If you want to get the latest Microsoft 70-742 exam dumps, you should choose Pass4itsure! https://www.pass4itsure.com/70-742.html Updated: Jan 03, 2020.Try Free Now-practice exam and PDF formats share!
Steps to prepare for Microsoft 70-742 exam
First step: Syllabus | The syllabus can be found on the official website https://www.microsoft.com/en-us/learning/exam-70-742.aspx |
Second step: Study Materials | Instructor-led training/Online Training(videos, books,lectures, projects and also some practice tests ) |
Third step: Practice tests | Practice tests should be taken seriously and obtained from https://www.pass4itsure.com/70-742.html…. |
You may also like…
FREE 70-761 guide | get the latest and valid 70-761 dumps PDF
The practice test for exam 70-742 Identity with Windows Server 2016
The best way to prepare for the 70-742 exam is not to read 70-742 textbooks, but to practice 70-742 questions and understand the correct answers.
QUESTION 1
Your network contains two Active Directory forests named fabrikam.com and contoso.com. Each forest contains a single
domain.
Contoso.com has a Group Policy object (GPO) named Cont_GPO1.
You need to apply the settings from Cont_GPO1 to the computers in fabrikam.com.
Which two actions should you perform? Each correct answer presents a complete solution.
NOTE: Each correct section is worth one point.
A. Back up Cont_GPO1. In fabrikam.com, create and link a new GPO by using the Group Policy Management Console
(GPMC), and then run the Import Setting Wizard.
B. Back up Cont_GPO1. In fabrikam.com, run the Restore-GPO cmdlet, and then run the New-GPLink cmdlet.
C. Back up Cont_GPO1. In fabrikam.com run the Import-GPO cmdlet, and then run the New-GPLink cmdlet.
D. Copy\\contoso.com\SysVol\contoso.com\Policies to \\fabrikam.com\SysVol\ fabrikam.com\Policies. In fabrikam.com,
run the New-GPLink cmdlet.
E. Back up Cont_GPO1. In fabrikam.com, create and link a new GPO by using the Group Policy Management Console
(GPMC), and then run the Restore Group Policy Object Wizard.
Correct Answer: AC
QUESTION 2
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
Your network contains an Active Directory domain.
You have a user account that is a member of the Domain Admins group.
You have 100 laptops that have a standard corporate image installed. The laptops are in workgroups and have random
names.
A technician named Tech1 is assigned the task of joining the laptops to the domain. The computer accounts of each
laptop must be in an organizational unit (OU) that is associated to the department of the user who will use the laptop.
The
laptop names must start with four characters indicating the department, followed by a four-digit number.
Tech1 is a member of the Domain Users group only. Tech1 has the administrator logon credentials for all the laptops.
You need Tech1 to join the laptops to the domain. The solution must ensure that the laptops are named correctly, and
the computer accounts of the laptops are in the correct OUs.
Solution: You instruct Tech1 to sign in to each laptop, to rename each laptop by using System in Control Panel, and
then to join each laptop to the domain by using the Netdom join command.
Does this meet the goal?
A. Yes
B. No
Correct Answer: A
QUESTION 3
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1
that runs Windows Server 2016. The computer account for Server1 is in organizational unit (OU) named OU1.
You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1.
You need to add a domain user named User1 to the local Administrators group on Server1.
Solution: From the Computer Configuration node of GPO1, you configure the Account Policies settings. Does this meet
the goal?
A. Yes
B. No
Correct Answer: B
Account Lockout Policy settings encapsulates Password Policy, Account Lockout Policy, and Kerberos Policy. It will not
allow you to add a domain user to a local Administrators group. References: https://technet.microsoft.com/ptpt/library/cc757692(v=ws.10).aspx
QUESTION 4
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
Your network contains an Active Directory domain named contoso.com.
The user account for a user named User1 is in an organizational unit (OU) named OU1.
You need to enable User1 to sign in as [email protected].
Solution: From Active Directory Users and Computers, you set the E-mail property of User1 to [email protected].
Does this meet the goal?
A. Yes
B. No
Correct Answer: B
QUESTION 5
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
Your network contains an Active Directory domain named contoso.com. The domain contains two domain controllers
named DC1 and DC2.
DC1 holds the RID master operations role. DC1 fails and cannot be repaired. You need to move the RID role to DC2.
Solution: On DC2, you open the command prompt, run dsmgmt.exe, connect to DC2, and use the Seize RID master
opinion.
Does this meet the goal?
A. Yes
B. No
Correct Answer: B
QUESTION 6
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
Your network contains an Active Directory domain named contoso.com.
A user named User1 is in an organizational unit (OU) named OU1.
You need to enable User1 to sign in as [email protected].
You need a list of groups to which User1 is either a direct member or an indirect member.
Solution: From Windows PowerShell, you run Set -Aduser User1 -UserPricncipalName [email protected].
Does this meet the goal?
A. Yes
B. No
Correct Answer: B
QUESTION 7
Your company has multiple branch offices.
The network contains an Active Directory domain named contoso.com.
In one of the branch offices, a new technician is hired to add computers to the domain.
After successfully joining multiple computers to the domain, the technician fails to join any more computers to the
domain.
You need to ensure that the technician can join an unlimited number of computers to the domain.
What should you do?
A. Configure the technician\\’s user account as a manager service account.
B. Run the Set-ADComputer cmdlet.
C. Modify the Security settings of the Computers container.
D. Add the technician to the Domain Computers group.
Correct Answer: C
Users who have the Create Account Objects privilege for the Computers container can create an unlimited number of
computer accounts in the domain. You can grant this privilege by accessing the Advanced Security settings on the
Security Tab of the Computer container via Active Directory Users And Computers or the Active Directory Administrative
Center.
References: https://books.google.co.za/books?id=LvNODQAAQBAJandpg=PT268andlpg=PT268anddq=Modify+the+Security+settings+of+the+Computers+container+2016andsource=blandots=1lRBQ21cL0andsig=1AUSon_6cjIqyN_927iOB7z3Egandhl=enandsa=Xandved=0ahUKEwjBi4OSrnbAhXKD8AKHerKDcgQ6AEISjAC#v=onepageandq=Modify%20the%20Security%20settings%20of%20the%20Computers%20container%202016andf=false
QUESTION 8
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
Your network contains an Active Directory domain named contoso.com.
The user account for a user named User1 is in an organizational unit (OU) named OU1.
You need to enable User1 to sign in as [email protected].
Solution: From Windows PowerShell, you run
Set-ADObject \\’CN=User1,OU=OU1,DC=Contoso,DC=com\\’
–Add @{UserPrincipalName=\\’[email protected]\\’}
–Remove @ {UserPrincipalName=\\’[email protected]\\’}.
Does this meet the goal?
A. Yes
B. No
Correct Answer: B
QUESTION 9
Your network contains an Active Directory domain named contoso.com.
The domain contains an enterprise root certification authority (CA) on a server that runs Windows Server 2016.
You need to configure the CA to support Online Certificate Status Protocol (OCSP) responders.
Which two actions should you perform? Each correct selection presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Add a new certificate template to issue.
B. Modify the Authority Information Access (AIA) of the CA.
C. Configure an enrollment agent.
D. Install a standalone subordinate CA.
E. Modify the CRL distribution point (CDP) of the CA.
Correct Answer: AB
Once the OCSP service is configured, we need to configure the OCSP Response Signing template. This process
includes adding an Authority Information Access (AIA) extension and then issuing a new certificate template.
References: https://www.poweradmin.com/blog/deploying-active-directory-certificate-services-and-online-responder/
QUESTION 10
You create a user account that will be used as a template for new user accounts.
Which setting will be copied when you copy the user account from Active Directory Users and Computers?
A. the Department attribute
B. the Description attribute
C. Permission
D. Remote Desktop Services Profile
Correct Answer: A
A user template in Active Directory can be used if you are creating users for a specific department, with exactly the
same properties, and membership to the same user groups. A user template is nothing more than a disabled user
account that has all these settings already in place.
References: http://www.rebeladmin.com/2014/07/create-users-with-user-templates-in-ad/
QUESTION 11
Your company has a main office and three branch offices. The network contains an Active Directory domain named
contoso.com.
The main office contains three domain controllers. Each branch office contains one domain controller.
You discover the new settings in the Default Domain Policy are not applied in one of the branch offices, but all other
Group Policy objects (GPOs) are applied.
You need to check the replication of the Default Domain Policy for the branch office.
What should you do from a domain controller in the main office?
A. From Group Policy Management, click Default Domain Policy under Contoso.com, and then open the Scope tab.
B. From a command prompt, run dcdiag.exe.
C. From a command prompt, run repadmin.exe.
D. From Windows PowerShell, run the Get-GPOReport cmdlet.
Correct Answer: C
QUESTION 12
Your network contains an Active Directory domain named contoso.com.
Some user accounts in the domain have the P.O. Box attribute set.
You plan to remove the value of the P.O. Box attribute for all of the users by using Ldifde.
You have a user named User1 who is located in the Users container.
How should you configure the LDIF file to remove the value of the P.O. Box attribute for User1? To answer, select the
appropriate options in the answer area.
Hot Area:
Correct Answer:
QUESTION 13
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
Your network contains the Active Directory forests and domains shown in the following table:
A two-way forest trust exists between ForestA and ForestB.
Each domain in ForestB contains user accounts that are used to manage servers.
You need to ensure that the user accounts used to manage the servers in ForestB are members of the Server
Operators in ForestA.
Solution: In each domain in ForestB, you create a global group that contains the user accounts of the respective
domain. You create a universal group in DomainBRoot. You add the new global groups to the new universal group. You
modify
the membership of the Server Operators in ForestA.
Does this meet the goal?
A. Yes
B. No
Correct Answer: A
References: https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directorysecurity-groups#bkmk-serveroperators
At Google Drive: Microsoft 70-742 PDF Dumps Download
Microsoft 70-742 PDF Dumps ( 2020 free )
https://drive.google.com/open?id=1ud1Ol6gLEAE1JhCHsOZgKadew8f9sUUr
2020 full year discount – Pass4itsure!
12% Off Coupon Code:”2020PASS“!Buy Pass4itsure all products valid all year.You still don’t act?
Why should you choose Pass4itsure Dumps to pass the exam in 2020
You can adopt all valid question and actual question from https://www.pass4itsure.com/70-742.html – set yourself up for 70-742 exam success!