Question 1
Question
You work as an administrator at Contoso.com. The Contoso.com network consists of a
single domain named Contoso.com. All servers on the Contoso.com network have
Windows Server 2012 installed.
You are in the process of installing a Server Core installation of Windows Server 2012 on a
new Contoso.com server, named ENSUREPASS-SR13.
Which of the following is TRUE with regards to a installing a Server Core installation of
Windows Server 2012? (Choose all that apply.)
Answer
-
The Desktop Experience is not available.
-
You are able to access the Microsoft Management Console locally
-
Server roles can be configured locally via Server Manager.
-
Server roles can be configured locally via the command prompt using Windows
PowerShell
-
The Server Graphical Shell is installed, but not enabled.
Question 2
Question
You install Windows Server 2012 R2 on a standalone server named Server1. You
configure Server1 as a VPN server.
You need to ensure that client computers can establish PPTP connections to Server1.
Which two firewall rules should you create? (Each correct answer presents part of the
solution. Choose two.)
Answer
-
An inbound rule for protocol 47
-
An outbound rule for protocol 47
-
An inbound rule for TCP port 1723
-
An inbound rule for TCP port 1701
-
An outbound rule for TCP port 1723
-
An outbound rule for TCP port 1701
Question 3
Question
Your network contains an Active Directory domain named contoso.com. The domain
contains a server named Server1. Server1 runs Windows Server 2012 R2 and has the
Hyper-V server role installed.
On Server1, an administrator creates a virtual machine named VM1.
A user named User1 is the member of the local Administrators group on Server1.
User1 attempts to modify the settings of VM1 as shown in the following exhibit. (Click the
Exhibit button.)
You need to ensure that User1 can modify the settings of VM1 by running the Set-Vm
cmdlet.
What should you instruct User1 to do?
Answer
-
Import the Hyper-V module.
-
Install the Integration Services on VM1.
-
Run Windows PowerShell with elevated privileges.
-
Modify the membership of the local Hyper-V Administrators group.
Question 4
Question
Your network contains an Active Directory domain named contoso.com. All servers run
Windows Server 2012 R2. The domain contains a server named Server1.
You install the Windows PowerShell Web Access gateway on Server1.
You need to provide administrators with the ability to manage the servers in the domain by
using the Windows PowerShell Web Access gateway.
Which two cmdlets should you run on Server1? (Each correct answer presents part of the
solution. Choose two.)
Question 5
Question
You work as an administrator at ABC.com. The ABC.com network consists of a single
domain named ABC.com. All servers in the ABC.com domain, including domain controllers,
have Windows Server 2012 R2 installed.
ABC.com has a domain controller, named ABC-DC01, which contains the ABC.com
domain’s primary DNS zone. ABC.com’s workstations refer to ABC-DC01 as their primary
DNS server.
You have been instructed to make sure that any DNS requests that are not for the
ABC.com domain, is resolved by ABC-DC01 querying the DNS server of ABC.com’s
Internet Service Provider (ISP).
Which of the following actions should you take?
Answer
-
You should consider configuring a reverse lookup zone.
-
You should consider configuring forward lookup zone
-
You should consider configuring Forwarders.
-
You should consider configuring 019 IP Layer Forwarding
Question 6
Question
A company’s server administration team would like to take advantage of the newest file
systems available with Windows Server 2012 R2. The team needs a file system capable of
managing extremely large data drives that can auto-detect data corruption and
automatically perform needed repairs without taking a volume offline.
Which file system should the server administration team choose?
Question 7
Question
You have a print server named Server1.
You install a printer on Server1. You share the printer as Printer1.
You need to configure Printer1 to be available only from 19:00 to 05:00 every day.
Which settings from the properties of Printer1 should you modify?
Answer
-
Sharing
-
Security
-
Advanced
-
Device Settings
-
Ports
Question 8
Question
Your network contains an Active Directory domain named contoso.com.
An organizational unit (OU) named OU1 contains the user accounts and the computer
accounts for laptops and desktop computers. A Group Policy object (GPO) named GP1 is
linked to OU1. You need to ensure that the configuration settings in GP1 are applied only
to the laptops in OU1. The solution must ensure that GP1 is applied automatically to new
laptops that are added to OU1.
What should you do?
Answer
-
Modify the GPO Status of GP1.
-
Configure the WMI Filter of GP1
-
Modify the security settings of GP1.
-
Modify the security settings of OU1
Question 9
Question
You work as an administrator at Contoso.com. The Contoso.com network consists of a
single domain named Contoso.com. All servers on the Contoso.com network have
Windows Server 2012 R2 installed.
You have received instructions to convert a basic disk to a GPT disk.
Which of the following is TRUE with regards to GPT disks? (Choose all that apply.)
Answer
-
To convert a basic disk to a GPT disk, the disk must not contain any partitions or
volumes.
-
You can convert a basic disk to a GPT disk, regardless of partitions or volumes.
-
GPT is required for disks larger than 2 TB.
-
GPT is required for disks smaller than 2 TB.
-
The GPT partition style can be used on removable media.
-
GPT disks make use of the standard BIOS partition table.
Question 10
Question
You work as an administrator at Contoso.com. The Contoso.com network consists of a
single domain named Contoso.com.
Contoso.com has a Windows Server 2012 R2 domain controller, named ENSUREPASSDC01,
which has the Domain Naming master and the Schema master roles installed.
Contoso.com also has a Windows Server 2008 R2 domain controller, named
ENSUREPASS-DC02, which has the PDC Emulator, RID master, and Infrastructure master
roles installed.
You have deployed a new Windows Server 2012 server, which belongs to a workgroup, in
Contoso.com’s perimeter network.
You then executed the djoin.exe command.
Which of the following is the purpose of the djoin.exe command?
Answer
-
It sets up a computer account in a domain and requests an offline domain join when a
computer restarts.
-
It sets up a user account in a domain and requests an online domain join when a
computer restarts
-
It sets up a computer account in a domain and requests an offline domain join
immediately.
-
It sets up a computer account in a domain and requests an online domain join
immediately.
Question 11
Question
Your network contains an Active Directory forest. The forest contains two domains named
contoso.com and corp.contoso.com. All domain controllers run Windows Server 2012 R2
and are configured as global catalog servers. The corp.contoso.com domain contains a
domain controller named DC1.
You need to disable the global catalog on DC1.
What should you do?
Answer
-
From Active Directory Users and Computers, modify the properties of the DC1 computer
account.
-
From Active Directory Administrative Center, modify the properties of the DC1 computer
account.
-
From Active Directory Sites and Services, modify the NTDS Settings of the DC1 server
object.
-
From Active Directory Domains and Trusts, modify the properties of the
corp.contoso.com domain.
Question 12
Question
How can you manage a newly installed Windows Server 2012 R2 core from a another
Windows Server 2012 R2 with computer manager?
Exhibit:
Question 13
Question
Your network contains an Active Directory domain named contoso.com. The domain
contains a DHCP server named Server1that runs Windows Server 2012 R2.
You create a DHCP scope named Scope1. The scope has a start address of 192168.1.10,
an end address of 192.168.1.50, and a subnet mask of 255.255.255.192.
You need to ensure that Scope1 has a subnet mask of 255.255.255.0. What should you do
first?
Answer
-
From Windows PowerShell, run the Remove-DhcpServerv4PolicyIPRange cmdlet.
-
From the DHCP console, modify the Scope Options of Scope1
-
From Windows PowerShell, run the Remove-DhcpServerv4Scope cmdlet.
-
From Windows PowerShell, run the Set-DhcpServerv4Scope cmdlet.
Question 14
Question
You work as an administrator at Contoso.com. The Contoso.com network consists of a
single domain named Contoso.com. All servers on the Contoso.com network have
Windows Server 2012 installed.
A server named, ENSUREPASS-SR13, has a Server Core Installation of Windows Server
2012 installed.
You are instructed to convert ENSUREPASS-SR13’s installation to a Server with GUI
installation.
You want to use a Windows PowerShell cmdlet that uses Windows Update as a source.
Which of the following actions should you take?
Answer
-
You should consider making use of the Install-WindowsFeature Server-Gui-Mgmt-Infra,
Server-Gui-Shell - Restart cmdlet.
-
You should consider making use of the Install-WindowsFeature Server-Gui-Mgmt-Infra,
Server-Gui-Shell - Restart -Source c:\mountdir\windows\winsxs cmdlet.
-
You should consider making use of the Uninstall-WindowsFeature Server-Gui-
Shell–Remove cmdlet.
-
You should consider making use of the Set-ExecutionPolicy cmdlet.
Question 15
Question
Your company has a remote office that contains 1,600 client computers on a single subnet.
You need to select a subnet mask for the network that will support all of the client
computers. The solution must minimize the number of unused addresses. Which subnet
mask should you select?
Answer
-
255.255.248.0
-
255.255.252.0
-
55.255.254.0
-
255.255.240.0
Question 16
Question
You have a server named Server1 that runs Windows Server 2012 R2. Server1 has 2 dualcore
processors and 16 GB of RAM.
You install the Hyper-V server role in Server1.
You plan to create two virtual machines on Server1.
You need to ensure that both virtual machines can use up to 8 GB of memory. The solution
must ensure that both virtual machines can be started simultaneously.
What should you configure on each virtual machine?
Answer
-
Dynamic Memory
-
NUMA topology
-
Memory weight
-
Resource Control
Question 17
Question
Which of the following groups do you use to consolidate groups and accounts that either
span multiple domains or the entire forest?
Answer
-
Global
-
Domain local
-
Built-in
-
Universal
Question 18
Question
Your network contains three servers that run Windows Server 2012 R2. The servers are
configured as shown in the following table. Server3 is configured to obtain an IP address
automatically.
You need to ensure that Server3 only receives an IP address from Server1. The IP address
must always be the same.
Which two tasks should you perform? (Each correct answer presents part of the solution.
Choose two.)
Answer
-
Create an exclusion on Server1.
-
Create a filter on Server1.
-
Create a reservation on Server2
-
Create a reservation on Server1
-
Create a filter on Server2
Question 19
Question
You have a server named Server1 that runs a Server Core installation of Windows Server
2012 R2. Server1 is configured to obtain an IPv4 address by using DHCP. You need to
configure the IPv4 settings of the network connection on Server1 as follows:
IP address: 10.1.1.1
Subnet mask: 255.255.240.0
Default gateway: 10.1.1.254
What should you run?
Answer
-
Set-NetlPInterface
-
netcfg.exe
-
New-NetlPAddress
-
msconfig.exe
Question 20
Question
A network technician installs Windows Server 2012 R2 Standard on a server named
Server1.
A corporate policy states that all servers must run Windows Server 2012 R2 Enterprise.
You need to ensure that Server1 complies with the corporate policy.
You want to achieve this goal by using the minimum amount of administrative effort.
What should you perform?
Answer
-
a clean installation of Windows Server 2012 R2
-
an upgrade installation of Windows Server 2012 R2
-
online servicing by using Dism
-
offline servicing by using Dism
Question 21
Question
Catalog Servers. Your domain structure contains one root domain and one child domain.
You modify the folder permissions on a file server that is in the child domain. You discover
that some Access Control entries start with S-1-5-21 and that no account name is listed.
You need to list the account names. What should you do?
Answer
-
Move the RID master role in the child domain to a domain controller that holds the
Global Catalog.
-
Modify the schema to enable replication of the friendly names attribute to the Global
Catalog.
-
Move the RID master role in the child domain to a domain controller that does not hold
the Global Catalog.
-
Move the infrastructure master role in the child domain to a domain controller that does
not hold the Global Catalog
Question 22
Question
You have a laptop named Computer1. Computer1 runs Windows 8 Enterprise.
Computer1 has a wired network adapter and a wireless network adapter. Computer1
connects to a wireless network named Network1.
For testing purposes, you install Windows Server 2012 R2 on Computer1 as a second
operating system. You install the drivers for the wireless network adapter.
You need to ensure that you can connect to Network1 from Windows Server 2012 R2.
What should you do?
Answer
-
Restart the WLAN AutoConfig service
-
From a local Group Policy object (GPO), configure the Wireless Network (IEEE 802.11)
Policies settings
-
From a local Group Policy object (GPO), configure the settings of Windows Connection
Manager.
-
From Server Manager, install the Wireless LAN Service feature.
Question 23
Question
You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the
Hyper-V server role installed. You have fixed-size VHD named Files.vhd.
You need to make the contents in Files.vhd available to several virtual machines. The
solution must meet the following requirements:
Ensure that if the contents are changed on any virtual machine, the changes are
not reflected on the other virtual machines.
Minimize the amount of disk space used.
What should you do?
Answer
-
Create a fixed-size VHDX. Transfer the information from Files.vhd to the new VHDX file
-
Convert Files.vhd to a dynamically expanding VHD?
-
Create a dynamically expanding VHDX. Transfer the information from Files.vhd to the
new VHDX file.
-
Create differencing VHDs that use Files.vhd as the parent disk
Question 24
Question
Your network contains an Active Directory domain named contoso.com. All servers run
either Windows Server 2008 R2 or Windows Serve 2012 R2. All client computers run either
Windows 7 or Windows 8. The domain contains a member server named Server1 that runs
Windows Server 2012 R2. Server1 has the File and Storage Services server role installed.
On Server1, you create a share named Share1.
You need to ensure that users can use Previous Versions to restore the files in Share1.
What should you configure on Server1?
Answer
-
The Shadow Copies settings
-
A Windows Server Backup schedule
-
A data recovery agent
-
The Recycle Bin properties
Question 25
Question
Which of the following are the two built-in user accounts created automatically on a
computer running Windows Server 2012 R2?
Answer
-
Network
-
nteractive
-
Administrator
-
Guest
Question 26
Question
Your network contains an Active Directory domain named contoso.com.
The domain contains 20 computer accounts in an organizational unit (OU) named OU1. A
user account named User1 is in an OU named OU2.
You are configuring a Group Policy object (GPO) named GPO1.
You need to assign User1 the Backup files and directories user right to all of the computer
accounts in OU1.
Which two actions should you perform? (Each correct answer presents part of the solution.
Choose two.)
Answer
-
From User Configuration in GPO1, modify the security settings.
-
Link GPO1 to OU1.
-
From Computer Configuration in GPO1, modify the security settings.
-
Modify the Delegation settings of GPO1.
-
Link GPO1 to OU2.
Question 27
Question
Your network contains an Active Directory domain named contoso.com. The domain
contains a print server named Server1 that runs Windows Server 2012 R2. Server1
contains a local group named Group1.
You share a printer named Printer1 on Server1.
You need to configure Printer1 to meet the following requirements:
Ensure that the members of Group1, the Server Operators group, the
Administrators group, and the Print Operators group can send print jobs to
Printer1.
Prevent other users from sending print jobs to Printer1.
Which two actions should you perform? (Each correct answer presents part of the solution.
Choose two.)
Answer
-
Remove the permissions for the Creator Owner group.
-
Assign the Print permission to the Administrators group.
-
Remove the permissions for the Everyone group
-
Assign the Print permission to the Server Operators group.
-
Assign the Print permission to Group1.
Question 28
Question
You work as an administrator at Contoso.com. The Contoso.com network consists of a
single domain named Contoso.com. All servers in the Contoso.com domain, including
domain controllers, have Windows Server 2012 R2 installed.
You have created and linked a new Group Policy object (GPO) to an organizational unit
(OU), named ENSUREPASSServ, which host the computer accounts for servers in the
Contoso.com domain.
You have been tasked with adding a group to a local group on all servers in the
Contoso.com domain. This group should not, however, be removed from the local group.
Which of the following actions should you take?
Answer
-
You should consider adding a restricted group
-
You should consider adding a global group.
-
You should consider adding a user group
-
You should consider adding a server group
Question 29
Question
You work as a senior administrator at Lead2pass.com. The Lead2pass.com network
consists of a single domain named Lead2pass.com. All servers on the Lead2pass.com
network have Windows Server 2012 R2 installed.
You are running a training exercise for junior administrators. You are currently discussing
storage pools.
Which of the following are TRUE with regards to storage pools?
Answer
-
It allows you to group physical disks into one or more containers.
-
It prevents you from grouping physical disks into one or more containers.
-
It allows you to easily add storage with minor impact on users.
-
It allows you to easily add storage without impacting users.
Question 30
Question
You work as an administrator at Contoso.com. The Contoso.com network consists of a
single domain named Contoso.com. All servers on the Contoso.com network have
Windows Server 2012 R2 installed.
Contoso.com has a server, named ENSUREPASS-SR07, which has two physical disks
installed. The C: drive hosts the boot partition, while the D: drive is not being used. Both
disks are online.
You have received instructions to create a virtual machine on ENSUREPASS-SR07.
Subsequent to creating the virtual machine, you have to connect the D: drive to the virtual
machine.
Which of the following is TRUE with regards to connecting a physical disk to a virtual
machine?
Answer
-
The physical disk should not be online
-
The physical disk should be uninstalled and re-installed.
-
The physical disk should be configured as a striped disk
-
The physical disk should be configured as a mirrored disk.
Question 31
Question
You work as an administrator at ABC.com. The ABC.com network consists of a single
domain named ABC.com. All servers in the ABC.com domain, including domain controllers,
have Windows Server 2012 R2 installed.
You have installed the DNS Server Role on an ABC.com server, named ABC-SR13.
ABC.com’s workstations make use of a web proxy to access the Internet, and refer to ABCSR13
as a primary DNS server.
You have been instructed to make sure that Internet host names for ABC.com’s
workstations are not resolved by ABC-SR13.
Which of the following actions should you take?
Answer
-
You should consider configuring a primary zone on ENSUREPASS-SR13.
-
You should consider configuring a secondary zone on ENSUREPASS-SR13.
-
You should consider configuring a reverse lookup zone on ENSUREPASS-SR13.
-
You should consider configuring a forward lookup zone on ENSUREPASS-SR13.
Question 32
Question
Your network contains an Active Directory domain named contoso.com. All client
computers run Windows 8.
An administrator creates an application control policy and links the policy to an
organizational unit (OU) named OU1. The application control policy contains several deny
rules. The deny rules apply to the Everyone group.
You need to prevent users from running the denied application.
What should you configure?
To answer, select the appropriate object in the answer area.
Question 33
Question
You work as an administrator at Contoso.com. The Contoso.com network consists of a
single domain named Contoso.com. All servers on the Contoso.com network have
Windows Server 2012 R2 installed.
Contoso.com has a server, named ENSUREPASS-SR13, which is configured as the
primary DNS server in the Contoso.com domain. Contoso.com has another server, named
ENSUREPASS-SR14, which makes use of ENSUREPASSSR13 for DNS queries.
You want to make sure that running nslookup.exe from ENSUREPASS-SR14 produces a
result that shows the proper name of the default server.
Which of the following actions should you take?
Answer
-
You should consider creating a reverse lookup zone on ENSUREPASS-SR14.
-
You should consider creating a forward lookup zone on ENSUREPASS-SR14.
-
You should consider creating a reverse lookup zone on ENSUREPASS-SR13
-
You should consider creating a forward lookup zone on ENSUREPASS-SR13.
Question 34
Question
You have a DNS server named DNS1 that runs windows server 2012 R2.
DNS1 is used to resolve the names of internet resources by using several DNS forwarders.
You need to prevent DNS1 from performing iterative queries if the DNS forwarders are
unable to reslove the queries.
Which cmdlet should you use?
Answer
-
Remove-DNSServerRootHint
-
Set-DNSServerPrimaryZone
-
Ser-DNSServerGlobalNameZone
-
Unregister-DNSserverDrirectoryPartition
Answer: A
You work as an administrator at Contoso.com. The Contoso.com network consists of a
single domain named Contoso.com. All servers on the Contoso.com network have
Windows Server 2012 R2 installed.
Contoso.com has a server, named ENSUREPASS-SR13, which is configured as the
primary DNS server in the Contoso.com domain. Contoso.com has another server, named
ENSUREPASS-SR14, which makes use of ENSUREPASSSR13 for DNS queries.
You want to make sure that running nslookup.exe from ENSUREPASS-SR14 produces a
result that shows the proper name of the default server.
Which of the following actions should you take?
A. You should consider creating a reverse lookup zone on ENSUREPASS-SR14.
B. You should consider creating a forward lookup zone on ENSUREPASS-SR14.
C. You should consider creating a reverse lookup zone on ENSUREPASS-SR13.
D. You should consider creating a forward lookup zone on ENSUREPASS-SR13.
Answer: C
Explanation:
When you start Nslookup from a command line, the following error message may be
Question No
Question 35
Question
Your network contains an Active Directory domain named contoso.com. The domain
contains a member server named Server1. Server1 runs Windows Server 2012 R2 and has
the File and Storage Services server role installed.
On Server1, you create a share named Documents. The Share permission for the
Documents share is configured as shown in the following table.
The NTFS permission for the Documents share is configured as shown in the following
table.
You need to configure the Share and NTFS permissions for the Documents share.
The permissions must meet the following requirements:
Ensure that the members of a group named Group1 can read files and run
programs in Documents.
Ensure that the members of Group1 can modify the permissions on only their own
files in Documents.
Ensure that the members of Group1 can create folders and files in Documents.
Minimize the number of permissions assigned to users and groups.
How should you configure the permissions?
To answer, drag the appropriate permission to the correct location. Each permission may
be used once, more than once, or not at all. You may need to drag the split bar between
panes or scroll to view content.
Answer
-
Allow creator full control
-
Allow creator owner modify
-
Allow Group 1 change
-
Allow Group 1 Full control
-
Allow Group1 Modify
-
Allow Group 1 Read& execute, list folder contents, Read, Write
Question 36
Question
You run a Windows 2012 and implementing 3 new printers in a warehouse. You need to
makean exclusion forthese IP addresses within DHCP server.
Select the location where would configure at the DHCP console?
Answer
-
Address Pool
-
Address Leases
-
Reservations
-
Scope Options
-
Policies
Question 37
Question
Your network contains an Active Directory domain named contoso.com. The network
contains a domain controller named DC1 that has the DNS Server server role installed.
DC1 has a standard primary DNS zone for contoso.com.
You need to ensure that only client computers in the contoso.com domain will be able to
add their records to the contoso.com zone.
What should you do first?
Answer
-
Sign the contoso.com zone.
-
Modify the Security settings of DC1.
-
Modify the Security settings of the contoso.com zone
-
Store the contoso.com zone in Active Directory.
Question 38
Question
Your network contains a server named Server1 that runs Windows Server 2012 R2.
Server1 is located on the same subnet as all of the client computers. A network technician
reports that he receives a “Request timed out” error message when he attempts to use the
ping utility to connect to Server1 from his client computer. The network technician confirms
that he can access resources on Server1 from his client computer.
You need to configure Windows Firewall with Advanced Security on Server1 to allow the
ping utility to connect.
Which rule should you enable?
Answer
-
File and Printer Sharing (Echo Request – ICMPv4-In)
-
Network Discovery (WSD-In)
-
File and Printer Sharing (NB-Session-In)
-
Network Discovery (SSDP-In)
Question 39
Question
You have a server named Server1 that runs Windows Server 2012 R2.
You need to remove Windows Explorer, Windows Internet Explorer, and all related
components and files from Server1.
What should you run on Server1?
Answer
-
Uninstall-WindowsFeature Server-Gui-Mgmt-Infra Remove
-
Uninstall-WindowsFeature Server-Gui-Shell Remove
-
msiexec.exe /uninstall iexplore.exe /x
-
msiexec.exe /uninstall explorer.exe /x
Question 40
Question
Which of the following is not a type of user account that can be configured in Windows
Server 2012 R2?
Answer
-
local accounts
-
domain accounts
-
network accounts
-
built-in accounts
Question 41
Question
You work as an administrator at Contoso.com. The Contoso.com network consists of a
single domain named Contoso.com. All servers in the Contoso.com domain, including
domain controllers, have Windows Server 2012 R2 installed.
You have been instructed to make sure that Contoso.com users are not able to install a
Windows Store application. You then create a rule for packaged apps.
Which of the following is the rule based on? (Choose all that apply.)
Answer
-
The publisher of the package
-
The publisher of the application.
-
The name of the package
-
The name of the application
-
The package version
-
The application version.
Question 42
Question
You work as a senior administrator at Contoso.com. The Contoso.com network consists of
a single domain named Contoso.com. All servers on the Contoso.com network have
Windows Server 2012 installed.
You are running a training exercise for junior administrators. You are currently discussing
Storage Spaces.
Which of the following is TRUE with regards to Storage Spaces?
Answer
-
Mirroring and parity are optional resilient storage modes of Storage Spaces
-
Failover clustering is not supported by Storage Spaces.
-
Storage spaces are virtual disks with associated attributes such as a preferred level of
resiliency, and thin or fixed provisioning.
-
Storage spaces are a collection of physical disks with associated attributes such as a
preferred level of resiliency, and thin or fixed provisioning
Question 43
Question
Your network contains an Active Directory domain named contoso.com. All domain
controllers run Windows Server 2012 R2. You need to ensure that the local Administrator
account on all computers is renamed to L_Admin. Which Group Policy settings should you
modify?
Answer
-
Security Options
-
User Rights Assignment
-
Restricted Groups
-
Preferences
Question 44
Question
Your infrastructure divided in 2 sites. You have a forest root domain and child domain.
There is only one DC on site 2 with no FSMO roles. The link goes down to site 2 and no
users can log on. What FSMO roles you need on to restore the access?
Answer
-
Infrastructure master
-
RID master
-
Domain Naming master
-
PDC Emulator
Question 45
Question
You have a file server named File1 that runs Windows Server 2012 R2.
File1 contains a shared folder named Share1. Share1 contains an Application named
SalesAppl.exe.
The NTFS permissions for Share1 are shown in the following table.
The members of L_Sales discover that they cannot add files to Share1. Domain users can
run SalesAppl.exe successfully.
You need to ensure that the members of L_Sales can add files to Share1.
What should you do?
Answer
-
Add the Domain Users group to L_Sales.
-
Add L_Sales to the Domain Users group.
-
Edit the Share permissions
-
Edit the NTFS permissions.
Question 46
Question
You work as an administrator at Contoso.com. The Contoso.com network consists of a
single domain named Contoso.com.
Contoso.com has a server, named ENSUREPASS-SR15, which has Windows Server 2012
R2 installed. Contoso.com also has a server, named ENSUREPASS-SR16, which has
Windows Server 2008 R2 SP1 installed.
You have been instructed to make sure that ENSUREPASS-SR16 is able to run Windows
PowerShell 3.0.
Which of the following actions should you take? (Choose two.)
Answer
-
You should consider making sure that ENSUREPASS-SR16 has a full installation of
Microsoft .NET Framework 4 installed.
-
You should consider making sure that ENSUREPASS-SR16 has a full installation of
Microsoft .NET Framework 2 installed.
-
You should consider making sure that ENSUREPASS-SR16 has WS-Management 3.0
installed.
-
You should consider making sure that ENSUREPASS-SR16 is upgraded to Windows
Server 2012 R2.
Question 47
Question
You have a domain controller named Server1 that runs Windows Server 2012 R2 and has
the DNS Server server role installed. Server1 hosts a DNS zone named contoso.com and a
GlobalNames zone.
You discover that the root hints were removed from Server1.
You need to view the default root hints of Server1.
What should you do?
Answer
-
From Event Viewer, open the DNS Manager log.
-
From Notepad, open the Cache.dns file.
-
From Windows Powershell, run Get-DNSServerDiagnostics
-
From nslookup, run root server1.contoso.com
Question 48
Question
You work as an administrator at Contoso.com. The Contoso.com network consists of a
single domain named Contoso.com. All servers in the Contoso.com domain, including
domain controllers, have Windows Server 2012 R2 installed.
You have configured a server, named ENSUREPASS-SR07, as a VPN server. You are
required to configure new firewall rules for workstation connections.
You want to achieve this using the least amount of administrative effort.
Which of the following actions should you take?
Answer
-
You should consider making use of the Enable-NetFirewallRule cmdlet
-
You should consider making use of the New-NetFirewallRule cmdlet.
-
You should consider making use of dism.exe from the command prompt.
-
You should consider making use of dsadd.exe from the command prompt.
Question 49
Question
You have a Hyper-V host named Server1 that runs Windows Server 2012 R2. Server1
hosts 50 virtual machines that run Windows Server 2012 R2.
Your company uses smart cards for authentication.
You need to ensure that you can use smart card authentication when you connect to the
virtual machine by using Virtual Machine Connection.
What should you configure?
Answer
-
The RemoteFX settings
-
The Enhanced Session Mode Policy
-
The NUMA Spanning settings
-
The Integration Services settings
Question 50
Question
Your network contains an Active Directory domain named contoso.com. The domain
contains a domain controller named DC1 that runs Windows Server 2012 R2. You need to
configure a central store for the Group Policy Administrative Templates.
What should you do on DC1?
Answer
-
From Server Manager, create a storage pool
-
From Windows Explorer, copy the PolicyDefinitions folder to the
SYSVOL\contoso.com\policies folder.
-
From Server Manager, add the Group Policy Management feature
-
From Windows Explorer, copy the PolicyDefinitions folder to the NETLOGON share.