Actual 70-742 Exam Dumps 2021

Exam Code: 70-742 (), Exam Name: Identity with Windows Server 2021, Certification Provider: Microsoft Certifitcation, Free Today! Guaranteed Training- Pass 70-742 Exam.

Microsoft 70-742 Free Dumps Questions Online, Read and Test Now.

NEW QUESTION 1
Your network contains a signle-domin Active Directory forest named contoso.com. The forest functional level is Windows Server 2021. The forest has Dynamic Access Control enabled.
The domin contains two domain controllers named DC1 and DC2. Privileged user accounts used to manage Active Directory reside in a group named ContosoAD_Admins.
You create an authentication policy named Policy1 and an authentication policy silo named Silo1.
You need to ensure that the accounts in the ContosoAD-Admins group can sign in to the domain controllers only.
Which three configurations should you perform? Each correction answer presents part of the solution.

  • A. Create an access control condition in Policy1.
  • B. Create a managed service account and add the account to Permitted Accounts in Silo1.
  • C. Add the domain controllers to the ContosoAD_Admins group.
  • D. Add the privileged user accounts and the domain controllers to Permitted Accounts in Silo1.
  • E. Assign Silo1 to the privileged user accounts and the domain controllers.

Answer: ADE

NEW QUESTION 2
Your network contains an Active Directory domain named contoso.com. You discover that users can use passwords that contain only numbers.
You need to ensure that all the user passwords in the domain contain at least three of the following types of characters:
• Numbers
• Uppercase letters
• Lowercase letters
• Special characters What should you do?

  • A. the Default Domain Policy
  • B. the local policy on each client computer
  • C. the Default Domain Controllers Policy
  • D. the local policy on each domain controller

Answer: A

NEW QUESTION 3
Your company has a marketing department.
The network contains an Active Directory domain named comoso.com.
The domain contains two top-level organizational units (OUs) named MKT_Comps and MKT_Users. MKT_Comps contains the computer accounts for the computers in the marketing department. MKT_Users contains the user accounts for the users in the marketing department.
You link a new Group Policy object (GPO) named GPO1 to MKT_Comps.
You need to deploy a VPN connection to all of the users who sign in to the marketing department computers. The users must be

  • A. Computer Configuration/Policies/Administrative Templates/Network/Network Connections
  • B. Computer Configuration/Preferences/Control Panel Settings/Network Options
  • C. User Configuration/Preferences/Control Panel Settings/Network Options
  • D. User configuration/Policies/Administrative Templates/Network/Network Connections

Answer: B

NEW QUESTION 4
You have a server named Server1 that runs Windows Server 2021. Server1 has the Web Application Proxy role service installed.
You are publishing an application named App1 that will use Integrated Windows authentication as shown in the following graphic.
70-742 dumps exhibit
Use the drop-down menus to select the answer area choice that completes each statement based on the information presented in the graphic.
70-742 dumps exhibit

    Answer:

    Explanation: 70-742 dumps exhibit

    NEW QUESTION 5
    Your network contains an Active Directory forest named contoso.com. All domain controllers run Windows Server 2012 R2. You deploy a new server named Server1 that runs Windows Server 2021.
    A server administrator named ServerAdmin01 is a member of the Domain users group. You add ServerAdmin01 to the Administrators group on Server1.
    ServerAdmin01 signs in to Server1 and successfully configures a new Active Directory flights Management Services (AD RMS) cluster.
    You need to ensure that clients can discover the AD RMS cluster by querying Active Directory. What should you do?

    • A. Register a Service Connection Point (SCP).
    • B. Modify the Security settings of the computer account of Server1.
    • C. Update the Active Directory schema.
    • D. Upgrade one domain controller to Windows Server 2021.

    Answer: A

    NEW QUESTION 6
    Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.
    Start of repeated scenario.
    Your network contains an Active Directory domain named contoso.com. The domain contains a single site named Site1. All computers are in Site1.
    The Group Policy objects (GPOs) for the domain are configured as shown in the exhibit. (Click the Exhibit button.)
    70-742 dumps exhibit
    The relevant users and client computer in the domain are configured as shown in the following table.
    70-742 dumps exhibit
    End of repeated scenario.
    You plan to enforce the GPO link for A6.
    Which five GPOs will apply to User1 in sequence when the user signs in to Computer1 after the link is enforced? To answer, move the appropriate GPOs from the list of GPOs to the answer area and arrange them in the correct order.
    70-742 dumps exhibit

      Answer:

      Explanation: 70-742 dumps exhibit

      NEW QUESTION 7
      Your network contains an Active Directory domain named contoso.com.
      You have an organizational unit (OU) named TestOU that contains test computers.
      You need to enable a technician named Tech1 to create Group Policy objects (GPOs) and to link the GPOs to TestOU. The solution must use the principle of least privilege.
      Which two actions should you perform? Each correct answer presents part of the solution.

      • A. Add Tech1 to the Group Policy Creator Owners group.
      • B. From Group Policy Management, modify the Delegation settings of the TestOU OU.
      • C. Add Tech1 to the Protected Users group.
      • D. From Group Policy Management, modify the Delegation settings of the contoso.com container.
      • E. Create a new universal security group and add Tech1 to the group.

      Answer: AB

      NEW QUESTION 8
      Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
      After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
      Your network contains an Active Directory domain named contoso.com. The domain contains two domain controllers named DC1 and DC2.
      DC1 holds the RID master operations role. DC1 fails and cannot be repaired. You need to move the RID role to DC2.
      Solution: On DC2, you open the command prompt, run dsmgmt.exe, connect to DC2, and use the Seize RID master opinion.
      Does this meet the goal?

      • A. Yes
      • B. No

      Answer: B

      NEW QUESTION 9
      Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other
      questions in this series. Information and details provided in a question apply only to that question.
      Your network contains an Active Directory domain named contoso.com. The domain functional level is Windows Server 2012 R2.
      Your company hires a new security administrator to manage sensitive user data. You create a user account named Security1 for the security administrator.
      You need to ensure that the password for Security1 has at least 12 characters and is modified every 10 days. The solution must apply to Security1 only.
      Which tool should you use?

      • A. Dsadd quota
      • B. Dsmod
      • C. Active Directory Administrative Center
      • D. Dsacls
      • E. Dsmain
      • F. Active Directory Users and Computers
      • G. Ntdsutil
      • H. Group Policy Management Console

      Answer: F

      NEW QUESTION 10
      Your network contains an Active Directory domain named contoso.com.
      You plan to deploy a new Active Directory Rights Management Services (AD RMS) cluster on a server named Server1.
      You need to create the AD RMS service account. The solution must use the principle of least privilege What should you do?

      • A. Create a domain user account and add the account to the Account Operators group in the domain.
      • B. Create a local user account on Server1 and add the account to the Administrators group on Server1.
      • C. Create a domain user account and add the account to the Domain Users group in the domain.
      • D. Create a domain user account and add the account to the Administrators group on Server1.

      Answer: C

      NEW QUESTION 11
      Your company implements Active Directory Federation Services (AD FS).
      You confirm that the company meets all the prerequisites for using Microsoft Azure Multi-Factor Authentication (MFA) and AD FS.
      You need to ensure that you can select MFA as the primary authentication method for AD FS.
      Which three actions should you perform in sequence? To answer move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
      70-742 dumps exhibit

        Answer:

        Explanation: 70-742 dumps exhibit

        NEW QUESTION 12
        Your network contains an Active Directory forest. The forest contains two domain controllers named DC1 and DC2 that run Windows Server 2021. DC1 holds all of the operations master roles.
        DC1 experiences a hardware failure.
        You plan to use an automated process that will create 1,000 user accounts. You need to ensure that the automated process can complete successfully.
        Which command should you run? To answer, select the appropriate options in the answer area.
        70-742 dumps exhibit

          Answer:

          Explanation: Box 1: Move-ADDirectoryServerOperationMasterRole
          Box 2: RIDMaster
          Box 3: -Force

          NEW QUESTION 13
          Your network contains an Active Directory forest named contoso.com. The forest contains several domains. An administrator named Admin01 installs Windows Server 2021 on a server named Server1 and then joins
          Server1 to the contoso.com domain.
          Admin01 plans to configure Server1 as an enterprise root certification authority (CA).
          You need to ensure that Admin01 can configure Server1 as an enterprise CA. The solution must use the principle of least privilege.
          To which group should you add Admin01?

          • A. Server Operators in the contoso.com domain
          • B. Cert Publishers on Server1
          • C. Enterprise Key Admins in the contoso.com domain
          • D. Enterprise Admins in the contoso.com domain.

          Answer: D

          NEW QUESTION 14
          Your network contains an Active Directory domain named contoso.com.
          The domain contain the computers configured as shown in the following table.
          70-742 dumps exhibit
          The domain contains a user named User1.
          A Group Policy object (GPO) named GPO1 is linked to the domain. GPO1 contains a user preference that is configured as shown in the Shortcut1 Properties exhibit.
          70-742 dumps exhibit
          Item-level targeting for the user preference is configured as shown in the Targeting exhibit. (Click the Exhibit button.)
          70-742 dumps exhibit
          For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
          70-742 dumps exhibit

            Answer:

            Explanation: 70-742 dumps exhibit

            NEW QUESTION 15
            Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server 2021.
            Server1 has IP Address Management (IPAM) installed. Server2 has the DHCP Server role installed. The IPAM server retrieves data from Server2.
            You create a domain user account named User1.
            You need to ensure that User1 can use IPAM to manage DHCP.
            Which command should you run on Server1? To answer, select the appropriate options in the answer area.
            70-742 dumps exhibit

              Answer:

              Explanation: 70-742 dumps exhibit

              NEW QUESTION 16
              Your network contains an Active Directory domain named contoso.com.
              You create a domain security group named Group1 and add several users to it.
              You need to force all of the users in Group1 to change their password every 35 days. The solution must affect the Group1 users only.
              What should you do?

              • A. From Windows PowerShell, run the Set-ADDomain cmdlet, and then run the Set-ADAccountPassword cmdlet.
              • B. Modify the Password Policy settings in a Group Policy object (GPO) that is linked to the domain, and then filter the GPO to Group1 only.
              • C. Create a forms authentication provider, and then set the forms authentication credentials.
              • D. From Active Directory Administrative Center, create a Password Setting object (PSO).

              Answer: D

              NEW QUESTION 17
              Your network contains an Active Directory domain named contoso.com. The domain contains a member
              server named Server1 that runs Windows Server 2021.
              Server1 has IP Address Management (IPAM) installed. IPAM uses a Windows Internal Database. You install Microsoft SQL Server on Server1.
              You plan to move the IPAM database to SQL Server.
              You need to create a SQL Server login for the IPAM service account.
              For which user should you create the login? To answer, select the appropriate options in the answer area.
              70-742 dumps exhibit

                Answer:

                Explanation: References:
                https://blogs.technet.microsoft.com/yagmurs/2014/07/31/moving-ipam-database-from-windows-internal-databas

                NEW QUESTION 18
                Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.
                Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named Server1.
                You recently restored a backup of the Active Directory database from Server1 to an alternate Location. The restore operation does not interrupt the Active Directory services on Server1.
                You need to make the Active Directory data in the backup accessible by using Lightweight Directory Access Protocol (LDAP).
                Which tool should you use?

                • A. Dsadd quota
                • B. Dsmod
                • C. Active Directory Administrative Center
                • D. Dsacls
                • E. Dsamain
                • F. Active Directory Users and Computers
                • G. Ntdsutil
                • H. Group Policy Management Console

                Answer: E

                NEW QUESTION 19
                Your network is isolated from the Internet. The network contains computers that are members of a domain and computers that are members of a workgroup. All the computers are configured to use internal DNS servers and WINS servers for name resolution.
                The domain has a certification authority (CA). You run the Get-CACrlDistributionPoint cmdlet and receive the output as shown in the following exhibit.
                70-742 dumps exhibit
                70-742 dumps exhibit
                70-742 dumps exhibit

                  Answer:

                  Explanation: 70-742 dumps exhibit

                  P.S. Easily pass 70-742 Exam with 222 Q&As 2passeasy Dumps & pdf Version, Welcome to Download the Newest 2passeasy 70-742 Dumps: https://www.2passeasy.com/dumps/70-742/ (222 New Questions)