Virtual Microsoft 70-742 Bootcamp

Certleader offers free demo for 70-742 exam. \"Identity with Windows Server 2016\", also known as 70-742 exam, is a Microsoft Certification. This set of posts, Passing the Microsoft 70-742 exam, will help you answer those questions. The 70-742 Questions & Answers covers all the knowledge points of the real exam. 100% real Microsoft 70-742 exams and revised by experts!

Page: 1 / 22
Total 266 questions Full Exam Access
Question 1
Your network contains an Active Directory domain named contoso.com. The domain contains an Active Directory Federation Services (AD FS) server named Server1.
On a standalone server named Server2. You install and configure the Web Application Proxy.
You have an internal web application named WebApp1. AD FS has a replying party trust for WebApp1. You need to provide external users with access to WebApp1. Authentication to WebApp1, must use AD FS
preauthentication.
Which tool should you use to publish webapp1?
My answer: -
Reference answer: E
Reference analysis:

None

Question 2
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com. A user named User1 is in an organizational unit (OU) named OU1.
You need to enable User1 to sign in as user1@adatum.com.
You need a list of groups to which User1 is either a direct member or an indirect member.
Solution: From Windows PowerShell, you run Set -Aduser User1 -UserPricncipalName User1@Adatum.com. Does this meet the goal?
My answer: -
Reference answer: B
Reference analysis:

None

Question 3
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2016. The computer account for Server1 is in organizational unit (OU) named OU1.
You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1.
You need to add a domain user named User1 to the local Administrators group on Server1. Solution: From a domain controller, you run the Set-AdComputer cmdlet.
Does this meet the goal?
My answer: -
Reference answer: B
Reference analysis:

None

Question 4
A technician named Tech1 is assigned the task of joining the laptops to the domain. The computer accounts of each laptop must be in an organizational unit (OU) that is associated to the department of the user who will use that laptop. The laptop names must start with four characters indicating the department followed by a
four-digit number
Tech1 is a member of the Domain Users group only. Tech1 has the administrator logon credentials for all the laptops.
You need Tech1 to join the laptops to the domain. The solution must ensure that the laptops are named correctly, and that the computer accounts of the laptops are in the correct OUs.
Solution: You pre-create the computer account of each laptop in Active Directory users and computers. You instruct Tech1 to sign in to each laptop, and then to run djoin.exe.
Does this meet the goal?
My answer: -
Reference answer: B
Reference analysis:

None

Question 5
Your network contains an Active Directory domain named contoso.com. The domain contains a Group Policy object (GPO) named GPO1.
You configure the Internet Settings preference in GPO1 as shown in the exhibit. (Click the Exhibit button.)
70-742 dumps exhibit
A user reports that the homepage of Internet Explorer is not set to http://www.contoso.com. You confirm that the other settings in GPO1 are applied.
You need to configure GPO1 to set the Internet Explorer homepage. What should you do?
My answer: -
Reference answer: A
Reference analysis:

The red dotted line under the homepage URL means that setting is disabled. Pressing F5 enables all settings.

Question 6
Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.
Start of repeated scenario.
Your network contains an Active Directory domain named contoso.com. The domain contains a single site named Site1. All computers are in Site1.
The Group Policy objects (GPOs) for the domain are configured as shown in the exhibit. (Click the Exhibit button.)
70-742 dumps exhibit
The relevant users and client computer in the domain are configured as shown in the following table.
70-742 dumps exhibit
End of repeated scenario.
Which five GPOs will apply to User1 in sequence when the user signs in to Computer1? To answer, move the appropriate GPOs from the list to the answer area and arrange them in the correct order.
70-742 dumps exhibit
Solution:
70-742 dumps exhibit

Does this meet the goal?
My answer: -
Reference answer: A
Reference analysis:

None

Question 7
You are deploying a web application named WebApp1 to your internal network. WebApp1 is hosted on a server named Web1 that runs Windows Server 2016.
You deploy an Active Directory Federation Services (AD FS) infrastructure and a Web Application Proxy to provide access to WebApp1 for remote users.
You need to ensure that Web1 can authenticate the remote users. What should you do?
My answer: -
Reference answer: A
Reference analysis:

None

Question 8
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a server named Web1 that runs Windows Server 2016.
You need to list all the SSL certificates on Web1 that will expire during the next 60 days. Solution: You run the following command.
Get-ChildItem Cert:\LocalMachine\My |? { $_.NotAfter –It (Get-Date).AddDays( 60 ) } Does this meet the goal?
My answer: -
Reference answer: B
Reference analysis:

None

Question 9
Your network contains an Active Directory forest. The forest functional level is Windows Server 2016. You have a failover cluster named Cluster1. Cluster1 has two nodes named Server1 and Server2. All the
optional features in Active Directory are enabled.
A junior administrator accidentally deletes the computer object named Cluster1. You discover that Cluster1 is offline.
You need to restore the operation of Cluster1 in the least amount of time possible. What should you do?
My answer: -
Reference answer: D
Reference analysis:

None

Question 10
Your network contains two network domains sales.fabrikam.com, and contoso.com, You recently added a site named Europe.
The forest contains four users who are members of the groups shown in the following table.
70-742 dumps exhibit
You need to create a Group Policy object (GPO) named GP01 and to link GPO1 to the Europe site. Which users can perform each task? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point
70-742 dumps exhibit
Solution:
70-742 dumps exhibit

Does this meet the goal?
My answer: -
Reference answer: A
Reference analysis:

None

Question 11
Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.
Start of repeated scenario.
Your network contains an Active Directory domain named contoso.com. The domain contains a single site named Site1. All computers are in Site1.
The Group Policy objects (GPOs) for the domain are configured as shown in the exhibit. (Click the Exhibit button.)
70-742 dumps exhibit
The relevant users and client computer in the domain are configured as shown in the following table.
70-742 dumps exhibit
End of repeated scenario.
You are evaluating what will occur when you block inheritance on OU4.
Which GPO or GPOs will apply to User1 when the user signs in to Computer1 after block inheritance is configured?
My answer: -
Reference answer: D
Reference analysis:

None

Question 12
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2016.
You install IP Address Management (IPAM) on Server1. You select the automatic provisioning method, and then you specify a prefix of IPAM1.
You need to configure the environment for automatic IPAM provisioning.
Which cmdlet should you run? To answer, select the appropriate options in the answer area.
70-742 dumps exhibit
Solution:
70-742 dumps exhibit

Does this meet the goal?
My answer: -
Reference answer: A
Reference analysis:

None

Question 13
You have an Active Directory Rights Management Services (AD RMS) server named RMS1. Multiple documents are protected by using RMS1.
RMS1 fails and cannot be recovered.
You install the AD RMS server role on a new server named RMS2. You restore the AD RMS database from RMS1 to RMS2.
Users report that they fail to open the protected documents and to protect new documents. You need to ensure that the users can access the protected content.
What should you do?
My answer: -
Reference answer: D
Reference analysis:

None

Question 14
Your network contains an Active Directory domain named contoso.com.
The user account for a user named User1 is in an organizational unit (OU) named OU1. You need to enable User1 to sign in as user1@adatum.com.
Solution: From Windows PowerShell, You run Set-ADuser User1 –UserPrincipalName User1@Adatum.com. Does this meet the goal?
My answer: -
Reference answer: A
Reference analysis:

None

Question 15
Your network contains an Active Directory domain named contoso.com. You deploy a standalone root certification authority (CA) named CA1.
You need to auto enroll domain computers for certificates by using a custom certificate template. What should you do first?
My answer: -
Reference answer: D
Reference analysis:

You can’t create templates or configure auto-enrollment on a standalone CA.

Question 16
Your network contains an Active Directory forest. The forest contains a domain named contoso.com. The domain contains three domain controllers.
A domain controller named lon-dc1 fails. You are unable to repair lon-dc1.
You need to prevent the other domain controllers from attempting to replicate to lon-dc1.
Solution: From Active Directory Users and Computers, you remove the computer account of lon-dc1. Does this meet the goal?
My answer: -
Reference answer: A
Reference analysis:

To remove the failed server object from the domain controllers container, access Active Directory Users and Computers, expand the domain controllers container, and delete the computer object associated with the failed domain controller
References: https://www.petri.com/delete_failed_dcs_from_ad

Question 17
Your company has a marketing department.
The network contains an Active Directory domain named contoso.com.
The main office contains three domain controllers. Each branch office contains one domain controller.
You discover that new settings in the Default Domain Policy are not applied on one of the branch offices, but all other Group Policy objects (GPOs) are applied.
You need to check the replication of the Default Domain Policy for the branch Office. What should you do from a domain controller in the main office?
My answer: -
Reference answer: A
Reference analysis:

None

Question 18
Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.
Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named Server1.
You recently restored a backup of the Active Directory database from Server1 to an alternate Location. The restore operation does not interrupt the Active Directory services on Server1.
You need to make the Active Directory data in the backup accessible by using Lightweight Directory Access Protocol (LDAP).
Which tool should you use?
My answer: -
Reference answer: E
Reference analysis:

None

Question 19
Your network contains an Active Directory domain named contoso.com.
A user named User1 and a computer named Conputer1 are in an organizational unit OU1. A user named User2 and a computer named Computer 2 are in an OU named OU2.
A Group Policy object (GPO) named GPO1 is linked to the domain. GPO1 contains a user preference that is configured as shown in the Shortcut1 Properties exhibit. (Click the Exhibit button.)
70-742 dumps exhibit
Item-level targeting for the user preference is configured as shown in the Targeting exhibit. (Click the Exhibit button.)
70-742 dumps exhibit
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
70-742 dumps exhibit
Solution:
References:
https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc73075

Does this meet the goal?
My answer: -
Reference answer: A
Reference analysis:

None

Question 20
Your network contains an Active Directory forest. The forest contains two domains named litwarenc.com and contoso.com. The contoso.com domain contains two domains controllers named LON-DC01 and LON-DC02.
The domain controllers are located in a site named London that is associated to a subnet of 192.168.10.0/24
You discover that LON-DC02 is not a global catalog server. You need to configure LON-DC02 as a global catalog server.
What should you do?
My answer: -
Reference answer: A
Reference analysis:

None

Question 21
Your network contains an Active Directory named contoso.com
You have three top-level organizational units (OUs) named OU1, OU2 and OU3. OU1 contains user accounts. OU2 contains the computer accounts for shared public computers. 0U3 contains the computer accounts for laptops.
You have two Group Policy objects (GPOs) named GPO1 and GP02. GPO1 is linked to OU1. GP02 is linked to OU2.
You need to prevent the user settings in GPO1 from being applied when a user signs in to a shared public computer. If a user signs in to a laptop, the user settings in GPO1 must be applied.
What should you configure?
My answer: -
Reference answer: C
Reference analysis:

None

Question 22
Your network contains an Active Directory domain named contoso.com.
All the accounts of the users in the sales department are in an organizational unit (OU) named SalesOU. An application named App1 is deployed to the user accounts in SalesOU by using a Group Policy object
(GPO) named SalesGPO. You need to set the registry value of
\HKEY_CURRENT_USER\Software\App1\CoIlaboration to 0.
Solution: You add a user preference that has an Update action. Does this meet the goal?
My answer: -
Reference answer: A
Reference analysis:

None

Question 23
You network contains an Active Directory domain named contoso.com. The domain contains an enterprise certification authority (CA) named CA1.
You have a test environment that is isolated physically from the corporate network and the Internet.
You deploy a web server to the test environment. On CA1, you duplicate the Web Server template, and you name the template Web_Cert_Test.
For the web server, you need to request a certificate that does not contain the revocation information of CA1. What should you do first?
My answer: -
Reference answer: D
Reference analysis:

None

Question 24
Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server 2016.
Server1 has IP Address Management (IPAM) installed. Server2 has the DHCP Server role installed. The IPAM server retrieves data from Server2.
You create a domain user account named User1.
You need to ensure that User1 can use IPAM to manage DHCP.
Which command should you run on Server1? To answer, select the appropriate options in the answer area.
70-742 dumps exhibit
Solution:
70-742 dumps exhibit

Does this meet the goal?
My answer: -
Reference answer: A
Reference analysis:

None

Question 25
Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.
Start of repeated scenario.
Your network contains an Active Directory domain named contoso.com. The domain contains a single site named Site1. All computers are in Site1.
The Group Policy objects (GPOs) for the domain are configured as shown in the exhibit. (Click the Exhibit button.)
70-742 dumps exhibit
The relevant users and client computer in the domain are configured as shown in the following table.
70-742 dumps exhibit
End of repeated scenario.
You are evaluating what will occur when you disable the Group Policy link for A6.
Which GPOs will apply to User2 when the user signs in to Computer1 after the link for A6 is disabled?
My answer: -
Reference answer: D
Reference analysis:

None

Question 26
Your network contains an Active Directory domain named contoso.com. The domain contains three servers named Server1, Server2, and Server3 that run Windows Server 2016.
Server1 has IP Address Management (IPAM) installed. Server2 and Server3 have the DHCP Server role installed and have several DHCP scopes configured. The IPAM server retrieves data from Server2 and Server3.
A domain user named User1 is a member of the groups shown in the following table.
70-742 dumps exhibit
On Server1, you create a security policy for User1. The policy grants the IPAM DHCP Scope Administrator Role with the \Global access scope to the user.
Which actions can User1 perform? To answer, select the appropriate options in the answer area.
70-742 dumps exhibit
Solution:
User1 is using Server Manager, not IPAM to perform the administration. Therefore, only the “DHCP Administrators” permission on Server2 and the “DHCP Users” permissions on Server3 are applied.
The permissions granted through membership of the “IPAM DHCP Scope Administrator Role” are not applied when the user is not using the IPAM console.

Does this meet the goal?
My answer: -
Reference answer: A
Reference analysis:

None

Question 27
Your company has a main office and three branch offices. The network contains an Active Directory domain named contoso.com.
The main office contains three domain controllers. Each branch office contains one domain controller.
You discover the new settings in the Default Domain Policy are not applied in one of the branch offices, but all other Group Policy objects (GPOs) are applied.
You need to check the replication of the Default Domain Policy for the branch office. What should you do from a domain controller in the main office?
My answer: -
Reference answer: C
Reference analysis:

None

Question 28
Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1.
You create and link a Group Policy object (GPO) named SalesAppGPO to an organizational unit (OU) named SalesOU. All the computer accounts are in the Computers container. All the user accounts of the users in the sales department are in SalesOU.
You have a line-of-business application named SalesApp that is installed by using a Windows Installer package.
You need to make SalesApp available to only the sales department users.
Which three actions should you perform in sequence? To answer move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
70-742 dumps exhibit
Solution:
70-742 dumps exhibit

Does this meet the goal?
My answer: -
Reference answer: A
Reference analysis:

None

Question 29
Your network contains an Active Directory forest. The forest contains two domains named litwarenc.com and contoso.com. The contoso.com domain contains two domains controllers named LON-DC01 and LON-DC02. The domain controllers are located in a site named London that is associated to a subnet of 192.168.10.0/24
You discover that LON-DC02 is not a global catalog server. You need to configure LON-DC02 as a global catalog server. What should you do?
My answer: -
Reference answer: C
Reference analysis:

None

Question 30
You have an internal web server that hosts websites. The websites use HTTP and HTTPS. You deploy a Web Application Proxy to your perimeter network.
You need to ensure that users from the Internet can access the websites by using HTTPS only. Internet access to the websites must use the Web Application Proxy.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
My answer: -
Reference answer: AE
Reference analysis:

None

Page: 1 / 22
Total 266 questions Full Exam Access