70-742 exam dumps 70-742 exam questions 70-742 free dumps 70-742 practice dumps 70-742 study guide latest 70-742 braindumps MCSA

[Newest Version] Free Geekcert Microsoft 70-742 PDF and Exam Questions Download 100% Pass Exam

Geekcert 2021 Valid Microsoft 70-742 MCSA Exam VCE and PDF Dumps for Free Download!

70-742 MCSA Exam PDF and VCE Dumps : 289QAs Instant Download: https://www.geekcert.com/70-742.html [100% 70-742 Exam Pass Guaranteed or Money Refund!!]
☆ Free view online pdf on Geekcert free test 70-742 PDF: https://www.geekcert.com/online-pdf/70-742.pdf

How to pass Hotest 70-742 study guide exam easily with less time? Geekcert provides the most valid Hotest 70-742 pdf dumps exam preparation material to boost your success rate in Microsoft MCSA Hotest 70-742 study guide Identity with Windows Server 2016 exam. If you are one of the successful candidates with Geekcert Dec 15,2021 Newest 70-742 pdf PDF and VCEs, do not hesitate to share your reviews on our Microsoft MCSA materials.

latest microsoft, cisco, comptia,oracle,ibm,sun,juniper,hp and all 70-742 certification dumps – Geekcert. Geekcert – your reliable partner and professional 70-742 certification exam material provider. Geekcert it exam study material and real exam questions and answers help you pass 70-742 exams and get 70-742 certifications easily.

We Geekcert has our own expert team. They selected and published the latest 70-742 preparation materials from Microsoft Official Exam-Center: https://www.geekcert.com/70-742.html

The following are the 70-742 free dumps. Go through and check the validity and accuracy of our 70-742 dumps.The following questions and answers are from the latest 70-742 free dumps. It will help you understand the validity of the latest 70-742 dumps.

Question 1:

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while

others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You network contains an Active Directory forest named contoso.com. The forest contains an Active Directory Rights Management Services (AD RMS) deployment.

Your company establishes a partnership with another company named Fabrikam, Inc. The network of Fabrikam contains an Active Directory forest named fabrikam.com and an AD RMS deployment.

You need to ensure that the users in contoso.com can access rights protected documents sent by the users in fabrikam.com.

Solution: From AD RMS in fabrikam.com, you configure contoso.com as a trusted publisher domain.

Does this meet the goal?

A. Yes

B. No

Correct Answer: B

Contoso needs to trust Fabrikam.

References: https://books.google.co.za/books?id=gjR-BAAAQBAJandpg=PA397andlpg=PA397anddq=configure a partners forest as a trusted publishing domain – AD RMSandsource=blandots=mohQXTyW9sandsig=NJ7oFHuLYOs72o9EMyQiIscUW8andhl=enandsa=Xandved=0ahUKEwjuivW24sPbAhWGRMAKHQcEB6EQ6AEIOzAD#v=onepageandq=configure a partners forest as a trusted publishing domain – AD RMSandf=false


Question 2:

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an Active Directory forest named contoso.com. The forest contains a member server named Server1 that runs Windows Server 2016. All domain controllers run Windows Server 2012 R2.

Contoso.com has the following configuration.

PS C:\> (Get-ADForest).ForestMode

Windows2008R2Forest PS C:\> (Get-ADDomain).DomainMode Windows2008R2Domain PS C:\>

You plan to deploy an Active Directory Federation Services (AD FS) farm on Server1 and to configure device registration.

You need to configure Active Directory to support the planned deployment.

Solution: You upgrade a domain controller to Windows Server 2016.

Does this meet the goal?

A. Yes

B. No

Correct Answer: A

Device Registration requires Windows Server 2012 R2 forest schema. Upgrading a domain controller will run adprep.exe to upgrade the schema as part of the upgrade process.

References: https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/configure-a-federation-server-with-device-registration-service https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/upgrade-domain-controllers-towindows-server-2012-r2-and-windows-server-2012


Question 3:

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while

others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2016. The computer account for Server1 is in organizational unit (OU) named OU1.

You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1.

You need to add a domain user named User1 to the local Administrators group on Server1.

Solution: From a domain controller, you run the Set-AdComputer cmdlet.

Does this meet the goal?

A. Yes

B. No

Correct Answer: B

The Set-AdComputer cmdlet modifies an Active Directory computer object. It will not allow you to add a domain user to a local Administrators group. References: https://technet.microsoft.com/es-es/library/hh852268(v=wps.620).aspx


Question 4:

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while

others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2016. The computer account for Server1 is in organizational unit (OU) named OU1.

You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1.

You need to add a domain user named User1 to the local Administrators group on Server1.

Solution: From the Computer Configuration node of GPO1, you configure the Local Users and Groups preference.

Does this meet the goal?

A. Yes

B. No

Correct Answer: A

to add uses to the Local Administrator built In group on all the computers using Group Policy, open group policy editor and create or edit existing GPO. Go to User Configuration -> Preferences -> Control Panel Settings -> Local users and groups.

References: https://www.ntweekly.com/2015/01/10/how-to-add-users-to-local-admin-group-using-group-policy-windows-server-2012/


Question 5:

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while

others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named Server1.

You recently restored a backup of the Active Directory database from Server1 to an alternate Location. The restore operation does not interrupt the Active Directory services on Server1.

You need to make the Active Directory data in the backup accessible by using Lightweight Directory Access Protocol (LDAP).

Which tool should you use?

A. Dsadd quota

B. Dsmod

C. Active Directory Administrative Center

D. Dsacls

E. Dsamain

F. Active Directory Users and Computers

G. Ntdsutil

H. Group Policy Management Console

Correct Answer: E

Dsamain.exe, allows an ntds.dit file to be mounted and exposed as an LDAP server, which means you can use such familiar tools as ADSIEdit, LDP.exe, and Active Directory Users and Computers to interact with a mounted database.

References: http://www.itprotoday.com/windows-8/using-active-directory-snapshots-and-dsamain-tool


Question 6:

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series.

Information and details provided in a question apply only to that question.

Your network contains an Active Directory domain named contoso.com.

You need to limit the number of Active Directory Domain Services (AD DS) objects that a user can create in the domain.

Which tool should you use?

A. Dsadd quota

B. Dsmod

C. Active Directory Administrative Center

D. Dsacls

E. Dsamain

F. Active Directory Users and Computers

G. Ntdsutil

H. Group Policy Management Console

Correct Answer: A

Dsadd quota adds a quota specification to a directory partition. A quota specification determines the maximum number of directory objects that a given security principal can own in a specified directory partition.

References: https://blogs.technet.microsoft.com/activedirectoryua/2009/03/19/active-directory-quotas/


Question 7:

You have users that access web applications by using HTTPS. The web applications are located on the servers in your perimeter network. The servers use certificates obtained from an enterprise root certification authority (CA). The

certificates are generated by using a custom template named WebApps. The certificate revocation list (CRL) is published to Active Directory.

When users attempt to access the web applications from the Internet, the users report that they receive a revocation warning message in their web browser. The users do not receive the message when they access the web applications from

the intranet.

You need to ensure that the warning message is not generated when the users attempt to access the web applications from the Internet. What should you do?

A. Install the Certificate Enrollment Web Service role service on a server in the perimeter network.

B. Modify the WebApps certificate template, and then issue the certificates used by the web application servers.

C. Install the Web Application Proxy role service on a server in the perimeter network. Create a publishing point for the CA.

D. Modify the CRL distribution point, and then reissue the certificates used by the web application servers.

Correct Answer: D


Question 8:

Your network contains an Active Directory forest named contoso.com. The forest contains several domains.

An administrator named Admin01 installs Windows Server 2016 on a server named Server1 and then joins Server1 to the contoso.com domain.

Admin01 plans to configure Server1 as an enterprise root certification authority (CA).

You need to ensure that Admin01 can configure Server1 as an enterprise CA. The solution must use the principle of least privilege.

To which group should you add Admin01?

A. Server Operators in the contoso.com domain

B. Cert Publishers on Server1

C. Enterprise Key Admins in the contoso.com domain

D. Enterprise Admins in the contoso.com domain.

Correct Answer: D

To install Active Directory Certificate Services, log on as a member of both the Enterprise Admins group and the root domain\’s Domain Admins group. References: https://docs.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/install-the-certification-authority


Question 9:

Your network contains an Active Directory forest named contoso.com. The forest contains three domains named contoso.com, corp.contoso.com, and ext.contoso.com. The forest contains three Active Directory sites named Site1, Site2, and Site3.

You have the three administrators as described in the following table.

You create a Group Policy object (GPO) named GPO1. Which administrator or administrators can link GPO1 to Site2?

A. Admin1 and Admin2 only

B. Admin1, Admin2, and Admin3

C. Admin3 only

D. Admin1 and Admin3 only

Correct Answer: D

To link an existing GPO to a site, domain, or OU, you must have Link GPOs permission on that site, domain, or OU. By default, only domain administrators and enterprise administrators have this privilege for domains and OUs. Enterprise administrators and domain administrators of the forest root domain have this privilege for sites.

References: https://technet.microsoft.com/en-us/library/cc732979(v=ws.11).aspx


Question 10:

Your network contains an Active Directory domain named contoso.com. The domain contains a Group Policy object (GPO) named GPO1.

You configure the Internet Settings preference in GPO1 as shown in the exhibit. (Click the Exhibit button.)

A user reports that the homepage of Internet Explorer is not set to http://www.contoso.com.

You confirm that the other settings in GPO1 are applied.

You need to configure GPO1 to set the Internet Explorer homepage.

What should you do?

A. Edit the GPO1 preference and press F5.

B. Modify Security Settings for GPO1.

C. Modify WMI Filtering for GPO1.

D. Modify the GPO1 preference to use item-level targeting.

Correct Answer: A

The red dotted line under the homepage URL means that setting is disabled. Pressing F5 enables all settings. References: https://community.spiceworks.com/topic/285312-add-default-website-in-group-policy


Question 11:

You network contains an Active Directory domain named contoso.com. The domain contains 1,000 desktop computers and 500 laptops. An organizational unit (OU) named OU1 contains the computer accounts for the desktop computers and

the laptops.

You create a Windows PowerShell script named Script1.ps1 that removes temporary files and cookies. You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1.

You need to run the script once weekly only on the laptops.

What should you do?

A. In GPO1, create a File preference that uses item-level targeting.

B. In GPO1, create a Scheduled Tasks preference that uses item-level targeting.

C. In GPO1, configure the File System security policy. Attach a WMI filter to GPO1.

D. In GPO1, add Script1.ps1 as a startup script. Attach a WMI filter to GPO1.

Correct Answer: B


Question 12:

Your network contains an Active Directory domain named contoso.com.

You have an organizational unit (OU) named TestOU that contains test computers.

You need to enable a technician named Tech1 to create Group Policy objects (GPOs) and to link the GPOs to TestOU. The solution must use the principle of least privilege.

Which two actions should you perform? Each correct answer presents part of the solution.

A. Add Tech1 to the Group Policy Creator Owners group.

B. From Group Policy Management, modify the Delegation settings of the TestOU OU.

C. Add Tech1 to the Protected Users group.

D. From Group Policy Management, modify the Delegation settings of the contoso.com container.

E. Create a new universal security group and add Tech1 to the group.

Correct Answer: AB

The Group Policy Creator Owners group lets its members create new GPOs.

You can delegate the ability for users to be given the ability to link GPOs to an OU or domain via the Delegation tab of the OU/domain/site within the GPMC.

References:

http://www.itprotoday.com/management-mobility/what-group-policy-creator-owners-group

http://www.itprotoday.com/management-mobility/how-do-i-delegate-permissions-someone-edit-gpo


Question 13:

Your company recently deployed a new child domain to an Active Directory forest.

You discover that a user modified the Default Domain Policy to configure several Windows components in the child domain.

A company policy states that the Default Domain Policy must be used only to configure domain-wide security settings.

You create a new Group Policy object (GPO) and configure the settings for the Windows components in the new GPO.

You need to restore the Default Domain Policy to the default settings from when the domain was first installed.

What should you do?

A. From Group Policy Management, click Starter GPOs, and then click Manage Backups.

B. From a command prompt, run the dcgpofix.exe command.

C. From Windows PowerShell, run the Copy-GPO cmdlet.

D. Run ntdsutil.exe to perform a metadata cleanup and a semantic database analysis.

Correct Answer: B


Question 14:

Your network contains an Active Directory domain named contoso.com.

You open Group Policy Management as shown in the exhibit. (Click the Exhibit button.)

You discover that some of the settings configured in the A1 Group Policy object (GPO) fail to apply to the users in the OU1 organizational unit (OU).

You need to ensure that all of the settings in A1 apply to the users in OU1.

What should you do?

A. Enable loopback policy processing in A1.

B. Block inheritance on OU1.

C. Modify the policy processing order for OU1.

D. Modify the GPO Status of A1.

E. Modify Security Settings for A1

Correct Answer: C

Reference: https://blogs.technet.microsoft.com/musings_of_a_technical_tam/2012/02/15/group-policy-basics-part-2-understanding-which-gpos-to-apply/


Question 15:

Your network contains an Active Directory domain named contoso.com.

You have a Group Policy object (GPO) named GPO1. GPO1 is linked to an organizational unit (OU) named OU1.

GPO1 contains several corporate desktop restrictions that apply to all computers.

You plan to deploy a printer to the computers in OU1.

You need to ensure that any user who signs in to a computer that runs Windows 10 in OU1 receives the new printer. All of the computers in OU1 must continue to apply the corporate desktop restrictions from GPO1.

What should you configure?

A. a user preference and a WMI filter on GPO1.

B. a computer preference that uses item-level targeting

C. a computer preference and WMI filter on GPO1

D. a user preference that uses item-level targeting

Correct Answer: B


Geekcert exam braindumps are pass guaranteed. We guarantee your pass for the 70-742 exam successfully with our Microsoft materials. Geekcert Identity with Windows Server 2016 exam PDF and VCE are the latest and most accurate. We have the best Microsoft in our team to make sure Geekcert Identity with Windows Server 2016 exam questions and answers are the most valid. Geekcert exam Identity with Windows Server 2016 exam dumps will help you to be the Microsoft specialist, clear your 70-742 exam and get the final success.

70-742 Microsoft exam dumps (100% Pass Guaranteed) from Geekcert: https://www.geekcert.com/70-742.html [100% Exam Pass Guaranteed]