Explanation/Reference:
Explanation:
The root domain in the forest must be at Windows Server 2012level. First upgrade DC1 to this level (A), then raise the contoso.com domain functional level to Windows Server 2012 (D).
(A) To support resources that use claims-based access control, the principal's domains will need to be running one of the following:
All Windows Server 2012 domain controllers

Sufficient Windows Server 2012domain controllers to handle all the Windows 8 device authentication

requests
Sufficient Windows Server 2012 domain controllers to handle all the Windows Server 2012 resource

protocol transition requests to support non-Windows 8 devices.
References: What's New in Kerberos Authentication
https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/ hh831747(v=ws.11)