Microsoft 70-410: Installing and Configuring Windows Server 2012 — Questions and Answers
Question 1: According to Microsoft best practices, what should an administrator do before applying a cumulative update to a production Windows Server 2012 R2 domain controller?
- Apply the update to all domain controllers simultaneously to maintain consistency
- Apply the update directly during business hours for maximum staff availability
- Test the update in a non-production environment and take a system state backup (Correct answer)
- Disable antivirus before patching and re-enable afterward
Correct answer: Test the update in a non-production environment and take a system state backup
Best practices require testing updates in a non-production environment and performing a system state backup before applying changes to production domain controllers.
Question 2: In Windows Server 2012, which NTFS feature allows a large file to be compressed but still appears at its original size to applications?
- Sparse Files
- Quotas
- NTFS Encryption (EFS)
- NTFS Compression (Correct answer)
Correct answer: NTFS Compression
NTFS Compression transparently compresses files on disk while presenting them at their original size to applications, saving disk space without requiring application changes.
Question 3: NERC CIP standards require physical and logical access controls for critical infrastructure. Which Active Directory feature in Windows Server 2012 helps restrict which computers privileged accounts can log on to?
- DNS conditional forwarders
- DHCP reservations
- Account tab 'Log On To' restrictions in AD user properties (Correct answer)
- Password Policy settings
Correct answer: Account tab 'Log On To' restrictions in AD user properties
The 'Log On To' setting in an AD user account restricts which workstations or servers that account can authenticate to.
Question 4: You need to ensure a Windows Server 2012 role service starts automatically after a reboot. Which command sets the service startup type to Automatic?
- Set-Service -Name <name> -StartupType Auto (Correct answer)
- Start-Service -Name <name> -Auto
- Enable-Service -Name <name>
- sc config <name> start= demand
Correct answer: Set-Service -Name <name> -StartupType Auto
Set-Service with the -StartupType parameter set to Automatic configures a service to start automatically at boot.
Question 5: A department head requests real-time visibility into server uptime for their business-critical application hosted on Windows Server 2012. What should the administrator propose?
- Email the stakeholder a weekly uptime report
- Set up a monitoring dashboard using Windows Server's Performance Monitor or a third-party tool and share access with the stakeholder (Correct answer)
- Install a second server as a visual uptime indicator
- Give the stakeholder remote desktop access to the server
Correct answer: Set up a monitoring dashboard using Windows Server's Performance Monitor or a third-party tool and share access with the stakeholder
A shared monitoring dashboard gives stakeholders self-service visibility into uptime without requiring IT involvement for each status check.
Question 6: Which Windows Server 2012 logging mechanism should be configured to capture verbose DNS query logs for quality assurance of name resolution?
- Enable DNS Debug Logging in DNS Manager (Correct answer)
- Enable DHCP audit logging
- Enable NetLogon debug logging
- Enable Windows Firewall verbose logging
Correct answer: Enable DNS Debug Logging in DNS Manager
DNS Debug Logging in DNS Manager records incoming and outgoing DNS queries, responses, and errors to a log file for analysis.
Question 7: A company accepts a risk because the cost of mitigation exceeds the potential loss. Which risk response strategy is being used?
- Risk mitigation
- Risk acceptance (Correct answer)
- Risk transference
- Risk avoidance
Correct answer: Risk acceptance
Risk acceptance means acknowledging a risk and choosing not to act when mitigation costs outweigh potential losses.
Question 8: A Hyper-V virtual machine needs to use more than 4 processors and boot from a virtual hard disk larger than 2TB. Which generation and disk format should be configured?
- Generation 1 VM with VHD disk
- Generation 1 VM with VHDX disk
- Generation 2 VM with VHD disk
- Generation 2 VM with VHDX disk (Correct answer)
Correct answer: Generation 2 VM with VHDX disk
Generation 2 VMs support more than 4 virtual processors and UEFI boot, while VHDX format supports disks larger than 2TB (up to 64TB).
Question 9: What DHCP object groups multiple scopes together to serve clients on a multineted physical network segment?
- Superscope (Correct answer)
- DHCP relay
- Multicast scope
- BOOTP integration
Correct answer: Superscope
A superscope groups multiple DHCP scopes, allowing a single server to manage addresses for multiple IP subnets on one physical segment.
Question 10: A Windows Server 2012 administrator wants to get approval to enable Remote Desktop access for a new team. Which justification is most persuasive to management?
- Request approval verbally without any written documentation
- Mention that competitors are already using Remote Desktop
- Quantify productivity gains and reduced travel costs, and explain the security controls that will be applied (Correct answer)
- Explain the RDP protocol technical architecture in detail
Correct answer: Quantify productivity gains and reduced travel costs, and explain the security controls that will be applied
Management approves IT requests more readily when they see a clear business benefit paired with a security assurance.
Question 11: Under NIST 800-171, CUI must be protected with FIPS 140-2 validated encryption. How do you enable FIPS compliance mode in Windows Server 2012?
- Enable the 'System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing' policy setting (Correct answer)
- Enable BitLocker without any additional policy change
- Change the registry key HKLM\System\CurrentControlSet\Services\LanManServer only
- Install an additional encryption driver from a third party
Correct answer: Enable the 'System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing' policy setting
The FIPS policy setting in Security Options forces Windows components to use only FIPS 140-2 validated cryptographic modules.
Question 12: Which Windows Server 2012 role service enables IP routing between network segments?
- Remote Access (Routing) (Correct answer)
- Network Policy Server
- DirectAccess
- DHCP Server
Correct answer: Remote Access (Routing)
The Routing role service within the Remote Access server role enables Windows Server 2012 to route IP packets between network segments.
Question 13: Which Windows Server 2012 feature caches frequently accessed files on local branch office servers or client PCs to reduce WAN traffic?
- DFS Replication
- Storage Spaces
- BranchCache (Correct answer)
- Offline Files
Correct answer: BranchCache
BranchCache caches content from headquarters servers at branch office locations (either on a hosted cache server or distributed among PCs), reducing WAN bandwidth consumption.
Question 14: Your organization must comply with HIPAA. Which Windows Server 2012 feature best helps enforce data encryption for Protected Health Information (PHI) stored on disk?
- Encrypting File System (EFS)
- NTFS permissions
- Windows Firewall with Advanced Security
- BitLocker Drive Encryption (Correct answer)
Correct answer: BitLocker Drive Encryption
BitLocker Drive Encryption provides full-volume encryption, protecting PHI on disk even if the physical drive is removed.
Question 15: A vendor is coming on-site to upgrade a Windows Server 2012 host. Which communication step is essential before granting the vendor access?
- Obtain internal approval, verify the vendor's identity, and brief them on site security and acceptable use policies (Correct answer)
- Give the vendor full administrator credentials in advance
- Have the vendor work unsupervised overnight to minimize disruption
- Allow the vendor to begin work immediately upon arrival
Correct answer: Obtain internal approval, verify the vendor's identity, and brief them on site security and acceptable use policies
Third-party access to servers requires authorization, identity verification, and policy briefing to maintain security and compliance.
Question 16: Which Windows Server 2012 tool generates a detailed report of a server's hardware and software inventory for quality documentation purposes?
- Resource Monitor
- System Information (msinfo32) (Correct answer)
- Reliability Monitor
- Performance Monitor
Correct answer: System Information (msinfo32)
System Information (msinfo32) provides a comprehensive snapshot of hardware resources, components, and software environment.
Question 17: Which Windows Server 2012 tool can generate a security baseline report comparing current settings against a known-good configuration to identify risk deviations?
- Disk Management Console
- Performance Monitor (PerfMon)
- Resource Monitor
- Microsoft Baseline Security Analyzer (MBSA) (Correct answer)
Correct answer: Microsoft Baseline Security Analyzer (MBSA)
Microsoft Baseline Security Analyzer scans for missing patches and misconfigurations by comparing settings against Microsoft security baselines.
Question 18: During a Windows Server 2012 domain controller promotion, which stakeholder should sign off on the change before it is implemented in production?
- Only the server administrator performing the work
- The end-user help desk team
- The internet service provider
- The change advisory board (CAB) or designated change manager (Correct answer)
Correct answer: The change advisory board (CAB) or designated change manager
Promoting a domain controller is a significant infrastructure change that requires formal change management approval before production implementation.
Question 19: Which Windows Server 2012 audit policy category should be enabled to detect unauthorized privilege escalation attempts?
- Policy Change
- Object Access
- Account Management
- Privilege Use (Correct answer)
Correct answer: Privilege Use
The Privilege Use audit category tracks when users exercise sensitive privileges, helping detect escalation attempts.
Question 20: Which DNS record type maps a hostname to an IPv6 address?
- AAAA (Correct answer)
- A
- PTR
- CNAME
Correct answer: AAAA
The AAAA (quad-A) record maps a fully qualified domain name to a 128-bit IPv6 address.
Question 21: When implementing the principle of least privilege on Windows Server 2012, what is the correct approach for administrative accounts?
- Disable UAC to allow administrators unrestricted access at all times
- Use a single shared administrator account for all admins to simplify auditing
- Use separate standard and privileged accounts; only elevate when necessary (Correct answer)
- Give all users Domain Admin rights to prevent access issues
Correct answer: Use separate standard and privileged accounts; only elevate when necessary
The principle of least privilege requires administrators to use standard accounts for daily tasks and only use elevated privileged accounts when administrative tasks require it.
Question 22: A PCI DSS requirement mandates that a unique ID be assigned to each person with computer access. How is this enforced in Windows Server 2012 Active Directory?
- By enabling anonymous access on all services
- By sharing a single service account among all staff
- By using a single local Administrator account
- By creating individual user accounts in AD with no shared credentials (Correct answer)
Correct answer: By creating individual user accounts in AD with no shared credentials
Individual AD user accounts provide unique identifiers and enable per-user accountability required by PCI DSS requirement 8.
Question 23: An administrator is preparing a Windows Server 2012 disaster recovery plan. Which stakeholder group is most critical to involve during the planning phase?
- Only the backup software vendor
- The physical facilities team only
- Junior IT technicians who will perform the recovery
- Business unit owners who can define recovery time objectives (RTO) and recovery point objectives (RPO) for their applications (Correct answer)
Correct answer: Business unit owners who can define recovery time objectives (RTO) and recovery point objectives (RPO) for their applications
Business unit owners define how quickly and to what point systems must be recovered, which drives all technical disaster recovery decisions.
Question 24: A server running Windows Server 2012 must host both a web application and a file server role. After adding the File Services role, web performance degrades. What is the MOST likely cause?
- File Services requires exclusive use of port 80
- IIS cannot run alongside File Services on the same server
- The Web Server role was uninstalled automatically
- SMB traffic is competing with HTTP traffic on the same NIC (Correct answer)
Correct answer: SMB traffic is competing with HTTP traffic on the same NIC
SMB and HTTP traffic sharing a single network adapter causes resource contention, degrading web performance; NIC teaming or separate NICs resolves this.
Question 25: Which type of trust is automatically created when a child domain is added to an existing Active Directory forest?
- Forest trust
- Shortcut trust
- Parent-child trust (Correct answer)
- External trust
Correct answer: Parent-child trust
Parent-child trusts are automatically created as two-way transitive trusts when a new child domain is added within an existing domain tree.
Question 26: What role does data analytics play in Installing and Configuring Windows Server 2012 Exam practice?
- It is only for IT professionals
- It supports evidence-based decision making by identifying patterns and trends in relevant data (Correct answer)
- It replaces professional judgment
- It creates unnecessary complexity
Correct answer: It supports evidence-based decision making by identifying patterns and trends in relevant data
This is fundamental to Installing and Configuring Windows Server 2012 Exam practice. It supports evidence-based decision making by identifying patterns and trends in relevant data represents the professional standard for technology in the Installing and Configuring Windows Server 2012 Exam certification framework.
Question 27: What is the benefit of interdisciplinary collaboration in Installing and Configuring Windows Server 2012 Exam practice?
- It is only for complex projects
- It slows down decision making
- It creates confusion
- It brings diverse expertise and perspectives that improve outcomes and innovation (Correct answer)
Correct answer: It brings diverse expertise and perspectives that improve outcomes and innovation
This is fundamental to Installing and Configuring Windows Server 2012 Exam practice. It brings diverse expertise and perspectives that improve outcomes and innovation represents the professional standard for practical in the Installing and Configuring Windows Server 2012 Exam certification framework.
Question 28: A Windows Server 2012 WSUS server shows that approved updates are not installing on client computers. Clients show 'No updates available' in Windows Update. What should the administrator check first?
- Whether the Group Policy pointing clients to the WSUS server URL is applied (Correct answer)
- Whether the WSUS console shows updates as approved
- Whether the WSUS server has sufficient disk space
- Whether the Windows Update service is set to Automatic on clients
Correct answer: Whether the Group Policy pointing clients to the WSUS server URL is applied
Clients must receive the correct WSUS server URL via Group Policy; without this setting, clients default to Microsoft Update and will not see WSUS-approved updates.
Question 29: What is Hyper-V Replica in Windows Server 2012?
- An asynchronous VM replication feature that copies VMs to a secondary site for disaster recovery (Correct answer)
- A feature that synchronizes snapshots between two VMs
- A feature that clones virtual machines within the same host
- A load balancing mechanism that distributes VM workloads
Correct answer: An asynchronous VM replication feature that copies VMs to a secondary site for disaster recovery
Hyper-V Replica asynchronously replicates virtual machines to a secondary Hyper-V host or site for disaster recovery without requiring shared storage.
Question 30: Which Windows Server 2012 feature allows administrators to enforce least privilege by granting temporary elevated access only when needed, reducing standing risk?
- Managed Service Accounts
- User Account Control (UAC) (Correct answer)
- Protected Users security group
- Just Enough Administration (JEA)
Correct answer: User Account Control (UAC)
User Account Control prompts for elevation only when needed, enforcing least privilege and reducing the risk of persistent elevated sessions.
Question 31: How should an Installing and Configuring Windows Server 2012 Exam professional handle a situation outside their scope of competency?
- Decline all unfamiliar work
- Attempt it anyway
- Recognize limitations and refer to or consult with appropriate specialists (Correct answer)
- Ignore the situation
Correct answer: Recognize limitations and refer to or consult with appropriate specialists
This is fundamental to Installing and Configuring Windows Server 2012 Exam practice. Recognize limitations and refer to or consult with appropriate specialists represents the professional standard for professional standards in the Installing and Configuring Windows Server 2012 Exam certification framework.
Question 32: You need to delegate control of an Organizational Unit (OU) to a department manager without giving them full Domain Admin rights. Which tool should you use?
- Active Directory Users and Computers Delegation of Control Wizard (Correct answer)
- Group Policy Management Console
- DNS Manager
- Active Directory Sites and Services
Correct answer: Active Directory Users and Computers Delegation of Control Wizard
The Delegation of Control Wizard in ADUC lets you grant specific administrative permissions over an OU to designated users or groups.
Question 33: Research on Windows Server 2012 certificate services recommends which CA hierarchy for an enterprise with high security requirements?
- No internal CA, use only public certificates
- Two-tier hierarchy with an offline root CA
- Three-tier hierarchy with an offline root CA (Correct answer)
- Single-tier hierarchy with an online root CA
Correct answer: Three-tier hierarchy with an offline root CA
A three-tier hierarchy with an offline root CA and offline policy CA provides the highest assurance level, recommended by security research for high-security environments.
Question 34: A Windows Server 2012 administrator wants to configure a DHCP server to always assign the same IP address to a specific client. Which DHCP feature should be used?
- DHCP Exclusion
- Static IP on the client
- DHCP Reservation (Correct answer)
- DHCP Scope Option
Correct answer: DHCP Reservation
A DHCP reservation binds a specific IP address to a client's MAC address so that client always receives the same address.
Question 35: Which Windows Server 2012 resiliency option in Storage Spaces requires a minimum of 5 disks and provides both striping and parity?
- Parity (Correct answer)
- Three-way mirror
- Simple (no resiliency)
- Two-way mirror
Correct answer: Parity
The Parity resiliency type in Storage Spaces stripes data with parity information across disks, typically requiring at least 3 disks, and provides fault tolerance while conserving space compared to mirroring.
Question 36: Which Windows Server 2012 feature enables administrators to manage servers remotely using a graphical interface from a single console?
- Server Manager (Correct answer)
- Remote Desktop Services
- Windows Admin Center
- Remote Assistance
Correct answer: Server Manager
Server Manager in Windows Server 2012 allows centralized management of multiple remote servers from one console.
Question 37: A Windows Server 2012 server hosts a critical application that must survive hardware failure. The administrator wants automatic failover with no manual intervention. Which clustering feature should be implemented?
- DFS Replication with manual promotion
- Network Load Balancing
- Hyper-V replication only
- Failover Clustering with Always-On (Correct answer)
Correct answer: Failover Clustering with Always-On
Failover Clustering automatically moves resources and applications to surviving nodes when a node fails, with no administrator intervention required.
Question 38: What distinguishes a peer-reviewed study in Installing and Configuring Windows Server 2012 Exam literature?
- It was published quickly
- It was published in any format
- Independent experts in the field evaluated the methodology and conclusions before publication (Correct answer)
- It was written by multiple authors
Correct answer: Independent experts in the field evaluated the methodology and conclusions before publication
This is fundamental to Installing and Configuring Windows Server 2012 Exam practice. Independent experts in the field evaluated the methodology and conclusions before publication represents the professional standard for research in the Installing and Configuring Windows Server 2012 Exam certification framework.
Question 39: Research on Windows Server 2012 Remote Desktop Services recommends which licensing mode for devices that are always the same physical machine?
- External Connector License
- Per Device CAL (Correct answer)
- Trial mode
- Per User CAL
Correct answer: Per Device CAL
Per Device CALs are cost-effective when a fixed number of devices access RDS, regardless of how many users share each device, per Microsoft licensing research.
Question 40: What is a compliance management system in Installing and Configuring Windows Server 2012 Exam practice?
- A structured framework of policies, procedures, and controls that ensure regulatory adherence (Correct answer)
- A software application only
- A government reporting requirement
- An optional business tool
Correct answer: A structured framework of policies, procedures, and controls that ensure regulatory adherence
This is fundamental to Installing and Configuring Windows Server 2012 Exam practice. A structured framework of policies, procedures, and controls that ensure regulatory adherence represents the professional standard for regulatory in the Installing and Configuring Windows Server 2012 Exam certification framework.
Question 41: A Windows Server 2012 administrator needs to maintain accurate asset inventory for licensing compliance. Which built-in capability can report installed roles, features, and software?
- Control Panel's Display settings
- Server Manager's All Servers view and PowerShell Get-WindowsFeature (Correct answer)
- Task Manager processes list
- Notepad manual logging
Correct answer: Server Manager's All Servers view and PowerShell Get-WindowsFeature
Server Manager provides a centralized view of installed roles and features across managed servers, and Get-WindowsFeature cmdlet can programmatically enumerate installed components for inventory purposes.
Question 42: FERPA requires protecting student education records. A Windows Server 2012 administrator should configure which setting to prevent unauthorized users from viewing sensitive shared folders?
- Apply NTFS permissions and Share permissions following least privilege (Correct answer)
- Disable auditing to reduce overhead
- Enable the Guest account on file servers
- Store data in the Public share
Correct answer: Apply NTFS permissions and Share permissions following least privilege
Combining restrictive NTFS and Share permissions with least privilege ensures only authorized users access student records.
Question 43: Where are new user accounts created by default in Active Directory if no OU is specified?
- Users container (Correct answer)
- Built-in container
- Computers container
- Domain root
Correct answer: Users container
New user accounts created without specifying an OU are placed in the default Users container, which is not an OU and cannot have GPOs linked directly to it.
Question 44: After deploying Windows Server Update Services (WSUS) on Windows Server 2012, the administrator needs to communicate the patching schedule to application owners. What detail is most critical to include?
- The Windows Update Agent version installed on clients
- The WSUS server's internal IP address and port
- The full list of KB article numbers in the update batch
- The patch deployment day and time, expected reboot behavior, and the process to request a deferral for business-critical systems (Correct answer)
Correct answer: The patch deployment day and time, expected reboot behavior, and the process to request a deferral for business-critical systems
Application owners need to know when reboots will occur and how to defer patching for systems that cannot tolerate unplanned restarts.
Question 45: An administrator is performing a qualitative risk assessment. Which approach is most appropriate for this method?
- Using a probability and impact matrix with descriptive scales (Correct answer)
- Running Monte Carlo simulations on loss data
- Calculating exact financial figures for each risk
- Applying actuarial tables to predict risk frequency
Correct answer: Using a probability and impact matrix with descriptive scales
Qualitative risk assessment uses descriptive scales (low/medium/high) plotted on a probability and impact matrix rather than exact financial values.
Question 46: Which type of storage in Windows Server 2012 uses a pool of physical disks to provide resilient, flexible storage volumes?
- Storage Spaces (Correct answer)
- Dynamic Disks
- RAID-5 volumes
- Basic Disks
Correct answer: Storage Spaces
Storage Spaces allows you to group physical disks into a storage pool and create virtual disks with resiliency options like mirroring or parity.
Question 47: An administrator configures a Windows Server 2012 DNS server with a stub zone for contoso.com. What does a stub zone contain?
- Only SOA, NS, and A records (glue records) for the authoritative name servers of contoso.com (Correct answer)
- A full copy of all DNS records for contoso.com
- A list of forwarders for contoso.com queries
- Only the SOA record for contoso.com
Correct answer: Only SOA, NS, and A records (glue records) for the authoritative name servers of contoso.com
A stub zone contains only the SOA record, NS records, and necessary A records (glue) for the authoritative name servers of the delegated zone.
Question 48: Which Windows Server 2012 feature helps organizations identify and classify sensitive data to support risk management decisions?
- Network Policy Server (NPS)
- Dynamic Access Control (DAC) (Correct answer)
- Windows Firewall with Advanced Security
- BitLocker Drive Encryption
Correct answer: Dynamic Access Control (DAC)
Dynamic Access Control allows administrators to classify and label data, enabling risk-based access decisions.
Question 49: Windows Server 2012 R2 is installed on two servers in your network called Server1 and Server2. A workgroup consists of servers Server1 and Server2. <br> You establish a local user account called Admin1 and add it to the local Administrators group on Servers 1 and 2. Admin1 has the same password on both systems.<br> You sign in as Admin1 to Server1. You launch Computer Management and link up with Server2. <br> Access Denied alerts appears whenever you try to create a scheduled job, view the event logs, or manage shared folders. <br> You must make sure that using Computer Management, you may remotely manage Server2 from Server1. <br> What settings ought to be made on Server2?
- From Local Users and Groups, modify the membership of the Remote Management Users group
- From Server Manager, modify the Remote Management setting
- From Windows Firewall, modify the Windows Management Instrumentation (WMI) firewall rule
- From Registry Editor, configure the LocalAccountTokenFilterPolicy registry value.. (Correct answer)
Correct answer: From Registry Editor, configure the LocalAccountTokenFilterPolicy registry value..
Explanation: <br> Administrator credentials used for remote computer administration are affected by the LocalAccountTokenFilterPolicy setting.
Question 50: Which Windows Server 2012 feature allows an administrator to apply consistent security configurations across multiple servers using predefined templates?
- Security Configuration Wizard (SCW) (Correct answer)
- Local Security Policy
- Server Manager
- Windows Firewall with Advanced Security
Correct answer: Security Configuration Wizard (SCW)
The Security Configuration Wizard (SCW) allows administrators to create, edit, apply, and roll back security policies based on server roles, reducing the attack surface.
Microsoft 70-410: Installing and Configuring Windows Server 2012
The Microsoft 70-410 exam (MCSA: Windows Server 2012) validates skills in installing, configuring, and administering Windows Server 2012, covering server roles, Hyper-V virtualization, Active Directory, network services, and Group Policy.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds