when they run a Microsoft Management Console (MMC). Which setting should you modify from the Local Security Policy?

To answer, select the appropriate settings in the answer area.

 

70-410-demo-8

 

Correct Answer: B

 

70-410-demo-9

 

 

QUESTION 9

You have a network printer connected to print server. You need to be able to print if print server goes down. What should you chose?

 

A.

brach office direct printing

B.

printer pooling

C.

spooling

D.

Print forwarding

 

Correct Answer: A

 

QUESTION 10

You have external virtual switch with srv-io enabled with 10 Virtual Machines on it. You need to make the Virtual Machines able to talk only to each other.

 

A.

remove the vswitch and recreate it as private.

B.

add new vswitch

C.

remove vswitch and recreate it as public

D.

adjust srv-io settings

 

Correct Answer: A

 

QUESTION 21

Your network contains three servers that run Windows Server 2012 R2. The servers are configured as shown in the following table.

 

70-410-demo-22

 

Server3 is configured to obtain an IP address automatically.

You need to prevent Server3 from receiving an IP address from Server1. What should you create on Server1?

 

A.

A reservation

B.

A filter

C.

A scope option

D.

An exclusion

 

Correct Answer: B

 

QUESTION 22

Your network contains an Active Directory forest. The forest contains two domains named contoso.com and corp.contoso.com. The forest contains four domain controllers. The domain controllers are configured as shown in the following table.

 

70-410-demo-24

 

All domain controllers are DNS servers. In the corp.contoso.com domain, you plan to deploy a new domain controller named DCS.

You need to identify which domain controller must be online to ensure that DCS can be promoted successfully to a domain controller.

Which domain controller should you identify?

 

A.

DC1

B.

DC2

C.

DC3

D.

DC4

 

Correct Answer: C

QUESTION 23

Your network contains an Active Directory domain named contoso.com. You log on to a domain controller by using an account named Admin1. Admin1 is a member of the Domain Admins group. You view the properties of a group named Group1 as shown in the exhibit. (Click the Exhibit button.) Group1 is located in an organizational unit (OU) named OU1.

You need to ensure that users from Group1 can modify the Security settings of OU1 only.

What should you do from Active Directory Users and Computers?

 

70-410-demo-26

 

A.

Modify the Managed By settings on OU1.

B.

Right-click contoso.com and select Delegate Control.

C.

Right-click OU1 and select Delegate Control.

D.

Modify the Security settings of Group1.

 

Correct Answer: C

 

QUESTION 24

Your network contains an Active Directory forest named contoso.com. All domain controllers currently run Windows Server 2008 R2.

You plan to install a new domain controller named DC4 that runs Windows Server 2012 R2.

The new domain controller will have the following configurations:

 

 Schema master

 Global catalog server

 DNS Server server role

 Active Directory Certificate Services server role

 

You need to identify which configurations Administrators by using the Active Directory Installation Wizard.

Which two configurations should you identify? (Each correct answer presents part of the solution. Choose two.)

 

A.

Transfer the schema master.

B.

Enable the global catalog server.

C.

Install the DNS Server role

D.

Install the Active Directory Certificate Services role.

 

Correct Answer: AD

 

QUESTION 25

Your network contains an Active Directory domain named contoso.com. The domain contains two domain controllers. The domain controllers are configured as shown in the following table.

 

70-410-demo-28

 

In the perimeter network, you install a new server named Server1 that runs Windows Server 2012 R2. Server1 is in a workgroup. You need to perform an offline domain join of Server1 to the contoso.com domain. What should you do first?

 

A.

Transfer the PDC emulator role to Dc1.

B.

Run the djoin.exe command.

C.

Run the dsadd.exe command.

D.

Transfer the infrastructure master role to DC1.

Correct Answer: B

 

QUESTION 26

Your network contains two Active Directory forests named adatum.com and contoso.com. Both forests contain multiple domains. A two-way trust exists between the forests. The contoso.com domain contains a domain local security group named Group1. Group1 contains contoso\user1 and adatum\user1.

You need to ensure that Group1 can only contain users from the contoso.com domain.

Which three actions should you perform?

To answer, move three actions from the list of actions to the answer area and arrange them in the correct order.

 

70-410-demo-29

 

Correct Answer:

 

70-410-demo-30

 

QUESTION 27

Your network contains an Active Directory domain named contoso.com. You discover that when you join client computers to the domain manually, the computer accounts are created in the Computers container.

You need to ensure that new computer accounts are created automatically in an organizational unit (OU) named Corp.

Which tool should you use?

 

A.

net.exe

B.

redircmp.exe

C.

regedit.exe

D.

dsadd.exe

 

Correct Answer: B

 

 

QUESTION 28

You have a server named Server2 that runs Windows Server 2012 R2. Server2 has the Hyper-V server role installed. The disks on Server2 are configured as shown in the exhibit. (Click the Exhibit button.) You create a virtual machine on Server2 named VM1.

You need to ensure that you can configure a pass-through disk for VM1.

What should you do?

 

70-410-demo-31

 

A.

Convert Disk 1 to a basic disk.

B.

Take Disk 1 offline.

C.

Create a partition on Disk 1.

D.

Convert Disk 1 to a MBR disk.

 

Correct Answer: B

 

 

QUESTION 29

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the Hyper-V server role installed. Server1 is connected to two Fibre Channel SANs and is configured as shown in the following table.

 

70-410-demo-32

 

You have a virtual machine named VM1. You need to configure VM1 to connect to SAN1.

What should you do first?

 

A.

Add one HBA

B.

Create a Virtual Fibre Channel SAN.

C.

Create a Hyper-V virtual switch.

D.

Configure network adapter teaming.

 

Correct Answer: B

 

QUESTION 30

You work as a senior administrator at ENSUREPASS.com. The ENSUREPASS.com network consists of a single domain named ENSUREPASS.com. All servers on the ENSUREPASS.com network have Windows Server 2012 installed, and all workstations have Windows 8 installed.

You are running a training exercise for junior administrators. You are currently discussing the Always Offline Mode.

Which of the following is TRUE with regards to the Always Offline Mode? (Choose all that apply.)

 

A.

It allows for swifter access to cached files and redirected folders.

B.

To enable Always Offline Mode, you have to satisfy the forest and domain functional-level requirements,

as well as schema requirements.

C.

It allows for lower bandwidth usage due to users are always working offline.

D.

To enable Always Offline Mode, you must have workstations running Windows 7 or Windows

Server 2008 R2.

 

Correct Answer: AC

Explanation:

Offline Files have four modes of operation:

Online

Slow link

Auto offline

Manual offline

Offline Files transition between the three modes online, slow link and auto offline depending on connection speed. The user can always override the automatic mode selection by manually switching to manual offline mode.

To determine the connection speed two pings with default packet size are sent to the file server. If the average round-trip time is below 80 ms (Windows 7) or 35 ms (Windows 8), the connection is put into online mode, otherwise into slow link mode. The latency value of 35/80 ms is configurable through the Group Policy setting Configure slow-link mode.

Reads, Writes and Synchronization

In online mode, changes to files are made on the file server as well as in the local cache (this induces a performance hit – see this article for details). Reads are satisfied from the local cache (if in sync).

In slow link mode, changes to files are made in the local cache. The local cache is background-synchronized with the file server every 6 hours (Windows 7) or 2 hours (Windows 8), by default. This can be changed through the Group Policy setting Configure Background Sync. . In auto offline mode, all reads and writes go to the local cache. No synchronization occurs. . In manual offline mode, all reads and writes go to the local cache. No synchronization occurs by default, but background synchronization can be enabled through the Group Policy setting Configure Background Sync.

http://technet.microsoft.com/en-us/library/hh968298.aspx

http://helgeklein.com/blog/2012/04/windows-7-offline-files-survival-guide/

 

QUESTION 31

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012 R2. You need to configure a central store for the Group Policy Administrative Templates. What should you do on DC1?

 

A.

From Server Manager, create a storage pool.

B.

From Windows Explorer, copy the PolicyDefinitions folder to the SYSVOL\contoso.com\policies folder.

C.

From Server Manager, add the Group Policy Management feature

D.

From Windows Explorer, copy the PolicyDefinitions folder to the NETLOGON share.

 

Correct Answer: B

 

QUESTION 32

You install Windows Server 2012 R2 on a standalone server named Server1. You configure Server1 as a VPN server.

You need to ensure that client computers can establish PPTP connections to Server1.

Which two firewall rules should you create? (Each correct answer presents part of the solution. Choose two.)

 

A.

An inbound rule for protocol 47

B.

An outbound rule for protocol 47

C.

An inbound rule for TCP port 1723

D.

An inbound rule for TCP port 1701

E.

An outbound rule for TCP port 1723

F.

An outbound rule for TCP port 1701

 

Correct Answer: AC

 

QUESTION 33

Your network contains an Active Directory domain named adatum.com. The computer accounts for all member servers are located in an organizational unit (OU) named Servers. You link a Group Policy object (GPO) to the Servers OU.

You need to ensure that the domain’s Backup Operators group is a member of the local Backup Operators group on each member server. The solution must not remove any groups from the local Backup Operators groups.

What should you do?

 

A.

Add a restricted group named adatum\Backup Operators. Add Backup Operators to the This group is

a member of list.

B.

Add a restricted group named adatum\Backup Operators. Add Backup Operators to the Members of

this group list.

C.

Add a restricted group named Backup Operators. Add adatum\Backup Operators to the This group is

a member of list.

D.

Add a restricted group named Backup Operators. Add adatum\Backup Operators to the Members of

this group list.

 

Correct Answer: A

 

QUESTION 34

Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2. An application named Appl.exe is installed on all client computers. Multiple versions of Appl.exe are installed on different client computers. Appl.exe is digitally signed.

You need to ensure that only the latest version of Appl.exe can run on the client computers.

What should you create?

 

A.

An application control policy packaged app rule

B.

A software restriction policy certificate rule

C.

An application control policy Windows Installer rule

D.

An application control policy executable rule

 

Correct Answer: D

 

 

QUESTION 35

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2. You need to ensure that the local Administrator account on all computers is renamed to L_Admin. Which Group Policy settings should you modify?

 

A.

Security Options

B.

User Rights Assignment

C.

Restricted Groups

D.

Preferences

 

Correct Answer: A

 

 

QUESTION 36

You have a server that runs Windows Server 2012 R2. The disks on the server are configured as shown in the exhibit. (Click the Exhibit button.) You need to create a storage pool that contains Disk 1 and Disk 2. What should you do first?

 

70-410-demo-37

 

A.

Delete volume E

B.

Convert Disk 1 and Disk 2 to dynamic disks

C.

Convert Disk 1 and Disk 2 to GPT disks

D.

Create a volume on Disk 2

 

Correct Answer: A 

 

QUESTION 37

You have a server named Server1 that runs Windows Server 2012 R2. You add a 4-TB disk named Disk 5 to Server1. You need to ensure that you can create a 3-TB volume on Disk 5. What should you do?

 

A.

Create a storage pool.

B.

Convert the disk to a dynamic disk.

C.

Create a VHD, and then attach the VHD.

D.

Convert the disk to a GPT disk.

 

Correct Answer: D

 

QUESTION 38

You have a server named Server1 that has a Server Core installation of Windows Server 2008 R2. Server1 has the DHCP Server server role and the File Server server role installed.

You need to upgrade Server1 to Windows Server 2012 R2 with the graphical user interface (GUI). The solution must meet the following requirements:

 

• Preserve the server roles and their configurations.

• Minimize Administrative effort.

 

What should you do?

 

A.

On Server1, run setup.exe from the Windows Server 2012 R2 installation media and select Server with a GUI.

B.

Start Server1 from the Windows Server 2012 R2 installation media and select Server Core Installation.

When the installation is complete, add the Server Graphical Shell feature.

C.

Start Server1 from the Windows Server 2012 R2 installation media and select Server with a GUI.

D.

On Server1, run setup.exe from the Windows Server 2012 R2 installation media and select Server Core

Installation.

When the installation is complete, add the Server Graphical Shell feature

 

Correct Answer: D

 

QUESTION 39

Your network contains two servers named Server1 and Server2 that run Windows Server 2012 R2. You need to install the Remote Desktop Services server role on Server2 remotely from Server1. Which tool should you use?

 

A.

The dsadd.exe command

B.

The Server Manager console

C.

The Remote Desktop Gateway Manager console

D.

The Install-RemoteAccess cmdlet

 

Correct Answer: B

 

QUESTION 40

You have a server named Server1 that runs a full installation of Windows Server 2012 R2.

You need to uninstall the graphical user interface (GUI) on Server1. You must achieve this goal by using the minimum amount of Administrative effort. What should you do?

 

A.

Reinstall Windows Server 2012 R2 on the server.

B.

From Server Manager, uninstall the User Interfaces and Infrastructure feature.

C.

From Windows PowerShell, run Uninstall-WindowsFeature PowerShell-ISE

D.

From Windows PowerShell, run Uninstall-WindowsFeature Desktop-Experience.

Correct Answer: B

 

QUESTION 41

Your network contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Hyper-V server role installed. Server1 hosts four virtual machines named VM1, VM2, VM3, and VM4. Server1 is configured as shown in the following table.

 

70-410-demo-40

You install Windows Server 2012 R2 on VM2 by using Windows Deployment Services (WDS).

You need to ensure that the next time VM2 restarts, you can connect to the WDS server by using PXE. Which virtual machine setting should you configure for VM2?

 

A.

NUMA topology

B.

Resource control

C.

Resource metering

D.

Virtual Machine Chimney

E.

The VLAN ID

F.

Processor Compatibility

G.

The startup order

H.

Automatic Start Action

I.

Integration Services

J.

Port mirroring

K.

Single-root I/O virtualization

 

Correct Answer: G

 

QUESTION 42

Your network contains an Active Directory domain named contoso.com. The domain contains two domain controllers. The domain controllers are configured as shown in the following table.

 

70-410-demo-42

 

In the perimeter network, you install a new server named Server1 that runs a Server Core Installation of Windows Server 2012 R2. You need to join Server1 to the contoso.com domain. What should you use?

 

A.

The New-ADComputer cmdlet

B.

The djoin.exe command

C.

The dsadd.exe command

D.

The Add-Computer cmdlet

 

Correct Answer: B

 

 

QUESTION 43

Your network contains an Active Directory domain named adatum.com. The domain contains three domain DC3 loses network connectivity due to a hardware failure. You plan to remove DC3 from the domain. You log on to DC3. You need to identify which service location (SRV) records are registered by DC3. What should you do?

 

70-410-demo-43

 

A.

Open the %windir%\system32\config\netlogon.dns file.

B.

Run dcdiag /test:dns

C.

Open the %windir%\system32\dns\backup\adatum.com.dns file.

D.

Run ipconfig /displaydns.

 

Correct Answer: A


QUESTION 44

Your network contains an Active Directory forest that contains three domains. A group named Group1 is configured as a domain local distribution group in the forest root domain. You plan to grant Group1 read-only access to a shared folder named Share1. Share1 is located in a child domain.

You need to ensure that the members of Group1 can access Share1.

What should you do first?

 

A.

Convert Group1 to a global distribution group.

B.

Convert Group1 to a universal security group.

C.

Convert Group1 to a universal distribution group.

D.

Convert Group1 to a domain local security group

 

Correct Answer: B


QUESTION 45

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2008 R2. One of the domain controllers is named DCI. The network contains a member server named Server1 that runs Windows Server 2012 R2.

You need to promote Server1 to a domain controller by using install from media (IFM).

What should you do first?

 

A.

Create a system state backup of DC1.

B.

Create IFM media on DC1.

C.

Upgrade DC1 to Windows Server 2012 R2.

D.

Run the Active Directory Domain Services Configuration Wizard on Server1.

E.

Run the Active Directory Domain Services Installation Wizard on DC1.

 

Correct Answer: C

 

 

QUESTION 46

Your network contains an Active Directory domain named contoso.com. The domain contains 100 servers. The servers are contained in a organizational unit (OU) named ServersOU. You need to create a group named Group1 on all of the servers in the domain.

You must ensure that Group1 is added only to the servers.

What should you configure?

 

A.

a Local Users and Groups preferences setting in a Group Policy linked to the Domain Controllers OU

B.

a Restricted Groups setting in a Group Policy linked to the domain

C.

a Local Users and Groups preferences setting in a Group Policy linked to ServersOU

D.

a Restricted Groups setting in a Group Policy linked to ServersOU

 

Correct Answer: C

 

 

QUESTION 47

Your network contains an Active Directory domain named adatum.com. The domain contains several thousand member servers that run Windows Server 2012 R2. All of the computer accounts for the member servers are in an organizational unit (OU) named ServersAccounts. Servers are restarted only occasionally.

You need to identify which servers were restarted during the last two days.

What should you do?

 

A.

Run dsquery computerand specify the -staiepwdpara meter.

B.

Run Get-ADComputerand specify the SearchScope parameter.

C.

Run Get-ADComputerand specify the IastLogonproperty.

D.

Run dsquery serverand specify the -oparameter

 

Correct Answer: C

 

 

QUESTION 48

Your network contains an Active Directory domain named contoso.com. You log on to a domain controller by using an account named Admin1. Admin1 is a member of the Domain Admins group. You view the properties of a group named Group1 as shown in the exhibit. (Click the Exhibit button.) Group1 is located in an organizational unit (OU) named OU1.

You need to ensure that you can modify the Security settings of Group1 by using Active Directory Users and Computers. What should you do from Active Directory Users and Computers?

 

70-410-demo-47

 

A.

From the View menu, select Users, Contacts, Groups, and Computers as containers.

B.

Right-click OU1 and select Delegate Control

C.

From the View menu, select Advanced Features.

D.

Right-click contoso.com and select Delegate Control.

 

Correct Answer: C

 

QUESTION 49

Your network contains an Active Directory domain named contoso.com. The domain contains two domain controllers named DC1 and DC2. You install Windows Server 2012 on a new computer named DC3. You need to manually configure DC3 as a domain controller. Which tool should you use?

 

A.

Server Manager

B.

winrm.exe

C.

Active Directory Domains and Trusts

D.

dcpromo.exe

 

Correct Answer: A


QUESTION 50

You have a server named Core1 that has a Server Core Installation of Windows Server 2012 R2. Core1 has the Hyper-V server role installed Core1 has two network adapters from different third-party hardware vendors.

You need to configure network traffic failover to prevent connectivity loss if a network adapter fails.

What should you use?

 

A.

New-NetSwitchTeam

B.

Add-NetSwitchTeamMember

C.

Install-Feature

D.

netsh.exe

 

Correct Answer: A

 

QUESTION 51

You have a server named Server1 that runs Windows Server 2012 R2. You connect three new hard disks to Server1.

You need to create a storage space that contains the three disks. The solution must meet the following requirements:

 

– Provide fault tolerance if a single disk fails.

– Maximize the amount of files that can be stored in the storage space.

 

What should you create?

 

A.

A simple space

B.

A spanned volume

C.

A mirrored space

D.

A parity space

 

Correct Answer: D

 

QUESTION 52

You perform a Server Core Installation of Windows Server 2012 R2 on a server named Server1. You need to add a graphical user interface (GUI) to Server1.

Which tool should you use?

 

A.

The setup.exe command

B.

The dism.exe command

C.

The imagex.exe command

D.

The Add-WindowsPackage cmdlet

 

Correct Answer: B

 

QUESTION 53

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has five network adapters. Three of the network adapters an connected to a network named LAN1. The two other network adapters are connected to a network named LAN2.

You need to create a network adapter team from the three network adapters connected to LAN 1.

Which tool should you use?

 

A.

Routing and Remote Access

B.

Network and Sharing Center

C.

Server Manager

D.

Network Load Balancing Manager

 

Correct Answer: C

QUESTION 54

You have a server named Server1 that runs Windows Server 2012 R2.

You need to remove Windows Explorer, Windows Internet Explorer, and all related components and files from Server1. What should you run on Server1?

 

A.

Uninstall-WindowsFeature Server-Gui-Mgmt-Infra Remove

B.

Uninstall-WindowsFeature Server-Gui-Shell Remove

C.

msiexec.exe /uninstall iexplore.exe /x

D.

msiexec.exe /uninstall explorer.exe /x

 

Correct Answer: B 

 

QUESTION 55

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the Hyper-V server role installed. On Server1, you create a virtual machine named VM1. VM1 has a legacy network adapter. You need to assign a specific amount of available network bandwidth to VM1. What should you do first?

 

A.

Remove the legacy network adapter, and then run the Set-VMNetworkAdaptercmdlet.

B.

Add a second legacy network adapter, and then run the Set-VMNetworkAdoptercmdlet

C.

Add a second legacy network adapter, and then configure network adapter teaming.

D.

Remove the legacy network adapter, and then add a network adapter

 

Correct Answer: D

 

 

QUESTION 56

Your network contains an Active Directory domain named adatum.com. The domain contains a server named Server1 that runs Windows Server 2012 R2.

On a server named Core1, you perform a Server Core Installation of Windows Server 2012 R2. You join Core1 to the adatum.com domain.

You need to ensure that you can use Event Viewer on Server1 to view the event logs on Core1. What should you do on Core1?

 

A.

Run the Enable-NetFirewallRulecmdlet.

B.

Run sconfig.exeand configure remote management

C.

Run the Disable-NetFirewallRulecmdlet.

D.

Run sconfiq.exeand configure the network settings.

 

Correct Answer: A

 

 

QUESTION 57

Your network contains a file server named Server1 that runs Windows Server 2012 R2. All client computers run Windows 8.

You need to ensure that when users are connected to the network, they always use local offline files that are cached from Server1.

Which Group Policy setting should you configure?

 

A.

Configure slow-link mode.

B.

Configure Slow link speed

C.

Enable file synchronization on costed networks

D.

Turn on economical application of Administratively assigned Offline Files.

 

Correct Answer: A

 

 

QUESTION 58

Your network contains an Active Directory domain named contoso.com. All servers run either Windows Server 2008 R2 or Windows Serve 2012 R2. All client computers run either Windows 7 or Windows 8. The domain contains a member server named Server1 that runs Windows Server 2012 R2. Server1 has the File and Storage Services server role installed. On Server1, you create a share named Share1.

You need to ensure that users can use Previous Versions to restore the files in Share1.

What should you configure on Server1?

 

A.

The Shadow Copies settings

B.

A Windows Server Backup schedule

C.

A data recovery agent

D.

The Recycle Bin properties

 

Correct Answer: A

 

 

QUESTION 59

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the Print and Document Services server role installed. Server1 is connected to two identical print devices.

You need to ensure that users can submit print jobs to the print devices. The solution must ensure that if one print device fails, the print jobs will print automatically on the other print device.

What should you do on Server1?

 

A.

Add two printers and configure the priority of each printer.

B.

Add one printer and configure printer pooling.

C.

Install the Network Load Balancing (NLB) feature, and then add one printer.

D.

Install the Failover Clustering feature, and then add one printer

 

Correct Answer: B

  

QUESTION 60

You have a server named Server2 that runs Windows Server 2012 R2. You open Server Manager on Server2 as shown in the exhibit. (Click the Exhibit button.) The Everyone group has read share permission and read NTFS permission to Sources.

You need to ensure that when users browse the network, the Sources share is not visible.

What should you do?

 

70-410-demo-59

 

A.

From the properties of the Sources folder, remove the Sources share, and then share the Sources folder as Sources$

B.

From the properties of the Sources folder, deny the List Folder Contents permission for the Everyone group

C.

From the properties of the Sources share, configure access-based enumeration

D.

From the properties of the Sources folder, configure the hidden attribute

Correct Answer: A

 

QUESTION 61

Your network contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Print and Document Services server role installed. You connect a new print device to the network. The marketing department and the sales department will use the print device.

You need to provide users from both departments with the ability to print to the network print device. The solution must ensure that if there are multiple documents queued to print, the documents from the sales users print before the documents from the marketing users.

What should you do on Server1?

 

A.

Add two printers. Modify the priorities of each printer and the security settings of each printer

B.

Add two printers and configure printer pooling

C.

Add one printer and configure printer pooling.

D.

Add one printer. Modify the printer priority and the security settings

 

Correct Answer: A

 

QUESTION 62

Your network contains an Active Directory domain named contoso.com. The network contains a server named Server1 that runs Window Server 2012 and a server named Server2 that runs Windows Server 2008 R2 Service Pack 1 (SP1). Server1 and Server2 are member server.

You need to ensure that you can manage Server2 from Server1 by using Server Manager.

Which two tasks should you perform? (Each correct answer presents part of the solution. Choose two.)

 

A.

Install Remote Server Administration Tools on Server1.

B.

Install Windows Management Framework 3.0 on Server2.

C.

Install the Windows PowerShell 2.0 engine on Server1.

D.

Install Microsoft .NET Framework 4 on Server2.

E.

Install Remote Server Administration Tools on Server2

 

Correct Answer: BD

 

 

QUESTION 63

You have a DNS server named Server1. Server1 runs Windows Server 2012 R2. The network ID is 10.1.1.0/24. An administrator creates several reverse lookup zones. You need to identify which reverse lookup zone is configured correctly. Which zone should you identify? To answer, select the appropriate zone in the answer area.

 

70-410-demo-62

 

Correct Answer:

 

70-410-demo-63

 

 

QUESTION 64

You have a server named Server1. Server1 runs Windows Server 2012 R2. Server1 has two network adapters. Each network adapter must be configured as shown in the following table.

 

70-410-demo-64

You need to configure the correct IPv6 address prefix for each network adapter. Which prefix should you select for each network adapter?

To answer, drag the appropriate IPv6 prefix to the correct network adapter in the answer area. Each prefix may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

 

70-410-demo-65

 

Correct Answer:

70-410-demo-66

 

Explanation:

 

70-410-demo-67

 

http://www.iana.org/assignments/ipv6-address-space/ipv6-address-space.xml

 

 

QUESTION 65

Your company has a main office that contains 225 client computers. The client computers are located on a subnet that uses the network ID of 10.10.1.0/24. The company plans to open two branch offices. The offices will be configured as shown in the following table.

 

70-410-demo-68

 

You need to select a network prefix for each office to ensure that there are enough IPv4 addresses for each client computer. The solution must minimize the number of unused IP addresses. Which network prefixes should you select?

To answer, drag the appropriate network prefix to the correct branch office in the answer area.

 

70-410-demo-69

 

Correct Answer:

70-410-demo-70

 

QUESTION 66

Your infrastructure divided in 2 sites. You have a forest root domain and child domain. There is only one DC on site 2 with no FSMO roles. The link goes down to site 2 and no users can log on. What FSMO roles you need on to restore the access?

 

A.

Infrastructure master

B.

RID master

C.

Domain Naming master

D.

PCD emulator

 

Correct Answer: D 

 

 

QUESTION 67

You perform a Server Core Installation of window Server 2012 R2 on server named Server1.

You need to add a graphical user interface (GUI) to server1. Which tool should you use?

 

A.

the Add-WindowsFeature cmdlet

B.

the Install-Module cmdlet

C.

the setup.exe command

D.

the Add-WindowsPackage cmdlet

 

Correct Answer: A

 

QUESTION 68

A network technician installs Windows Server 2012 R2 Standard on a server named Server1.

A corporate policy states that all servers must run Windows Server 2012 R2 Enterprise.

You need to ensure that Server1 complies with the corporate policy.

You want to achieve this goal by using the minimum amount of administrative effort.

What should you perform?

 

A.

a clean installation of Windows Server 2012 R2

B.

an upgrade installation of Windows Server 2012 R2

C.

online servicing by using Dism

D.

offline servicing by using Dism

 

Correct Answer: C

Explanation:

A. Not least effort

B. Not least effort

C. dism /online /set-edition

D. offline would be less ideal and more workex: DISM /online /Set-

Edition:ServerEnterprise/ProductKey:489J6-VHDMP-X63PK-3K798-CPX3YWindows Server 2008 R2/2012 contains a command-line utility called DISM (Deployment Image Servicing

andManagement tool). This tool has many features, but one of those features is the ability to upgrade the edition ofWindows in use. Note that this process is for upgrades only and is irreversible. You cannot set a Windowsimage to a lower edition. The lowest edition will not appear when you run the /Get- TargetEditions option.

If the server is running an evaluation version of Windows Server 2012 R2 Standard or Windows Server 2012 R2 Datacenter, you can convert it to a retail version as follows:

If the server is a domain controller, you cannot convert it to a retail version. In this case, install an additionaldomain controller on a server that runs a retail version and remove AD DS from the domain controller thatruns on the evaluation version. From an elevated command prompt, determine the current edition name with the command DISM /online /Get-CurrentEdition. Make note of the edition ID, an abbreviated form of the edition name. Then run DISM /online /Set-Edition:<edition ID> /ProductKey:XXXXXXXXXX-XXXXX-XXXXX- XXXXX/AcceptEula,providing the edition ID and a retail product key.

The server will restart twice.

http://technet.microsoft.com/en-us/library/jj574204.aspx

http://technet.microsoft.com/en-us/library/dd744380%28v=ws.10%29.aspx http://blogs.technet.com/b/server_core/archive/2009/10/14/upgrading-windows-server2008-r2- without-media.aspx

http://communities.vmware.com/people/vmroyale/blog/2012/05/30/howto-upgradingwindows- edition-with-dism

 

 

QUESTION 69

You have a domain controller named Server1 that runs Windows Server 2012 R2 and has the DNS Server server role installed. Server1 hosts a DNS zone named contoso.com and a GlobalNames zone. You discover that the root hints were removed from Server1. You need to view the default root hints of Server1.

What should you do?

 

A.

From Event Viewer, open the DNS Manager log.

B.

From Notepad, open the Cache.dns file.

C.

From Windows Powershell, run Get-DNSServerDiagnostics.

D.

From nslookup, run root server1.contoso.com

 

Correct Answer: B

Explanation:

A. Allows you to troubleshoot DNS issues

B. DNS Server service implements root hints using a file, Cache.dns, stored in the

systemroot\System32\Dnsfolder on the server

C. Gets DNS event logging details

D.

http://technet.microsoft.com/en-us/library/cc758353(v=ws.10).aspx

 

 

QUESTION 70

Your company has a main office and two branch offices. The offices connect to each other by using a WAN link. In the main office, you have a server named Server1 that runs Windows Server 2012 R2. Server1 is configured to use an IPv4 address only. You need to assign an IPv6 address to Server1. The IP address must be private and routable. Which IPv6 address should you assign to Server1?

 

A.

fe80:ab32:145c::32cc:401b

B.

ff00:3fff:65df:145c:dca8::82a4

C.

2001:ab32:145c::32cc:401b

D.

fd00:ab32:14:ad88:ac:58:abc2:4

 

Correct Answer: D

 

QUESTION 71

Your network contains an Active Directory domain named contoso.com. All client computers run Windows 8.

You deploy a server named Server1 that runs Windows Server 2012 R2.

You install a new client-server application named App1 on Server1 and on the client computers. The client computers must use TCP port 6444 to connect to App1 on Server1. Server1 publishes the information of App1 to an intranet server named Server2 by using TCP port 3080. You need to ensure that all of the client computers can connect to App1. The solution must ensure that the application can connect to Server2.

Which Windows Firewall rule should you create on Server1?

 

A.

an inbound rule to allow a connection to TCP port 3080

B.

an outbound rule to allow a connection to TCP port 3080

C.

an outbound rule to allow a connection to TCP port 6444

D.

an inbound rule to allow a connection to TCP port 6444

 

Correct Answer: D

Explanation:

A. Server2 needs inbound on 3080

B. All ports outbound allowed by default

D. Server1 gets request from Client PC’s it needs a inbound rule for 6444

By default, Windows Firewall with Advanced Security blocks all unsolicited inbound networktraffic, and allows all outbound network traffic. For unsolicited inbound network traffic to reach your computer, you must create an allow rule to permit that type of network traffic. If a network program cannot get access, verify that in the Windows Firewall with Advanced Security snap-in there is an active allow rule for the current profile. To verify that there is an active allow rule, double-click Monitoring and then click Firewall.

If there is no active allow rule for the program, go to the Inbound Rules node and create a new rule for that program. Create either a program rule, or a service rule, or search for a group that applies to the feature and make sure all the rules in the group are enabled. To permit the traffic, you must create a rule for the program that needs to listen for that traffic. If you know the TCP or UDP port numbers required by the program, you can additionally restrict the rule to only those ports, reducing the vulnerability of opening up all ports for the program.

http://social.technet.microsoft.com/wiki/contents/articles/13894.troubleshooting-windows-firewall-with-advanced-security-in-windows-server-2012.aspx

 

 

QUESTION 72

Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2.

The domain contains a server named Server1.

You install the Windows PowerShell Web Access gateway on Server1.

You need to provide administrators with the ability to manage the servers in the domain by using the Windows PowerShell Web Access gateway.

Which two cmdlets should you run on Server1? (Each correct answer presents part of the solution. Choose two.)

 

A.

Set-WSManQuickConfig

B.

Set-WSManInstance

C.

Add-PswaAuthorizationRule

D.

Set-BCAuthentication

E.

Install-PswaWebApplication

 

Correct Answer: CE

Explanation:

A. Configures the local computer for remote management.

B. Modifies the management information that is related to a resource.

C. Adds a new authorization rule to the Windows PowerShell Web Access authorization rule set. D. Specifies the BranchCache computer authentication mode.

E. Configures the Windows PowerShell ® Web Access web Application in IIS.

http://technet.microsoft.com/en-us/library/hh849867.aspx

http://technet.microsoft.com/en-us/library/hh849875.aspx

http://technet.microsoft.com/en-us/library/jj592890(v=wps.620).aspx http://technet.microsoft.com/en-us/library/hh848404(v=wps.620).aspx http://technet.microsoft.com/en-us/library/jj592894(v=wps.620).aspx

 

 

 

 

QUESTION 73

Your network contains an Active Directory domain named contoso.com. All user accounts in the sales department reside in an organizational unit (OU) named OU1.

You have a Group Policy object (GPO) named GPO1. GPO1 is used to deploy a logon script to all of the users in the sales department.

You discover that the logon script does not run when the sales users log on to their computers. You open Group Policy Management as shown in the exhibit.

You need to ensure that the logon script in GPO1 is applied to the sales users. What should you do?

 

70-410-demo-73

 

A.

Enforce GPO1.

B.

Modify the link order of GPO1.

C.

Modify the Delegation settings of GPO1.

D.

Enable the link of GPO1.

 

Correct Answer: D

Explanation:

D. GPO1 needs to be linked to OU1

 

70-410-demo-74

 

http://technet.microsoft.com/en-us/library/cc732979.aspx

http://technet.microsoft.com/en-us/library/cc776004%28v=ws.10%29.aspx#BKMK_icons_link

 

 

QUESTION 74

You have a server named Server 1 that runs Windows Server 2012 R2. Server 1 has the Hyper-V server role installed.

You have fixed-size VHD named Files.vhd.

You need to make the contents in Files.vhd available to several virtual machines. The solution must meet the following requirements:

 

– Ensure that if the contents are changed on any virtual machine, the changes are not reflected on the other virtual machines.

– Minimize the amount of disk space used.

 

What should you do?

 

A.

Create a fixed-size VHDX. Transfer the information from Files.vhd to the new VHDX file.

B.

Convert Files.vhd to a dynamically expanding VHD?

C.

Create a dynamically expanding VHDX. Transfer the information from Files.vhd to the new VHDX file.

D.

Create differencing VHDs that use Files.vhd as the parent disk.

 

Correct Answer: D

Explanation:

A. A conversion would be needed from VHD to VHDX. Not available to multiple VM’s

B. Single VHD not available to multiple VM’s. Changes wouldn’t be reflected

C. A conversion would be needed from VHD to VHDX. Not available to multiple VM’s

D. Child disk for multiple VM’s with Files.vhd as parent A differencing disk is associated with another virtual hard disk that you select when you create the differencing disk. This means that the disk to which you want to associate the differencing disk must exist first. This virtual hard disk is called the “parent” disk and the differencing disk is the “child” disk.

The parent disk can be any type of virtual hard disk.

The differencing disk stores all changes that would otherwise be made to the parent disk if the differencing disk was not being used. The differencing disk provides an ongoing way to save changes without altering the parent disk. You can use the differencing disk to store changes indefinitely, as long as there is enough space on the physical disk where the differencing disk is stored. The differencing disk expands dynamically as data is written to it and can grow as large as the maximum size allocated for the parent disk when the parent disk was created.

http://technet.microsoft.com/en-us/library/cc720381(v=ws.10).aspx

 

 

QUESTION 75

Your network contains an Active Directory domain named adatum.com. The domain contains several thousand member servers that run Windows Server 2012 R2. All of the computer accounts for the member servers are in an organizational unit (OU) named ServersAccounts. Servers are restarted only occasionally.

You need to identify which servers were restarted during the last two days.

What should you do?

 

A.

Run dsquery computer and specify the -stalepwd parameter

B.

Run dsquery server and specify the -o parameter.

C.

Run Get-ADComputer and specify the lastlogon property.

D.

Run Get-ADComputer and specify the SearchScope parameter

 

Correct Answer: C

Explanation:

A. dsquery computer -stalepwdnumber_of_days – Searches for all computers that have not changed theirpassword for the specified number_of_days.

B. dsquery server -o {dn | rdn | samid} – Specifies the format in which the list of entries found by the search willbe displayed: dn distinguished name of each entry, default; rdn relative distinguished name of each entry;

samid SAM account name of each entry computer group server user; upn user principal name of each entryuser

C. Gets one or more Active Directory computers lastLogondate should be used

D. SearchScope specifies the scope of an Active Directory search. Possible values for this parameter are:

Base or 0; OneLevel or 1; Subtree or 2 – A Base query searches only the current path or object. AOneLevelquery searches the immediate children of that path or object. A Subtree query searches the current path orobject and all children of that path or object.

 

70-410-demo-75

 

http://technet.microsoft.com/en-us/library/ee617192.aspx

http://technet.microsoft.com/en-us/library/cc732952(v=ws.10).aspx

 

 

QUESTION 76

Your network contains three servers that run Windows Server 2012 R2. The servers are configured as shown in the following table (click Exhibit). Server3 is configured to obtain an IP address automatically.

You need to ensure that Server3 only receives an IP address from Server1. The IP address must always be the same.

Which two tasks should you perform? (Each correct answer presents part of the solution. Choose two.)

 

70-410-demo-76

 

A.

Create an exclusion on Server1.

B.

Create a filter on Server1.

C.

Create a reservation on Server2

D.

Create a reservation on Server1

E.

Create a filter on Server2.

 

Correct Answer: DE

Explanation:

A. Exclude range of IP’s for lease

B. Wrong Server

C. Wrong Sever

D. For clients that require a constant IP address, you can either manually configure a static IP address,or assign a reservation on the DHCP server

E. DHCP Deny Filter at Server2 to exclude MAC address of Server3 MAC address filterEnable and define an explicit allow list. The DHCP server provides DHCP services only to clients whose MACaddresses are in the allow list. Any client that previously received IP addresses is denied address renewal if its MAC address isn’t onthe allow list.

Enable and define an explicit deny list. The DHCP server denies DHCP services only to clients whose MACaddresses are in the deny list.

Any client that previously received IP addresses is denied address renewal if its MAC address is on thedeny list.

Enable and define an allow list and a block list.

The block list has precedence over the allow list. This means that the DHCP server provides DHCPservices only to clients whose MAC addresses are in the allow list, provided that no corresponding matchesare in the deny list.

If a MAC address has been denied, the address is always blocked even if the address is on the allowlist.

http://technet.microsoft.com/en-us/library/cc754537(v=ws.10).aspx http://technet.microsoft.com/en-us/magazine/ff521761.aspx

http://technet.microsoft.com/en-us/library/cc779507(v=ws.10).aspx

 

 

QUESTION 77

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012 R2 and a client computer named Computer1 that runs Windows 8. DC1 is configured as a DHCP server as shown in the exhibit. (Click the Exhibit button.) Computer1 is configured to obtain an IP address automatically.

You need to ensure that Computer1 can receive an IP address from DC1.

What should you do?

 

70-410-demo-77

 

A.

Disable the Allow filters.

B.

Disable the Deny filters

C.

Activate Scope [10.1.1.0] Contoso.com.

D.

Authorize dc1.contoso.com.

 

Correct Answer: D

 

QUESTION 78

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named Server1 that has the DNS Server server role installed. Server1 hosts a primary zone for contoso.com. The domain contains a member server named Server2 that is configured to use Server1 as its primary DNS server. From Server2, you run nslookup.exe as shown in the exhibit. (Click the Exhibit button.)

You need to ensure that when you run Nslookup, the correct name of the default server is displayed.

What should you do?

 

70-410-demo-78

 

A.

From Advanced TCP/IP Settings on Server1, add contoso.com to the DNS suffix list

B.

On Server1, modify the Security settings of the contoso.com zone

C.

On Server1, create a reverse lookup zone.

D.

From Advanced TCP/IP Settings on Server2, add contoso.com to the DNS suffix list

 

Correct Answer: C

Explanation:

C. Make sure that a reverse lookup zone that is authoritative for the PTR resource record exists. For more information about adding a reverse lookup zone, see “Adding a Reverse Lookup Zone” http://technet.microsoft.com/en-us/library/cc961417.aspx

 

 

QUESTION 79

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that hosts the primary DNS zone for contoso.com. All client computers are configured to use DC1 as the primary DNS server.

You need to configure DC1 to resolve any DNS requests that are not for the contoso.com zone by querying the DNS server of your Internet Service Provider (ISP).

What should you configure?

 

A.

Name server (NS) records

B.

Condition& forwarders

C.

Forwarders

D.

Naming Authority Pointer (NAPTR) DNS resource records (RR)

 

Correct Answer: C

 

QUESTION 80

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2012 R2. The domain contains a server named Server1 that runs Windows Server 2012 R2.

You need to ensure that when users log on to Server1, their user account is added automatically to a local group named Group1 during the log on process.

Which Group Policy settings should you modify?

 

A.

Restricted Groups

B.

Security Options

C.

User Rights Assignment

D.

Preferences

 

Correct Answer: D

 

QUESTION 81

Your network contains an Active Directory domain named contoso.com.

You need to prevent users from installing a Windows Store app named App1.

What should you create?

 

A.

An application control policy executable rule

B.

An application control policy packaged app rule

C.

A software restriction policy certificate rule

D.

An application control policy Windows Installer rule

 

Correct Answer: B

 

 

 

 

QUESTION 82

Your network contains an Active Directory domain named contoso.com. The domain contains 500 servers that run Windows Server 2012 R2. You have a written security policy that states the following:

 

– Only required ports must be open on the servers.

– All of the servers must have Windows Firewall enabled.

– Client computers used by Administrators must be allowed to access all of the ports on all of the servers.

– Client computers used by the Administrators must be authenticated before the client computers can access the servers.

 

You have a client computer named Computer1 that runs Windows 8. You need to ensure that you can use Computer1 to access all of the ports on all of the servers successfully. The solution must adhere to the security policy.

Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

 

A.

On Computer1, create a connection security rule

B.

On all of the servers, create an outbound rule and select the Allow the connection if it is secureoption.

C.

On all of the servers, create an inbound rule and select the Allow the connection if it is secureoption.

D.

On Computer1, create an inbound rule and select the Allow the connection if it is secureoption.

E.

On Computer1, create an outbound rule and select the Allow the connection if it is secureoption

F.

On all of the servers, create a connection security rule

 

Correct Answer: ACF

Explanation:

http://technet.microsoft.com/en-us/library/cc772017.aspx

Unlike firewall rules, which operate unilaterally, connection security rules require that both communicating computers have a policy with connection security rules or another compatible IPsec policy.

http://technet.microsoft.com/en-us/library/cc753463.aspx

Traffic that matches a firewall rule that uses the Allow connection if it is secure setting bypasses Windows Firewall. The rule can filter the traffic by IP address, port, or protocol. This method is supported on Windows Vista or Windows Server 2008.

 

 

QUESTION 83

Your company’s security policy states that all of the servers deployed to a branch office must not have the graphical user interface (GUI) installed. In a branch office, a support technician installs a server with a GUI installation of Windows Server 2012 on a new server, and then configures the server as a DHCP server.

You need to ensure that the new server meets the security policy. You want to achieve this goal by using the minimum amount of Administrative effort.

What should you do?

 

A.

Reinstall Windows Server 2012 on the server.

B.

From Windows PowerShell, run Uninstall-WindowsFeature Desktop-Experience.

C.

From Windows PowerShell, run Uninstall-WindowsFeature PowerShell-ISE.

D.

From Server Manager, uninstall the User Interfaces and Infrastructure feature.

 

Correct Answer: D

Explanation:

A. Not least effort

B. Uninstalls desktop experience not the full GUI

C. Uninstalls the powershell ISE

D. Least effort and removes full GUI

 

 

70-410-demo-79

 

http://www.howtogeek.com/111967/how-to-turn-the-gui-off-and-on-in-windows-server-2012/ http://technet.microsoft.com/en-us/library/cc772567.aspx http://blogs.technet.com/b/server_core/archive/2012/05/09/configuring-the-minimal- serverinterface.aspx

 

 

 

 

 

 

 

 

 

 

 

 

 

QUESTION 84

Your network contains three servers. The servers are configured as shown in the following table.

 

70-410-demo-80

 

Your company plans to standardize all of the servers on Windows Server 2012 R2.

You need to recommend an upgrade path for each server. The solution must meet the following requirements:

 

• Upgrade the existing operating system whenever possible.

• Minimize hardware purchases.

 

Which upgrade path should you recommend for each server?

To answer, drag the appropriate upgrade path to each server in the answer area. Each upgrade path may be used once, more than once, or not at all.

 

70-410-demo-81

 

Correct Answer:

 

70-410-demo-82

 

 

 

QUESTION 85

Your network contains a file server named Server1 that runs Windows Server 2012 R2. All client computers run Windows 8. Server1 contains a folder named Folder1. Folder1 contains the installation files for the company’s desktop applications. A network technician shares Folder1 as Share 1.

You need to ensure that the share for Folder1 is not visible when users browse the network.

What should you do?

 

A.

From the properties of Folder1, deny the List Folder Contents permission for the Everyone group.

B.

From the properties of Folder1, remove Share1, and then share Folder1 as Share1$.

C.

From the properties of Folder1, configure the hidden attribute.

D.

From the properties of Share1, configure access-based enumeration

 

Correct Answer: B

Explanation:

A. Will deny everyone list of folder content

B. Remove share and re-add using $ for Hidden/Administrative share

C. This will hide the physical folder

D. lists only the files and folders to which they have access when browsing content on the file server A hidden share is identified by a dollar sign ($) at the end of the share name

Hidden shares are not listed when you look through the shares on a computer or use the “net view” command

Why Use Hidden Shares?

Using hidden shares on your network is useful if you do not want a shared folder or drive on the network to beeasily accessible. Hidden shares can add another layer of protection for shared files against unauthorizedpeople connecting to your network. Using hidden shares helps eliminate the chance for people to guess yourpassword (or be logged into an authorized Windows account) and then receive access to the shared resource.

 

70-410-demo-84

 

http://support.microsoft.com/kb/314984

http://technet.microsoft.com/en-us/library/cc784710(v=ws.10).aspx

 

 

QUESTION 86

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2 and a server named Server2 that runs Windows Server 2008 R2 Service Pack 1 (SP1). Both servers are member servers. On Server2, you install all of the software required to ensure that Server2 can be managed remotely from Server Manager.

You need to ensure that you can manage Server2 from Server1 by using Server Manager.

Which two tasks should you perform on Server2? (Each correct answer presents part of the solution. Choose two.)

 

A.

Run the systempropertiesremote.execommand

B.

Run the Enable-PsRemotingcmdlet.

C.

Run the Enable-PsSessionConfigurationcmdlet

D.

Run the Confiqure-SMRemoting.ps1script

E.

Run the Set-ExecutionPolicycmdlet.

 

Correct Answer: DE

 

 

 

 

QUESTION 87

Your network contains an Active Directory domain named contoso.com. The domain contains a print server named Server1 that runs Windows Server 2012 R2. You share several printers on Server1. You need to ensure that you can view the printer objects associated to Server1 in Active Directory Users and Computers.

Which option should you select? To answer, select the appropriate option in the answer area.

 

70-410-demo-86

 

Correct Answer:

 

70-410-demo-87

 

Explanation:

You can view printer objects in Active Directory by clicking Users, Groups, and Computers as containers from the View menu in the Active Directory Users and Computers snap-in.

By default, printer objects are created under the machine object in which they are shared. After you turn on the Users, Groups, and Computers as containers option, you can see printers by expanding the printer’s host computer.

http://support.microsoft.com/kb/235925

 

 

QUESTION 88

Your network contains an Active Directory domain named contoso.com. The domain contains two member servers named Server1 and Server2 that run Windows Server 2012 R2. You log on to Server1. You need to retrieve the IP configurations of Server2. Which command should you run from Server1?

 

A.

winrs -r:server2 ipconfig

B.

winrm get server2

C.

dsquery *-scope base-attr ip, server2

D.

ipconfig > server2.ip

 

Correct Answer: A

 

 

 

QUESTION 89

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the Hyper-V server role installed. The disks on Server1 are configured as shown in the exhibit. (Click the Exhibit button.) You create a virtual machine on Server1. You need to ensure that you can configure a pass-through disk for the virtual machine. What should you do?

 

70-410-demo-89

 

A.

Delete partition E.

B.

Convert Disk 1 to a GPT disk

C.

Convert Disk 1 to a dynamic disk.

D.

Take Disk 1 offline.

 

Correct Answer: D

Explanation:

Pass-Through Disk must be offline

Pass-through Disk Configuration

Hyper-V allows virtual machines to access storage mapped directly to the Hyper-V server without requiring thevolume be configured. The storage can either be a physical disk internal to the Hyper-V server or it can be aStorage Area Network (SAN) Logical Unit (LUN) mapped to the Hyper-V server. To ensure the Guest hasexclusive access to the storage, it must be placed in an Offline state from the Hyper-V serverperspective

http://blogs.technet.com/b/askcore/archive/2008/10/24/configuring-pass-through-disks-inhyper- v.aspx

http://technet.microsoft.com/pt-pt/library/ff404147%28v=ws.10%29.aspx

 

 

 

 

 

QUESTION 90

You work as an administrator at ENSUREPASS.com. The ENSUREPASS.com network consists of a single domain named ENSUREPASS.com. All servers on the ENSUREPASS.com network have Windows Server 2008 R2 installed. Some of ENSUREPASS.com’s workstations have Windows 7 installed, while the rest have Windows 8 installed.

After installing a new Windows Server 2012 computer in the ENSUREPASS.com domain, you configure it to run the File and Storage Services server role. You are instructed to create a shared folder on the new server, and configure the use of Previous Versions for restoring files located in the shared folder.

Which of the following actions should you take?

 

A.

You should consider configuring the Shadow Copies settings on the new server.

B.

You should consider configuring the Snapshot settings on the new server.

C.

You should consider configuring the Background Copy settings on the new server.

D.

You should consider configuring the Permission settings on the new server.

 

Correct Answer: A

 

QUESTION 91

Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server2 runs Windows Server 2012 R2. You create a security template named Template 1 by using the Security Templates snap-in. You need to apply template 1 to Server 2. Which tool should you use?

 

A.

Security Templates.

B.

Computer Management.

C.

Security Configuration and Analysis.

D.

System Configuration.

 

Correct Answer: C

Explanation:

Security templates are inactive until imported into a Group Policy object or the Security Configurationand Analysis.

 

70-410-demo-90

 

http://technet.microsoft.com/en-us/library/jj730960.aspx

http://windows.microsoft.com/en-us/windows-vista/using-system-configuration

 

 

QUESTION 92

Your network contains an active directory domain named contoso.com. The domain contains a domain controller named DCS. DCS has a server core installation of windows server 2012. You need to uninstall Active Directory from DCS manually. Which tool should you use?

 

A.

The Remove-WindowsFeature cmdlet

B.

the dsamain.exe command

C.

the ntdsutil.exe command

D.

the Remove-ADComputer cmdlet

 

Correct Answer: C

Explanation:

A. Removes Roles and Features to remove DC use Uninstall-addsdomaincontroller

B.Exposes Active Directory data that is stored in a snapshot or backup as a Lightweight Directory Access

Protocol (LDAP) server

C. Manually removes a domain controller

D. Removes AD computer object

http://technet.microsoft.com/en-us/library/ee662310.aspx

http://support.microsoft.com/kb/216498

http://technet.microsoft.com/en-us/library/ee617250.aspx

 

 

QUESTION 93

You have a server named Server 2 that runs Windows Server 2012 R2. Server 2 has the Hyper-V server role installed.

The disks on Server2 are configured as shown in the exhibit. (Click the Exhibit button).

You create a virtual machine on Server2 named VM1. You need to ensure that you can configure a pass-through disk for VM1. What should you do?

 

70-410-demo-91

 

A.

Convert Disk 1 to a MBR disk.

B.

Convert Disk 1 to a basic disk.

C.

Take Disk 1 offline.

D.

Create a partition on Disk 1.

 

Correct Answer: C

Explanation:

Pass-through Disk Configuration

Hyper-V allows virtual machines to access storage mapped directly to the Hyper-V server without requiring the volume be configured. The storage can either be a physical disk internal to the Hyper-V server or it can be a Storage Area Network (SAN) Logical Unit (LUN) mapped to the Hyper-V server. To ensure the Guest has exclusive access to the storage, it must be placed in an Offline state from the Hyper-V server perspective

http://blogs.technet.com/b/askcore/archive/2008/10/24/configuring-pass-through-disks-in-hyper-v.aspx

 

  

QUESTION 94

You have a file server named Server1 that runs Windows Server 2012 R2. Server1 has following hardware configurations:

 

 16GB of RAM

 A single quad-core CPU

 Three network teams that have two network adapters each

 

You add additional CPUs and RAM to Server 1.

You repurpose Server1 as a virtualization host. You install the Hyper-V server role on Server1. You need to create four external virtual switches in Hyper-V. Which cmdlet should you run first?

 

A.

Set-NetAdapter.

B.

Add-Net1.bfoTeamNic

C.

Add-VMNetworkAdapter

D.

Remove-NetLbfoTeam

 

Correct Answer: D

 

QUESTION 95

Your network contains an Active Directory domain named contoso.com. The domain contains two servers that run Windows Server 2012 R2.

You create a security template named template 1 by using the Security Templates snap-in.

You need to apply Template 1 to Server2.

Which tool should you use?

 

A.

Authorization Manager

B.

Local Security Policy

C.

Certificate Templates

D.

System Configuration

 

Correct Answer: B

Explanation:

A security policy is a combination of security settings that affect the security on a computer. You can use your local security policy to edit account policies and local policies on your local computer.

 

 

QUESTION 96

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server 2012. You create a group Manged Service Account named gservice1. You need to configure a service named Service1 to run as the gservice1 account. How should you configure Service1?

 

A.

From a command prompt, run sc.exe and specify the config parameter.

B.

From Windows PowerShell,run Set-Service and specify the -PassThrough parameter

C.

From Windows PowerShell,run Set-Service and specify the -StartupType parameter

D.

From Services Console configure the General settings

 

Correct Answer: A

 

 

QUESTION 97

Your network contains an Active Directory domain named adatum.com. The domain contains a member server named Server1 and a domain controller named DC2. All servers run Windows Server 2012 R2. On DC2, you open Server Manager and you add Server1 as another server to manage. From Server Manager on DC2, you right-click Server1 as shown in the exhibit. You need to ensure that when you right-click Server1, you see the option to run the DHCP console. What should you do?

 

70-410-demo-92

 

A.

On Server1, install the Feature Administration Tools.

B.

In the domain, add DC1 to the DHCP Administrators group.

C.

On DC2 and Server1, run winrm quickconfig.

D.

On DC2, install the Role Administration Tools.

Correct Answer: D

Explanation:

http://technet.microsoft.com/en-us/library/hh831825.aspx

 

 

QUESTION 98

Your network contains an Active Directory domain named contoso.com. An organizational unit (OU) named OU1 contains user accounts and computer accounts. A Group Policy object (GPO) named GP1 is linked to the domain. GP1 contains Computer Configuration settings and User Configuration settings.

You need to prevent the User Configuration settings in GP1 from being applied to users. The solution must ensure that the Computer Configuration settings in GP1 are applied to all client computers. What should you configure?

 

A.

the Group Policy loopback processing mode

B.

the Block Inheritance feature

C.

the Enforced setting

D.

the GPO Status

 

Correct Answer: A

Explanation:

A. Group Policy loopback with replace option needs to be used B. Blocking inheritance prevents Group Policy objects (GPOs) that are linked to higher sites, domains, ororganizational units from being automatically inherited by the child-level C. Enforced prevent blocking at lower level

D. The GPO Status. This indicates whether either the user configuration or computer configuration of the GPOis enabled or disabled.

You can use the Group Policy loopback feature to App1y Group Policy Objects (GPOs) that depend only onwhich computer the user logs on to.

User Group Policy loopback processing can be enabled in one of two modes: merge or replace. In mergemode, both GPOs App1ying to the user account and GPOs App1ying to the computer account are processedwhen a user logs in. GPOs that App1y to the computer account are processed second and therefore takeprecedence ?if a setting is defined in both the GPO(s) App1ying to the user account, and the GPO(s) App1yingto the computer account, the setting in the GPO(s) App1ying to the computer account will be enforced. With thereplace mode, GPOs App1ying to the user account are not processed ?only the GPOs App1ying to thecomputer account are App1ied. Loopback can be set to Not Configured, Enabled, or Disabled. In the Enabled state, loopback can be set toMerge or Replace. In either case the user only receives user-related policy settings. Loopback with Replace–In the case of Loopback with Replace, the GPO list for the user is replaced in itsentirety by the GPO list that is already obtained for the computer at computer startup (during step 2 in GroupPolicy processing and precedence). The User Configuration settings from this list are App1ied to the user.

Loopback with Merge–In the case of Loopback with Merge, the Group Policy object list is a concatenation.

The default list of GPOs for the user object is obtained, as normal, but then the list of GPOs for the computer(obtained during computer startup) is appended to this list. Because the computer’s GPOs are processed afterthe user’s GPOs, they have precedence if any of the settings conflict. This is a COMPUTER setting, which is found under Computer Configuration | Administrative Templates |

System | Group Policy | User Group Policy Loopback Processing Mode You want to create a new OU in AD that is dedicated to computer accounts that will have loopbackprocessing enabled. Create a new GPO in your new OU to enable User Group Policy Loopback Processing and set theappropriate mode (merge / replace).

You will define the user settings you want to App1y to the loopback-enabled PCs via GPOs in this same newOU. You can define these settings either in the same GPO where you enabled the User Group PolicyLoopback Processing setting, or you create another new GPO in the same OU for your user settings.

Remember that when using the REPLACE mode, none of your other user GPOs will be App1ied whena user logs in to a machine that has loopback processing enabled. ONLY the user settings that aredefined in the GPOs that App1y to that machine will be App1ied.

http://msmvps.com/blogs/cgross/archive/2009/10/12/group-policy-loopbackprocessing.aspx http://technet.microsoft.com/en-us/library/cc782810(v=ws.10).aspx http://technet.microsoft.com/en-us/library/cc731076.aspx

http://technet.microsoft.com/en-us/library/cc753909.aspx

http://technet.microsoft.com/en-us/library/cc778238%28v=ws.10%29.aspx http://technet.microsoft.com/en-us/magazine/dd673616.aspx

 

 

QUESTION 99

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1. Server1 runs Windows Server 2012 R2 and has the Hyper-V server role installed.

On Server1, you create a virtual machine named VM1. When you try to add a RemoteFX 3D Video Adapter to VM1, you discover that the option is unavailable as shown in the following exhibit.

 

70-410-demo-93

 

You need to add the RemoteFX 3D Video Adapter to VM1.

What should you do first?

 

A.

On Server1, run the Enable-VMRemoteFxPhysicalVideoAdapter cmdlet.

B.

On Server1, install the Media Foundation feature.

C.

On Server1, run the Add-VMRemoteFx3dVideoAdapter cmdlet.

D.

On Server1, install the Remote Desktop Virtualization Host (RD Virtualization Host) role service.

 

Correct Answer: D

 

QUESTION 100

Your network contains two Hyper-V hosts named Host1 and Host2. Host1 contains a virtual machine named VM1. Host2 contains a virtual machine named VM2. VM1 and VM2 run Windows Server 2012 R2. You install the Network Load Balancing feature on VM1 and VM2. You need to ensure that the virtual machines are configured to support Network Load Balancing (NLB). Which virtual machine settings should you configure on VM1 and VM2?

 

A.

Router guard

B.

DHCP guard

C.

Port mirroring

D.

MAC address

 

Correct Answer: D

QUESTION 101

Your network contains a Windows Server 2012 R2 image named Server12.wim. Server12.wim contains the images shown in the following table.

 

70-410-demo-94

 

Server12.wim is located in C:\.

You need to enable the Windows Server Migration Tools feature in the Windows Server 2012 R2 Server Datacenter image. You want to achieve this goal by using the minimum amount of Administrative effort.

Which command should you run first?

 

A.

dism.exe /mount-wim /wimfile:c:\Server12.wim /index:4 /mountdir:c:\mount

B.

imagex.exe /capture c: c:\Server12.wim “windows server 2012server datacenter”

C.

dism.exe /image: c:\Server12.wim /enable-feature /featurename: servermigration

D.

imagex.exe /apply c:\Server12.wim 4 c:\

 

Correct Answer: A

Explanation:

A. Mounts the image before making any chnages

B. imagex /capture creates windows images .wim

C. You need to mount the image first

D. imagex /App1y App1ies image to drive

The Deployment Image Servicing and Management (DISM) tool is a command-line tool that is used to modifyWindows?images. You can use DISM to enable or disable Windows features directly from the commandprompt, or by App1ying an answer file to the image. You can enable or disable Windows features offline on a WIM or VHD file, or online on a running operating system.

You can also use the DISM image management command to list the image index numbers or to verify thearchitecture for the image that you are mounting.ex:

Dism /Mount-Image /ImageFile:C:\test\images\install.wim /Name:”Base Windows Image”

/MountDir:C:\test\offline

By default, DISM is installed at C:\Program Files (x86)\Windows Kits\8.0\Assessment and

Deployment Kit\Deployment Tools\

http://technet.microsoft.com/en-us/library/hh824822.aspx

http://technet.microsoft.com/en-us/library/hh825258.aspx

http://technet.microsoft.com/en-us/library/cc749447(v=ws.10).aspx http://technet.microsoft.com/en-us/library/dd744382(v=ws.10).aspx

 

 

QUESTION 102

Your network contains an Active Directory domain named contoso.com. The network contains a domain controller named DC1 that has the DNS Server server role installed. DC1 has a standard primary DNS zone for contoso.com.

You need to ensure that only client computers in the contoso.com domain will be able to add their records to the contoso.com zone.

What should you do first?

 

A.

Modify the Security settings of Dc1

B.

Modify the Security settings of the contoso.com zone.

C.

Store the contoso.com zone in Active Directory

D.

Sign the contoso.com zone.

 

Correct Answer: C

Explanation:

C. Only Authenticated users can create records when zone is stored in AD Secure dynamic updates allow an administrator to control what computers update what names and preventunauthorized computers from overwriting existing names in DNS. If you have an Active Directory infrastructure, you can only use Active Directory – integrated zones on ActiveDirectory domain controllers. If you are using Active Directory – integrated zones, you must decide whether or not to store Active Directory – integrated zones in the Application directory partition. To configure computers to update DNS data more securely, store DNS zones in Active Directory DomainServices (AD DS) and use the secure dynamic update feature. Secure dynamic update restricts DNS zone updates to only those computers that are authenticated and joinedto the Active Directory domain where the DNS server is located and to the specific security settings that aredefined in the access control lists (ACLs) for the DNS zone.

http://technet.microsoft.com/en-us/library/cc731204(v=ws.10).aspx http://technet.microsoft.com/en-us/library/cc755193.aspx

http://technet.microsoft.com/en-us/library/cc786068%28v=ws.10%29.aspx

 

 

QUESTION 103

Your network contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Hyper-V server role installed. Server1 hosts four virtual machines named VM1, VM2, VM3, and VM4. Server1 is configured as shown in the following table.

 

70-410-demo-95

 

You install a network monitoring application on VM2.

You need to ensure that all of the traffic sent to VM3 can be captured on VM2.

What should you configure?

 

A.

NUMA topology

B.

Resource control

C.

resource metering

D.

virtual Machine Chimney

E.

the VLAN ID

F.

Processor Compatibility

G.

the startup order

H.

Automatic Start Action

I.

Integration Services

J.

Port mirroring

K.

Single-root I/O virtualization

 

Correct Answer: J

Explanation:

J. With Hyper-V Virtual Switch port mirroring, you can select the switch ports that are monitored as well as the switch port that receives copies of all the traffic

 

70-410-demo-96

 

http://technet.microsoft.com/en-us/library/jj679878.aspx#bkmk_portmirror

 

 

QUESTION 104

Your network contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Hyper-V server role installed. Server1 hosts four virtual machines named VM1, VM2, VM3, and VM4. Server1 is configured as shown in the following table.

 

70-410-demo-97

 

You plan to schedule a complete backup of Server1 by using Windows Server Backup.

You need to ensure that the state of VM1 is saved before the backup starts.

What should you configure?

 

A.

NUMA topology

B.

Resource control

C.

resource metering

D.

virtual Machine Chimney

E.

the VLAN ID

F.

Processor Compatibility

G.

the startup order

H.

Automatic Start Action

I.

Integration Services

J.

Port mirroring

K.

Single-root I/O virtualization

 

Correct Answer: I

 

 

QUESTION 105

Your network contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Hyper-V server role installed. Server1 hosts four virtual machines named VM1, VM2, VM3, and VM4. Server1 is configured as shown in the following table.

 

70-410-demo-99

 

VM3 is used to test applications. You need to prevent VM3 from synchronizing its clock to Server1. What should you configure?

 

A.

NUMA topology

B.

Resource control

C.

resource metering

D.

virtual Machine Chimney

E.

the VLAN ID

F.

Processor Compatibility

G.

the startup order

H.

Automatic Start Action

I.

Integration Services

J.

Port mirroring

K.

Single-root I/O virtualization

 

Correct Answer: I

 

QUESTION 106

Your network contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Hyper-V server role installed. Server1 hosts four virtual machines named VM1, VM2, VM3, and VM4. Server1 is configured as shown in the following table.

 

70-410-demo-101

 

You need to configure VM4 to track the CPU, memory, and network usage.

What should you configure?

 

A.

NUMA topology

B.

Resource control

C.

resource metering

D.

Virtual Machine Chimney

E.

the VLAN ID

F.

Processor Compatibility

G.

the startup order

H.

Automatic Start Action

I.

Integration Services

J.

Port mirroring

K.

Single-root I/O virtualization

 

Correct Answer: C

 

QUESTION 107

Your network contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Hyper-V server role installed. Server1 hosts four virtual machines named VM1, VM2, VM3, and VM4. Server1 is configured as shown in the following table.

 

70-410-demo-102

 

You need to ensure that VM1 can use more CPU time than the other virtual machines when the CPUs on Server1 are under a heavy load.

What should you configure?

 

A.

NUMA topology

B.

Resource control

C.

resource metering

D.

Virtual Machine Chimney

E.

The VLAN ID

F.

Processor Compatibility

G.

The startup order

H.

Automatic Start Action

I.

Integration Services

J.

Port mirroring

K.

Single-root I/O virtualization

 

Correct Answer: B

Explanation:

B. Resource controls provide you with several ways to control the way that Hyper-V allocates resources to virtual machine

When you create a virtual machine, you configure the memory and processor to provide the appropriate computing resources for the workload you plan to run on the virtual machine. This workload consists of the guest operating system and all applications and services that will run at the same time on the virtual machine.

Resource controls provide you with several ways to control the way that Hyper-V allocates resources to virtual machines.

Virtual machine reserve. Of the processor resources available to a virtual machine, specifies the percentage that is reserved for the virtual machine. This setting guarantees that the percentage you specify will be available to the virtual machine. This setting can also affect how many virtual machines you can run at one time.

Virtual machine limit. Of the processor resources available to a virtual machine, specifies the maximum percentage that can be used by the virtual machine. This setting applies regardless of whether other virtual machines are running.

Relative weight. Specifies how Hyper-V allocates resources to this virtual machine when more than one virtual machine is running and the virtual machines compete for resources.

http://technet.microsoft.com/en-us/library/cc742470.aspx

70-410-demo-103

 

 

QUESTION 108

Your network contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Hyper-V server role installed. Server1 hosts four virtual machines named VM1, VM2, VM3, and VM4. Server1 is configured as shown in the following table.

 

70-410-demo-104

 

VM2 sends and receives large amounts of data over the network. You need to ensure that the network traffic of VM2 bypasses the virtual switches of the parent partition. What should you configure?

 

A.

NUMA topology

B.

Resource control

C.

Resource metering

D.

Virtual Machine Chimney

E.

The VLAN ID

F.

Processor Compatibility

G.

The startup order

H.

Automatic Start Action

I.

Integration Services

J.

Port mirroring

K.

Single-root I/O virtualization

 

Correct Answer: K

 

 

QUESTION 109

Your network contains an Active Directory domain named contoso.com. The network contains a member server named Server1 that runs Windows Server 2012 R2. Server1 has the DNS Server server role installed and has a primary zone for contoso.com. The Active Directory domain contains 500 client computers. There are an additional 20 computers in a workgroup. You discover that every client computer on the network can add its record to the contoso.com zone.

You need to ensure that only the client computers in the Active Directory domain can register records in the contoso.com zone.

What should you do first?

 

A.

Move the contoso.com zone to a domain controller that is configured as a DNS server

B.

Configure the Dynamic updates settings of the contoso.com zone

C.

Sign the contoso.com zone by using DNSSEC

D.

Configure the Security settings of the contoso.com zone.

 

Correct Answer: A

 

QUESTION 110

Your company has a remote office that contains 1,600 client computers on a single subnet.

You need to select a subnet mask for the network that will support all of the client computers. The solution must minimize the number of unused addresses. Which subnet mask should you select?

 

A.

255.255.248.0

B.

255.255.252.0

C.

255.255.254.0

D.

255.255.240.0

 

Correct Answer: A

 

QUESTION 111

You plan to deploy a DHCP server that will support four subnets. The subnets will be configured as shown in the following table.

 

70-410-demo-107

 

You need to identify which network ID you should use for each subnet.

What should you identify? To answer, drag the appropriate network ID to the each subnet in the answer area.

 

70-410-demo-108

 

Correct Answer:

 

70-410-demo-109

 

 

 

 

QUESTION 112

You work as a senior administrator at ENSUREPASS.com. The ENSUREPASS.com network consists of a single domain named ENSUREPASS.com. All servers on the ENSUREPASS.com network have Windows Server 2012 R2 installed, and all workstations have Windows 8 installed.

You are running a training exercise for junior administrators. You are currently discussing a Windows PowerShell cmdlet that activates previously de-activated firewall rules.

Which of the following is the cmdlet being discussed?

 

A.

Set-NetFirewallRule

B.

Enable-NetFirewallRule

C.

Set-NetIPsecRule

D.

Enable-NetIPsecRule

 

Correct Answer: B

 

QUESTION 113

Your network contains a server named Server1 that runs Windows Server 2012 R2. Server1 is located on the same subnet as all of the client computers. A network technician reports that he receives a “Request timed out” error message when he attempts to use the ping utility to connect to Server1 from his client computer. The network technician confirms that he can access resources on Server1 from his client computer.

You need to configure Windows Firewall with Advanced Security on Server1 to allow the ping utility to connect. Which rule should you enable?

 

A.

File and Printer Sharing (Echo Request – ICMPv4-In)

B.

Network Discovery (WSD-In)

C.

File and Printer Sharing (NB-Session-In)

D.

Network Discovery (SSDP-In)

 

Correct Answer: A

 

 

QUESTION 114

You have a file server named Server1 that runs Windows Server 2012 R2.

You need to ensure that a user named User1 can use Windows Server Backup to create a complete backup of Server1. What should you configure?

 

A.

The local groups by using Computer Management

B.

A task by using Authorization Manager

C.

The User Rights Assignment by using the Local Group Policy Editor

D.

The Role Assignment by using Authorization Manager

 

Correct Answer: A

 

 

QUESTION 115

Your network contains a production Active Directory forest named contoso.com and a test Active Directory forest named contoso.test. A trust relationship does not exist between the forests. In the contoso.test domain, you create a backup of a Group Policy object (GPO) named GPO1. You transfer the backup of GPO1 to a domain controller in the contoso.com domain.

You need to create a GPO in contoso.com based on the settings of GPO1. You must achieve this goal by using the minimum amount of Administrative effort.

What should you do?

 

A.

From Windows PowerShell, run the Get-GPO cmdlet and the Copy- GPO cmdlet.

B.

From Windows PowerShell, run the New-GPO cmdlet and the Import- GPO cmdlet.

C.

From Group Policy Management, create a new starter GPO. Right-click the new starter GPO, and then

click Restore from Backup.

D.

From Group Policy Management, right-click the Croup Policy Objects container, and then click Manage

Backups.

 

Correct Answer: B

 

 

QUESTION 116

Your network contains an active directory forest. The forest functional level is Windows server

2012. The forest contains a single domain. The domain contains a member server named

Server1 that run windows server 2012. You purchase a network scanner named Scanner1 that

supports Web Services on Devices (WDS). You need to share the network scanner on Server1

Which server role should you install on Server1?

 

A.

Web Server (IIS)

B.

Fax Server

C.

File and Storage Services

D.

Print and Document Services

 

Correct Answer: D

 

 

QUESTION 117

Your network contains an Active Directory forest named contoso.com. The forest contains a child domain named europe.contoso.com. The europe.contoso.com child domain contains a server named Server1 that runs Windows Server 2012 R2. You install the DHCP Server server role on Server1. You have access to the administrative accounts shown in the following table.

 

70-410-demo-113

 

You need to authorize Server1. Which user account should you use?

 

A.

Admin1

B.

Admin2

C.

Admin3

D.

Admin4

 

Correct Answer: D

 

 

QUESTION 118

Your network contains a server named Server1 that runs Windows Server 2012 R2. App1 has the Print and Document Services server role installed. All client computers run Windows 8. The network contains a network-attached print device named Printer1. From App1, you share Printer1. You need to ensure that users who have connected to Printer1 previously can print to Printer1 if App1 fails. What should you configure?

To answer, select the appropriate option in the answer area.

 

70-410-demo-114

 

Correct Answer:

 

70-410-demo-115

  

QUESTION 119

You have a server named Server1. Server1 runs Windows Server 2012 R2. Server1 has two network adapters and is located in a perimeter network. You need to install a DHCP Relay Agent on Server1. Which node should you use to add the DHCP Relay Agent? To answer, select the appropriate node in the answer area.

 

70-410-demo-116

 

Correct Answer:

 

70-410-demo-117

 

 

 

QUESTION 120

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has following storage spaces:

 

– Data

– Users

– Backups

– Primordial

 

You add an additional hard disk to Server1. You need to identify which storage space contains the new hard disk. Which storage space contains the new disk?

 

A.

Data

B.

Primordial

C.

Users

D.

Backups

 

Correct Answer: B

QUESTION 121

You have a server named Server1. Server1 runs Windows Server 2012 R2 and has the File and Storage Services server role installed. You attach four 500-GB disks to Server1. You need to configure the storage to meet the following requirements:

 

– Storage for an application named Application1 must be provided. Application1 requires 20 GB and will require a maximum of 800 GB in three years.

– Storage for an application named Application2 must be provided. Application2 requires 20 GB and will require a maximum of 900 GB in three years.

– The solution must provide the ability to dynamically add storage without requiring configuration changes to the applications.

– The storage must be available if a single disk fails.

 

Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

 

A.

From File and Storage Services, create virtual disks by using fixed provisioning.

B.

From File and Storage Services, create a storage pool that uses all four disks.

C.

From Disk Management, create two new mirror volumes that use two disks each.

D.

From Disk Management, create a new RAID-5 volume that uses all four disks.

E.

From File and Storage Services, create virtual disks by using thin provisioning.

 

Correct Answer: BE

 

QUESTION 122

Your network contains multiple subnets. On one of the subnets, you deploy a server named Server1 that runs Windows Server 2012 R2. You install the DNS Server server role on Server1, and then you create a standard primary zone named contoso.com. You need to ensure that client computers can resolve single-label names to IP addresses. What should you do first?

 

A.

Create a reverse lookup zone.

B.

Convert the contoso.com zone to an Active Directory-integrated zone.

C.

Configure dynamic updates for contoso.com.

D.

Create a GlobalNames zone.

 

Correct Answer: D

 

 

QUESTION 123

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has six network adapters. Two of the network adapters are connected to a network named LAN1, two of the network adapters are connected to a network named LAN2, and two of the network adapters are connected to a network named LAN3. You create a network adapter team named Team1 from the two adapters connected to LAN1. You create a network adapter team named Team2 from the two adapters connected to LAN2. A company policy states that all server IP addresses must be assigned by using a reserved address in DHCP. You need to identify how many DHCP reservations you must create for Server1. How many reservations should you identify?

 

A.

3

B.

4

C.

6

D.

8

 

Correct Answer: B

Explanation:

2 Adapters = LAN1 = Team1 = 1 IP

2 Adapters = LAN2 = Team2 = 1 IP

2 Adapters = LAN3 = No Team = 2 IP

1 + 1 + 2 = 4

 

 

QUESTION 124

Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2. The domain contains a server named Server1. You open Review Options in the Active Directory Domain Services Configuration Wizard, and then you click View script. You need to ensure that you can use the script to promote Server1 to a domain controller. Which file extension should you use to save the script?

 

A.

.pal

B.

.bat

C.

.xml

D.

.cmd

 

Correct Answer: A

 

 

QUESTION 125

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server!. Server1 runs a Server Core installation of Windows Server 2012 R2. You install the DNS Server server role on Server1. You need to perform the following configurations on Server1:

 

– Create an Active Directory-integrated zone named adatum.com.

– Send unresolved DNS client queries for other domain suffixes to the DNS server of your company’s Internet Service Provider (ISP).

 

Which Windows PowerShell cmdlets should you use?

To answer, drag the appropriate cmdlet to the correct configuration in the answer area. Each cmdlet may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

 

70-410-demo-120

 

Correct Answer:

 

70-410-demo-121

 

QUESTION 126

Your network contains an Active Directory domain named contoso.com. The network contains 500 client computers that run Windows 8. All of the client computers connect to the Internet by using a web proxy. You deploy a server named Server1 that runs Windows Server 2012 R2. Server1 has the DNS Server server role installed. You configure all of the client computers to use Server1 as their primary DNS server. You need to prevent Server1 from attempting to resolve Internet host names for the client computers. What should you do on Server1?

 

A.

Create a primary zone named “.”.

B.

Configure the Security settings of the contoso.com zone.

C.

Create a zone delegation for GlobalNames.contoso.com.

D.

Create a stub zone named “root”.

 

Correct Answer: A

 

QUESTION 127

Your network contains an Active Directory domain named contoso.com. The domain contains 100 user accounts that reside in an organizational unit (OU) named 0U1. You need to ensure that a user named User1 can link and unlink Group Policy objects (GPOs) to OU1. The solution must minimize the number of permissions assigned to User1. What should you do?

 

A.

Modify the permissions on OU1.

B.

Run the Set-GPPermission cmdlet.

C.

Add User1 to the Group Policy Creator Owners group.

D.

Modify the permissions on the User1 account.

 

Correct Answer: A

 

QUESTION 128

You have a server that runs Windows Server 2012 R2. The server contains the disks configured as shown in the following table.

 

70-410-demo-124

 

You need to create a volume that can store up to 3 TB of user files. The solution must ensure that the user files are available if one of the disks in the volume fails.

What should you create?

 

A.

a mirrored volume on Disk 1 and Disk 4

B.

a mirrored volume on Disk 2 and Disk 3

C.

a RAID-5 volume on Disk 1, Disk 2, and Disk 3

D.

a spanned volume on Disk 0 and Disk 4

 

Correct Answer: B

 

 

QUESTION 129

What should you do for server core so it can be managed from another server 2012 R2?

 

70-410-demo-126

 

A.

1

B.

2

C.

3

D.

4

E.

5

F.

6

G.

7

H.

8

I.

9

J.

10

K.

11

L.

12

M.

13

N.

14

O.

15

 

Correct Answer: H

 

 

QUESTION 130

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1. Server1 runs Windows Server 2012 R2. On Server1, you create a printer named Printer1. You share Printer1 and publish Printer1 in Active Directory.

You need to provide a group named Group1 with the ability to manage Printer1.

What should you do?

 

A.

From Print Management, configure the Sharing settings of Printer1.

B.

From Active Directory Users and Computers, configure the Security settings of Server1- Printer1.

C.

From Print Management, configure the Security settings of Printer1.

D.

From Print Management, configure the Advanced settings of Printer1.

 

Correct Answer: C


QUESTION 131

Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2.

Client computers run either Windows 7 or Windows 8.

All of the computer accounts of the client computers reside in an organizational unit (OU) named Clients. A Group Policy object (GPO) named GP01 is linked to the Clients OU. All of the client computers use a DNS server named Server1.

You configure a server named Server2 as an ISATAP router. You add a host (A) record for ISATAP to the contoso.com DNS zone.

You need to ensure that the client computers locate the ISATAP router.

What should you do?

 

A.

Run the Add-DnsServerResourceRecord cmdlet on Server1.

B.

Configure the DNS Client Group Policy setting of GPO1.

C.

Configure the Network Options Group Policy preference of GPO1.

D.

Run the Set-DnsServerGlobalQueryBlockList cmdlet on Server1.

 

Correct Answer: D 

 

 

QUESTION 132

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2 and has the Remote Access server role installed.

A user named User1 must connect to the network remotely. The client computer of User1 requires Challenge Handshake Authentication Protocol (CHAP) for remote connections. CHAP is enabled on Server1.

You need to ensure that User1 can connect to Server1 and authenticate to the domain.

What should you do from Active Directory Users and Computers?

 

A.

From the properties of Server1, select Trust this computer for delegation to any service (Kerberos only).

B.

From the properties of Server1, assign the Allowed to Authenticate permission to User1.

C.

From the properties of User1, select Use Kerberos DES encryption types for this account.

D.

From the properties of User1, select Store password using reversible encryption.

 

Correct Answer: D

 

 

QUESTION 133

Your network contains a Hyper-V host named Hyperv1 that runs Windows Server 2012 R2.

Hyperv1 has a virtual switch named Switch1.

You replace all of the network adapters on Hyperv1 with new network adapters that support single-root I/O virtualization (SR-IOV). You need to enable SR-IOV for all of the virtual machines on Hyperv1. Which two actions should you perform? (Each correct answer presents part of the solution.

Choose two.)

 

A.

On each virtual machine, modify the Advanced Features settings of the network adapter.

B.

Modify the settings of the Switch1 virtual switch.

C.

Delete, and then recreate the Switch1 virtual switch.

D.

On each virtual machine, modify the BIOS settings.

E.

On each virtual machine, modify the Hardware Acceleration settings of the network adapter.

 

Correct Answer: CE

 

QUESTION 134

Your network contains a server named Server1 that runs Windows Server 2012 R2. Server1 is a member of a workgroup. You need to configure a local Group Policy on Server1 that will apply only to non- administrators.

Which tool should you use?

 

A.

Server Manager

B.

Group Policy Management Editor

C.

Group Policy Management

D.

Group Policy Object Editor

 

Correct Answer: D

 

 

QUESTION 135

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server! that runs Windows Server 2012 R2. Server1 contains a virtual machine named VM1 that runs Windows Server 2012 R2.

You need to ensure that a user named User1 can install Windows features on VM1. The solution must minimize the number of permissions assigned to User1.

To which group should you add User1?

 

A.

Administrators on VM1

B.

Power Users on VM1

C.

Hyper-V Administrators on Server1

D.

Server Operators on Server1

 

Correct Answer: A

 

 

QUESTION 136

Your network contains an Active Directory domain named adatum.com. The domain contains a member server named LON-DC1. LON-DC1 runs Windows Server 2012 R2 and has the DHCP Server server role installed.

The network contains 100 client computers and 50 IP phones. The computers and the phones are from the same vendor. You create an IPv4 scope that contains addresses from 172.16.0.1 to 172.16.1.254.

You need to ensure that the IP phones receive IP addresses in the range of 172.16.1.100 to 172.16.1.200. The solution must minimize administrative effort.

What should you create?

 

A.

Server level policies

B.

Filters

C.

Reservations

D.

Scope level policies

 

Correct Answer: D

  

 

 

QUESTION 137

Your network contains an Active Directory forest. The forest contains a single domain named contoso.com. The domain contains four domain controllers. The domain controllers are configured as shown in the following table.

 

70-410-demo-134

 

You plan to deploy a new domain controller named DC5 in the contoso.com domain.

You need to identify which domain controller must be online to ensure that DC5 can be promoted successfully to a domain controller. Which domain controller should you identify?

 

A.

DC1

B.

DC2

C.

DC3

D.

DC4

 

Correct Answer: D

 

QUESTION 138

Your network contains an Active Directory domain named contoso.com. The domain contains a member server named HVServer1. HVServer1 runs Windows Server 2012 R2 and has the Hyper-V server role installed.

HVServer1 hosts two virtual machines named Server1 and Server2. Both virtual machines connect to a virtual switch named Switch1.

On Server2, you install a network monitoring application named App1.

You need to capture all of the inbound and outbound traffic to Server1 by using App1.

Which two commands should you run from Windows PowerShell? (Each correct answer presents part of the solution. Choose two.)

 

A.

Get-VM “Server2″ | Set-VMNetworkAdapter -IovWeight 1

B.

Get-VM “Server1″ | Set-VMNetworkAdapter -Allow/Teaming On

C.

Get-VM “Server1″ | Set-VMNetworkAdapter -PortMirroring Source

D.

Get-VM “Server2″ | Set-VMNetworkAdapter -PortMirroring Destination

E.

Get-VM “Server1″ | Set-VMNetworkAdapter -IovWeight 0

F.

Get-VM “Server2″ | Set-VMNetworkAdapter-AllowTeaming On

 

Correct Answer: CD

 

 

QUESTION 139

You have a server named Server 1. Server1 runs Windows Server 2012 R2. Server1 has a thin provisioned disk named Disk1. You need to expand Disk1. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

 

A.

From File and Storage Services, extend Disk1.

B.

From File and Storage Services, add a physical disk to the storage pool.

C.

From Disk Management, extend the volume.

D.

From Disk Management, delete the volume, create a new volume, and then format the volume.

E.

From File and Storage Services, detach Disk1.

 

Correct Answer: AB

  

QUESTION 140

Drag and Drop Question

You plan to deploy a DHCP server that will support four subnets. The subnets will be configured as shown in the following table.

 

70-410-demo-138

 

You need to identify which network ID you should use for each subnet. What should you identify? To answer, drag the appropriate network ID to the each subnet in the answer area.

 

70-410-demo-139

Correct Answer:

 

70-410-demo-140