KEMBAR78
MCSA Answer | PDF | Active Directory | Group Policy
0% found this document useful (0 votes)
171 views12 pages

MCSA Answer

1. The document contains a 30 question, 30 mark multiple choice exam about configuring and managing servers running Windows Server 2012. Questions cover topics like Active Directory, Group Policy, DNS, DFS, WSUS, NAP, and Windows Deployment Services. 2. To summarize the key points, the exam tests knowledge of tools and procedures for common server administration tasks in a Windows Server 2012 environment, including configuring services to run as managed service accounts, delegating permissions to link GPOs, optimizing memory allocation on Hyper-V hosts, and forcing zone replication between DNS servers. 3. Common actions referenced are using PowerShell cmdlets, running wizards, modifying permissions or group membership, and config
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
171 views12 pages

MCSA Answer

1. The document contains a 30 question, 30 mark multiple choice exam about configuring and managing servers running Windows Server 2012. Questions cover topics like Active Directory, Group Policy, DNS, DFS, WSUS, NAP, and Windows Deployment Services. 2. To summarize the key points, the exam tests knowledge of tools and procedures for common server administration tasks in a Windows Server 2012 environment, including configuring services to run as managed service accounts, delegating permissions to link GPOs, optimizing memory allocation on Hyper-V hosts, and forcing zone replication between DNS servers. 3. Common actions referenced are using PowerShell cmdlets, running wizards, modifying permissions or group membership, and config
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
You are on page 1/ 12

MCSA

No. of questions: 30 Total Marks: 30 Duration: 30 minutes

1.Your network contains an active directory domain named Contoso.com. The


domain contains a server named Server1 that runs Windows Server 2012 R2.
You create a group Managed Service Account named gservice1.

You need to configure a service named service1 to run as the gservice1 account.
How should you configure service1?

A. From Services Console configure the recovery settings


B. From a command prompt ,run sc.exe and specify the config parameter
C. From Windows PowerShell,run Set-Service and specify the -PassThrough
parameter
D. From a command prompt ,run sc.exe and specify the sdset parameter

2.Your network contains an active directory domain named Contoso.com. The


domain contains 100 user accounts that reside in an organizational unit (OU)
named OU1. You need to ensure that user named user1 can link and unlink Group
Policy Objects(GPOs) to OU1. The solution must minimize the number of
permissions assigned to user1. What should you do?

A. Run the Delegation of Control Wizard on the Policies containers


B. Run the Set-GPPermission cmdlet
C. Run the Delegation of Control Wizard on OU1
D. Modify the permission on the user1 account

3.You have a server named Server1 that runs Windows Server 2012 R2. Server1
has 2 dual-core processors and 16 GB of RAM.
You install the Hyper-V server role in Server1.
You plan to create two virtual machines on Server1.
You need to ensure that both virtual machines can use up to 8 GB of memory. The
solution must ensure that both virtual machines can be started simultaneously.
What should you configure on each virtual machine?
A. Dynamic Memory
B. NUMA topology
C. Memory weight
D. Ressource Control

4. Your network contains an Active Directory domain named contoso.com. The


domain contains a server named Server1 that runs Windows Server 2012 R2.
Server1 contains a single virtual machine named VM1.
You need to ensure that a user named User1 can manage the virtual machine
settings of VM1.

The solution must minimize the number of permissions assigned to User1.


To which group should you add User1?

A. Server Operators
B. Administrators
C. Power Users
D. Hyper-V Administrators

5. Your network contains an Active Directory domain named contoso.com. You


discover that when you join client computers to the domain manually, the
computer accounts are created in the Computers container.

You need to ensure that new computer accounts are created automatically in an
organizational
unit (OU) named Corp.
Which tool should you use?
A. net.exe
B. redircmp.exe
C. regedit.exe
D. dsadd.exe
6. You work as a senior administrator at ENSUREPASS.com. The ENSUREPASS.com
network consists of a single domain named ENSUREPASS.com. All servers on the
ENSUREPASS.com network have Windows Server 2012 installed, and all
workstations have Windows 8 installed. You are running a training exercise for
junior administrators. You are currently discussing the Always Offline Mode.
Which of the following is TRUE with regards to the Always Offline Mode? (Choose
all that apply.)

A. It allows for swifter access to cached files and redirected folders.


B. To enable Always Offline Mode, you have to satisfy the forest and domain
functional-level requirements,
as well as schema requirements.
C. It allows for lower bandwidth usage due to users are always working offline.
D. To enable Always Offline Mode, you must have workstations running Windows
7 or Windows
Server 2008 R2.

7. Your network contains two servers named Server1 and Server2 that run
Windows Server 2012 R2. You need to install the Remote Desktop Services server
role on Server2 remotely from Server1. Which tool should you use?

A. The dsadd.exe command


B. The Server Manager console
C. The Remote Desktop Gateway Manager console
D. The Install-RemoteAccess cmdlet

8. Your network contains an Active Directory domain named contoso.com. The


domain contains 100 servers. The servers are contained in a organizational unit
(OU) named ServersOU. You need to create a group named Group1 on all of the
servers in the domain. You must ensure that Group1 is added only to the servers.
What should you configure?
A. a Local Users and Groups preferences setting in a Group Policy linked to the
Domain Controllers OU
B. a Restricted Groups setting in a Group Policy linked to the domain
C. a Local Users and Groups preferences setting in a Group Policy linked to
ServersOU
D. a Restricted Groups setting in a Group Policy linked to ServersOU

9. Your network contains an Active Directory domain named contoso.com. The


domain contains two
domain controllers named DC1 and DC2. You install Windows Server 2012 on a
new computer
named DC3. You need to manually configure DC3 as a domain controller. Which
tool should you
use?
A. Server Manager
B. winrm.exe
C. Active Directory Domains and Trusts
D. dcpromo.exe

10.Your network contains an Active Directory domain named contoso.com.


Domain controllers run either Windows Server 2008, Windows Server 2008 R2, or
Windows Server 2012. You have a Password Settings object (PSOs) named PSO1.
You need to view the settings of PSO1. Which tool
should you use?

A. Get-ADFineGrainedPasswordPolicy
B. Get-ADAccountResultantPasswordReplicationPolicy
C. Get-ADDomainControllerPasswordReplicationPolicy
D. Get-ADDefaultDomainPasswordPolicy
11. Your network contains an Active Directory domain named contoso.com. The
domain contains 30 organizational units (OUs). You need to ensure that a user
named User1 can link Group Policy Objects (GPOs) in the domain. What should
you do?
A. From the Active Directory Users and Computers, add User1 to the Network
Configuration
Operators group.
B. From the Group Policies Management, click the contoso.com node and modify
the
Delegation settings.
C. From the Group Policies Management, click the Group policy Objects node and
modify the
Delegation settings.
D. From the Active Directory Users and Computers, add User1 to the Group Policy
Creator
Owners group.

12. Your network contains two servers named Server1 and Server2. Both servers
run Windows Server
2012 and have the DNS Server role installed. Server1 hosts a primary zone for
contoso.com.
Server2 hosts a secondary zone for contoso.com. The zone is not configure to
notify secondary
servers of changes automatically. You update several records on Server1. You
need to force the
replication of the contoso.com zone records from Server1 to Server2. What
should you do from
Server2?
A. Right-click Server2 and click Update Server Data Files.
B. Right-click Server2 and click Refresh.
C. Right-click the contoso.com zone and click Reload.
D. Right-click the contoso.com zone and click Transfer from Master.
13.You have a DNS server named Server1 that has a Server Core Installation on
Windows Server 2012. You need to view the time-to-live (TTL) value of a name
server (NS) record that is cached by
the DNS Server service on Server1. What should you run?
A. Show-DNSServerCache
B. dnscacheugc.exe
C. ipconfiq.exe /displaydns
D. nslookup.exe

14. Your network contains multiple Active Directory sites. You have a Distributed
File System (DFS)
namespace that has a folder target in each site. You discover that some client
computers connect
to DFS targets in other sites. You need to ensure that the client computers only
connect to a DFS
target in their respective site. What should you modify?
A. the properties of the Active Directory site links
B. the properties of the Active Directory sites
C. the delegation settings of the namespace
D. the referral settings of the namespace

15. You have a server named Server1 that runs Windows Server 2012. Server1 has
the File Server Resource Manager role service installed. Server1 has a folder
named Folder1 that is used by the human resources department. You need to
ensure that an email notification is sent immediately to the human resources
manager when a user copies an audio file or a video file to Folder1. What
should you configure on Server1?

A. A file screen
B. A file screen exception
C. A file group
D. A storage report task

16.On the DFS replication your receive a wrap error on the sysvol on domain
controller 4. Which 3
steps should you do to recover this error in the correct order?
A. Stop FSR
B. Start FSR
C. Edit the computer object in AD
D. Edit the registry
E. Stop DFSR
F. Start DFRS

17. Your network contains an Active Directory domain named contoso.com. The
domain contains 2 WSUS servers, ServerA and ServerB. ServerB is a replica server
of ServerA. You need to configure WSUS to report data from SERVERB to
SERVERA. What should you configure?

A. Update Reports
B. Synchronization
C. Computer Groups
D. Reporting Rollup

18.Your network contains an Active Directory domain named contoso.com. The


domain contains a server named Server1 that runs Windows Server 2012 and a
server named Server2 that has the File Services server role installed. You install
the Windows Deployment Services server role on Server1. You plan to use Server2
as a reference computer. You need to create an image of Server2 by using
Windows Deployment Services. Which type of image should you add to Server1
first?

A. Install
B. Boot
C. Discovery
D. Capture

19. You have a server named Server1 that runs Windows Server 2012. You create
a Data Collector Set (DCS) named DCS1. You need to configure DCS1 to log data to
D:\logs. What should you do?
A. Right-click DCS1 and click Properties.
B. Right-click DCS1 and click Save template.
C. Right-click DCS1 and click Data Manager.
D. Right-click DCS1 and click Export list.

20. Your network contains an Active Directory domain named contoso.com. The
domain contains a server named Server1 that runs Windows Server 2012. Server1
has the Network Policy Server role service installed. You plan to configure Server1
as a Network Access Protection (NAP) health policy server for VPN enforcement
by using the Configure NAP wizard. You need to ensure that you can configure the
VPN enforcement method on Server1 successfully. What should you install
on Server1 before you run the Configure NAP wizard?

A. The Host Credential Authorization Protocol (HCAP)


B. A system health validator (SHV)
C. The Remote Access server role
D. A Computer certificate

21. Your network contains an Active Directory domain named contoso.com. All
domain controllers run Windows Server 2012. You pre-create a read-only domain
controller (P.QDC) account named RODC1. You export the settings of RODC1 to a
file named File1.txt. You need to promote RODC1 by using File1.txt. Which tool
should you use?

A. The Dcpromo command


B. The Install-WindowsFeature cmdlet
C. The Install-ADDSDomainController cmdlet
D. The Add-WindowsFeature cmdlet
E. The Dism command

22. You need to stop an application from running in Task Manager. Which tab
would you use to stop an application from running?
A. Performance
B. Users
C. Options
D. Details

23. Your network contains servers that run Windows Server 2012 R2. The network
contains a large number of iSCSI storage locations and iSCSI clients. You need to
deploy a central repository that can discover and list iSCSI resources on the
network automatically. Which feature should you deploy?

A. the Windows Standards-Based Storage Management feature


B. the iSCSI Target Server role service
C. the iSCSI Target Storage Provider feature
D. the iSNS Server service feature

24. You have a file server named FS1 that runs Windows Server 8. Data
Deduplication is enabled on FS1. You need to configure Data Deduplication to run
at a normal priority from 20:00 to 06:00 daily. What should you configure?

A. File and Storage Services in Server Manager.


B. The Data Deduplication process in Task Manager.
C. Disk Management in Computer Management.
D. The properties of drive C.

25. Your network contains two Active Directory forests named contoso.com and
fabrikam.com. The contoso.com forest contains two domains named
corp.contoso.com and contoso.com. You establish a two-way forest trust
between contoso.com and fabrikam.com. Users from the corp.contoso.com
domain report that they cannot log on to client computers in the fabrikam.com
domain by using their corp.contoso.com user account. When they try to log on,
they receive following error message:
The computer you are signing into is protected by an authentication firewall. The
specified account is not allowed to authenticate to the computer.
Corp.contoso.com users can log on successfully to client computers in the
contoso.com domain by using their corp.contoso.com user account credentials.
You need to allow users from the corp.contoso.com domain to log on to the client
computers in the fabrikam.com forest. What should you do?

A. Configure Windows Firewall with Advanced Security.


B. Enable SID history.
C. Configure forest-wide authentication.
D. Instruct the users to log on by using a user principal name (UPN).

26.Your network contains two Active Directory forests named contoso.com and
adatum.com. Both forests contain multiple domains. All domain controllers run
Windows Server 2012 R2. Contoso.com has a one-way forest trust to
adatum.com. A domain named paris.eu.contoso.com hosts several legacy
App1ications that use NTLM authentication. Users in a domain named
ondon.europe.adatum.com report that it takes a long time to be authenticated
when they attempt to access the legacy App1ications hosted in
paris.eu.contoso.com. You need to reduce how long it takes for the
london.europe.adatum.com users to be authenticated in
paris.eu.contoso.com. What should you do?

A. Create a shortcut trust.


B. Create an external trust between the forest root domains.
C. Disable SID filtering on the existing trust.
D. Create an external trust.

27.Your network contains an Active Directory domain named contoso.com. All


servers run Windows
Server 2012 R2. You are creating a central access rule named TestFinance that will
be used to audit members of the Authenticated Users group for access failure to
shared folders in the finance department. You need to ensure that access
requests are unaffected when the rule is published. What should you do?
A. Add a User condition to the current permissions entry for the Authenticated
Users principal.
B. Set the Permissions to Use the following permissions as proposed permissions.
C. Add a Resource condition to the current permissions entry for the
Authenticated Users
principal.
D. Set the Permissions to Use following permissions as current permissions.

28.You have a server named Server1 that runs a Server Core Installation of
Windows Server 2012 R2.
Shadows copies are enabled on all volumes. You need to delete a specific shadow
copy. The solution must minimize server downtime. Which tool should you use?
A. Vssadmin
B. Diskpart
C. Wbadmin
D. Shadow

29.Your company recently deployed a new Active Directory forest named


contoso.com. The forest contains two Active Directory sites named Site1 and
Site2. The first domain controller in the forest runs Windows Server 2012 R2. You
need to force the replication of the SYSVOL folder from Site1 to Site2. Which tool
should you use?

A. Active Directory Sites and Services


B. DFS Management
C. Repadmin
D. Dfsrdiag

30. Your network contains an Active Directory forest named contoso.com. The
forest contains a single domain. The forest functional level is Windows Server
2012 R2. You have a domain controller named DC1. On DC1, you create a new
Group Policy object (GPO) named GPO1. You need to verify that GPO1 was
replicated to all of the domain controllers. Which tool should you
use?

A. Group Policy Management


B. Active Directory Sites and Services
C. DFS Management
D. Active Directory Administrative Center

You might also like