Our pass rate is high to 98.9% and the similarity percentage between our and real exam is 90% based on our seven-year educating experience. Do you want achievements in the Microsoft 70-742 exam in just one try? I am currently studying for the . Latest , Try Microsoft 70-742 Brain Dumps First.
Microsoft 70-742 Free Dumps Questions Online, Read and Test Now.
NEW QUESTION 1
Your network contains an Active Directory domain named contoso.com.
You plan to deploy a new Active Directory Rights Management Services (AD RMS) cluster on a server named Server1.
You need to create the AD RMS service account. The solution must use the principle of least privilege What should you do?
- A. Create a domain user account and add the account to the Account Operators group in the domain.
- B. Create a local user account on Server1 and add the account to the Administrators group on Server1.
- C. Create a domain user account and add the account to the Domain Users group in the domain.
- D. Create a domain user account and add the account to the Administrators group on Server1.
Answer: C
NEW QUESTION 2
Your network contains an Active Directory domain named contoso.com. The domain contains a user named User1, a group named Group1, and an organizational unit (OU) named OU1.
You need to enable User1 to link Group Policies to OU1.
Solution: From Active Directory Administrative Center, you add User1 to Group1 and grant Group1 Full Control permission to OU1.
Does this meet the goal?
- A. Yes
- B. No
Answer: A
NEW QUESTION 3
You deploy a new certification authority (CA) to a server that runs Windows Server 2021. You need to configure the CA to support recovery of certificates.
What should you do first?
- A. Modify the Recovery Agents settings from the properties of the CA.
- B. Assign the Request Certificates permission to the user account that will be responsible for recovering certificates.
- C. Configure the Key Recovery Agent template as a certificate template to issue.
- D. Modify the extensions of the OCSP Response Signing template.
Answer: C
Explanation: References:
http://markgossa.blogspot.co.uk/2021/03/enable-key-archival-in-server-2012-r2.html
NEW QUESTION 4
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution. Determine whether the solution meets the stated goals.
Your network contains an Active Directory domain named contoso.com. The domain contains a DNS server named Server1. All client computers run Windows 10.
On Server1, you have the following zone configuration.
You need to ensure that all of the client computers in the domain perform DNSSEC validation for the fabrikam.com namespace.
Solution: From a Group Policy object (GPO) in the domain, you add a rule to the Name Resolution Policy Table (NRPT).
Does this meet the goal?
- A. Yes
- B. No
Answer: A
Explanation: The NRPT stores configurations and settings that are used to deploy DNS Security Extensions (DNSSEC), and also stores information related to DirectAccess, a remote access technology.
Note: The Name Resolution Policy Table (NRPT) is a new feature available in Windows Server 2008 R2. The NRPT is a table that contains rules you can configure to specify DNS settings or special behavior for names or namespaces. When performing DNS name resolution, the DNS Client service checks the NRPT before sending a DNS query. If a DNS query or response matches an entry in the NRPT, it is handled according to settings in the policy. Queries and responses that do not match an NRPT entry are processed normally.
References: https://technet.microsoft.com/en-us/library/ee649207(v=ws.10).aspx
NEW QUESTION 5
Your network contains an Active Directory domain named contoso.com. The domain contains a user named User1 and an organizational unit (OU) named OU1.
What should you do?
- A. Modify the security settings of GPO1.
- B. Modify the security settings of OU1.
- C. Add User1 to the Group Policy Creator Owner group.
- D. Modify the security settings of User.
Answer: B
NEW QUESTION 6
Your network contains an Active Directory domain named contoso.com.
You open Group Policy Management as shown in the Group Policy Management exhibit. (Click the Exhibit button.)
A user named User1 is in OU1. A computer named Computer2 is in OU2.
The settings of GPO1 are configured as shown in the GPO1 exhibit. (Click the Exhibit button.)
The settings of GPO2 are configured as shown in the GPO2 exhibit. (Click the Exhibit button.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Answer:
Explanation: 
NEW QUESTION 7
Your company implements Active Directory Federation Services (AD FS).
You confirm that the company meets all the prerequisites for using Microsoft Azure Multi-Factor Authentication (MFA) and AD FS.
You need to ensure that you can select MFA as the primary authentication method for AD FS.
Which three actions should you perform in sequence? To answer move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation: 
NEW QUESTION 8
Your network contains an Active Directory domain named contoso.com.
You need to create a central store for Group Policy administrative templates. What should you use?
- A. Server Manager
- B. File Explorer
- C. Dcgpofix.exe
- D. Group Policy Management Console (GPMC)
Answer: B
NEW QUESTION 9
Your network contains an Active Directory domain named contoso.com.
A user named User1 and a computer named Conputer1 are in an organizational unit OU1. A user named User2 and a computer named Computer 2 are in an OU named OU2.
A Group Policy object (GPO) named GPO1 is linked to the domain. GPO1 contains a user preference that is configured as shown in the Shortcut1 Properties exhibit. (Click the Exhibit button.)
Item-level targeting for the user preference is configured as shown in the Targeting exhibit. (Click the Exhibit button.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Answer:
Explanation: References:
https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc73075
NEW QUESTION 10
Your company has multiple offices.
The network contains an Active Directory domain named contoso.com. An Active Directory site exists for each office. All of the sites connect to each other by using DEFAULTIPSITELINK.
The company plans to open a new office. The new office will have a domain controller and 100 client computers.
You install Windows Server 2021 on a member server in the new office. The new server will become a domain controller.
You need to deploy the domain controller to the new office. The solution must ensure that the client computers in the new office will authenticate by using the local domain controller.
Which three actions should you perform next in sequence? To answer, move the appropriate actions from the
list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation: 
NEW QUESTION 11
Your company has a marketing department and a security department.
The network contains an Active Directory domain named contoso.com. The domain contains an enterprise certification authority (CA).
You have two organizational units (OUs) named MKT_UsersOU and MKT_ComputersOU. MKT_UsersOU contains the user accounts for the users in the marketing department. MKT_ComputersOU contains the computer accounts for the computers in the marketing department.
A Group policy object (GPO) named GPO1 is linked to MKT_UsersOU. A GPO named GPO2 linked to MKT_ComputersOU.
You plan to deploy a web application for the marketing department users. The application will require certificates for authentication.
The security department configures the CA to support the planned deployment.
You need to ensure that the web application can authenticate the marketing department users. What should you do?
- A. From the User Configuration node of GPO1, create an Internet Setting preference.
- B. From the User Configuration node of GPO1, configure the Certificate Services Client - Auto enrollment settings.
- C. From the Computer Configuration node of GPO2, configure the Certificate Services Client - Certificate Enrollment Policy settings.
- D. From the Computer Configuration node of GPO2, create the Automatic Certificate Request Settings.
Answer: A
NEW QUESTION 12
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory forest named contoso.com. The forest contains a member server named Server1 that runs Windows Server 2021. All domain controllers run Windows Server 2012 R2.
Contoso.com has the following configuration. PS C:> (Get-ADForest).ForestMode Windows2008R2Forest
PS C:> (Get-ADDomain).DomainMode
Windows2008R2Domain PS C:>
You plan to deploy an Active Directory Federation Services (AD FS) farm on Server1 and to configure device registration.
You need to configure Active Directory to support the planned deployment. Solution: You upgrade a domain controller to Windows Server 2021.
Does this meet the goal?
- A. Yes
- B. No
Answer: B
Explanation: Device Registration requires Windows Server 2012 R2 forest schema.
NEW QUESTION 13
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com. A user named User1 is in an organizational unit (OU) named OU1.
You are troubleshooting a folder access issue for User1.
You need a list of groups to which User1 is either a direct member or ab indirect member. Solution: You run dsget user cn=User1, ou=OU1, dc=contoso, dc=com –memberof –expand. Does this meet the goal?
- A. Yes
- B. No
Answer: A
Explanation: DSGET displays the properties of a user in the directory. There are two variations of this command. The first variation displays the properties of multiple users. The second variation displays the group membership information of a single user.
To show the list of groups, recursively expanded, to which the user Mike Danseglio belongs, type: dsget user "CN=Mike Danseglio,CN=users,dc=ms,dc=tld" -memberof –expand
References:
https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc73253
NEW QUESTION 14
You network contains an Active Directory domain named contoso.com. The domain contains an enterprise certification authority (CA).
A user named Admin1 is a member of the Domain Admins group.
You need to ensure that you can archive keys on the CA. The solution must use Admin1 as a key recovery agent.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation: 
NEW QUESTION 15
Your network contains an Active Directory domain. The domain contains a domain controller named DC1 that runs Windows Server 2021.
You start DC1 in Directory Services Restore Mode (DSRM). You need to compact the Active Directory database on DC1. Which three action should you perform in sequence?
Answer:
Explanation: https://technet.microsoft.com/en-us/library/cc794920(v=ws.10).aspx
NEW QUESTION 16
Your network contains an Active Directory domain.
Users do not have administrative privileges to their client computer You modify a computer setting in a Group Policy object (GPO).
You need to ensure that the setting is applied to five client computers as soon as possible. What should you do?
- A. From a domain controller, run the gpudate.exe command and specify the Force parameter.
- B. From each client computer, run the gpresult.exe command and specify the /r parameter.
- C. From each client computer, run the Get-Gpo cmdlet and specify the -alt parameter.
- D. From a domain controller, run the Invoke-GPUpdate cmdlet.
Answer: D
Explanation: https://technet.microsoft.com/en-us/library/hh852337(v=ws.11).aspx
Recommend!! Get the Full 70-742 dumps in VCE and PDF From Surepassexam, Welcome to Download: https://www.surepassexam.com/70-742-exam-dumps.html (New 222 Q&As Version)