It is more faster and easier to pass the Microsoft 70-410 exam by using Virtual Microsoft Installing and Configuring Windows Server 2012 questuins and answers. Immediate access to the Avant-garde 70-410 Exam and find the same core area 70-410 questions with professionally verified answers, then PASS your exam with a high score now.

♥♥ 2021 NEW RECOMMEND ♥♥

Free VCE & PDF File for Microsoft 70-410 Real Exam (Full Version!)

★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions

Free Instant Download NEW 70-410 Exam Dumps (PDF & VCE):
Available on:

2021 Apr 70-410 free draindumps

Q181. - (Topic 3) 

A company’s server security team needs a solution that will prevent users from installing and using unauthorized applications on their Windows 8 desktop computers. 

Which technology should the team choose? 

A. Starter GPOs 

B. Group Policy Objects 

C. Software Restriction Policies 

D. AppLocker 



AppLocker (Application Locker) can help prevent malicious (malware) and unsupported 

applications from affecting computers. These include executable files, scripts, Windows 

Installer files, DLLs, Packaged apps and Packaged app installers. 

Quick Tip: AppLocker is also supported by Windows Server 2008 R2 and Windows 7. 

Q182. HOTSPOT - (Topic 3) 

You have a server named Server1 that runs Windows Server 2012 R2. Server1 is a member of a workgroup. 

You need to ensure that only members of the Administrators group and members of a group named Group1 can log on locally to Server1. 

Which settings should you modify from the Local Security Policy? To answer, select the appropriate settings in the answer area. 


Q183. - (Topic 1) 

Your network contains an Active Directory forest. The forest functional level is Windows Server 2012 R2. The forest contains a single domain. The domain contains a member server named Server1. Server1 runs windows Server 2012 R2. 

You purchase a network scanner named Scanner1 that supports Web Services on Devices (WSD). 

You need to share the network scanner on Server1. 

Which server role should you install on Server1? 

A. Web Server (IIS) 

B. Fax Server 

C. Print and Document Services 

D. File and Storage Services 



The Print and Document Services role allows for the configuration to share printers, 

scanners and fax devices. 


Exam Ref 70-410: Installing and Configuring Windows Server 2012 R2, Chapter 1: 

Installing and Configuring servers, Objective 1.2: Configure servers, p. 8 

Q184. - (Topic 2) 

Your company has a main office and four branch offices. The main office contains a server named Server1 that runs Windows Server 2012 R2. 

The IP configuration of each office is configured as shown in the following table. 

You need to add a single static route on Server1 to ensure that Server1 can communicate with the hosts on all of the subnets. 

Which command should you run? 

A. route.exe add -p mask 

B. route.exe add -p mask 

C. route.exe add -p mask 

D. route.exe add -p mask 



These parameters will allow communication with all the hosts. 


Exam Ref: 70-410: Installing and Configuring Windows Server 2012 R2, Chapter4: 

Deploying and configuring core network services, Objective 4.1: Configure IPv4 and IPv6 

addressing, p.192, 196 

Q185. - (Topic 3) 

A company’s server deployment team needs to introduce many new Windows Server 2012 R2 domain controllers throughout the network into a single Windows Server 2008 R2 domain. The team has chosen to use Windows PowerShell. 

Which Windows PowerShell module includes the command-line options for installing domain controllers? 

A. AD DS Administration cmdlets 

B. AD DS Deployment cmdlets 

C. AD CS Deployment cmdlets 

D. AD CS Administration cmdlets 



First use the Import-Module ADDSDeployment command in PowerShell–it includes the cmdlets needed to add new domain controllers. Then run Install-ADDSDomainController along with the required arguments. Quick Tip: DCPromo.exe has been deprecated but can still be used along with an answer file, and ADPrep.exe runs automatically when needed (but can be run with elevated rights for more control). 

Regenerate 70-410 exam question:

Q186. - (Topic 3) 

You have a file server named Server1 that runs Windows Server 2012 R2. Server1 contains a folder named Folder1. 

You share Folder1 as Share1 by using Advanced Sharing. Access-based enumeration is 


Share1 contains an application named Appl.exe. 

You configure the NTFS permissions on Folder1 as shown in the following table. 

The members of Group2 report that they cannot make changes to the files in Share1. The 

members of Group1 and Group2 run Appl.exe successfully. 

You need to ensure that the members of Group2 can edit the files in Share1. 

What should you do? 

A. Replace the NTFS permissions on all of the child objects. 

B. Edit the Share permissions. 

C. Edit the NTFS permissions. 

D. Disable access-based enumeration. 



Share permissions and NTFS permissions are independent in the sense that neither changes the other. The final access permissions on a shared folder are determined by taking into consideration both the share permission and the NTFS permission entries. The more restrictive permissions are then applied. 

References: Training Guide: Installing and Configuring Windows Server 2012 R2: Chapter8: File Services and Storage, Lesson 2: Provisioning and Managing Shared Storage, p.388 

Q187. - (Topic 3) 

Your network contains an Active Directory domain named 

All user accounts in the marketing department reside in an organizational unit (OU) named OU1. 

You have a Group Policy object (GPO) named GPO1. GPO1 contains Folder Redirection settings. GPO1 has default permissions. 

You discover that the Folder Redirection settings are not applied to the users in the marketing department. 

You open Group Policy Management as shown in the exhibit. (Click the Exhibit button.) 

You need to ensure that the Folder Redirection settings in GPO1 apply to the marketing users. 

What should you do? 

A. Modify the Delegation settings of GPO1. 

B. Enable the link of GPO1. 

C. Enforce GPO1. 

D. Modify the link order of GPO1. 


Q188. - (Topic 3) 

Your network contains a domain controller that is configured as a DNS server. The server hosts an Active Directory-integrated zone for the domain. 

You need to reduce how long it takes until stale records are deleted from the zone. What should you do? 

A. From the configuration directory partition of the forest, modify the tombstone lifetime. 

B. From the configuration directory partition of the forest, modify the garbage collection interval. 

C. From the aging properties of the zone, modify the no-refresh interval and the refresh interval. 

D. From the start of authority (SOA) record of the zone, modify the refresh interval and the expire interval. 



Scavenging automates the deletion of old records. When scavenging is enabled, then you should also change the no-refresh and refresh intervals of the aging properties of the zone else it may take too long for stale records to be deleted and the size of the DNS database can become large and have an adverse effect on performance. 

Q189. HOTSPOT - (Topic 2) 

You have a server named DHCP1 that runs Windows Server 2012 R2. DHCP1 does not 

have access to the Internet. 

All roles are removed completely from DHCP1. 

You mount a Windows Server 2012 R2 installation image to the C:Mount folder. 

You need to install the DHCP Server server role on DHCP1 by using Server Manager. 

Which folder should you specify as the alternate path for the source files? 

To answer, select the appropriate folder in the answer area. 


Q190. - (Topic 3) 

Your network contains an Active Directory domain named The domain contains three domain controllers. 

The domain controllers are configured as shown in the following table. 

DC3 loses network connectivity due to a hardware failure. 

You plan to remove DC3 from the domain. 

You log on to DC3. 

You need to identify which service location (SRV) records are registered by DC3. 

What should you do? 

A. Open the %windir%system32confignetlogon.dns file. 

B. Run dcdiag /test:dns 

C. Open the file. 

D. Run ipconfig /displaydns. 



A. Netlogon service creates a log file that contains all the locator resource records and 

places the logfile in the following location: 

B. Analyzes the state of domain controllers in a forest or enterprise and reports any 

problems to help introubleshooting. 

C. dns backup file 

D. used to display current resolver cache content You can verify SRV locator resource 

records by viewing netlogon.dns, located in the %systemroot%System32Config folder. 

The SRV record is a Domain Name System (DNS) resource record that is used to identify 

computers that host specific services. 

SRV resource records are used to locate domain controllers for Active Directory. 

You can use Notepad, to view this file. 

The first record in the file is the domain controller’s Lightweight Directory Access Protocol 

(LDAP) SRV record. 

This record should appear similar to the following: _ldap._tcp.Domain_Name