Q121. - (Topic 2) 

Your network contains an Active Directory domain named contoso.com. 

You log on to a domain controller by using an account named Admin1. Admin1 is a member of the Domain Admins group. 

You view the properties of a group named Group1 as shown in the exhibit. (Click the Exhibit button.) 

Group1 is located in an organizational unit (OU) named OU1. 

You need to ensure that you can modify the Security settings of Group1 by using Active Directory Users and Computers. 

What should you do from Active Directory Users and Computers? 

A. From the View menu, select Users, Contacts, Groups, and Computers as containers. 

B. Right-click OU1 and select Delegate Control 

C. From the View menu, select Advanced Features 

D. Right-click contoso.com and select Delegate Control. 

Answer:

Explanation: 

From ADUC select view toolbar then select advanced features. When you open up the ADUC in a default installation of Active Directory, you are only presented with the basic containers. These basic containers include the only organizational unit (OU), which is the Domain Controllers OU, as wellas the other containers such as Users and Computers. To see more in-depth containers, you need to configure the ADUC by going to the View option on the toolbar, then selecting Advanced Features. This will refresh the view within the ADUC and add some new containers. There are no hidden (or Advanced) OUs that will show up when you configure the ADUC in this way. 


Q122. - (Topic 1) 

Your network contains an Active Directory forest named contoso.com. 

The forest contains two domains named contoso.com and child.contoso.com and two sites named Site1 and Site2. The domains and the sites are configured as shown in following table. 

When the link between Site1 and Site2 fails, users fail to log on to Site2. 

You need to identify what prevents the users in Site2 from logging on to the child.contoso.com domain. 

What should you identify? 

A. The placement of the global catalog server 

B. The placement of the infrastructure master 

C. The placement of the domain naming master 

D. The placement of the PDC emulator 

Answer:

Explanation: 

The exhibit shows that Site2 does not have a PDC emulator. This is important because of the close interaction between the RID operations master role and the PDC emulator role. The PDC emulator processes password changes from earlier-version clients and other domain controllers on a best-effort basis; handles password authentication requests involving passwords that have recently changed and not yet been replicated throughout the domain; and, by default, synchronizes time. If this domain controller cannot connect to the PDC emulator, this domain controller cannot process authentication requests, it may not be able to synchronize time, and password updates cannot be replicated to it. The PDC emulator master processes password changes from client computers and replicates these updates to all domain controllers throughout the domain. At any time, there can be only one domain controller acting as the PDC emulator master in each domain in the forest. 


Q123. - (Topic 1) 

Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server 2012 R2. 

Server1 has the Group Policy Management feature installed. Server2 has the Print and Document Services server role installed. 

On Server2, you open Print Management and you deploy a printer named Printer1 by using a Group Policy object (GPO) named GPO1.When you open GPO1 on Server1, you discover that the Deployed Printers node does not appear. 

You need to view the Deployed Printers node in GPO1. 

What should you do? 

A. On Server1, modify the Group Policy filtering options of GPO1. 

B. On a domain controller, create a Group Policy central store. 

C. On Server2, install the Group Policy Management feature. 

D. On Server1, configure the security filtering of GPO1. 

Answer:

Explanation: 

Pre-Requisites To use Group Policy for printer deployment you will need to have a Windows Active Directory domain, and this article assumes that your Domain Controller is a Windows 2008 R2 Server. You will also need the Print Services role installed on a server (can be on your DC), and you will be using the Print Management and Group Policy Management consoles to configure the various settings. It’s assumed that you have already followed Part One and have one or more printers shared on your server with the necessary drivers, ready to deploy to your client computers. 


Q124. - (Topic 3) 

Your network contains an Active Directory domain named contoso.com. The domain contains servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 has the Active Directory Federation Services server role installed.Server2 is a file server. 

Your company introduces a Bring Your Own Device (BYOD) policy. 

You need to ensure that users can use a personal device to access domain resources by using Single Sign-On (SSO) while they are connected to the internal network. 

Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.) 

A. Enable the Device Registration Service in Active Directory. 

B. Publish the Device Registration Service by using a Web Application Proxy. 

C. Configure Active Directory Federation Services (AD FS) for the Device Registration Service. 

D. Install the Work Folders role service on Server2. 

E. Create and configure a sync share on Server2. 

Answer: A,C 

Explanation: 

*Prepare your Active Directory forest to support devices. This is a one-time operation that you must run to prepare your Active Directory forest to support devices. To prepare the Active Directory forest On your federation server, open a Windows PowerShell command window and type: Initialize-ADDeviceRegistration *Enable Device Registration Service on a federation server farm node. To enable Device Registration Service: 

1. On your federation server, open a Windows PowerShell command window and type: Enable-AdfsDeviceRegistration. 

2.  Repeat this step on each federation farm node in your AD FS farm. 


Q125. - (Topic 3) 

Your infrastructure divided in 2 sites. You have a forest root domain and child domain. There is only one DC on site 2 with no FSMO roles. The link goes down to site 2 and no users can log on. What FSMO roles you need on to restore the access? 

A. Infrastructure master 

B. RID master 

C. Domain Naming master 

D. PDC Emulator 

Answer:

Explanation: 

D. The PDC emulator is used as a reference DC to double-check incorrect passwords and it also receives new password changes. PDC Emulator is the most complicated and least understood role, for it runs a diverse range of critical tasks. It is a domain-specific role, so exists in the forest root domain and every child domain. Password changes and account lockouts are immediately processed at the PDC Emulator for a domain, to ensure such changes do not prevent a user logging on as a result of multi-master replication delays, such as across Active Directory sites. 


Q126. DRAG DROP - (Topic 2) 

You have a Hyper-V host named Host1.Host1 contains two virtual machines named VM1 and VM2.VM1 is configured as a print server.VM1 runs Windows Server 2008 R2.VM2 is configured as a file server.VM2 runs Windows Server 2012 R2. 

You need to migrate all of the printers on VM1 to VM2. 

Which actions should you perform on the virtual machines? 

To answer, drag the appropriate action to the correct servers in the answer area. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. 

Answer: 


Q127. - (Topic 3) 

Your network contains an active directory domain named contoso.com. The domain consists 20 

member Servers and 5 domain controllers. All servers run Windows Server 2012 R2. The domain contains 500 client computers. 

You plan to deploy a domain controller for contoso.com in Microsoft Azure. 

You need to prepare the conversation for planned deployment. The solution should ensure that the domain controller hosted in Azure always have the same IP address. 

Witch two actions should you perform? Each correct answer is a part of the solution. 

A. From an Azure virtual machine run the Set-AzureStaticVNetIP cmdlet 

B. Deploy a Side by side virtual private network (VPN) 

C. From Azure virtual machine run the Set –NetIPAuthentication cmdlet 

D. From an domain controller run the Set-NetIPAdresses cmdlet 

E. From an domain controller run adprep.exe 

Answer:

Explanation: 

Set the static VNet IP address information to a VM object. 


Q128. - (Topic 3) 

A company’s server administration team would like to take advantage of the newest file systems available with Windows Server 2012 R2. The team needs a file system capable of managing extremely large data drives that can auto-detect data corruption and automatically perform needed repairs without taking a volume offline. 

Which file system should the server administration team choose? 

A. NFS 

B. DFS 

C. NTFS 

D. ReFS 

Answer:

Explanation: 

The ReFS (Resilient File System) is capable of managing extremely large data drives (1 

YB Yottabyte), can auto-detect data corruption, and automatically perform needed repairs 

without taking the volume offline. 

Quick Tip: The command fsutil fsinfo volumeinfo x: will display the volume file system. 

ReFS is only intended for data drives and not compatible with all Windows Server 2012 R2 

file system technologies, however it is compatible with the new Storage Spaces. 


Q129. - (Topic 3) 

You work as a senior administrator at Contoso.com. The Contoso.com network consists of a single domain named Contoso.com. All servers on the Contoso.com network have Windows Server 2012 R2 installed. 

You are running a training exercise for junior administrators. You are currently discussing what happens when you run the Remove-NetLbfoTeam Windows PowerShell cmdlet. 

Which of the following describes the results of running this cmdlet? 

A. It removes one or more network adapters from a specified NIC team. 

B. It removes a team interface from a NIC team. 

C. It removes a specified NIC team from the host. 

D. It removes a network adapter member from a switch team. 

Answer:

Explanation: 

Remove-NetLbfoTeam removes the specified NIC team from the host. 

The Remove-NetLbfoTeam cmdlet removes the specified NIC team from the host. This 

cmdlet disconnects all associated team members and providers from the team. You can 

specify the team to remove by using either a team object retrieved by Get-NetLbfoTeam, or 

by specifying a team name. 

You can use Remove-NetLbfoTeam to remove all NIC teams from the server. 

You need administrator privileges to use Remove-NetLbfoTeam. 


Q130. - (Topic 3) 

You work as an administrator at Contoso.com. The Contoso.com network consists of a single domain named Contoso.com. All servers on the Contoso.com network have Windows Server 2012 R2 installed. 

Contoso.com has a server, named ENSUREPASS-SR07, which has the ADDS, DHCP, and DNS server roles installed. Contoso.com also has a server, named ENSUREPASS-SR08, which has the DHCP, and Remote Access server roles installed. You have configured a server, which has the File and Storage Services server role installed, to automatically acquire an IP address. The server is named ENSUREPASSSR09. 

You then create reservation on ENSUREPASS-SR07, and a filter on ENSUREPASS-SR08. 

Which of the following is a reason for this configuration? 

A. It allows ENSUREPASS-SR09 to acquire a constant IP address from ENSUREPASS-SR08 only. 

B. It configures ENSUREPASS-SR09 with a static IP address. 

C. It allows ENSUREPASS-SR09 to acquire a constant IP address from ENSUREPASS-SR07 and ENSUREPASSSR08. 

D. It allows ENSUREPASS-SR09 to acquire a constant IP address from ENSUREPASS-SR07 only. 

Answer:

Explanation: 

To configure the Deny filter In the DHCP console tree of DHCP Server 1, under IPv4, click Filters, right-click Deny under Filters, and then click New Filter. In the New Deny Filter dialog box, in MAC Address, enter a six hexadecimal number representing the MAC or physical address of DHCP Client 2, click Add, and then click Close. Under Filters right-click the Deny node, and then click the Enable pop-up menu item.