Any Them multilevel is growing very quick. It has produced room designed for numerous grounds, and maybe they are moving on very quick too. Any Microsoft is definitely the among every one of the Job areas of computer and that is moving on having more and more often. The person with the favorite accreditation of computer includes a importance from the industrial sectors. Any Microsoft Company worked as a chef very difficult to achieve this regular, thus they will launched a documentation software towards the individuals who wishes to function as qualified in the foreseeable future by means of Microsoft.

2021 Dec 70-412 free practice test

Q131. Your network contains an Active Directory domain named contoso.com. The domain contains two member servers named Server1 and Server2. All servers run Windows Server 2012 R2. 

Server1 and Server2 are nodes in a Hyper-V cluster named Cluster1. Cluster1 hosts 10 virtual machines. All of the virtual machines run Windows Server 2012 R2 and are members of the domain. 

You need to ensure that the first time a service named Service1 fails on a virtual machine, the virtual machine is moved to a different node. 

You configure Service1 to be monitored from Failover Cluster Manager. 

What should you configure on the virtual machine? 

A. From the Recovery settings of Service1, set the First failure recovery action to Take No Action. 

B. From the General settings, modify the Startup type. 

C. From the Recovery settings of Service1, set the First failure recovery action to Restart the Service. 

D. From the General settings, modify the Service status. 

Answer:

Explanation: 

When a monitored service fails the Recovery features of the service will take action. 

Example: 

Service Recovery 

In this case for the first failure the service will be restarted by the Service Control Manager inside the guest operating system, if the service fails for a second time the service will again be restarted via guest operating system. In case of a third failure the Service Control Manager will take no action and the Cluster service running on the Hyper-V host will take over recovery actions. 

Reference: How to configure VM Monitoring in Windows Server 2012 


Q132. Your network contains an Active Directory domain named adatum.com. You create a new 

Group Policy object (GPO) named GPO1. 

You need to verify that GPO1 was replicated to all of the domain controllers. 

Which tool should you use? 

A. Gpupdate 

B. Gpresult 

C. Group Policy Management 

D. Active Directory Sites and Services 

Answer:

Explanation: 

In Windows Server 2012, the Group Policy Management Console (GPMC) was enhanced to provide a report for the overall health state of the Group Policy infrastructure for a domain, or to scope the health view to a single GPO. 

Reference: Check Group Policy Infrastructure Status 

http://technet.microsoft.com/en-us/library/jj134176.aspx 


Q133. DRAG DROP 

Your network contains an Active Directory domain named adatum.com. The domain contains three servers. The servers are configured as shown in the following table. 

Server1 is configured as shown in the exhibit. (Click the Exhibit button.) 

Template1 contains custom cryptography settings that are required by the corporate security team. 

On Server2, an administrator successfully installs a certificate based on Template1. 

The administrator reports that Template1 is not listed in the Certificate Enrollment wizard on Server3, even after selecting the Show all templates check box. 

You need to ensure that you can install a server authentication certificate on Server3. The certificate must comply with the cryptography requirements. 

Which three actions should you perform in sequence? 

To answer, move the appropriate three actions from the list of actions to the answer area 

and arrange them in the correct order. 

Answer: 


Q134. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. The domain contains an enterprise certification authority (CA). 

The domain contains a server named Server1 that runs Windows Server 2012 R2. You install the Active Directory Federation Services server role on Server1. 

You plan to configure Server1 as an Active Directory Federation Services (AD FS) server. The Federation Service name will be set to adfs1.contoso.com. 

You need to identify which type of certificate template you must use to request a certificate for AD FS. 

Answer: 


Q135. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Active Directory Federation Services (AD FS) server role installed. 

Adatum.com is a partner organization. 

You are helping the administrator of adatum.com set up a federated trust between adatum.com and contoso.com. The administrator of adatum.com asks you to provide a file containing the federation metadata of contoso.com. 

You need to identify the location of the federation metadata file. Which node in the AD FS 

console should you select? 

To answer, select the appropriate node in the answer area. 

Answer: 


Down to date 70-412 question:

Q136. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Active Directory Rights Management Services server role installed. 

The domain contains a domain local group named Group1. 

You create a rights policy template named Template1. You assign Group1 the rights to Template1. 

You need to ensure that all the members of Group1 can use Template1. 

What should you do? 

A. Configure the email address attribute of Group1. 

B. Convert the scope of Group1 to global. 

C. Convert the scope of Group1 to universal. 

D. Configure the email address attribute of all the users who are members of Group1. 

Answer:

Explanation: 

Explanation/Reference: When a user or group is created in Active Directory, the mail attribute is an optional attribute that can be set to include a primary email address for the user or group. For AD RMS to work properly, this attribute must be set because all users must have an email attribute to protect and consume content. 

Reference: AD RMS Troubleshooting Guide http://social.technet.microsoft.com/wiki/contents/articles/13130.ad-rms-troubleshooting-guide.aspx 


Q137. Your network contains an Active Directory domain named adatum.com. The domain contains a file server named FS1 that runs Windows Server 2012 R2 and has the File Server Resource Manager role service installed. All client computers run Windows 8. 

File classification and Access-Denied Assistance are enabled on FS1. 

You need to ensure that if users receive an Access Denied message, they can request assistance by email from the Access Denied dialog box. 

What should you configure? 

A. A file management task 

B. A classification property 

C. The File Server Resource Manager Options 

D. A report task 

Answer:

Explanation: 

You can configure access-denied assistance individually on each file server by using the File Server Resource Manager console. 

Note: 

To configure access-denied assistance by using File Server Resource Manager 

Open File Server Resource Manager. In Server Manager, click Tools, and then 

click File Server Resource Manager. 

Right-click File Server Resource Manager (Local), and then click Configure 

Options. 

Click the Access-Denied Assistance tab. 

Select the Enable access-denied assistance check box. 

In the Display the following message to users who are denied access to a folder or 

file box, type a message that users will see when they are denied access to a file 

or folder. 

You can add macros to the message that will insert customized text. 

Click Configure email requests, select the Enable users to request assistance 

check box, and then click OK. 

Click Preview if you want to see how the error message will look to the user. 

Click OK. 

Reference: Deploy Access-Denied Assistance (Demonstration Steps) 


Q138. You have a file server named Server1 that runs a Server Core Installation of Windows Server 2012 R2. 

Server1 has a volume named D that contains user data. Server1 has a volume named E that is empty. 

Server1 is configured to create a shadow copy of volume D every hour. You need to configure the shadow copies of volume D to be stored on volume E. 

What should you run? 

A. The Set-Volume cmdlet with the -driveletter parameter 

B. The Set-Volume cmdlet with the -path parameter 

C. The vssadmin.exe add shadowstorage command 

D. The vssadmin.exe create shadow command 

Answer:

Explanation: 

Add ShadowStorage 

Adds a shadow copy storage association for a specified volume. 

Incorrect: 

Not A. Sets or changes the file system label of an existing volume. -DriveLetter Specifies a 

letter used to identify a drive or volume in the system. 

Not B. Create Shadow 

Creates a new shadow copy of a specified volume. 

Not C. Sets or changes the file system label of an existing volume -Path Contains valid 

path information. 

Reference: Vssadmin; Set-Volume 

http://technet.microsoft.com/en-us/library/cc754968(v=ws.10).aspx 

http://technet.microsoft.com/en-us/library/hh848673(v=wps.620).aspx 


Q139. Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The forest contains three Active Directory sites named SiteA, SiteB, and SiteC. The sites contain four domain controllers. The domain controllers are configured as shown in the following table. 

An IP site link exits between each site. 

You discover that the users in SiteC are authenticated by the domain controllers in SiteA and SiteB. 

You need to ensure that the SiteC users are authenticated by the domain controllers in SiteB, unless all of the domain controllers in SiteB are unavailable. 

What should you do? 

A. Create an SMTP site link between SiteB and SiteC. 

B. Create additional connection objects for DC3 and DC4. 

C. Decrease the cost of the site link between SiteB and SiteC. 

D. Create additional connection objects for DC1 and DC2. 

Answer:

Explanation: 

By decreasing the site link cost between SiteB and SiteC the SiteC users would be authenticated by SiteB rather than by SiteA. 


Q140. Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2. 

The domain contains a domain controller named DC1 that is configured as an enterprise root certification authority (CA). 

All users in the domain are issued a smart card and are required to log on to their domain-joined client computer by using their smart card. 

A user named User1 resigned and started to work for a competing company. 

You need to prevent User1 immediately from logging on to any computer in the domain. The solution must not prevent other users from logging on to the domain. 

Which tool should you use? 

A. Active Directory Users and Computers 

B. Server Manager 

C. The Certificates snap-in 

D. Active Directory Administrative Center 

Answer:

Explanation: 

To disable or enable a user account using Active Directory Administrative Center 

1. To open Active Directory Administrative Center, click Start , click Administrative Tools , 

and then click Active Directory Administrative Center . 

To open Active Directory Users and Computers in Windows Server 2012, click Start , type 

dsac.exe. 

2. In the navigation pane, select the node that contains the user account whose status you 

want to change. 

3. In the management list, right-click the user whose status you want to change. 

4. Depending on the status of the user account, do one of the following: . uk.co.certification.simulator.questionpool.PList@ef38f20 

Reference: Disable or Enable a User Account