Want to know features? Want to lear more about experience? Study . Gat a success with an absolute guarantee to pass Microsoft 70-742 (Identity with Windows Server 2021) test on your first attempt.

Online 70-742 free questions and answers of New Version:

NEW QUESTION 1
Your network contains an Active Directory domain. The domain contains computer named Comouter1 and an organizational unit (OU) named TestOU. TestOU contains 10 computer accounts that are used for testing. A Group Policy object (GPO) named GPO1 is linked to TestOU.
On Computer1, you modify the User Right Assignment by using the local policy.
You need to apply the User Right Assignment from Computer1 to the 10 test computers. What should you do?

  • A. On Computer1, run the gprcsult.exe command and specify the A paramete
  • B. From Group Policy Management, run the Restore Group Policy Object Wizard.
  • C. On Computer1, run the secedit.exe command and specify the /export paramete
  • D. From Group Policy Management, run the Import Settings Wizard.
  • E. On Computer1, run the gpresult.exe command and specify the A paramete
  • F. Edit GPO1, and then import a security template.
  • G. On Computer1 run the secedit.exe command and specify the /export paramete
  • H. Edit GPO1, and then import a security template.

Answer: D

NEW QUESTION 2
Your network contains an Active Directory domain named contoso.com. The domain contains five domain controllers.
You have a branch office that has a local support technician named Tech1. Tech1 installs Windows Server 2021 on a server named RODC1 in a workgroup.
You need Tech1 to deploy RODC1 as a read-only domain controller (RODC) in the contoso.com domain.
Which three actions should you perform? Each correct answer presents part of the solution.

  • A. Instruct Tech1 to run the Active Directory Domain Services Configuration Wizard.
  • B. Create an RODC computer account by using Active Administrative Center.
  • C. Instruct Tech1 to run dcpromo.exe on RODC1.
  • D. Instruct Tech1 to install the Active Directory Domain Services server role on RODC1.
  • E. Modify the permissions of the Domain Controllers organizational unit (OU).

Answer: ACD

NEW QUESTION 3
Your network contains an Active Directory forest named contoso.com. The forest contains a member server named Server1 that runs Windows Server 2021. Server1 is located in the perimeter network.
You install the Active Directory Federation Services server role on Server1. You create an Active Directory Federation Services (AD FS) farm by using a certificate that has a subject name of sts.contoso.com.
You need to enable certificate authentication from the Internet on Server1.
Which two inbound TCP ports should you open on the firewall? Each correct answer presents part of the solution.

  • A. 389
  • B. 443
  • C. 3389
  • D. 8531
  • E. 49443

Answer: BE

NEW QUESTION 4
Your network is isolated from the Internet. The network contains computers that are members of a domain and computers that are members of a workgroup. All the computers are configured to use internal DNS servers and WINS servers for name resolution.
The domain has a certification authority (CA). You run the Get-CACrlDistributionPoint cmdlet and receive the output as shown in the following exhibit.
70-742 dumps exhibit
70-742 dumps exhibit
70-742 dumps exhibit

    Answer:

    Explanation: 70-742 dumps exhibit

    NEW QUESTION 5
    Your network contains an Active Directory forest.
    Some users report experiencing difficulties signing in to domain controllers. You suspect that the service location (SRV) records might be causing the issue.
    What are two possible commands that you can run to verify the SRV records? Each correct answer presents a complete solution.
    NOTE. Each correct selection is worth one point.

    • A. dcdiag.exe /test:connectivity
    • B. dnscmd /info
    • C. dnscmd /DirectoryPartitionInfo
    • D. dcdiag.exe /test:dns /DnsRecordRegistration
    • E. dcdiag.exe /test:dns
    • F. dnscmd /IPValidate

    Answer: BD

    Explanation: https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/troubleshoot/verify-dns-functionality-to

    NEW QUESTION 6
    Your network contains an Active Directory forest. The forest contains a domain named contoso.com. The domain contains three domain controllers.
    A domain controller named lon-dc1 fails. You are unable to repair lon-dc1.
    You need to prevent the other domain controllers from attempting to replicate to lon-dc1.
    Solution: From Active Directory Users and Computers, you remove the computer account of lon-dc1. Does this meet the goal?

    • A. Yes
    • B. No

    Answer: A

    Explanation: To remove the failed server object from the domain controllers container, access Active Directory Users and Computers, expand the domain controllers container, and delete the computer object associated with the failed domain controller
    References: https://www.petri.com/delete_failed_dcs_from_ad

    NEW QUESTION 7
    Your network contains an Active Directory forest named contoso.com. All domain controllers run Windows Server 2012 R2. You deploy a new server named Server1 that runs Windows Server 2021.
    A server administrator named ServerAdmin01 is a member of the Domain users group. You add ServerAdmin01 to the Administrators group on Server1.
    ServerAdmin01 signs in to Server1 and successfully configures a new Active Directory flights Management Services (AD RMS) cluster.
    You need to ensure that clients can discover the AD RMS cluster by querying Active Directory. What should you do?

    • A. Register a Service Connection Point (SCP).
    • B. Modify the Security settings of the computer account of Server1.
    • C. Update the Active Directory schema.
    • D. Upgrade one domain controller to Windows Server 2021.

    Answer: A

    NEW QUESTION 8
    You deploy a new enterprise certification authority (CA) named CA1. You plan to issue certificates based on the User certificate template.
    You need to ensure that the issued certificates are valid for two years and support autoenrollment. What should you do first?

    • A. Run the certutil.exe command and specify the resubmit parameter.
    • B. Duplicate the User certificate template.
    • C. Add a new certificate template for CA1 to issue.
    • D. Modify the Request Handling settings for the CA.

    Answer: B

    NEW QUESTION 9
    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    Your network contains an Active Directory domain named contoso.com. The domain contains two domain controllers named DC1 and DC2.
    DC1 holds the RID master operations role. DC1 fails and cannot be repaired. You need to move the RID role to DC2.
    Solution: On DC2, you open the command prompt, run dsmgmt.exe, connect to DC2, and use the Seize RID master opinion.
    Does this meet the goal?

    • A. Yes
    • B. No

    Answer: B

    NEW QUESTION 10
    Note: This question is part of a series of questions that use the same or similar answer choices. An answer
    choice may be correct for more than one question in the series. Each question is independent of the other questions in this series.
    Information and details provided in a question apply only to that question.
    Your network contains an Active Directory domain named contoso.com. The domain contains 5,000 user accounts.
    You have a Group Policy object (GPO) named DomainPolicy that is linked to the domain and a GPO named DCPolicy that is linked to the Domain Controllers organizational unit (OU).
    You need to ensure that all of the client computers on the network automatically download and install Windows updates.
    What should you do?

    • A. From the Computer Configuration node of DCPolicy, modify Security Settings.
    • B. From the Computer Configuration node of DomainPolicy, modify Security Settings.
    • C. From the Computer Configuration node of DomainPolicy, modify Administrative Templates.
    • D. From the User Configuration node of DCPolicy, modify Security Settings.
    • E. From the User Configuration node of DomainPolicy, modify Folder Redirection.
    • F. From user Configuration node of DomainPolicy, modify Administrative Templates.
    • G. From Preferences in the User Configuration node of DomainPolicy, modify Windows Settings.
    • H. From Preferences in the Computer Configuration node of DomainPolicy, modify Windows Settings.

    Answer: F

    NEW QUESTION 11
    Your network contains an Active Directory domain named contoso.com.
    You plan to deploy a new Active Directory Rights Management Services (AD RMS) cluster on a server named Server1.
    You need to create the AD RMS service account. The solution must use the principle of least privilege. What should you do?

    • A. Create a domain user account and add the account to the Administrators group on Server1.
    • B. Create a local user account on Server1 and add the account to the Administrators group on Server1.
    • C. Create a domain user account and add the account to the Domain Users group in the domain
    • D. Create a domain user account and add the account to the Account Operators group in the domain.

    Answer: A

    NEW QUESTION 12
    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2021. The computer account for Server1 is in organizational unit (OU) named OU1.
    You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1.
    You need to add a domain user named User1 to the local Administrators group on Server1. Solution: From a domain controller, you run the Set-AdComputer cmdlet.
    Does this meet the goal?

    • A. Yes
    • B. No

    Answer: B

    NEW QUESTION 13
    Your network contains an Active Directory domain named contoso.com.
    The domain contains an enterprise root certification authority (CA) on a server that runs Windows Server 2021.
    You need to configure the CA to support Online Certificate Status Protocol (OCSP) responders. Which two actions should you perform? Each correct selection presents part of the solution. NOTE: Each correct selection is worth one point.

    • A. Add a new certificate template to issue.
    • B. Modify the Authority Information Access (AIA) of the CA.
    • C. Configure an enrollment agent.
    • D. Install a standalone subordinate CA.
    • E. Modify the CRL distribution point (CDP) of the CA.

    Answer: AB

    Explanation: Once the OCSP service is configured, we need to configure the OCSP Response Signing template. This process includes adding an Authority Information Access (AIA) extension and then issuing a new certificate template.
    References:
    https://www.poweradmin.com/blog/deploying-active-directory-certificate-services-and-online-responder/

    NEW QUESTION 14
    Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server 2021. The computer accounts of Server1 and Server2 are in the Computers container.
    A Group Policy object (GPO) named GPO1 is linked to the domain. GPO1 has multiple computer settings defined and has following configurations.
    70-742 dumps exhibit
    An administrator discovers that GPO1 is not applied to Server1. GPO1 is applied to Server2. Which configuration possibly prevents GPO1 from being applied to Server1?

    • A. The permissions on the domain object of contoso.com
    • B. The WMI filter settings
    • C. The Enforced setting of GPO1
    • D. The GpoStatus property

    Answer: B

    NEW QUESTION 15
    You have a server named Server1 in a workgroup.
    You need to configure a Group Policy setting on Server1 that will apply to only non-administrative users. What should you do?

    • A. Run mnc.ex
    • B. Add the Group Policy Object Editor snap-in and change the Group Policy object (GPO)
    • C. Open Local Group Policy Edito
    • D. From the File menu, modify the Options settings.
    • E. Open Local Users and Group
    • F. Create a new group Run New.GPO.
    • G. Open Local Group Policy Edito
    • H. From the View menu, modify the Customize settings.

    Answer: A

    NEW QUESTION 16
    Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.
    Your network contains an Active Directory forest named contoso.com. The forest functional level is Windows Server 2012 R2.
    You need to ensure that a domain administrator can recover a deleted Active Directory object quickly. Which tool should you use?

    • A. Dsadd quota
    • B. Dsmod
    • C. Active Directory Administrative Center
    • D. Dsacls
    • E. Dsamain
    • F. Active Directory Users and Computers
    • G. Ntdsutil
    • H. Group Policy Management Console

    Answer: C

    P.S. Easily pass 70-742 Exam with 222 Q&As Surepassexam Dumps & pdf Version, Welcome to Download the Newest Surepassexam 70-742 Dumps: https://www.surepassexam.com/70-742-exam-dumps.html (222 New Questions)