70-742 Premium Bundle

70-742 Premium Bundle

Identity with Windows Server 2016 Certification Exam

4.5 
(44250 ratings)
0 QuestionsPractice Tests
0 PDFPrint version
November 23, 2024Last update

Microsoft 70-742 Free Practice Questions

are updated and are verified by experts. Once you have completely prepared with our you will be ready for the real 70-742 exam without a problem. We have . PASSED First attempt! Here What I Did.

Free 70-742 Demo Online For Microsoft Certifitcation:

NEW QUESTION 1
Your network contains an Active Directory domain named contoso.com. All the accounts of the users in the sales department are in an organizational unit (OU) named SalesOU.
An application named App1 is deployed to the user accounts in SalesOU by using a Group Policy object (GPO) named Sales GPO.
You need to set the registry value of HKEY_CURRENT_USERSoftwareApp1Collaboration to 0. Solution: You add a computer preference that has a Create action.
Does this meet the goal?

  • A. Yes
  • B. NO

Answer: B

NEW QUESTION 2
Your network contains an Active Directory domain named contoso.com.
The user account for a user named User1 is in an organizational unit (OU) named OU1. You need to enable User1 to sign in as user1@adatum.com.
Solution: From Active Directory Users and Computers, you set the E-mail property of User1 to user1@adatum.com.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

NEW QUESTION 3
Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server 2021.
Server1 has IP Address Management (IPAM) installed. Server2 has Microsoft System Center 2021 Virtual Machine Manager (VMM) installed.
You need to integrate IPAM and VMM.
Which types of objects should you create on each server? To answer, drag the appropriate object types to the correct servers. Each object type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
70-742 dumps exhibit

    Answer:

    Explanation: Server 1 (IPAM): Access Policy
    VMM must be granted permission to view and modify IP address space in IPAM, and to perform remote management of the IPAM server. VMM uses a “Run As” account to provide these permissions to the IPAM network service plugin. The “Run As” account must be configured with appropriate permission on the IPAM server.
    To assign permissions to the VMM user account
    In the IPAM server console, in the upper navigation pane, click ACCESS CONTROL, right-click Access Policies in the lower navigation pane, and then click Add AccessPolicy.
    Etc.
    Server 2 (VMM) #1: Network Service Server 2 (VMM) #2: Run As Account
    Perform the following procedure using the System Center VMM console. To configure VMM (see step 1-3, step 6-7)
    70-742 dumps exhibit
    Etc.
    References: https://technet.microsoft.com/en-us/library/dn783349(v=ws.11).aspx

    NEW QUESTION 4
    You deploy a new certification authority (CA) to a server that runs Windows Server 2021. You need to configure the CA to support recovery of certificates.
    What should you do first?

    • A. Modify the Recovery Agents settings from the properties of the CA.
    • B. Assign the Request Certificates permission to the user account that will be responsible for recovering certificates.
    • C. Configure the Key Recovery Agent template as a certificate template to issue.
    • D. Modify the extensions of the OCSP Response Signing template.

    Answer: C

    Explanation: References:
    http://markgossa.blogspot.co.uk/2021/03/enable-key-archival-in-server-2012-r2.html

    NEW QUESTION 5
    Your company has a main office and three branch offices.
    The network contains an Active Directory domain named contoso.com.
    The main office contains three domain controllers. Each branch office contains one domain controller.
    You discover that new settings in the Default Domain Policy are not applied in one of the branch offices, but all other Group Policy objects (GPOs} are applied.
    You need to check the replication of the Default Domain Policy for the branch office. What should you do from a domain controller in the main office?

    • A. From a command prompt, run dcdiag.exe.
    • B. From Group Policy Management, click Default Domain Policy under Contoso.com, and then open theDetails tab.
    • C. From Group Policy Management, click Default Domain Policy under Contoso.com, and then open theScope tab.
    • D. From a command prompt, run repadmin.exe.

    Answer: D

    NEW QUESTION 6
    Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2021.
    Server1 has IP Address Management (IPAM) installed. IPAM is configured to use the Group Policy based provisioning method. The prefix for the IPAM Group Policy objects (GPOs) is IP.
    From Group Policy Management, you manually rename the IPAM GPOs to have a prefix of IPAM. You need to modify the GPO prefix used by IPAM.
    What should you do?

    • A. Click Configure server discovery in Server Manager.
    • B. Run the Set-IpamConfiguration cmdlet.
    • C. Run the Invoke-IpamGpoProvisioning cmdlet.
    • D. Click Provision the IPAM server in Server Manager.

    Answer: B

    Explanation: The Set-IpamConfiguration cmdlet modifies the configuration for the computer that runs the IPAM server. The -GpoPrefix<String> parameter specifies the unique Group Policy object (GPO) prefix name that IPAM
    uses to create the group policy objects. Use this parameter only when the value of the ProvisioningMethod parameter is set to Automatic.
    References: https://technet.microsoft.com/en-us/library/jj590816.aspx

    NEW QUESTION 7
    Your network contains an Active Directory named contoso.com
    You have three top-level organizational units (OUs) named OU1, OU2 and OU3. OU1 contains user accounts. OU2 contains the computer accounts for shared public computers. 0U3 contains the computer accounts for laptops.
    You have two Group Policy objects (GPOs) named GPO1 and GP02. GPO1 is linked to OU1. GP02 is linked to OU2.
    You need to prevent the user settings in GPO1 from being applied when a user signs in to a shared public computer. If a user signs in to a laptop, the user settings in GPO1 must be applied.
    What should you configure?

    • A. inheritance blocking
    • B. Security Filtering
    • C. loopback processing
    • D. GPO link enforcement

    Answer: C

    NEW QUESTION 8
    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    You network contains an Active Directory forest named contoso.com. The forest contains an Active Directory Rights Management Services (AD RMS) deployment.
    Your company establishes a partnership with another company named Fabrikam, Inc. The network of Fabrikam contains an Active Directory forest named fabrikam.com and an AD RMS deployment.
    You need to ensure that the users in contoso.com can access rights protected documents sent by the users in fabrikam.com.
    Solution: From AD RMS in fabrikam.com, you configure contoso.com as a trusted publisher domain. Does this meet the goal?

    • A. Yes
    • B. No

    Answer: B

    Explanation: Contoso needs to trust Fabrikam.

    NEW QUESTION 9
    Your network contains an Active Directory domain named contoso.com. Domain users use smart cards to sign in to their client computer.
    Some users report that it takes a long time to sign in to their computer and that the logon attempt times out, so they must restart the sign in process.
    You discover that the issues to checking the certificate revocation list (CRL) of the smart card certificates. You need to resolve the issue without diminishing the security of the smart card logons.
    What should you do?

    • A. From the properties of the smart card's certificate template, modify the Request Handling settings.
    • B. From the properties of the smart card's certificate template, modify the Issuance Requirements settings.
    • C. Deactivate certificate revocation checks on the computers.
    • D. Implement an Online Certification Status Protocol (OCSP) responder.

    Answer: D

    NEW QUESTION 10
    Your network contains an Active Directory domain named contoso.com. The domain contains a user named User1, a group named Group1, and an Organizational unit (OU) named OU1.
    You need to enable User1 to link Group Policies to OU1.
    Solution: From Active Directory Administrative Center, you add User1 to Group1. From Group Policy Management, you click the Group Policy Objects container. From the Delegation tab, you add Group1.

    • A. Yes
    • B. No

    Answer: B

    NEW QUESTION 11
    Your network contains an enterprise root certification authority (CA) named CA1.
    Multiple computers on the network successfully enroll for certificates that will expire in one year. The certificates are based on a template named Secure_Computer. The template uses schema version 2.
    You need to ensure that new certificates based on Secure_Computer are valid for three years. What should you do?

    • A. Modify the Validity period for the certificate template.
    • B. Instruct users to request certificates by running the certreq.exe command.
    • C. Instruct users to request certificates by using the Certificates console.
    • D. Modify the Validity period for the root CA certificate.

    Answer: A

    NEW QUESTION 12
    Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.
    Start of repeated scenario.
    Your network contains an Active Directory domain named contoso.com. The domain contains a single site named Site1. All computers are in Site1.
    The Group Policy objects (GPOs) for the domain are configured as shown in the exhibit. (Click the Exhibit button.)
    70-742 dumps exhibit
    The relevant users and client computer in the domain are configured as shown in the following table.
    70-742 dumps exhibit
    End of repeated scenario.
    Which five GPOs will apply to User1 in sequence when the user signs in to Computer1? To answer, move the appropriate GPOs from the list to the answer area and arrange them in the correct order.
    70-742 dumps exhibit

      Answer:

      Explanation: 70-742 dumps exhibit

      NEW QUESTION 13
      Your company has multiple offices.
      The network contains an Active Directory domain named contoso.com. An Active Directory site exists for each office. All of the sites connect to each other by using DEFAULTIPSITELINK.
      The company plans to open a new office. The new office will have a domain controller and 100 client computers.
      You install Windows Server 2021 on a member server in the new office. The new server will become a domain controller.
      You need to deploy the domain controller to the new office. The solution must ensure that the client computers in the new office will authenticate by using the local domain controller.
      Which three actions should you perform next in sequence? To answer, move the appropriate actions from the
      list of actions to the answer area and arrange them in the correct order.
      70-742 dumps exhibit

        Answer:

        Explanation: 70-742 dumps exhibit

        NEW QUESTION 14
        Your network contains an Active Directory forest.
        Some users report experiencing difficulties signing in to domain controllers. You suspect that the service location (SRV) records might be causing the issue.
        What are two possible commands that you can run to verify the SRV records? Each correct answer presents a complete solution.
        NOTE. Each correct selection is worth one point.

        • A. dcdiag.exe /test:connectivity
        • B. dnscmd /info
        • C. dnscmd /DirectoryPartitionInfo
        • D. dcdiag.exe /test:dns /DnsRecordRegistration
        • E. dcdiag.exe /test:dns
        • F. dnscmd /IPValidate

        Answer: BD

        Explanation: https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/troubleshoot/verify-dns-functionality-to

        NEW QUESTION 15
        You have a server named Server1 in a workgroup.
        You need to configure a Group Policy setting on Server1 that will apply to only non-administrative users. What should you do?

        • A. Open Local Group Policy Edito
        • B. From the File menu, modify the Options settings.
        • C. Run mmc.exe Add the Group Policy Object Editor snap-in and change the Group Policy object (GPO).
        • D. Open Local Group Policy Edito
        • E. From the View menu, modify the Customize settings.
        • F. Open Local Users and Groups, Create a new group Run New-GPO.

        Answer: A

        NEW QUESTION 16
        Your network contains an Active Directory domain named contoso.com.
        You need to create a central store for Group Policy administrative templates. What should you use?

        • A. Server Manager
        • B. File Explorer
        • C. Dcgpofix.exe
        • D. Group Policy Management Console (GPMC)

        Answer: B

        Recommend!! Get the Full 70-742 dumps in VCE and PDF From 2passeasy, Welcome to Download: https://www.2passeasy.com/dumps/70-742/ (New 222 Q&As Version)


        START 70-742 EXAM