70-742 Exam Questions - Online Test


70-742 Premium VCE File

Learn More 100% Pass Guarantee - Dumps Verified - Instant Download
150 Lectures, 20 Hours

surepassexam.com

Your success in is our sole target and we develop all our in a way that facilitates the attainment of this target. Not only is our material the best you can find, it is also the most detailed and the most updated. for Microsoft 70-742 are written to the highest standards of technical accuracy.

Free demo questions for Microsoft 70-742 Exam Dumps Below:

NEW QUESTION 1
Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server 2021.
Server1 has IP Address Management (IPAM) installed. Server2 has the DHCP Server role installed. The IPAM server retrieves data from Server2.
You create a domain user account named User1.
You need to ensure that User1 can use IPAM to manage DHCP.
Which command should you run on Server1? To answer, select the appropriate options in the answer area.
70-742 dumps exhibit

    Answer:

    Explanation: 70-742 dumps exhibit

    NEW QUESTION 2
    Your network contains an Active Directory domain named contoso.com.
    You plan to deploy a new Active Directory Rights Management Services (AD RMS) cluster on a server named Server1.
    You need to create the AD RMS service account. The solution must use the principle of least privilege What should you do?

    • A. Create a domain user account and add the account to the Account Operators group in the domain.
    • B. Create a local user account on Server1 and add the account to the Administrators group on Server1.
    • C. Create a domain user account and add the account to the Domain Users group in the domain.
    • D. Create a domain user account and add the account to the Administrators group on Server1.

    Answer: C

    NEW QUESTION 3
    Your network contains an Active Directory domain. The domain contains computer named Comouter1 and an organizational unit (OU) named TestOU. TestOU contains 10 computer accounts that are used for testing. A Group Policy object (GPO) named GPO1 is linked to TestOU.
    On Computer1, you modify the User Right Assignment by using the local policy.
    You need to apply the User Right Assignment from Computer1 to the 10 test computers. What should you do?

    • A. On Computer1, run the gprcsult.exe command and specify the A paramete
    • B. From Group Policy Management, run the Restore Group Policy Object Wizard.
    • C. On Computer1, run the secedit.exe command and specify the /export paramete
    • D. From Group Policy Management, run the Import Settings Wizard.
    • E. On Computer1, run the gpresult.exe command and specify the A paramete
    • F. Edit GPO1, and then import a security template.
    • G. On Computer1 run the secedit.exe command and specify the /export paramete
    • H. Edit GPO1, and then import a security template.

    Answer: D

    NEW QUESTION 4
    User1 is in OU1. GPO1 is linked to OU1.
    70-742 dumps exhibit
    The settings in GPO1 are configured as shown in the exhibit. (Click the Exhibit button)
    70-742 dumps exhibit
    Computer1 does not have any shortcuts on the desktop.

    • A. 1
    • B. 2
    • C. 3
    • D. 4

    Answer: D

    NEW QUESTION 5
    Your company has multiple offices.
    The network contains an Active Directory domain named contoso.com. An Active Directory site exists for each office. All of the sites connect to each other by using DEFAULTIPSITELINK.
    The company plans to open a new office. The new office will have a domain controller and 100 client computers.
    You install Windows Server 2021 on a member server in the new office. The new server will become a domain controller.
    You need to deploy the domain controller to the new office. The solution must ensure that the client computers in the new office will authenticate by using the local domain controller.
    Which three actions should you perform next in sequence? To answer, move the appropriate actions from the
    list of actions to the answer area and arrange them in the correct order.
    70-742 dumps exhibit

      Answer:

      Explanation: 70-742 dumps exhibit

      NEW QUESTION 6
      Your network contains an Active Directory domain named contoso.com.
      The domain contain the computers configured as shown in the following table.
      70-742 dumps exhibit
      The domain contains a user named User1.
      A Group Policy object (GPO) named GPO1 is linked to the domain. GPO1 contains a user preference that is configured as shown in the Shortcut1 Properties exhibit.
      70-742 dumps exhibit
      Item-level targeting for the user preference is configured as shown in the Targeting exhibit. (Click the Exhibit button.)
      70-742 dumps exhibit
      For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
      70-742 dumps exhibit

        Answer:

        Explanation: 70-742 dumps exhibit

        NEW QUESTION 7
        Your network contains an Active Directory domain named contoso.com. The domain functional level is Windows Server 2012 R2.
        You need to secure several high-privilege user accounts to meet the following requirements: What should you do?

        • A. Create a universal security group for the user accounts and modify the Security settings of the group.
        • B. Add the users to the Windows Authorization Access Group group.
        • C. Add the user to the Protected Users group.
        • D. Create a separate organizational unit (OU) for the user accounts and modify the Security settings of the OU.

        Answer: C

        NEW QUESTION 8
        Your network contains an Active Directory domain named contoso.com. The domain contains four servers named Server1, Server2, Server3, and Server4 that run Windows Server 2021.
        Server1 has IP Address Management (IPAM) installed. Server2, Server3, and Server 4 have the DHCP Server role installed. IPAM manages Server2, Server3, and Server4.
        A domain user named User1 is a member of the groups shown in the following table.
        70-742 dumps exhibit
        Which actions can User1 perform? To answer, select the appropriate options in the answer area.
        70-742 dumps exhibit

          Answer:

          Explanation: Box 1: Can be performed by User1
          DHCP Administrators can create DHCP scopes. Box 2: Cannot be performed by User1
          DHCP Users cannot create scopes. Box 3: Cannot be performed by User1 IPAM users cannot creates copes.
          References: https://technet.microsoft.com/en-us/library/dn741281(v=ws.11).aspx#create_access_scope

          NEW QUESTION 9
          Your network contains an Active Directory domain.
          Users do not have administrative privileges to their client computer You modify a computer setting in a Group Policy object (GPO).
          You need to ensure that the setting is applied to five client computers as soon as possible. What should you do?

          • A. From a domain controller, run the gpudate.exe command and specify the Force parameter.
          • B. From each client computer, run the gpresult.exe command and specify the /r parameter.
          • C. From each client computer, run the Get-Gpo cmdlet and specify the -alt parameter.
          • D. From a domain controller, run the Invoke-GPUpdate cmdlet.

          Answer: D

          Explanation: https://technet.microsoft.com/en-us/library/hh852337(v=ws.11).aspx

          NEW QUESTION 10
          Your company has a marketing department.
          The network contains an Active Directory domain named comoso.com.
          The domain contains two top-level organizational units (OUs) named MKT_Comps and MKT_Users. MKT_Comps contains the computer accounts for the computers in the marketing department. MKT_Users contains the user accounts for the users in the marketing department.
          You link a new Group Policy object (GPO) named GPO1 to MKT_Comps.
          You need to deploy a VPN connection to all of the users who sign in to the marketing department computers. The users must be

          • A. Computer Configuration/Policies/Administrative Templates/Network/Network Connections
          • B. Computer Configuration/Preferences/Control Panel Settings/Network Options
          • C. User Configuration/Preferences/Control Panel Settings/Network Options
          • D. User configuration/Policies/Administrative Templates/Network/Network Connections

          Answer: B

          NEW QUESTION 11
          You create a user account that will be used as a template for new user accounts.
          Which setting will be copied when you copy the user account from Active Directory Users and Computers?

          • A. the Department attribute
          • B. the Description attribute
          • C. Permission
          • D. Remote Desktop Services Profile

          Answer: A

          Explanation: A user template in Active Directory can be used if you are creating users for a specific department, with exactly the same properties, and membership to the same user groups. A user template is nothing more than a disabled user account that has all these settings already in place.
          References:
          http://www.rebeladmin.com/2014/07/create-users-with-user-templates-in-ad/

          NEW QUESTION 12
          Your network contains an Active Directory domain named contoso com. The domain contains a web application that uses Kerberos authentication.
          You change the domain name of the web application.
          You need to ensure that the service principal name (SPN) for the application is registered. Which tool should you use?

          • A. Repladmin
          • B. Setspn
          • C. Netsh
          • D. Pdspnf

          Answer: B

          Explanation: https://social.technet.microsoft.com/wiki/contents/articles/18996.active-directory-powershell-script-to-list-all-sp

          NEW QUESTION 13
          You have users that access web applications by using HTTPS. The web applications are located on the servers in your perimeter network. The servers use certificates obtained from an enterprise root certification authority (CA). The certificates are generated by using a custom template named WebApps. The certificate revocation list (CRL) is published to Active Directory.
          When users attempt to access the web applications from the Internet, the users report that they receive a revocation warning message in their web browser. The users do not receive the message when they access the web applications from the intranet.
          You need to ensure that the warning message is not generated when the users attempt to access the web applications from the Internet.
          What should you do?

          • A. Install the Certificate Enrollment Web Service role service on a server in the perimeter network.
          • B. Modify the WebApps certificate template, and then issue the certificates used by the web application servers.
          • C. Install the Web Application Proxy role service on a server in the perimeter networ
          • D. Create a publishing point for the CA.
          • E. Modify the CRL distribution point, and then reissue the certificates used by the web application servers.

          Answer: C

          NEW QUESTION 14
          Your network contains an Active Directory domain named contoso.com. The domain contains a user named User1, a group named Group1, and an organizational unit (OU) named OU1.
          You need to enable User1 to link Group Policies to OU1.
          Solution: From Active Directory Administrative Center, you add User1 to Group1 and grant Group1 Full Control permission to OU1.
          Does this meet the goal?

          • A. Yes
          • B. No

          Answer: A

          NEW QUESTION 15
          Your network contains an Active Directory forest named contoso.com. The forest contains several domains. An administrator named Admin01 installs Windows Server 2021 on a server named Server1 and then joins
          Server1 to the contoso.com domain.
          Admin01 plans to configure Server1 as an enterprise root certification authority (CA).
          You need to ensure that Admin01 can configure Server1 as an enterprise CA. The solution must use the principle of least privilege.
          To which group should you add Admin01?

          • A. Server Operators in the contoso.com domain
          • B. Cert Publishers on Server1
          • C. Enterprise Key Admins in the contoso.com domain
          • D. Enterprise Admins in the contoso.com domain.

          Answer: D

          NEW QUESTION 16
          Your network contains an Active Directory named contoso.com
          You have three top-level organizational units (OUs) named OU1, OU2 and OU3. OU1 contains user accounts. OU2 contains the computer accounts for shared public computers. 0U3 contains the computer accounts for laptops.
          You have two Group Policy objects (GPOs) named GPO1 and GP02. GPO1 is linked to OU1. GP02 is linked to OU2.
          You need to prevent the user settings in GPO1 from being applied when a user signs in to a shared public computer. If a user signs in to a laptop, the user settings in GPO1 must be applied.
          What should you configure?

          • A. inheritance blocking
          • B. Security Filtering
          • C. loopback processing
          • D. GPO link enforcement

          Answer: C

          P.S. Surepassexam now are offering 100% pass ensure 70-742 dumps! All 70-742 exam questions have been updated with correct answers: https://www.surepassexam.com/70-742-exam-dumps.html (222 New Questions)