2026 New 70-412 Exam Dumps with PDF and VCE Free: https://www.2passeasy.com/dumps/70-412/
We provide 70 412 exam which are the best for clearing 70-412 test, and to get certified by Microsoft Configuring Advanced Windows Server 2012 Services. The mcsa 70 412 covers all the knowledge points of the real 70-412 exam. Crack your Microsoft 70-412 Exam with latest dumps, guaranteed!
Online 70-412 free questions and answers of New Version:
NEW QUESTION 1
You are about to promote a server running the Windows Server 2012 R2 operating system to domain controller.
The domain is currently running at the Windows Server 2008 domain functional level. Your account is a member of the Domain Admins group.
Which additional groups should your account be a member of to ensure that the environment is appropriately configured for this domain controller running Windows Server 2012 R2? (Choose two. Each answer forms part of a complete solution.)
- A. Schema Admins
- B. Enterprise Admins
- C. Account Operators
- D. Server Operators
Answer: AB
NEW QUESTION 2
HOTSPOT
You have a server that runs Windows Server 2012 R2 and has the iSCSI Target Server role service installed.
You run the New-IscsiVirtualDisk cmdlet as shown in the New-IscsiVirtualDisk exhibit. (Click the Exhibit button.)
To answer, complete each statement according to the information presented in the exhibits. Each correct selection is worth one point.
Answer:
Explanation: * From the exhibit we see that the size is 10737418240 bytes. This is roughly 10 GB.
* From the exhibit we also see 'Status: Not connected'.
Note: Target: It is an object which allows the iSCSI initiator to make a connection. The Target keeps track of the initiators which are allowed to be connected to it. The Target also keeps track of the iSCSI virtual disks which are associated with it. Once the initiator establishes the connection to the Target, all the iSCSI virtual disks associated with the Target will be accessible by the initiator.
NEW QUESTION 3
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Active Directory Certificate Services server role installed and is configured as an enterprise certification authority (CA).
You need to ensure that all of the users in the domain are issued a certificate that can be used for the following purposes:
✑ Email security
✑ Client authentication
✑ Encrypting File System (EFS)
Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)
- A. From a Group Policy, configure the Certificate Services Client – Auto-Enrollmentsettings.
- B. From a Group Policy, configure the Certificate Services Client – Certificate Enrollment Policy settings.
- C. Modify the properties of the User certificate template, and then publish the template.
- D. Duplicate the User certificate template, and then publish the template.
- E. From a Group Policy, configure the Automatic Certificate Request Settings settings.
Answer: AD
Explanation: The default user template supports all of the requirements EXCEPT auto enroll as shown below:
However a duplicated template from users has the ability to autoenroll:
The Automatic Certificate Request Settings GPO setting is only available to Computer, not user.
Reference: Manage Certificate Enrollment Policy by Using Group Policy. http://technet.microsoft.com/en-us/library/dd851772.aspx
NEW QUESTION 4
You have an Active Directory Rights Management Services (AD RMS) cluster.
You need to prevent users from encrypting new content. The solution must ensure that the users can continue to decrypt content that was encrypted already.
Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)
- A. From the Active Directory Rights Management Services console, enable decommissioning.
- B. From the Active Directory Rights Management Services console, create a user exclusion policy.
- C. Modify the NTFS permissions of %systemdrive%inetpubwwwroot_wmcslicensing.
- D. Modify the NTFS permissions of %systemdrive%inetpubwwwroot_wmcsdecommission.
- E. From the Active Directory Rights Management Services console, modify the rights policy templates.
Answer: AD
Explanation: * Decommissioning refers to the entire process of removing the AD RMS cluster and its associated databases from an organization. This process allows you to save rights- protected files as ordinary files before you remove AD RMS from your infrastructure so that you do not lose access to these files.
Decommissioning an AD RMS cluster is achieved by doing the following:
/ Enable the decommissioning service. (A)
/ Modify permissions on the decommissioning pipeline.
/ Configure the AD RMS-enabled application to use the decommissioning pipeline.
* To modify the permissions on the decommissioning pipeline
1. Log on to ADRMS-SRV as cpandladministrator.
2. Click Start, type %systemdrive%inetpubwwwroot_wmcs in the Start Search box, and then press ENTER.
3. Right-click the decommission folder, and then click Properties.
4. Click the Security tab, click Edit, and then click Add. (D) Etc.
Reference: Step 1: Decommission AD RMS Root Cluster
NEW QUESTION 5
The Wingtip Toys forest hosts a web application that users in the Tailspin Toys forest need to access.
You are the system administrator at Tailspin Toys. A single federation server is present in each forest and you are configuring a federated trust.
Which of the following statements are true about the deployment solution? (Choose all that apply.)
- A. The AD FS server in the Wingtip Toys forest will function as the claims-provider server.
- B. The AD FS server in the Wingtip Toys forest will function as the relying-party server.
- C. You need to configure a relying-party trust on the AD FS server in the Tailspin Toys forest.
- D. You need to configure a claims-provider trust on the AD FS server in the Tailspin Toys forest.
Answer: BC
NEW QUESTION 6
You have a cluster named cluster1 that contains two nodes. both nodes run windows server 2012 r2.
cluster1 hosts a virtual machine named vm1 that runs windows server 2012 r2. you configure a custom service on vm1 named service1.
you need to ensure that vm1 will be moved to a different node3 if service1 fails. which comdlet should you run on cluster1?
- A. set-clusterresiurcedependency
- B. add-clustergenericservicerole
- C. enable-vmresourcemetering
- D. add-clustervmmonitoreditem
Answer: B
NEW QUESTION 7
Your network contains one Active Directory domain named contoso.com. The domain contains the domain controllers configured as shown in the following table.
The functional level of the domain and the forest is Windows Server 2008. An administrator named Admin1 is a member of the Domain Admins group.
You need to ensure that Admin1 can deploy a Windows Server 2012 R2 domain controller to contoso.com.
What should you do?
- A. Raise the forest functional level.
- B. Run the Set-ADForestMode cmdlet.
- C. Raise the domain functional level.
- D. Run the adprep.exe command.
- E. Demote DC1 to a member server.
- F. Upgrade DC1 to Windows Server 2012.
- G. Add Admin1 to the Schema Admin Group.
Answer: DF
Explanation: Adprep.exe commands run automatically as needed as part of the AD DS installation process on servers that run Windows Server 2012 or later. The commands need to run in the following cases:
* Before you add the first domain controller that runs a version of Windows Server that is later than the latest version that is running in your existing domain.
* Before you upgrade an existing domain controller to a later version of Windows Server, if that domain controller will be the first domain controller in the domain or forest to run that version of Windows Server.
Reference: Running Adprep.exe
https://technet.microsoft.com/en-us/library/dd464018(v=ws.10).aspx
NEW QUESTION 8
Your network contains two Active Directory forests named contoso.com and fabrikam.com. The contoso.com forest contains two domains named corp.contoso.com and contoso.com. You establish a two-way forest trust between contoso.com and fabrikam.com.
Users from the corp.contoso.com domain report that they cannot log on to client computers
in the fabrikam.com domain by using their corp.contoso.com user account. When they try to log on, they receive following error message:
"The computer you are signing into is protected by an authentication firewall. The specified account is not allowed to authenticate to the computer."
Corp.contoso.com users can log on successfully to client computers in the contoso.com domain by using their corp.contoso.com user account credentials.
You need to allow users from the corp.contoso.com domain to log on to the client computers in the fabrikam.com forest.
What should you do?
- A. Configure Windows Firewall with Advanced Security.
- B. Enable SID history.
- C. Configure forest-wide authentication.
- D. Instruct the users to log on by using a user principal name (UPN).
Answer: C
Explanation: The forest-wide authentication setting permits unrestricted access by any users in the trusted forest to all available shared resources in any of the domains in the trusting forest.
http://technet.microsoft.com/en-us/library/cc785875(v=ws.10).aspx
NEW QUESTION 9
Your network contains 20 iSCSI storage appliances that will provide storage for 50 Hyper-V hosts running Windows Server 2012 R2.
You need to configure the storage for the Hyper-V hosts. The solution must minimize administrative effort.
What should you do first?
- A. Install the iSCSI Target Server role service and configure iSCSI targets.
- B. Install the iSNS Server service feature and create a Discovery Domain.
- C. Start the Microsoft iSCSI Initiator Service and configure the iSCSI Initiator Properties.
- D. Install the Multipath I/O (MPIO) feature and configure the MPIO Properties.
Answer: A
Explanation: Windows Server 2012 includes an iSCSI Target role that, along with Failover Clustering, allows it to become a cost-effective and highly-available iSCSI Storage Array.
We can connect from our Hyper-V host to the iSCSI target on the storage array with the following PowerShell command line:
New-IscsiTargetPortal –TargetPortalAddress <IP_Address or FQDN of storage array>
$target = Get-IscsiTarget
Connect-IscsiTarget –NodeAddress $target.NodeAddress Incorrect:
Not B. Discovery Domains in an iSCSI fabric, like zones in a Fibre Channel fabric, enable you to partition the storage resources in your storage area network (SAN). By creating and managing Discovery Domains, you can control the iSCSI targets that each iSCSI initiator can see and log on to.
Reference: Configure iSCSI Target Server Role on Windows Server 2012
NEW QUESTION 10
You have two Hyper-V hosts named Host1 and Host2 that run Windows Server 2012 R2. Host1 hosts a virtual machine named VM1 that is replicated to Host2. VM1 hosts an
internal web application.
You need to test the failover of VM1 to Host2. The solution must ensure that clients continue to connect to VM1 on Host1.
Which cmdlet should you run?
- A. Start-VMFailover
- B. Export-VM
- C. Move-VM
- D. Test-VMReplicationConnection
- E. Compare-VM
Answer: A
Explanation: Start-VMFailover -AsTest
Creates a test virtual machine using the chosen recovery point. You can use a test virtual machine to validate a Replica virtual machine. To stop a test failover, use the Stop- VMFailover cmdlet.
The Start-VMFailover cmdlet can be used for the following tasks:
✑ Fail over a Replica virtual machine to a chosen recovery point.
✑ Start a planned failover on a primary virtual machine.
✑ Create a test virtual machine on a Replica virtual machine.
Reference: Start-VMFailover
https://technet.microsoft.com/en-us/library/jj136051(v=wps.630).aspx
NEW QUESTION 11
HOTSPOT
You have a file server named Server1 that runs Windows Server 2012 R2.
You need to ensure that you can use the NFS Share - Advanced option from the New Share Wizard in Server Manager.
Which two role services should you install?
To answer, select the appropriate two role services in the answer area.
Answer:
Explanation: *File Server Resource Manager Role
File Server Resource Manager is a set of features that allow you to manage and classify data that is stored on file servers.
Note: NFS Share – Advanced
This advanced profile offers additional options to configure a NFS file share.
Set the folder owners for access-denied assistance
Configure default classification of data in the folder for management and access policies Enable quotas
NEW QUESTION 12
Your network contains an Active Directory domain named contoso.com. The domain contains a main office and a branch office.
An Active Directory site exists for each office.
All domain controllers run Windows Server 2012 R2. The domain contains two domain controllers.
DC1 hosts an Active Directory- integrated zone for contoso.com. You add the DNS Server server role to DC2.
You discover that the contoso.com DNS zone fails to replicate to DC2.
You verify that the domain, schema, and configuration naming contexts replicate from DC1 to DC2.
You need to ensure that DC2 replicates the contoso.com zone by using Active Directory replication.
Which tool should you use?
- A. Dnscmd
- B. Dnslint
- C. Repadmin
- D. Ntdsutil
- E. DNS Manager
- F. Active Directory Sites and Services
- G. Active Directory Domains and Trusts
- H. Active Directory Users and Computers
Answer: F
Explanation: http://technet.microsoft.com/en-us/library/cc739941(v=ws.10).aspx If you see question about AD Replication, First preference is AD sites and services, then Repadmin and then DNSLINT.
NEW QUESTION 13
You have a server named Server1 that runs Windows Server 2012 R2. Each day, Server1 is backed up fully to an external disk.
On Server1, the disk that contains the operating system fails. You replace the failed disk.
You need to perform a bare-metal recovery of Server1 by using the Windows Recovery Environment (Windows RE).
What should you use?
- A. The Wbadmin.exe command
- B. The Repair-bde.exe command
- C. The Get-WBBareMetalRecovery cmdlet
- D. The Start-WBVolumeRecovery cmdlet
Answer: A
Explanation: Wbadmin enables you to back up and restore your operating system, volumes, files, folders, and applications from a command prompt.
Wbadmin start sysrecovery
runs a recovery of the full system (at least all the volumes that contain the operating system's state). This subcommand is only available if you are using the Windows Recovery Environment.
* Wbadmin start sysrecovery -backupTarget
Specifies the storage location that contains the backup or backups that you want to recover. This parameter is useful when the storage location is different from where backups of this computer
Incorrect:
Not B. Accesses encrypted data on a severely damaged hard disk if the drive was encrypted by using BitLocker. Repair-bde can reconstruct critical parts of the drive and salvage recoverable data as long as a valid recovery password or recovery key is used to decrypt the data.
Not C. Gets the value that indicates whether the ability to perform bare metal recoveries from backups has been added to the backup policy (WBPolicy object).
Not D. Starts a volume recovery operation.
Reference: Wbadmin start sysrecovery http://technet.microsoft.com/en-us/library/cc742118.aspx
NEW QUESTION 14
You have a server named Server1 that runs Windows Server 2012 R2. Server1 fails.
You identify that the master boot record (MBR) is corrupt. You need to repair the MBR.
Which tool should you use?
- A. Bcdedit
- B. Bcdboot
- C. Bootrec
- D. Fixmbr
Answer: C
Explanation: Repairing an unbootable Windows installation with bootrec.exe
If the boot/recovery partition is corrupted or lost, you can modify your Windows OS partition to boot.
✑ Boot from your Windows Vista/7/Server2008/R2/2012 media and choose the "Repair Windows" option.
✑ Open the command prompt.
✑ Using diskpart, mark your Windows partition as bootable.
✑ If your windows partition does not have it, copy the "boot" folder from the installation media.
✑ Run the following commands:
>c:
>cd boot
>attrib bcd -s -h -r
>ren c:bootbcd bcd.old
>bootrec /RebuildBcd
Reboot and Windowsshouldboot normally. If not, return to the command prompt and run:
>bootrec /FixMBR
>bootrec /FixBoot
Incorrect:
Not A. BCDEdit is a command-line tool for managing BCD stores. It can be used for a variety of purposes, including creating new stores, modifying existing stores, adding boot menu options, and so on. BCDEdit serves essentially the same purpose as Bootcfg.exe on earlier versions of Windows
Not B. The BCDboot tool is a command-line tool that enables you to manage system partition files
Not D. Fixmbr is not a tool. Fixmbr is an option when using the bootrec tool. Reference: Windows BCD Store
http://www.itsgotme.com/wiki/Windows_BCD
NEW QUESTION 15
HOTSPOT
Your network contains a DNS server named Server1. Server1 hosts a DNS zone for contoso.com.
You need to ensure that DNS clients cache records from contoso.com for a maximum for one hour.
Which value should you modify in the Start of Authority (SOA) record? To answer, select the appropriate setting in the answer area.
Answer:
Explanation: Minimum TTL - The minimum time-to-live value applies to all resource records in the zone file. This value is supplied in query responses to inform other servers how long they should keep the data in cache. The default value is 3,600.
NEW QUESTION 16
Your network contains two servers named Server1 and Server2 that run Windows Server 2012 R2.
Both servers have the Hyper-V server role installed. Server1 and Server2 are located in different offices. The offices connect to each other by using a high-latency WAN link.
Server2 hosts a virtual machine named VM1.
You need to ensure that you can start VM1 on Server1 if Server2 fails. The solution must minimize hardware costs.
What should you do?
- A. On Server1, install the Multipath I/O (MPIO) featur
- B. Modify the storage location of the VHDs for VM1.
- C. From the Hyper-V Settings of Server2, modify the Replication Configuration setting
- D. Enable replication for VM1.
- E. On Server2, install the Multipath I/O (MPIO) featur
- F. Modify the storage location of the VHDs for VM1.
- G. From the Hyper-V Settings of Server1, modify the Replication Configuration setting
- H. Enable replication for VM1.
Answer: D
Explanation: You first have to enable replication on the Replica server--Server1--by going to the server and modifying the "Replication Configuration" settings under Hyper-V settings. You then go to VM1--which presides on Server2-- and run the "Enable Replication" wizard on VM1.
NEW QUESTION 17
Your network contains an Active Directory domain named contoso.com.
All domain controllers run Windows Server 2012 R2. The domain contains two domain controllers.
The domain controllers are configured as shown in the following table.
The Branch site contains a perimeter network.
For security reasons, client computers in the perimeter network can communicate with client computers in the Branch site only.
You plan to deploy a new RODC to the perimeter network in the Branch site.
You need to ensure that the new RODC will be able to replicate from DC10. What should you do first on DC10?
- A. Run the Add-ADDSReadOnlyDomainControllerAccount cmdlet.
- B. Create an Active Directory site.
- C. Run the Active Directory Domain Services Configuration Wizard.
- D. Create an Active Directory subnet.
Answer: A
Explanation: Add-ADDSReadOnlyDomainControllerAccount Creates a read-only domain controller (RODC) account that can be used to install an RODC in Active Directory.
Note:
* Notes
Once you have added the RODC account, you can add an RODC to a server computer by using the Install-ADDSDomainController cmdlet with the -ReadOnlyReplica switch parameter.
* Example
Adds a new read-only domain controller (RODC) account to the corp.contoso.com domain using the North America site as the source site for the replication source domain controller. C:PS>Add-ADDSReadOnlyDomainControllerAccount -DomainControllerAccountName RODC1 - DomainName corp.contoso.com -SiteName NorthAmerica Incorrect:
Not B: There already is a branch site.
Reference: Add-ADDSReadOnlyDomainControllerAccount
NEW QUESTION 18
Your network contains an Active Directory forest.
The forest contains two domains named contoso.com and fabrikam.com. The functional level of the forest is Windows Server 2003.
The contoso.com domain contains domain controllers that run either Windows Server 2008 or Windows Server 2008 R2.
The functional level of the domain is Windows Server 2008.
The fabrikam.com domain contains domain controllers that run either Windows Server 2003 or Windows Server 2008.
The functional level of the domain is Windows Server 2003.
The contoso.com domain contains a member server named Server1 that runs Windows Server 2012 R2.
You install the Active Directory Domain Services server role on Server1.
You need to add Server1 as a new domain controller in the contoso.com domain. What should you do?
- A. Run the Active Directory Domain Services Configuration Wizard.
- B. Run adprep.exe /domainprep, and then run dcpromo.exe.
- C. Raise the functional level of the forest, and then run dcprorno.exe.
- D. Modify the Computer Name/Domain Changes properties.
Answer: A
Explanation: Windows Server 2012 R2 requires a Windows Server 2003 forest functional level.
That is, before you can add a domain controller that runs Windows Server 2012 R2 to an existing Active Directory forest, the forest functional level must be Windows Server 2003 or higher.
http://blogs.technet.com/b/askpfeplat/archive/2012/09/03/introducing-the-first- windowsserver-2012-domaincontroller.aspx
http://technet.microsoft.com/en-us/library/dd464018(v=ws.10).aspx http://technet.microsoft.com/en-us/library/jj574134.aspx


100% Valid and Newest Version 70-412 Questions & Answers shared by Surepassexam, Get Full Dumps HERE: https://www.surepassexam.com/70-412-exam-dumps.html (New 435 Q&As)