Provides a valid Microsoft MCSA 70-742 exam dumps | 100% Free

Braindump4it shares online exam exercise questions all year round! Microsoft MCSA 70-742 exam “Identity with Windows Server 2016”
https://www.leads4pass.com/70-742.html (276 Q&As).Continue to study and we provide an updated cisco 70-742 exam practice questions and answers. You can practice the test online!

Table of Contents:

Latest Microsoft MCSA 70-742 pdf

[PDF] Free Microsoft MCSA 70-742 pdf dumps download from Google Drive: https://drive.google.com/open?id=1z-4YLX55xHk9HRL327wpY62cc34TvGSa

Exam 70-742: Identity with Windows Server 2016 – Microsoft:https://www.microsoft.com/en-us/learning/exam-70-742.aspx

Skills measured

This exam measures your ability to accomplish the technical tasks listed below.

  • Install and Configure Active Directory Domain Services (AD DS) (20-25%)
  • Manage and Maintain AD DS (15-20%)
  • Create and Manage Group Policy (25-30%)
  • Implement Active Directory Certificate Services (AD CS) (10-15%)
  • Implement Identity Federation and Access Solutions (15-20%)

Who should take this exam?

Candidates for this exam manage identities using the functionalities in Windows Server 2016. Candidates install, configure, manage, and maintain Active Directory Domain Services (AD DS) as well as implement Group Policy Objects (GPOs).

Candidates should also be familiar implementing and managing Active Directory Certificate Services (AD CS), Active Directory Federations Services (AD FS), Active Directory Rights Management Services (AD RMS), and Web Application proxy.

Microsoft MCSA 70-742 Exam Practice Questions

QUESTION 1

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains

a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,

while others might not have a correct solution. 

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not

appear in the review screen. 

You deploy a new Active Directory forest. 

You need to ensure that you can create a group Managed Service Account (gMSA) for multiple member servers.

Solution: You configure Kerberos constrained delegation on the computer account of each member server. Does this

meet the goal? 

A. Yes 

B. No 

Correct Answer: B 

QUESTION 2

Your network contains an Active Directory domain named contoso.com. The domain contains two servers named

Server1 and Server2 that run Windows Server 2016. 

Server1 has IP Address Management (IPAM) installed. Server2 has the DHCP Server role installed. The IPAM server

retrieves data from Server2. 

You create a domain user account named User1. 

You need to ensure that User1 can use IPAM to manage DHCP. 

Which command should you run on Server1? To answer, select the appropriate options in the answer area. 

Hot Area:lead4pass 70-742 exam question q2

Correct Answer:

lead4pass 70-742 exam question q2-1

QUESTION 3
Your company has multiple branch offices.
The network contains an Active Directory domain named contoso.com.
In one of the branch offices, a new technician is hired to add computers to the domain.
After successfully joining multiple computers to the domain, the technician fails to join any more computers to the
domain.
You need to ensure that the technician can join an unlimited number of computers to the domain.
What should you do?
A. Run the Delegation of Control Wizard on the Computers container.
B. Run the redircmp.exe command.
C. Modify the Security settings of the technician\\’s user account.
D. Add the technician to the Windows Authorization Access group.
Correct Answer: A

QUESTION 4
Your company has two offices. The offices are located in Montreal and Seattle. The network contains an Active
Directory forest named contoso.com.
The forest contains three domain controllers configured as shown in the following table.lead4pass 70-742 exam question q4

The company physically relocates Server2 from the Montreal office to the Seattle office.
You discover that both Server1 and Server2 authenticate users who sign in to the client computers in the Montreal
office. Only Server3 authenticates users who sign in to the computers in the Seattle office.
You need to ensure that Server2 authenticates the users in the Seattle office during normal network operations.
What should you do?
A. From Windows PowerShell, run the Set-ADReplicationSite cmdlet.
B. From Active Directory Users and Computers, modify the Location Property of Server2.
C. From Network Connections on Server2, modify the Internet Protocol Version 4 (TCP/IPv4) configuration.
D. From Windows PowerShell, run the Move-ADDirectoryServer cmdlet.
Correct Answer: D

QUESTION 5
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
You deploy a new Active Directory forest.
You need to ensure that you can create a group Managed Service Account (gMSA) for multiple member servers.
Solution: You configure Kerberos constrained delegation on the computer account of each domain controller.
Does this meet the goal?
A. Yes
B. No
Correct Answer: B

QUESTION 6
DRAG DROP
Your company implements Active Directory Federation Services (AD FS).
You confirm that the company meets all the prerequisites for using Microsoft Azure Multi- Factor Authentication (MFA)
and AD FS.
You need to ensure that you can select MFA as the primary authentication method for AD FS.
Which three actions should you perform in sequence? To answer move the appropriate actions from the list of actions to
the answer area and arrange them in the correct order.
Select and Place:lead4pass 70-742 exam question q6

Correct Answer:

lead4pass 70-742 exam question q6-1

QUESTION 7
You network contains an Active Directory domain named contoso.com. The domain contains an enterprise certification
authority (CA).
A user named Admin1 is a member of the Domain Admins group.
You need to ensure that you can archive keys on the CA. The solution must use Admin1 as a key recovery agent.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to
the answer area and arrange them in the correct order.
Select and Place:lead4pass 70-742 exam question q7

Correct Answer:

lead4pass 70-742 exam question q7-1

http://markgossa.blogspot.com/2017/03/enable-key-archival-in-server-2012-r2.html

QUESTION 8
Your network contains an Active Directory domain named adatum.com. The domain has a password policy that requires
at least seven characters.
You create an organizational unit (OU) named 0U1. and then run the following commands.
redirusr OU=OU1.DC-Adatum,DC=com
New-ADUser User1
You need to identity the state of User1.
What should you identify?
A. User1 is created in OUT, is enabled, and is a member of Domain Guests.
B. User1 is created in the Users container, is enabled, and is a member of Domain Guests.
C. User1 is created in the Users container, is disabled, and is a member of Domain Users.
D. User1 is created in 0U1. is disabled, and is a member of Domain Users.
Correct Answer: D

QUESTION 9
You have a server named Server1 that runs Windows Server 2016. Server1 has the Web Application Proxy role service
installed.
You need to publish Microsoft Exchange Server 2013 services through the Web Application Proxy. The solution must
use preauthentication whenever possible.
How should you configure the preauthentication method for each service? To answer, select the appropriate options in
the answer area.
Hot Area:lead4pass 70-742 exam question q9

Correct Answer:

lead4pass 70-742 exam question q9-1

Box 1: Pass-through
Box 2: Active Directory Federation Services (ADFS)
Box 3: Pass-through
The following table describes the Exchange services that you can publish through Web Application Proxy and the
supported preauthentication for these services:

lead4pass 70-742 exam question q9-2

References: https://technet.microsoft.com/en-us/library/dn528827(v=ws.11).aspx

QUESTION 10
Your company has an office in Montreal. The network contains an Active Directory domain named contoso.com.
You have an organizational unit (OU) named Montreal that contains all of the users accounts for the users in the
Montreal office. An office manager in the Montreal office knows each user personally.
You need to ensure that the office manager can provide the users with a new password if the users forget their
password.
What should you do?
A. Create a Group Policy object (GPO) and link the GPO to the Montreal OU. Assign the office manager the Apply
Group Policy permission on the GPO. Configure the Password Policy settings of the GPO.
B. From the Security settings of each user account in the Montreal OU, assign the office manager the Change
Password permission.
C. From the Security settings of the Montreal OU, assign the office manager the Reset Password permission.
D. Create a Group Policy object (GPO) and link the GPO to the OU of the domain. Filter the GPO to the Montreal users.
Assign the office manager the Apply Group Policy permission on the GPO. Configure the Password Policy settings of
the GPO.
Correct Answer: C

QUESTION 11
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
Your network contains an Active Directory domain named contoso.com.
A user named User1 is in an organizational unit (OU) named OU1.
You need to enable User1 to sign in as [email protected].
Solution: From Windows PowerShell, you run Set -ADuser User1 -UserPrincipalName [email protected].
Does this meet the goal?
A. Yes
B. No
Correct Answer: B

QUESTION 12
Your network is isolated from the Internet. The network contains computers that are members of a domain and
computers that are members of a workgroup. All the computers are configured to use internal DNS servers and WINS
servers for name resolution.
The domain has a certification authority (CA). You run the Get-CACrlDistributionPoint cmdlet and receive the output as
shown in the following exhibit.lead4pass 70-742 exam question q12

Hot Area:

lead4pass 70-742 exam question q12-1

Correct Answer:

lead4pass 70-742 exam question q12-2

QUESTION 13
You network contains an Active Directory domain named contoso.com. The domain contains 1,000 desktop computers
and 500 laptops. An organizational unit (OU) named OU1 contains the computer accounts for the desktop computers
and
the laptops.
You create a Windows PowerShell script named Script1.ps1 that removes temporary files and cookies. You create a
Group Policy object (GPO) named GPO1 and link GPO1 to OU1.
You need to run the script once weekly only on the laptops.
What should you do?
A. In GPO1, create a File preference that uses item-level targeting.
B. In GPO1, create a Scheduled Tasks preference that uses item-level targeting.
C. In GPO1, configure the File System security policy. Attach a WMI filter to GPO1.
D. In GPO1, add Script1.ps1 as a startup script. Attach a WMI filter to GPO1.
Correct Answer: B