70-742 - Identity With Windows Server 2016: 70-742 Practice Exam Questions Demo

Download as pdf or txt
Download as pdf or txt
You are on page 1of 12

70-742 Practice Exam Questions Demo

https://www.certleader.com/70-742-dumps.html

70-742 - Identity with Windows Server 2016

https://www.certleader.com/70-742-dumps.html

The Leader of IT Certification visit - https://www.certleader.com


70-742 Practice Exam Questions Demo
https://www.certleader.com/70-742-dumps.html

1. Your company recently deployed a new child domain to an Active Directory forest.

You discover that a user modified the Default Domain Policy to configure several Windows components in the
child domain.

A company policy states that the Default Domain Policy must be used only to configure domain-wide security
settings.

You create a new Group Policy object (GPO) and configure the settings for the Windows components in the
new GPO.

You need to restore the Default Domain Policy to the default settings from when the domain was first
installed.

What should you do?

A. From Group Policy Management, click Starter GPOs, and then click Manage Backups.

B. From a command prompt, run the dcgpofix.exe command.

C. From Windows PowerShell, run the Copy-GPO cmdlet.

D. Run ntdsutil.exe to perform a metadata cleanup and a semantic database analysis.

Answer: B

2. Your network contains an Active Directory forest named contoso.com.

You have an Active Directory Federation Services (AD FS) farm. The farm contains a server named Server1
that runs Windows Server 2012 R2.

You add a server named Server2 to the farm. Server2 runs Windows Server 2016. You remove Server1 from
the farm.

You need to ensure that you can use role separation to manage the farm.

Which cmdlet should you run?

A. Set-AdfsFarmInformation

B. Update-AdfsRelyingPartyTrust

C. Set-AdfsProperties

D. Invoke-AdfsFarmBehaviorLevelRaise

Answer: D

Explanation:

AD FS for Windows Server 2016 introduces the ability to have separation between server administrators and

The Leader of IT Certification visit - https://www.certleader.com


70-742 Practice Exam Questions Demo
https://www.certleader.com/70-742-dumps.html

AD FS service administrators.

After upgrading our ADFS servers to Windows Server 2016, the last step is to raise the Farm Behavior Level
using the Invoke-AdfsFarmBehaviorLevelRaise PowerShell cmdlet.

To upgrade the farm behavior level from Windows Server 2012 R2 to Windows Server 2016 use the Invoke-
ADFSFarmBehaviorLevelRaise cmdlet.

References: https://technet.microsoft.com/en-us/library/mt605334(v=ws.11).aspx

3. HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains four servers
named Server1, Server2, Server3, and Server4 that run Windows Server 2016.

Server1 has IP Address Management (IPAM) installed. Server2, Server3, and Server 4 have the DHCP
Server role installed. IPAM manages Server2, Server3, and Server4.

A domain user named User1 is a member of the groups shown in the following table.

Which actions can User1 perform? To answer, select the appropriate options in the answer area.

Answer:

The Leader of IT Certification visit - https://www.certleader.com


70-742 Practice Exam Questions Demo
https://www.certleader.com/70-742-dumps.html

Explanation:

Box 1: Can be performed by User1

DHCP Administrators can create DHCP scopes. Box 2: Cannot be performed by User1

DHCP Users cannot create scopes. Box 3: Cannot be performed by User1 IPAM users cannot creates copes.

References: https://technet.microsoft.com/en- us/library/dn741281(v=ws.11).aspx#create_access_scope

4. HOTSPOT

You have a server named Server1 that runs Windows Server 2016. Server1 has the Web Application Proxy
role service installed.

You publish an application named App1 by using the Web Application Proxy.

You need to change the URL that users use to connect to App1 when they work remotely. Which command
should you run? To answer, select the appropriate options in the answer

area.

Answer:

The Leader of IT Certification visit - https://www.certleader.com


70-742 Practice Exam Questions Demo
https://www.certleader.com/70-742-dumps.html

Explanation:

The Set-WebApplicationProxyApplication cmdlet modifies settings of a web application published through


Web Application Proxy. Specify the web application to modify by using its ID. Note that the method of
preauthentication cannot be changed. The cmdlet ensures that no other applications are already configured to
use any specified ExternalURL or

BackendServerURL.

References: https://technet.microsoft.com/itpro/powershell/windows/wap/set-webapplicationproxyapplication

5. DRAG DROP

Your network contains an Active Directory domain named contoso.com. The domain contains two servers
named Server1 and Server2 that run Windows Server 2016.

Server1 has IP Address Management (IPAM) installed. Server2 has Microsoft System Center 2016 Virtual
Machine Manager (VMM) installed.

You need to integrate IPAM and VMM.

Which types of objects should you create on each server? To answer, drag the appropriate object types to the
correct servers. Each object type may be used once, more than once, or not at all. You may need to drag the
split bar between panes or scroll to view content.

Answer:

The Leader of IT Certification visit - https://www.certleader.com


70-742 Practice Exam Questions Demo
https://www.certleader.com/70-742-dumps.html

Explanation:

Server 1 (IPAM): Access Policy

VMM must be granted permission to view and modify IP address space in IPAM, and to perform remote
management of the IPAM server. VMM uses a “Run As” account to provide these permissions to the IPAM
network service plugin. The “Run As” account must be configured with appropriate permission on the IPAM
server.

To assign permissions to the VMM user account

In the IPAM server console, in the upper navigation pane, click ACCESS CONTROL, right- click Access
Policies in the lower navigation pane, and then click Add AccessPolicy.

Etc.

Server 2 (VMM) #1: Network Service Server 2 (VMM) #2: Run As Account

Perform the following procedure using the System Center VMM console. To configure VMM (see step 1-3,
step 6-7)

The Leader of IT Certification visit - https://www.certleader.com


70-742 Practice Exam Questions Demo
https://www.certleader.com/70-742-dumps.html

Etc.

References: https://technet.microsoft.com/en-us/library/dn783349(v=ws.11).aspx

6. Your network contains an Active Directory domain named contoso.com.

You have an organizational unit (OU) named TestOU that contains test computers.

You need to enable a technician named Tech1 to create Group Policy objects (GPOs) and to link the GPOs to
TestOU. The solution must use the principle of least privilege.

Which two actions should you perform? Each correct answer presents part of the solution.

A. Add Tech1 to the Group Policy Creator Owners group.

B. From Group Policy Management, modify the Delegation settings of the TestOU OU.

C. Add Tech1 to the Protected Users group.

The Leader of IT Certification visit - https://www.certleader.com


70-742 Practice Exam Questions Demo
https://www.certleader.com/70-742-dumps.html

D. From Group Policy Management, modify the Delegation settings of the contoso.com container.

E. Create a new universal security group and add Tech1 to the group.

Answer: A,B

7. Note: This question is part of a series of questions that use the same or similar answer choices. An answer
choice may be correct for more than one question in the series. Each question is independent of the other
questions in this series.

Information and details provided in a question apply only to that question.

Your network contains an Active Directory domain named contoso.com. The domain contains 5,000 user
accounts.

You have a Group Policy object (GPO) named DomainPolicy that is linked to the domain and a GPO named
DCPolicy that is linked to the Domain Controllers organizational unit (OU).

You need to configure the Documents folder of every user to be stored on a server named FileServer1.

What should you do?

A. From the Computer Configuration node of DCPolicy, modify Security Settings.

B. From the Computer Configuration node of DomainPolicy, modify Security Settings.

C. From the Computer Configuration node of DomainPolicy, modify Administrative Templates.

D. From the User Configuration node of DCPolicy, modify Security Settings.

E. From the User Configuration node of DomainPolicy, modify Folder Redirection.

F. From user Configuration node of DomainPolicy, modify Administrative Templates.

G. From Preferences in the User Configuration node of DomainPolicy, modify Windows Settings.

H. From Preferences in the Computer Configuration node of DomainPolicy, modify Windows Settings.

Answer: E

8. Note: This question is part of a series of questions that use the same or similar answer choices. An answer
choice may be correct for more than one question in the series. Each question is independent of the other
questions in this series. Information and details provided in a question apply only to that question.

Your network contains an Active Directory forest named contoso.com. The forest functional level is Windows
Server 2012 R2.

You need to ensure that a domain administrator can recover a deleted Active Directory object quickly.

Which tool should you use?

The Leader of IT Certification visit - https://www.certleader.com


70-742 Practice Exam Questions Demo
https://www.certleader.com/70-742-dumps.html

A. Dsadd quota

B. Dsmod

C. Active Directory Administrative Center

D. Dsacls

E. Dsamain

F. Active Directory Users and Computers

G. Ntdsutil

H. Group Policy Management Console

Answer: C

9. Note: This question is part of a series of questions that use the same or similar answer choices. An answer
choice may be correct for more than one question in the series. Each question is independent of the other
questions in this series.

Information and details provided in a question apply only to that question.

Your network contains an Active Directory domain named contoso.com. The domain contains 5,000 user
accounts.

You have a Group Policy object (GPO) named DomainPolicy that is linked to the domain and a GPO named
DCPolicy that is linked to the Domain Controllers organizational unit (OU).

You need to use the application control policy settings to prevent several applications from running on the
network.

What should you do?

A. From the Computer Configuration node of DCPolicy, modify Security Settings.

B. From the Computer Configuration node of DomainPolicy, modify Security Settings.

C. From the Computer Configuration node of DomainPolicy, modify Administrative Templates.

D. From the User Configuration node of DCPolicy, modify Security Settings.

E. From the User Configuration node of DomainPolicy, modify Folder Redirection.

F. From user Configuration node of DomainPolicy, modify Administrative Templates.

G. From Preferences in the User Configuration node of DomainPolicy, modify Windows Settings.

H. From Preferences in the Computer Configuration node of DomainPolicy, modify Windows Settings.

The Leader of IT Certification visit - https://www.certleader.com


70-742 Practice Exam Questions Demo
https://www.certleader.com/70-742-dumps.html

Answer: B

10. Your network contains an Active Directory domain named contoso.com. The domain contains a Group
Policy object (GPO) named GPO1.

You configure the Internet Settings preference in GPO1 as shown in the exhibit. (Click the Exhibit button.)

A user reports that the homepage of Internet Explorer is not set to http://www.contoso.com. You confirm that
the other settings in GPO1 are applied.

You need to configure GPO1 to set the Internet Explorer homepage. What should you do?

A. Edit the GPO1 preference and press F5.

B. Modify Security Settings for GPO1.

The Leader of IT Certification visit - https://www.certleader.com


70-742 Practice Exam Questions Demo
https://www.certleader.com/70-742-dumps.html

C. Modify WMI Filtering for GPO1.

D. Modify the GPO1 preference to use item-level targeting.

Answer: A

Explanation:

The red dotted line under the homepage URL means that setting is disabled. Pressing F5 enables all settings.

The Leader of IT Certification visit - https://www.certleader.com


70-742 Practice Exam Questions Demo
https://www.certleader.com/70-742-dumps.html

Thank You for Trying Our Product

* 100% Pass or Money Back


All our products come with a 90-day Money Back Guarantee.
* One year free update
You can enjoy free update one year. 24x7 online support.
* Trusted by Millions
We currently serve more than 30,000,000 customers.
* Shop Securely
All transactions are protected by VeriSign!

100% Pass Your 70-742 Exam with Our Prep Materials Via below:

https://www.certleader.com/70-742-dumps.html

The Leader of IT Certification visit - https://www.certleader.com


Powered by TCPDF (www.tcpdf.org)

You might also like