KDC support and DAC requirements are two different things.
DAC requires 2003 forest level and at least one 2012 DC in a domain to save resource properties and Central Access Rules.

So, I would be careful to read questions what they ask.

First of all, this KDC support requires 2008 or higher.
Second, to support 'Always provide Claims' and 'Fail unarmored authentication requests'(these two are new in 2012), you need 2012 domain functional level.

The question asks ''KDC support for claims, compound authentication, and Kerberos armoring' only, but didn't mention about the two 2012 features. This new authorization and auditing mechanism requires extensions to Active Directory. These new extensions build Windows claim types, which is where Windows stores claims for an Active Directory forest. <br /> <br /> <br /> <br /> Another dependency upon which claims authorization relies in the Kerberos Key Distribution Center (KDC). The Windows Server 2012 KDC contains Kerberos enhancements required to transport claims within a Kerberos ticket and compound authentication. Windows Server 2012 KDC also includes an enhancement to support Kerberos armoring. <br /> <br /> <br /> <br /> <br /> Note:<br /> <br /> <br /> Your environment only requires a Windows Server 2012 KDC when you base authorization decisions on claims that are sourced from Active Directory attributes or certificates. Authorization decisions based on group memberships, including conditional expressions that use the memberOf operator do not require a Windows Server 2012 KDC. <br /> <br /> Lastly, the Security Accounts Manager (SAM) portion of the Windows Server 2012 domain controller understands claim types, where they are stored, and claims transformation. The KDC relies on the SAM to retrieve claim information that it uses in Kerberos tickets.<br /> <br /> Claim-based authorization and auditing does not have a forest functional or domain functional requirement. You can implement and configure claims with a mixture of Windows Server 2008 and 2008 R2 domain controllers provided the domain has an adequate number Windows Server 2012 domain controllers to support authentication requests that include claim information.Monday, April 21, 2014 8:06 PM UTCharlielalicone Yeah you definitely got all the shitty questions ! :\ sorry about that.<br /> In fact this question is a little bit crappy since on some website it says that you will all get the new features if you have and only need one DC 2012 even tho the rest of the DCs are 2008R2. Obviously this question require an answer...<br /> <br /> The infrastructure required to implement claims-based authorization in Active Directory includes at least one Windows Server 2012 DC in the domain where the user resides that will use this feature, one or more Windows Server 2012 DCs in each domain that will implement claims to another forest, and a Windows 8 client (for device claims). There's no requirement for forest functional level -- that is, no need to raise the forest functional level to Windows Server 2012. <br /> <br /><br /> <br /> Prerequisites<br /> <br /> Claims-based authorization and auditing requires:<br /> <br /> • Windows Server 2012<br /> <br /> • At least one Windows Server 2012 domain controller accessible by the Windows client in the user's domain<br /> <br /> • At least one Windows Server 2012 domain controller in each domain when using claims across a forest trust<br /> <br /> Windows 8 client (required when using device claims) <br /> <br /> In that case, we already have the DC2012 in the child domain so nothing should needed...<br /> <br /> Oh well, exam is tomorrow! i will see !<br /> <br /> Btw, i changed one question answer. Depending on the number of nodes in your cluster (an even number or an odd number) you had a veritable plethora of quorum models to choose from including Node Majority, Node and Disk Majority or Node and File Share Majority amongst others.

Now, that choice has been made much simpler: you need only decide whether to use a Disk Witness or a File Share Witness? Unlike previous versions of Windows Server, using a Witness for our failover clusters is now recommended. Gone are the days when a failed Disk Witness could bring down a cluster. The other question i couldn't answer anything was the Q22 in Configure the AD infrastructure. "You need to ensure that the KDC support for claims, compound authentication, and kerberos armoring setting is enforced in the domain"<br /> There is nothing to be done here, the explanation is wrong, the Forest functional doesn't need to be raise to 2012 and we already have a DC 2012 to get all the KDC support for claims etc.<br /> <br /> I will look into that this weekend.. my exam is next Tuesday so if i find anything else ill post it here.Thursday, April 17, 2014 3:38 PM UTakrisz1975<br /> <br /> I think Node and disk majority & Node and File Share<br /> <br /> No majority Disk Only not recommended<br /> <br /> Tie Break for 50% Node Split<br /> <br /> Let’s look at a more complex example with a cluster that has four members, each having a vote along with a Witness that also has a vote.<br /> <br /> If the Witness goes offline then one of the cluster members will be chosen and their vote will be removed. This leaves us with a cluster that has three votes’, and we attain the odd number of votes necessary to maintain our cluster. This dynamic functionality is particularly useful for a geographically dispersed cluster.<br /> <br /> Where a four node cluster is split across two sites and the File Share Witness goes offline, one node is chosen and its vote is removed. Again, we are left with three votes and the cluster is maintained. If the two sites were then loose connectivity, the side of the cluster that has two votes would remain up and keep the cluster running.<br /> <br /> Although this behaviour is automatic, we can influence the choice of which cluster member loses its vote my using the new LowerQuorumPriorityNodeID Property. Assigning this property to a node at the disaster recovery (DR) site, we can make sure our primary site stays up.Thursday, April 17, 2014 3:24 PM UTJay i think the answer is :<br /> Node and File Share Majority<br /> Node and Disk Majority<br /> <br /> It is recommended to have an odd number of total votes in the cluster since quorum requires more than half of the votes to be online. If I have a 4-node cluster, and only give each node a vote for 4 total votes, I need 3 nodes to stay running to maintain quorum with more than half of the votes. This means I can only sustain a single node failure. However, by assigning a disk or FSW a 5th vote, I still need 3 votes to maintain quorum, however I can now sustain two node failures, instead of one. So by adding these extra votes by using a disk or file share, instead of requiring the purchase of an additional node, Failover Clustering can offer higher availability at a much lower cost.Thursday, April 17, 2014 2:36 PM UTT0nus to technet :<br /><br /> <br /> Table in section "Choosing the quorum mode for a particular cluster" says that : Node and disk majority is recommended when you have an even number of nodes BUT not in a multi-site cluster<br /> <br /> So, what do you think the answer is ?<br /> Node and disk majority & Node and File Share"<br /> or<br /> Node and File Share & No majority: disk only ?Wednesday, April 16, 2014 12:49 PM UTakrisz1975<br /> <br /> IMO<br /> Node and File Share Majority<br /> Node and Disk Majority<br /> <br /><br /> <br /> Now, that choice has been made much simpler: you need only decide whether to use a Disk Witness or a File Share Witness? Unlike previous versions of Windows Server, using a Witness for our failover clusters is now recommended. There are a couple of others as well I believe are wrong especially the work folders question where it says you need to ensure user1 from all domains have a unique folder under sync1. which powershell command would you run and the answer seems to be Set-SyncShare BUt you need to modify the -UserFolderName from username to alias@domain and this switch is only available in New-SyncShare commandlet. I think a part of the questions is missing and in the "real" MS question the part that needed to be added is " DC2012 hasnt been introduced yet to the domain" what should you do ?! :) well adprep it ! so A.

Same thing with the question 22 in "configure the AD infra" section. Nothing needs to be done there. I've learned dumps of snowden (old but good), Andy and Angela. Don't know which answers were wrong, but Microsoft has changed the possible answers for some questions. The change of the answers was not really a problem, i think the change made it a little bit easier.Friday, April 11, 2014 4:45 PM UTSkyTheLimit believe Jay is right... U dt just learn the questions by heart whch many people are doing and failing. Know what u are answering, do research from technet... put the right answers there...Friday, April 11, 2014 11:34 AM UTmark through these dumps one question is bugging me - any advice<br /> <br /> Question:<br /> Your network contains an Active Directory forest named The forest contains a single domain. The domain contains three domain controllers. 