Microsoft Identity with Windows Server 2016 70-742 Exam Questions

Page: 1 / 14
Total 285 questions
Question 1

Your network contains an Active Directory domain named contoso.com.

You have an application named App1 that is deployed to all the client computers in the domain. App1 writes a registry value named LocalStorage on all the client computers.

You need to delete the LocalStorage registry value from all the client computers in the domain that have less than 100 GB of free disk space on their system volume.

What should you do?



Answer : D

In Windows Server 2008 Microsoft introduced a Group Policy extension, named Group Policy Preferences (GPP). GPP that includes registry settings, allows you to add, remove or modify key values.

References: https://theitbros.com/add-modify-and-delete-registry-keys-using-group-policy/


Question 2

Your network contains an Active Directory forest named contoso.com. The forest contains an enterprise root certification authority (CA) on a server that runs Windows Server 2016.

You plan to create and issue a custom subordinate CA template.

You need to prevent subordinate CAs from issuing subordinate certificates.

What should you configure in the template?



Answer : C


Question 3

You create a user account that will be used as a template for new user accounts.

Which setting will be copied when you copy the user account from Active Directory Users and Computers?



Answer : B


Question 4

Note: This question is part of a series of questions that use the same scenario. For you convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.

Start of repeated scenario.

You work for a company named Contoso, Ltd.

The network contains an Active Directory forest named contoso.com. A forest trust exists between contoso.com and an Active Directory forest named adatum.com.

The contoso.com forest contains the objects configured as shown in the following table.

Group1 and Group2 contain only user accounts.

Contoso hires a new remote user named User3. User3 will work from home and will use a computer named Computer3 that runs Windows 10. Computer3 is currently in a workgroup.

An administrator named Admin1 is a member of the Domain Admins group in the contoso.com domain.

From Active Directory Users and Computers, you create an organizational unit (OU) named OU1 in the contoso.com domain, and then you create a contact named Contact1 in OU1.

An administrator of the adatum.com domain runs the Set-ADUser cmdlet to configure a user named User1 to have a user logon name of User1@litwareinc.com.

End of repeated scenario.

You need to ensure that User2 can add Group4 as a member of Group5.

What should you modify?



Answer : D


Question 5

Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.

Start of repeated scenario.

You work for a company named Contoso, Ltd.

The network contains an Active Directory forest named contoso.com. A forest trust exists between contoso.com and an Active Directory forest named adatum.com.

The contoso.com forest contains the objects configured as shown in the following table.

Group1 and Group2 contain only user accounts.

Contoso hires a new remote user named User3. User3 will work from home and will use a computer named Computer3 that runs Windows 10. Computer3 is currently in a workgroup.

An administrator named Admin1 is a member of the Domain Admins group in the contoso.com domain.

From Active Directory Users and Computers, you create an organizational unit (OU) named OU1 in the contoso.com domain, and then you create a contact named Contact1 in OU1.

An administrator of the adatum.com domain runs the Set-ADUser cmdlet to configure a user named User1 to have a user logon name of User1@litwareinc.com.

End of repeated scenario.

Admin1 attempts to delete OU1 and receives an error message.

You need to ensure that Admin1 can delete OU1.

What should you do first?



Question 6

Your network contains an Active Directory domain named adatum.com. The domain contains a security group named G_Research and an organizational unit (OU) named OU_Research.

All the users in the research department are members of G_Research and their user accounts are in OU_Research.

You need to ensure that all the research department users change their password every 28 days and enforce a complex password that is characters long.

What should you do?



Answer : C


Question 7

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You deploy a new Active Directory forest.

You need to ensure that you can create a group Managed Service Account (gMSA) for multiple member servers.

Solution: You configure Kerberos constrained delegation on the computer account of each member server.

Does this meet the goal?



Answer : B


Page:    1 / 14   
Total 285 questions