Question 1:

Your network contains an Active Directory domain named contoso.com. The domain contains a member server named Server1. Server1 runs Windows Server 2012 R2 and has the Hyper-V server role installed.

Server1 hosts 10 virtual machines. A virtual machine named VM1 runs Windows Server 2012 R2 and hosts a processor-intensive application named App1.

Users report that App1 responds more slowly than expected.

You need to monitor the processor usage on VM1 to identify whether changes must be made to the hardware settings of VM1.

Which performance object should you monitor on Server1?

A. Processor

B. Hyper-V Hypervisor Virtual Processor

C. Hyper-V Hypervisor Logical Processor

D. Hyper-V Hypervisor Root Virtual Processor

E. Process

Correct Answer: C

In the simplest way of thinking the virtual processor time is cycled across the available logical processors in a round-robin type of fashion. Thus all the processing power gets used over time, and technically nothing ever sits idle. To accurately measure the processor utilization of a guest operating system, use the “\Hyper-V Hypervisor Logical Processor (Total)\% Total Run Time” performance monitor counter on the Hyper-V host operating system.

Question 2:

You have a server named Server1 that runs Windows Server 2012 R2.

You create a custom Data Collector Set (DCS) named DCS1.

You need to configure Server1 to start DCS1 automatically when the network usage exceeds 70 percent.

Which type of data collector should you create?

A. A performance counter alert

B. A configuration data collector

C. A performance counter data collector

D. An event trace data collector

Correct Answer: A

Performance alerts notify you when a specified performance counter exceeds your configured threshold by logging an event to the event log. But rather than notifying you immediately when the counter exceeds the threshold, you can configure a time period over which the counter needs to exceed the threshold, to avoid unnecessary alerts.

Question 3:

Your network contains a domain controller named DC1 that runs Windows Server 2012 R2. You create a custom Data Collector Set (DCS) named DCS1.

You need to configure DCS1 to collect the following information:

The amount of Active Directory data replicated between DC1 and the other domain controllers

The current values of several registry settings

Which two should you configure in DCS1? (Each correct answer presents part of the solution. Choose two.)

A. Event trace data

B. A Performance Counter Alert

C. System configuration information

D. A performance counter

Correct Answer: BC

Automatically run a program when the amount of total free disk space on Server1 drops below 10 percent of capacity.

You can also configure alerts to start applications and performance logs

Log the current values of several registry settings.

System configuration information allows you to record the state of, and changes to, registry keys.

Total free disk space

Registry settings

Run a program on alert

Reference: http://technet.microsoft.com/en-us/library/cc766404.aspx

Question 4:

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 P.2.

Server1 has the Network Policy and Access Services server role installed.

Your company\’s security policy requires that certificate-based authentication must be used by some network services.

You need to identify which Network Policy Server (NPS) authentication methods comply with the security policy.

Which two authentication methods should you identify? (Each correct answer presents part of the solution.

Choose two.)



C. Chap



Correct Answer: BD

PEAP is similar in design to EAP-TTLS, requiring only a server-side PKI certificate to create a secure TLS tunnel to protect user authentication, and uses server- side public key certificates to authenticate the server. When you use EAP with a strong EAP type, such as TLS with smart cards or TLS with certificates, both the client and the server use certificates to verify their identities to each other.

Question 5:

Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2.

All sales users have laptop computers that run Windows 8. The sales computers are joined to the domain. All user accounts for the sales department are in an organizational unit (OU) named Sales_OU.

A Group Policy object (GPO) named GPO1 is linked to Sales_OU.

You need to configure a dial-up connection for all of the sales users.

What should you configure from User Configuration in GPO1?

A. Policies/Administrative Templates/Network/Windows Connect Now

B. Preferences/Control Panel Settings/Network Options

C. Policies/Administrative Templates/Windows Components/Windows Mobility Center

D. Policies/Administrative Templates/Network/Network Connections

Correct Answer: B

The Network Options extension allows you to centrally create, modify, and delete dial-up networking and virtual private network (VPN) connections. Before you create a network option preference item, you should review the behavior of each type of action possible with the extension.

To create a new Dial-Up Connection preference item

Open the Group Policy Management Console. Right-click the Group Policy object (GPO) that should contain the new preference item, and then click Edit. In the console tree under Computer Configuration or User Configuration, expand the

Preferences folder, and then expand the Control Panel Settings folder.

Right-click the Network Options node, point to New, and select Dial-Up Connection.





Question 6:

You have a server named Server1 that runs Windows Server 2012 R2. Server1 has the Windows Server Update Services server role installed. You need to configure Windows Server Update Services (WSUS) to support Secure Sockets Layer (SSL).

Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

A. From Internet Information Services (IIS) Manager, modify the connection strings of the WSUS website.

B. Install a server certificate.

C. Run the wsusutil.exe command.

D. Run the iisreset.exe command.

E. From Internet Information Services (IIS) Manager, modify the bindings of the WSUS website.

Correct Answer: BCE

Certificate needs to be installed to IIS, Bindings modifies and wsusutil run.


First we need to request a certificate for the WSUS web site, so open IIS, click the server name, then open Server Certificates.

On the Actions pane click Create Domain Certificate.


To add the signing certificate to the WSUS Web site in IIS 7.0

On the WSUS server, open Internet Information Services (IIS) Manager.

Expand Sites, right-click the WSUS Web site, and then click Edit Bindings.

In the Site Binding dialog box, select the https binding, and click Edit to open the Edit Site Binding dialog box.

Select the appropriate Web server certificate in the SSL certificate box, and then click OK.

Click Close to exit the Site Bindings dialog box, and then click OK to close Internet Information Services (IIS) Manager.


WSUSUtil.exe configuressl (the name in your certificate)

WSUSUtil.exe configuressl.


The next step is to point your clients to the correct url, by modifying the existing GPO or creating a new one. Open the policy Specify intranet Microsoft update service location and type the new url in the form https:


The gpupdate /force command will just download all the GPO\’s and re-apply them to the client, it won\’t force the client to check for updates. For that you need to use wuauclt /resetautorization /detectnow followed by wuauclt /reportnow

References: http://technet.microsoft.com/en-us/library/bb680861.aspx http://technet.microsoft.com/en-us/library/bb633246.aspx http://www.vkernel.ro/blog/configure-wsus-to-use-ssl

Question 7:

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2012 R2.

You mount an Active Directory snapshot on DC1.

You need to expose the snapshot as an LDAP server.

Which tool should you use?

A. Ldp

B. ADSI Edit

C. Dsamain

D. Ntdsutil

Correct Answer: C

dsamain /dbpath E:\$SNAP_200704181137_VOLUMED$\WINDOWS\NTDS\ntds. dit /ldapport51389

Reference: http://technet.microsoft.com/en-us/library/cc753609(v=ws.10).aspx

Question 8:

Your company has a main office and a branch office.

The main office contains a server that hosts a Distributed File System (DFS) replicated folder.

You plan to implement a new DFS server in the branch office.

You need to recommend a solution that minimizes the amount of network bandwidth used to perform the initial synchronization of the folder to the branch office.

You recommend using the Export-DfsrClone and Import-DfsrClonecmdlets.

Which additional command or cmdlet should you include in the recommendation?

A. Robocopy.exe

B. Synchost.exe

C. Export-BcCachePackage

D. Sync-DfsReplicationGroup

Correct Answer: A

By preseeding files before you set up DFS Replication, add a new replication partner, or replace a server, you can speed up initial synchronization and enable cloning of the DFS Replication database in Windows Server 2012 R2. The Robocopy method is one of several preceding methods

Question 9:

Your network contains on Active Directory domain named contoso.com. The domain contains an organizational unit (OU) named AIIServers_OU.

You create and link a Group Policy object (GPO) named GPO1 to AIIServer_OU. GPO1 is configured as shown in the exhibit. (Click the Exhibit button.)

You need to ensure that GPO1 only applies to servers that have Remote Desktop Services (RDS) installed What should you configure?

A. Item-level targeting

B. Block Inheritance

C. Security Filtering

D. WMI Filtering

Correct Answer: D

If you need to configure a Remote Desktop Server farm and need to setup some group policies that only applied to computers that are Remote Desktop Servers, there are a couple of obvious ways you could achieve this.

1) You could put your Remote Desktop Servers in a specific Organisational Unit and link your Group Policies there

2) You could create a WMI Filter to filter by name i.e.

SELECT * FROM Win32_ComputerSystem WHERE ((Name = `RDSERVER01\’) OR (Name = `RDSERVER02\’))

If you don\’t want to have to update the WMI Filter if you need to add more Remote Desktop Servers, you can use the following WMI Filter against the rootCIMV2TerminalServices Namespace:

Select * From Win32_TerminalServiceSetting Where TerminalServerMode=1



Question 10:

Your network contains an Active Directory domain named contoso.com. The domain contains three

servers named Server2, Server3, and Server4.

Server2 and Server4 host a Distributed File System (DFS) namespace named Namespace1.

You open the DFS Management console as shown in the exhibit. (Click the Exhibit button.)

To answer, complete each statement according to the information presented in the exhibit. Each correct selection is worth one point.

Hot Area:

Correct Answer:

Author: CertBus