The 70-412 Exam Practice Questions and Answers are ideal for the aspring candiates to grab exceptional grades in Microsoft 70-412 Exam! The 70-412 Questions and Answers are developed using the latest updated course content and all the answers are verified to ensure phenoment preparation for the actual 70-412 Exam!
Vendor: Microsoft
Exam Code: 70-412
Exam Name: Configuring Advanced Windows Server 2012 R2 Services
QUESTION 316
Which security groups must a user account be a member of to modify the AD RMS SCP? (Choose two answers. Each answer forms part of a complete solution.)
A. Domain Admins
B. AD RMS Enterprise Administrators
C. Enterprise Admins
D. Cryptographic Operators.
Answer: BC
QUESTION 317
Which of the following would you configure if you wanted to block computers running Windows 7 and earlier operating systems from consuming AD RMS-protected content?
A. Trusted publishing domain
B. Trusted user domain
C. Exclusion policies
D. Super Users
Answer: C
QUESTION 318
Which of the following must you back up or have a copy of to be able to ensure that you can restore an AD RMS cluster in the event that a single server hosting all AD RMS components suffers complete data loss? (Choose three answers.)
A. Cluster key password
B. Trusted publishing domain
C. Trusted user domain
D. AD RMS databases
Answer: ABD
QUESTION 319
You want to enable key archiving on a CA.
You need to issue a certificate from a specific template to the user who will recover private keys. Which certificate template will you use as the basis for this certificate?
A. Kerberos authentication
B. Code signing
C. OCSP response signing
D. Key recovery agent
Answer: D
QUESTION 320
Which group policy item should you configure to enable automatic reenrollment of certificates?
A. Certificate Path Validation Settings
B. Certificate Services Client – Certificate Enrollment Policy
C. Certificate Services Client – Auto-Enrollment
D. Trusted Root Certification Authorities
Answer: C
QUESTION 321
You need to ensure that clients will check at least every 30 minutes as to whether a certificate has been revoked. Which of the following should you configure to accomplish this goal?
A. Key recovery agent
B. CRL publication interval
C. Delta CRL publication interval
D. Certificate templates.
Answer: C
QUESTION 322
Which of the following revocation statuses can you change to alter the status of a certificate from revoked to valid?
A. Certificate Hold
B. CA Compromise
C. Key Compromise
D. Change Of Affiliation
Answer: A
QUESTION 323
Which of the following CA types would you deploy if you wanted to deploy a CA at the top of a hierarchy that could issue signing certificates to other CAs and which would be taken offline if not issuing, renewing, or revoking signing certificates?
A. Enterprise root
B. Enterprise subordinate
C. Standalone root
D. Standalone subordinate
Answer: C
QUESTION 324
Which of the following CA types must be deployed on domain-joined computers?
A. Enterprise root
B. Enterprise subordinate
C. Standalone root
D. Standalone subordinate
Answer: AB
QUESTION 325
Which permission should you assign on a CA to a group of users that you want to be able to respond to certificate requests but you do not want to provide them with the ability to change CA security settings?
A. Read
B. Issue And Manage Certificates
C. Manage CA
D. Request Certificates
Answer: B
QUESTION 326
Which permission should you assign on a CA to a group of users that you want to allow to alter the list of recovery agents?
A. Read
B. Issue And Manage Certificates
C. Manage CA
D. Request Certificates.
Answer: C
QUESTION 327
You are configuring AD FS. Which server should you deploy on your organization’s perimeter network?
A. Web appplication proxy
B. Relying-party server
C. Federation server
D. Claims-provider server
Answer: A
QUESTION 328
The Wingtip Toys forest hosts a web application that users in the Tailspin Toys forest need to access. You are the system administrator at Tailspin Toys. A single federation server is present in each forest and you are configuring a federated trust.
Which of the following statements are true about the deployment solution? (Choose all that apply.)
A. The AD FS server in the Wingtip Toys forest will function as the claims-provider server.
B. The AD FS server in the Wingtip Toys forest will function as the relying-party server.
C. You need to configure a relying-party trust on the AD FS server in the Tailspin Toys forest.
D. You need to configure a claims-provider trust on the AD FS server in the Tailspin Toys forest.
Answer: BC
QUESTION 330
The Wingtip Toys forest hosts a web application that users in the Tailspin Toys forest need to access. You are the system administrator at Wingtip Toys. A single federation server is present in each forest and you are configuring a federated trust.
Which of the following statements are true about the deployment solution? (Choose all that apply.)
A. The AD FS server in the Tailspin Toys forest will function as the claims-provider server.
B. The AD FS server in the Tailspin Toys forest will function as the relying-party server.
C. Configure a relying-party trust on the Wingtip Toys AD FS server.
D. Configure a claims-provider trust on the Wingtip Toys AD FS server.
Answer: AD
Braindump2go New Released 70-412 Dumps PDF are Now For Free Download, 346 Latest Questions, Download It Right Now and Pass Your Exam 100%: