aiotestking uk

70-742 Exam Questions - Online Test


70-742 Premium VCE File

Learn More 100% Pass Guarantee - Dumps Verified - Instant Download
150 Lectures, 20 Hours

Your success in is our sole target and we develop all our in a way that facilitates the attainment of this target. Not only is our material the best you can find, it is also the most detailed and the most updated. for Microsoft 70-742 are written to the highest standards of technical accuracy.

Free demo questions for Microsoft 70-742 Exam Dumps Below:

NEW QUESTION 1
You have an enterprise certification authority (CA). You create a global security group named Group1.
You need to provide members of Group1 with the ability to issue and manage certificates. The solution must prevent the Group1 members from managing certificates requested by members of the Domain Admins group.
Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • A. From the CA properties, modify the Policy Module settings.
  • B. From the Certificate Templates console, modify the Security settings of the Administrator certificate template.
  • C. From the CA properties, modify the security settings.
  • D. From the CA properties, modify the Enrollment Agents settings.
  • E. From the CA properties, modify the Certificate Managers Settings.
  • F. From the Certificate Templates console, modify the Security settings of the User certificate template.

Answer: AE

NEW QUESTION 2
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com. The domain contains two domain controllers named DC1 and DC2.
DC1 holds the RID master operations role. DC1 fails and cannot be repaired. You need to move the RID role to DC2.
Solution: On DC2, you open Windows PowerShell and run
Move-AddirectoryServerOperationMasterRole -OperationMasterRidMaster -Identity DC2.Adatum.com Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

Explanation: You would need to use the -Force parameter because the server that held the role (DC1) if offline.

NEW QUESTION 3
You network contains an Active Directory domain named contoso.com. The domain contains an enterprise certification authority (CA) named CA1.
You have a test environment that is isolated physically from the corporate network and the Internet.
You deploy a web server to the test environment. On CA1, you duplicate the Web Server template, and you name the template Web_Cert_Test.
For the web server, you need to request a certificate that does not contain the revocation information of CA1. What should you do first?

  • A. From the properties of CA1, allow certificates to be published to the file system.
  • B. From the properties of CA1, select Restrict enrollment agents, and then add Web_Cert_Test to the restricted enrollment agent.
  • C. From the properties of Web_Cert_Test, assign the Enroll permission to the guest account.
  • D. From the properties of Web_Cert_Test, set the Compatibility setting of CA1 to Windows Server 2021.

Answer: D

NEW QUESTION 4
Your network contains two Active Directory forests named fabrikam.com and contoso.com. Each forest contains two sites. Each site contains two domain controllers.
You need to configure all the domain controllers in both the forests as global catalog servers. Which snap-in should you us?

  • A. Active Directory Users and Computers
  • B. Active Directory Sites and Services
  • C. Active Directory Domains and Trusts
  • D. Active Directory Federation Services

Answer: B

NEW QUESTION 5
Your network contains an Active Directory domain.
Users do not have administrative privileges to their client computer You modify a computer setting in a Group Policy object (GPO).
You need to ensure that the setting is applied to five client computers as soon as possible. What should you do?

  • A. From a domain controller, run the gpudate.exe command and specify the Force parameter.
  • B. From each client computer, run the gpresult.exe command and specify the /r parameter.
  • C. From each client computer, run the Get-Gpo cmdlet and specify the -alt parameter.
  • D. From a domain controller, run the Invoke-GPUpdate cmdlet.

Answer: D

Explanation: https://technet.microsoft.com/en-us/library/hh852337(v=ws.11).aspx

NEW QUESTION 6
Your company has two offices. The offices are located in Montreal and Seattle. The network contains an Active Directory forest named contoso.com.
The forest contains three domain controllers configured as shown in the following table.
70-742 dumps exhibit
The company physically relocates Server2 from the Montreal office the Seattle office.
You discover that both Server1 and Server2 authenticate users who sign in to the client computers in the Montreal office. Only Server3 authentications users who sign in to the computers in the Seattle office.
You need to ensure that Server2 authenticates the users in the Seattle office during normal network operations. What should you do?

  • A. From Windows Power Shell, run the Move-AD Directory Server cmdlet.
  • B. From Active Directory Users and Computers, modify the Location property of Server2.
  • C. From Windows PowerShell, run the Set-ADReplicationSite cmdlet.
  • D. From Network Connections on Server2, modify the Internet Protocol Version 4 (TCP/IPv4) configuration.

Answer: C

NEW QUESTION 7
Your network contains an Active Directory domain named contoso.com. All the accounts of the users in the sales department are in an organizational unit (OU) named SalesOU.
An application named App1 is deployed to the user accounts in SalesOU by using a Group Policy object (GPO) named Sales GPO.
You need to set the registry value of HKEY_CURRENT_USERSoftwareApp1Collaboration to 0. Solution: You add a computer preference that has a Create action.
Does this meet the goal?

  • A. Yes
  • B. NO

Answer: B

NEW QUESTION 8
Your network contains an Active Directory domain named contoso.com. You need to create a central store for Group Policy administrator templates. What should you use?

  • A. Server Manager
  • B. File Explorer
  • C. Dcgpofix.exe
  • D. Group Policy Management Console (GPMC)

Answer: B

NEW QUESTION 9
Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series.
Information and details provided in a question apply only to that question.
Your network contains an Active Directory domain named contoso.com. The domain contains 5,000 user accounts.
You have a Group Policy object (GPO) named DomainPolicy that is linked to the domain and a GPO named DCPolicy that is linked to the Domain Controllers organizational unit (OU).
You need to force users to change their account password at least every 30 days. What should you do?

  • A. From the Computer Configuration node of DCPolicy, modify Security Settings.
  • B. From the Computer Configuration node of DomainPolicy, modify Security Settings.
  • C. From the Computer Configuration node of DomainPolicy, modify Administrative Templates.
  • D. From the User Configuration node of DCPolicy, modify Security Settings.
  • E. From the User Configuration node of DomainPolicy, modify Folder Redirection.
  • F. From user Configuration node of DomainPolicy, modify Administrative Templates.
  • G. From Preferences in the User Configuration node of DomainPolicy, modify Windows Settings.
  • H. From Preferences in the Computer Configuration node of DomainPolicy, modify Windows Settings.

Answer: B

NEW QUESTION 10
Your network contains an Active Directory forest. The forest contains one domain named contoso.com. The domain contains two domain controllers named DC1 and DC2. DC1 holds all of the operations master roles.
During normal network operations, you run the following commands on DC2:
Move-ADDirectoryServerOperationMasterRole -Identity “DC2” -OperationMasterRole PDCEmulator Move- ADDirectoryServerOperationMasterRole –Identity “DC2” -OperationMasterRole RIDMaster DC1 fails.
You remove DC1 from the network, and then you run the following command:
Move-ADDirectoryServerOperationMasterRole –Identity “DC2” -OperationMasterRole SchemaMaster For each of the following statements, select Yes if the statement is true. Otherwise, select No.
70-742 dumps exhibit

    Answer:

    Explanation: 70-742 dumps exhibit

    NEW QUESTION 11
    You create a user account that will be used as a template for new user accounts.
    Which setting will be copied when you copy the user account from Active Directory Users and Computers?

    • A. the Department attribute
    • B. the Description attribute
    • C. Permission
    • D. Remote Desktop Services Profile

    Answer: A

    Explanation: A user template in Active Directory can be used if you are creating users for a specific department, with exactly the same properties, and membership to the same user groups. A user template is nothing more than a disabled user account that has all these settings already in place.
    References:
    http://www.rebeladmin.com/2014/07/create-users-with-user-templates-in-ad/

    NEW QUESTION 12
    Your network contains an Active Directory forest named contoso.com. The forest contains a member server named Server1. Server1 has several line-of-business applications. Each application runs as a service that uses the Network Service account. You need to configure the line-of-business applications to run by using a virtual account. What should you do?

    • A. From the Services console, modify the Log On properties of the services.
    • B. From the Microsoft Application Compatibility Toolkit (ACT), create a shim.
    • C. From Windows PowerShell, run the Install-ADScrviceAccount cmdlet.
    • D. From Windows PowerShell, run the New-ADServiccAccount cmdlet.

    Answer: A

    NEW QUESTION 13
    Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.
    Start of repeated scenario.
    You work for a company named Contoso, Ltd.
    The network contains an Active Directory forest named contoso.com. A forest trust exists between contoso.com and an Active Directory forest named adatum.com.
    The contoso.com forest contains the objects configured as shown in the following table.
    70-742 dumps exhibit
    Group1 and Group2 contain only user accounts.
    Contoso hires a new remote user named User3. User3 will work from home and will use a computer named
    Computer3 that runs Windows 10. Computer3 is currently in a workgroup.
    An administrator named Admin1 is a member of the Domain Admins group in the contoso.com domain. From Active Directory Users and Computers, you create an organizational unit (OU) named OU1 in the
    contoso.com domain, and then you create a contact named Contact1 in OU1.
    An administrator of the adatum.com domain runs the Set-ADUser cmdlet to configure a user named User1 to have a user logon name of User1@litwareinc.com.
    End or repeated scenario.
    You need to ensure that Admin1 can add Group2 as a member of Group3. What should you modify?

    • A. Modify the Security settings of Group3.
    • B. Modify the group scope of Group3.
    • C. Modify the group type of Group3.
    • D. Set Admin1 as the manager of Group3.

    Answer: B

    NEW QUESTION 14
    Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server 2021.
    Server1 has IP Address Management (IPAM) installed. Server2 has the DHCP Server role installed. The IPAM server retrieves data from Server2.
    You create a domain user account named User1.
    You need to ensure that User1 can use IPAM to manage DHCP.
    Which command should you run on Server1? To answer, select the appropriate options in the answer area.
    70-742 dumps exhibit

      Answer:

      Explanation: 70-742 dumps exhibit

      NEW QUESTION 15
      Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server 2021.
      Server1 has IP Address Management (IPAM) installed. Server2 has the DHCP Server role installed. The IPAM server retrieves data from Server2.
      The domain has two users named User1 and User2 and a group named Group1. User1 is the only member of Group1.
      Server1 has one IPAM access policy. You edit the access policy as shown in the Policy exhibit. (Click the Exhibit button.)
      70-742 dumps exhibit
      The DHCP scopes are configured as shown in the Scopes exhibit. (Click the Exhibit button.)
      70-742 dumps exhibit
      For each of the following statements, select Yes if the statement is true. Otherwise, select No.
      70-742 dumps exhibit

        Answer:

        Explanation: 70-742 dumps exhibit

        NEW QUESTION 16
        Your network contains an Active Directory forest named contoso.com. The forest contains three domains named contoso.com, corp.contoso.com, and ext.contoso.com. The forest contains three Active Directory sites named Site1, Site2, and Site3.
        You have the three administrators as described in the following table.
        70-742 dumps exhibit
        You create a Group Policy object (GPO) named GPO1.
        Which administrator or administrators can link GPO1 to Site2?

        • A. Admin1 and Admin2 only
        • B. Admin1, Admin2, and Admin3
        • C. Admin3 only
        • D. Admin1 and Admin3 only

        Answer: D

        Explanation: References:
        https://technet.microsoft.com/en-us/library/cc732979(v=ws.11).aspx

        NEW QUESTION 17
        Your network contains an Active Directory domain named contoso.com. The domain contains a user named User1 and an organizational unit (OU) named OU1.
        You create a Group Policy object (GPO) named GPO1. You need to ensure that User1 can link GPO1 to OU1. What should you do?

        • A. Modify the security setting of User1.
        • B. Add User1 to the Group Policy Creator Owner group.
        • C. Modify the security setting of OU1.
        • D. Modify the security setting of GPO1.

        Answer: D

        NEW QUESTION 18
        Your network contains an Active Directory forest named contoso.com. The forest contains 10 domains. The root domain contains a global catalog server named DC1.
        You remove the global catalog server role from DC1.
        You need to decrease the size of the Active Directory database on DC1.
        Solution:You restart DC1 in Directory Services Repair Mode. You run compact.exe, and then restart DC1. Does this meet the goal?

        • A. Yes
        • B. No

        Answer: B

        Explanation: You need to run ntdsutil.exe with the ‘compact to’ option. References:
        https://theitbros.com/active-directory-database-compact-defrag/

        100% Valid and Newest Version 70-742 Questions & Answers shared by Dumpscollection, Get Full Dumps HERE: http://www.dumpscollection.net/dumps/70-742/ (New 222 Q&As)