Ensurepass

 

QUESTION 271

You have two servers named Server1 and Server2 that run Windows Server 2012 R2. Server1 has the DHCP Server server role installed. You need to create an IPv6 reservation for Server2. Which two values should you obtain from Server2? (Each correct answer presents part of the solution. Choose two.)

 

A.

the hardware ID

B.

the DHCPv6 unique identifier

C.

the DHCPv6 identity association ID

D.

the SMSBIOS GUID

E.

the MAC address

 

Correct Answer: BC

Explanation:

The Add-DhcpServerv6Reservation cmdlet reserves a specified IPv6 address for the client identified by the specified Dynamic Host Configuration Protocol (DHCP) v6 unique identifier (ID) (DUID) and identity association ID (IAID).

http://technet.microsoft.com/en-us/library/jj590730.aspx

 

 

QUESTION 272

Hotspot Question

You have two servers that run Windows Server 2012 R2. The servers are configured as shown in the following table.

 

clip_image001

 

You need to ensure that Server2 can be managed by using Server Manager from Server1. In the table below, identify which actions must be performed on Server1 and Server2. Make only one selection in each row. Each correct selection is worth one point.

 

clip_image002

 

Correct Answer:

 

clip_image004

Explanation:

http://technet.microsoft.com/library/hh831453.aspx

 

 

QUESTION 273

Your network contains an Active Directory domain named contoso.com. The domain contains two member servers named Server1 and Server2 that run Windows Server 2012 R2. You log on to Server1. You need to retrieve a list of the active TCP connections on Server2. Which command should you run from Server1?

 

A.

winrm get server2

B.

dsquery * -scope base -attrip,server2

C.

winrs -r:server2netstat

D.

netstat> server2

 

Correct Answer: C

Explanation:

http://msdn.microsoft.com/en-us/library/aa384291(v=vs.85).aspx

This command line tool enables administrators to remotely execute most Cmd.exe commands using the WS-Management protocol.

 

clip_image005

 

 

QUESTION 274

You have a server named Server1 that has the Print and Document Services server role installed. You need to provide users with the ability to manage print jobs on Server1 by using a web browser.

What should you do?

 

A.

Start the Computer Browser service and set the service to start automatically.

B.

Install the LPD Service role service.

C.

Install the Internet Printing role service.

D.

Start the Printer Extensions and Notifications service and set the service to start automatically.

 

Correct Answer: C

Explanation:

Internet printing makes it possible for computers running Windows Server 2008 to use printers located anywhere in the world by sending print jobs using Hypertext Transfer Protocol (HTTP).

http://technet.microsoft.com/en-us/library/cc731368(v=ws.10).aspx

 

 

QUESTION 275

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1. Server1 runs Windows Server 2012 R2. You plan to create a shared folder. The shared folder will have a quota limit. You discover that when you run the New Share Wizard, you cannot select the SMB Share Advanced option. You need to ensure that you can use SMB Share – Advanced to create the new share. What should you do on Server1 before you run the New Share Wizard?

 

A.

Configure the Advanced system settings.

B.

Run the Install-WindowsFeaturecmdlet.

C.

Run the Set-SmbSharecmdlet.

D.

Install the Share and Storage Management tool.

Correct Answer: B

Explanation:

clip_image007

 

Install-windowsfeature -name fs-resource-manager -includemanagementtools

Installs one or more Windows Server roles, role services, or features on either the local or a specified remote server that is running Windows Server 2012 R2. This cmdlet is equivalent to and replaces Add- WindowsFeature, the cmdlet that was used to install roles, role services, and features in Windows Server 2008 R2.

http://www.c-sharpcorner.com/UploadFile/cd7c2e/how-to-install-the-file-server-resource-manager-in-windows-s/

 

 

QUESTION 276

Your network contains two Active Directory forests named contoso.com and adatum.com. All servers run Windows Server 2012 R2. A one-way external trust exists between contoso.com and adatum.com. Adatum.com contains a universal group named Group1. You need to prevent Group1 from being used to provide access to the resources in contoso.com. What should you do?

 

A.

Change the scope of Group1 to domain local.

B.

Modify the Allowed to Authenticate permissions in adatum.com.

C.

Enable SID quarantine on the trust between contoso.com and adatum.com.

D.

Modify the Allowed to Authenticate permissions in contoso.com.

 

Correct Answer: B

Explanation:

* Accounts that require access to the customer Active Directory will be granted a special right called Allowed to Authenticate. This right is then applied to computer objects (Active Directory domain controllers and AD RMS servers) within the customer Active Directory to which the account needs access.

* For users in a trusted Windows Server 2008 or Windows Server 2003 domain or forest to be able to access resources in a trusting Windows Server 2008 or Windows Server 2003 domain or forest where the trust authentication setting has been set to selective authentication, each user must be explicitly granted the Allowed to Authenticate permission on the security descriptor of the computer objects (resource computers) that reside in the trusting domain or forest.

http://technet.microsoft.com/en-us/library/cc816733(v=ws.10).aspx

 

 

QUESTION 277

Your network contains an Active Directory domain named contoso.com. The domain contains 100 user accounts that reside in an organizational unit (OU) named OU1. You need to ensure that a user named User1 can link and unlink Group Policy objects (GPOs) to 0U1. The solution must minimize the number of permissions assigned to User1. What should you do?

 

A.

Add User1 to the Group Policy Creator Owners group.

B.

Run the Set-GPPermissioncmdiet.

C.

Modify the permission on the \Contoso.comSYSVOLContoso.comPolicies folder.

D.

Run the Delegation of Control Wizard on OU1.

 

Correct Answer: D

Explanation:

http://www.howtogeek.com/50166/using-the-delegation-of-control-wizard-to-assign-permissions-in-server-2008/

 

clip_image008

 

 

 

 

 

 

 

 

 

 

QUESTION 278

Your network contains an Active Directory forest named contoso.com. The forest contains two domains named contoso.com and child.contoso.com and two sites named Site1 and Site2. The domains and the sites are configured as shown in following table.

 

clip_image009

 

When the link between Site1 and Site2 fails, users fail to log on to Site2. You need to identify what prevents the users in Site2 from logging on to the child.contoso.com domain. What should you identify?

 

A.

the placement of the global catalog server

B.

the placement of the PDC emulator

C.

the placement of the infrastructure master

D.

the placement of the domain naming master

 

Correct Answer: B

Explanation:

http://technet.microsoft.com/en-us/library/dd391870(v=ws.10).aspx

The PDC emulator processes password changes from earlier-version clients and other domain controllers on a best-effort basis; handles password authentication requests involving passwords that have recently changed and not yet been replicated throughout the domain; and, by default, synchronizes time. If this domain controller cannot connect to the PDC emulator, this domain controller cannot process authentication requests, it may not be able to synchronize time, and password updates cannot be replicated to it.

http://technet.microsoft.com/en-us/library/cc773108(v=ws.10).aspx

The PDC emulator master processes password changes from client computers and replicates these updates to all domain controllers throughout the domain. At any time, there can be only one domain controller acting as the PDC emulator master in each domain in the forest.

 

 

 

 

 

 

 

 

 

 

 

 

QUESTION 279

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All servers runs Windows Server 2012 R2.The domain contains two domain controllers named DC1 and DC2. Both domain controllers are virtual machines on a HyperV host. You plan to create a cloned domain controller named DC3 from an image of DC1. You need to ensure that you can clone DC1. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

 

A.

Add the computer account of DC1 to the Cloneable Domain Controllers group.

B.

Create a DCCIoneConfig.xml file on DC1.

C.

Add the computer account of DC3 to the Cloneable Domain Controllers group.

D.

Run the Enable-AdOptionalFeaturecmdlet.

E.

Modify the contents of the DefaultDCCIoneAllowList.xml file on DC1.

 

Correct Answer: AB

Explanation:

A: Cloneable Domain Controllers Group There’s a new group in town. It’s called Cloneable Domain Controllers and you can find it in the Users container. Membership in this group dictates whether a DC can or cannot be cloned. This group has some permissions set on the domain head that should not be removed. Removing these permissions will cause cloning to fail. Also, as a best practice, DCs shouldn’t be added to the group until you plan to clone and DCs should be removed from the group once cloning is complete. Cloned DCs will also end up in the Cloneable Domain Controllers group.

B: DCCloneConfig.xml

There’s one key difference between a cloned DC and a DC that is being restored to a previous snapshot: DCCloneConfig.XML.

DCCloneConfig.xml is an XML configuration file that contains all of the settings the cloned DC will take when it boots. This includes network settings, DNS, WINS, AD site name, new DC name and more. This file can be generated in a few different ways.

The New-ADDCCloneConfigcmdlet in PowerShell

By hand with an XML editor

By editing an existing config file, again with an XML editor. Reference: Virtual Domain Controller Cloning in Windows Server 2012

 

 

QUESTION 280

Your network contains an Active Directory forest. The forest contains two domains named contoso.com and corp.contoso.com. All domain controllers run Windows Server 2012 R2 and are configured as global catalog servers. The corp.contoso.com domain contains a domain controller named DC1. You need to disable the global catalog on DC1. What should you do?

 

A.

From Active Directory Users and Computers, modify the properties of the DC1 computer account.

B.

From Active Directory Administrative Center, modify the properties of the DC1 computer account.

C.

From Active Directory Sites and Services, modify the NTDS Settings of the DC1 server object.

D.

From Active Directory Domains and Trusts, modify the properties of the corp.contoso.com domain.

 

Correct Answer: C

Explanation:

http://technet.microsoft.com/en-us/library/cc755257.aspx

To add or remove the global catalog

Open Active Directory Sites and Services. To open Active Directory Sites and Services, click Start , click Administrative Tools , and then click Active Directory Sites and Services .

To open Active Directory Sites and Services in Windows Server® 2012, click Start , type dssite.msc .

In the console tree, click the server object to which you want to add the global catalog or from which you want to remove the global catalog.

Where?

Active Directory Sites and ServicesSitesSiteNameServers

In the details pane, right-click NTDS Settings of the selected server object, and then click Properties .

Select the Global Catalog check box to add the global catalog, or clear the check box to remove the global catalog.

Free VCE & PDF File for Microsoft 70-410 Real Exam

Instant Access to Free VCE Files: MCSE|MCSA|MCITP…
Instant Access to Free PDF Files: MCSE|MCSA|MCITP…