We provide real 70 412 exam dumps exam questions and answers braindumps in two formats. Download PDF & Practice Tests. Pass Microsoft mcsa 70 412 Exam quickly & easily. The microsoft 70 412 PDF type is available for reading and printing. You can print more and practice many times. With the help of our Microsoft 70 412 exam dumps dumps pdf and vce product and material, you can easily pass the exam 70 412 exam.


♥♥ 2021 NEW RECOMMEND ♥♥

Free VCE & PDF File for Microsoft 70-412 Real Exam (Full Version!)

★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions

Free Instant Download NEW 70-412 Exam Dumps (PDF & VCE):
Available on: http://www.surepassexam.com/70-412-exam-dumps.html

Q11. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. The domain contains two member servers named Server1 and Server2. All servers run Windows Server 2012 R2. 

Server1 and Server2 have the Hyper-V server role installed. The servers are configured as shown in the following table. 

You add a third server named Server3 to the network. Server3 has Intel processors. 

You need to move VM3 and VM6 to Server3. The solution must minimize downtime on the 

virtual machines. 

Which method should you use to move each virtual machine? 

To answer, select the appropriate method for each virtual machine in the answer area. 

Answer: 


Q12. DRAG DROP 

Your network contains an Active Directory domain named contoso.com. The domain contains a file server named Server1. All servers run Windows Server 2012 R2. 

All domain user accounts have the Division attribute automatically populated as part of the user provisioning process. The Support for Dynamic Access Control and Kerberos armoring policy is enabled for the domain. 

You need to control access to the file shares on Server1 based on the values in the Division attribute and the Division resource property. 

Which three actions should you perform in sequence? 

Answer: 


Q13. DRAG DROP 

Your network contains an Active Directory domain named adatum.com. The domain contains three servers. The servers are configured as shown in the following table. 

Server1 is configured as shown in the exhibit. (Click the Exhibit button.) 

Template1 contains custom cryptography settings that are required by the corporate security team. 

On Server2, an administrator successfully installs a certificate based on Template1. 

The administrator reports that Template1 is not listed in the Certificate Enrollment wizard on Server3, even after selecting the Show all templates check box. 

You need to ensure that you can install a server authentication certificate on Server3. The certificate must comply with the cryptography requirements. 

Which three actions should you perform in sequence? 

To answer, move the appropriate three actions from the list of actions to the answer area 

and arrange them in the correct order. 

Answer: 


Q14. You have a server named Server1 that runs Windows Server 2012 R2. 

When you install a custom Application on Server1 and restart the server, you receive the 

following error message: "The Boot Configuration Data file is missing some required information. File: \Boot\BCD 

Error code: 0x0000034." 

You start Server1 by using Windows RE. 

You need to ensure that you can start Windows Server 2012 R2 on Server1. 

Which tool should you use? 

A. Bootsect 

B. Bootim 

C. Bootrec 

D. Bootcfg 

Answer:

Explanation: 

* Bootrec.exe tool to troubleshoot "Bootmgr Is Missing" issue. The /ScanOs option scans all disks for installations that are compatible with Windows Vista or Windows 7. Additionally, this option displays the entries that are currently not in the BCD store. Use this 

option when there are Windows Vista or Windows 7 installations that the Boot Manager menu does not list. 

* Error code 0x0000034 while booting. 

Resolution: 

1. Put the Windows Windows 7 installation disc in the disc drive, and then start the computer. 

2. Press any key when the message indicating "Press any key to boot from CD or DVD …". appears. 

3. Select a language, time, currency, and a keyboard or another input method. Then click Next. 

4. Click Repair your computer. 

5. Click the operating system that you want to repair, and then click Next. 

6. In the System Recovery Options dialog box, click Command Prompt. 

7. Type Bootrec /RebuildBcd, and then press ENTER. 

Incorrect: 

Not A. Bootsect.exe updates the master boot code for hard disk partitions to switch 

between BOOTMGR and NTLDR. You can use this tool to restore the boot sector on your 

computer. This tool replaces FixFAT and FixNTFS. 

Not D. The bootcfg command is a Microsoft Windows Server 2003 utility that modifies the 

Boot.ini file. 

Reference: Bootsect Command-Line Options 

http://technet.microsoft.com/en-us/library/cc749177(v=ws.10).aspx 

http://support.microsoft.com/kb/927392/en-us 

http://answers.microsoft.com/en-us/windows/forum/windows_7-system/error-code-0x0000034-in-windows-7/4dcb8d38-a206-40ed-bced-55e4a4de9bf2 


Q15. HOTSPOT 

Your network contains two application servers that run Windows Server 2012 R2. The application servers have the Network Load Balancing (NLB) feature installed. 

You create an NLB cluster that contains the two servers. 

You plan to deploy an application named App1 to the nodes in the cluster. App1 uses TCP port 8080 and TCP port 8081. 

Clients will connect to App1 by using HTTP and HTTPS via a single reverse proxy. App1 does not use session state information. 

You need to configure a port rule for Appl. The solution must ensure that connections to App1 are distributed evenly between the nodes. 

Which port rule should you use? 

To answer, select the appropriate rule in the answer area. 

Answer: 


Q16. Your network contains one Active Directory forest named contoso.com. The forest contains two child domains and six domain controllers. The domain controllers are configured as shown in the following table. 

You need to enable universal group membership caching for the Europe office and Asia office sites. 

What should you use? 

A. Set-ADSite 

B. Set-ADReplicationSite 

C. Set-ADDomain 

D. Set-ADReplicationSiteLink 

E. Set-ADGroup 

F. Set-ADForest 

G. Netdom 

Answer:

Explanation: 

https://technet.microsoft.com/en-us/library/hh852305(v=wps.630).aspx 


Q17. Your network contains two servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 and Server2 are configured as shown in the following table. 

You need to ensure that when new targets are added to Server1, the targets are registered on Server2 automatically. 

What should you do on Server1? 

A. Configure the Discovery settings of the iSCSI initiator. 

B. Configure the security settings of the iSCSI target. 

C. Run the Set-WmiInstance cmdlet. 

D. Run the Set-IscsiServerTarget cmdlet. 

Answer:

Explanation: 

Explanation/Reference: 

Manage iSNS server registration 

The iSNS server registration can be done using the following cmdlets, which manages the 

WMI objects. 

To add an iSNS server: 

Set-WmiInstance -Namespace root\wmi -Class WT_iSNSServer –Arguments 

@{ServerName="ISNSservername"} 

Note: The Set-WmiInstance cmdlet creates or updates an instance of an existing WMI 

class. The created or updated instance is written to the WMI repository. 

Reference: iSCSI Target cmdlet reference 

http://blogs.technet.com/b/filecab/archive/2012/06/08/iscsi-target-cmdlet-reference.aspx 


Q18. HOTSPOT 

Your network contains an Active Directory domain named contoso.com. The domain contains two member servers named Server1 and Server2. All servers run Windows Server 2012 R2. 

Server1 and Server2 have the Network Load Balancing (NLB) feature installed. The servers are configured as nodes in an NLB cluster named Cluster1. Both servers connect to the same switch. 

Cluster1 hosts a secure web Application named WebApp1. WebApp1 saves user state information in a central database. 

You need to ensure that the connections to WebApp1 are distributed evenly between the nodes. The solution must minimize port flooding. 

What should you configure? To answer, configure the appropriate affinity and the appropriate mode for Cluster1 in the answer area. 

Answer: 


Q19. Your network contains an Active Directory forest. The forest contains one domain named contoso.com. The domain contains three domain controllers. The domain controllers are configured as shown in the following table. 

DC1 has all of the operations master roles installed. 

You transfer all of the operations master roles to DC2, and then you uninstall Active Directory from DC1. 

You need to ensure that you can use Password Settings objects (PSOs) in the domain. 

What should you do? 

A. Change the domain functional level. 

B. Upgrade DC2. 

C. Run the dcgpofix.exe command. 

D. Transfer the schema master role. 

Answer:

Explanation: 

The domain functional level must be Windows Server 2008 to use PSO's 

Requirements and special considerations for fine-grained password and account lockout policies: 

* Domain functional level: The domain functional level must be set to Windows Server 2008 

or higher. 

Etc. 

Incorrect: 

Not B. DC2 is also Windows Server 2008. 

Not C. Recreates the default Group Policy Objects (GPOs) for a domain 

Not D. Schema isn't up to right level 

Reference: AD DS: Fine-Grained Password Policies 

http://technet.microsoft.com/en-us/library/cc770394(v=ws.10).aspx 


Q20. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 has an enterprise root certification authority (CA) for contoso.com. 

You deploy another member server named Server2 that runs Windows Server 2012 R2 and has the Web Server (IIS) server role installed. 

You need to designate a website on Server1 as the certificate revocation list (CRL) distribution point for the CA. The solution must ensure that CRLs are published automatically to Server2. 

Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.) 

A. Create an http:// CRL distribution point (CDP) entry. 

B. Configure a CA exit module. 

C. Create a file:// CRL distribution point (CDP) entry. 

D. Configure a CA policy module. 

E. Configure an enrollment agent. 

Answer: A,D 

Explanation: 

A. To specify CRL distribution points in issued certificates Open the Certification Authority snap-in. In the console tree, click the name of the CA. On the Action menu, click Properties , and then click the Extensions tab. Confirm that Select extension is set to CRL Distribution Point (CDP) .

. Do one or more of the following. (The list of CRL distribution points is in the Specify locations from which users can obtain a certificate revocation list (CRL) box.) 

/ To indicate that you want to use a URL as a CRL distribution point Click the CRL distribution point, select the Include in the CDP extension of issued certificates check box, and then click OK . 

. Click Yes to stop and restart Active Directory Certificate Services (AD CS). 

D. You can specify CRL Distribution Points (CDPs) in CAPolicy.inf. Note that any CDP in CAPolicy.inf will take precedence for certificate verifiers over the CDP's specified in the CA policy module. 

Note: 

CRLDistributionPoint 

You can specify CRL Distribution Points (CDPs) for a root CA certificate in the CAPolicy.inf. 

This section does not configure the CDP for the CA itself. After the CA has been installed 

you can configure the CDP URLs that the CA will include in each certificate that it issues. 

The URLs specified in this section of the CAPolicy.inf file are included in the root CA 

certificate itself. 

Example: 

[CRLDistributionPoint] 

URL=http://pki.wingtiptoys.com/cdp/WingtipToysRootCA.crl