70-742 - Identity With Windows Server 2016: 70-742 Practice Exam Questions Demo
70-742 - Identity With Windows Server 2016: 70-742 Practice Exam Questions Demo
70-742 - Identity With Windows Server 2016: 70-742 Practice Exam Questions Demo
https://www.certleader.com/70-742-dumps.html
https://www.certleader.com/70-742-dumps.html
1. Your company recently deployed a new child domain to an Active Directory forest.
You discover that a user modified the Default Domain Policy to configure several Windows components in the
child domain.
A company policy states that the Default Domain Policy must be used only to configure domain-wide security
settings.
You create a new Group Policy object (GPO) and configure the settings for the Windows components in the
new GPO.
You need to restore the Default Domain Policy to the default settings from when the domain was first
installed.
A. From Group Policy Management, click Starter GPOs, and then click Manage Backups.
Answer: B
You have an Active Directory Federation Services (AD FS) farm. The farm contains a server named Server1
that runs Windows Server 2012 R2.
You add a server named Server2 to the farm. Server2 runs Windows Server 2016. You remove Server1 from
the farm.
You need to ensure that you can use role separation to manage the farm.
A. Set-AdfsFarmInformation
B. Update-AdfsRelyingPartyTrust
C. Set-AdfsProperties
D. Invoke-AdfsFarmBehaviorLevelRaise
Answer: D
Explanation:
AD FS for Windows Server 2016 introduces the ability to have separation between server administrators and
AD FS service administrators.
After upgrading our ADFS servers to Windows Server 2016, the last step is to raise the Farm Behavior Level
using the Invoke-AdfsFarmBehaviorLevelRaise PowerShell cmdlet.
To upgrade the farm behavior level from Windows Server 2012 R2 to Windows Server 2016 use the Invoke-
ADFSFarmBehaviorLevelRaise cmdlet.
References: https://technet.microsoft.com/en-us/library/mt605334(v=ws.11).aspx
3. HOTSPOT
Your network contains an Active Directory domain named contoso.com. The domain contains four servers
named Server1, Server2, Server3, and Server4 that run Windows Server 2016.
Server1 has IP Address Management (IPAM) installed. Server2, Server3, and Server 4 have the DHCP
Server role installed. IPAM manages Server2, Server3, and Server4.
A domain user named User1 is a member of the groups shown in the following table.
Which actions can User1 perform? To answer, select the appropriate options in the answer area.
Answer:
Explanation:
DHCP Administrators can create DHCP scopes. Box 2: Cannot be performed by User1
DHCP Users cannot create scopes. Box 3: Cannot be performed by User1 IPAM users cannot creates copes.
4. HOTSPOT
You have a server named Server1 that runs Windows Server 2016. Server1 has the Web Application Proxy
role service installed.
You publish an application named App1 by using the Web Application Proxy.
You need to change the URL that users use to connect to App1 when they work remotely. Which command
should you run? To answer, select the appropriate options in the answer
area.
Answer:
Explanation:
BackendServerURL.
References: https://technet.microsoft.com/itpro/powershell/windows/wap/set-webapplicationproxyapplication
5. DRAG DROP
Your network contains an Active Directory domain named contoso.com. The domain contains two servers
named Server1 and Server2 that run Windows Server 2016.
Server1 has IP Address Management (IPAM) installed. Server2 has Microsoft System Center 2016 Virtual
Machine Manager (VMM) installed.
Which types of objects should you create on each server? To answer, drag the appropriate object types to the
correct servers. Each object type may be used once, more than once, or not at all. You may need to drag the
split bar between panes or scroll to view content.
Answer:
Explanation:
VMM must be granted permission to view and modify IP address space in IPAM, and to perform remote
management of the IPAM server. VMM uses a “Run As” account to provide these permissions to the IPAM
network service plugin. The “Run As” account must be configured with appropriate permission on the IPAM
server.
In the IPAM server console, in the upper navigation pane, click ACCESS CONTROL, right- click Access
Policies in the lower navigation pane, and then click Add AccessPolicy.
Etc.
Server 2 (VMM) #1: Network Service Server 2 (VMM) #2: Run As Account
Perform the following procedure using the System Center VMM console. To configure VMM (see step 1-3,
step 6-7)
Etc.
References: https://technet.microsoft.com/en-us/library/dn783349(v=ws.11).aspx
You have an organizational unit (OU) named TestOU that contains test computers.
You need to enable a technician named Tech1 to create Group Policy objects (GPOs) and to link the GPOs to
TestOU. The solution must use the principle of least privilege.
Which two actions should you perform? Each correct answer presents part of the solution.
B. From Group Policy Management, modify the Delegation settings of the TestOU OU.
D. From Group Policy Management, modify the Delegation settings of the contoso.com container.
E. Create a new universal security group and add Tech1 to the group.
Answer: A,B
7. Note: This question is part of a series of questions that use the same or similar answer choices. An answer
choice may be correct for more than one question in the series. Each question is independent of the other
questions in this series.
Your network contains an Active Directory domain named contoso.com. The domain contains 5,000 user
accounts.
You have a Group Policy object (GPO) named DomainPolicy that is linked to the domain and a GPO named
DCPolicy that is linked to the Domain Controllers organizational unit (OU).
You need to configure the Documents folder of every user to be stored on a server named FileServer1.
G. From Preferences in the User Configuration node of DomainPolicy, modify Windows Settings.
H. From Preferences in the Computer Configuration node of DomainPolicy, modify Windows Settings.
Answer: E
8. Note: This question is part of a series of questions that use the same or similar answer choices. An answer
choice may be correct for more than one question in the series. Each question is independent of the other
questions in this series. Information and details provided in a question apply only to that question.
Your network contains an Active Directory forest named contoso.com. The forest functional level is Windows
Server 2012 R2.
You need to ensure that a domain administrator can recover a deleted Active Directory object quickly.
A. Dsadd quota
B. Dsmod
D. Dsacls
E. Dsamain
G. Ntdsutil
Answer: C
9. Note: This question is part of a series of questions that use the same or similar answer choices. An answer
choice may be correct for more than one question in the series. Each question is independent of the other
questions in this series.
Your network contains an Active Directory domain named contoso.com. The domain contains 5,000 user
accounts.
You have a Group Policy object (GPO) named DomainPolicy that is linked to the domain and a GPO named
DCPolicy that is linked to the Domain Controllers organizational unit (OU).
You need to use the application control policy settings to prevent several applications from running on the
network.
G. From Preferences in the User Configuration node of DomainPolicy, modify Windows Settings.
H. From Preferences in the Computer Configuration node of DomainPolicy, modify Windows Settings.
Answer: B
10. Your network contains an Active Directory domain named contoso.com. The domain contains a Group
Policy object (GPO) named GPO1.
You configure the Internet Settings preference in GPO1 as shown in the exhibit. (Click the Exhibit button.)
A user reports that the homepage of Internet Explorer is not set to http://www.contoso.com. You confirm that
the other settings in GPO1 are applied.
You need to configure GPO1 to set the Internet Explorer homepage. What should you do?
Answer: A
Explanation:
The red dotted line under the homepage URL means that setting is disabled. Pressing F5 enables all settings.
100% Pass Your 70-742 Exam with Our Prep Materials Via below:
https://www.certleader.com/70-742-dumps.html