2026 New 70-742 Exam Dumps with PDF and VCE Free: https://www.surepassexam.com/70-742-exam-dumps.html
Act now and download your today! Do not waste time for the worthless tutorials. Download with real questions and answers and begin to learn with a classic professional.
Free 70-742 Demo Online For Microsoft Certifitcation:
NEW QUESTION 1
Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series.
Information and details provided in a question apply only to that question.
Your network contains an Active Directory domain named contoso.com. The domain contains 5,000 user accounts.
You have a Group Policy object (GPO) named DomainPolicy that is linked to the domain and a GPO named DCPolicy that is linked to the Domain Controllers organizational unit (OU).
You need to use the application control policy settings to prevent several applications from running on the network.
What should you do?
- A. From the Computer Configuration node of DCPolicy, modify Security Settings.
- B. From the Computer Configuration node of DomainPolicy, modify Security Settings.
- C. From the Computer Configuration node of DomainPolicy, modify Administrative Templates.
- D. From the User Configuration node of DCPolicy, modify Security Settings.
- E. From the User Configuration node of DomainPolicy, modify Folder Redirection.
- F. From user Configuration node of DomainPolicy, modify Administrative Templates.
- G. From Preferences in the User Configuration node of DomainPolicy, modify Windows Settings.
- H. From Preferences in the Computer Configuration node of DomainPolicy, modify Windows Settings.
Answer: B
NEW QUESTION 2
Your network contains an Active Directory forest. The forest contains a domain named contoso.com. The domain contains three domain controllers.
A domain controller named lon-dc1 fails. You are unable to repair lon-dc1.
You need to prevent the other domain controllers from attempting to replicate to lon-dc1.
Solution: From Active Directory Users and Computers, you remove the computer account of lon-dc1. Does this meet the goal?
- A. Yes
- B. No
Answer: A
Explanation: To remove the failed server object from the domain controllers container, access Active Directory Users and Computers, expand the domain controllers container, and delete the computer object associated with the failed domain controller
References: https://www.petri.com/delete_failed_dcs_from_ad
NEW QUESTION 3
Your network contains a signle-domin Active Directory forest named contoso.com. The forest functional level is Windows Server 2021. The forest has Dynamic Access Control enabled.
The domin contains two domain controllers named DC1 and DC2. Privileged user accounts used to manage Active Directory reside in a group named ContosoAD_Admins.
You create an authentication policy named Policy1 and an authentication policy silo named Silo1.
You need to ensure that the accounts in the ContosoAD-Admins group can sign in to the domain controllers only.
Which three configurations should you perform? Each correction answer presents part of the solution.
- A. Create an access control condition in Policy1.
- B. Create a managed service account and add the account to Permitted Accounts in Silo1.
- C. Add the domain controllers to the ContosoAD_Admins group.
- D. Add the privileged user accounts and the domain controllers to Permitted Accounts in Silo1.
- E. Assign Silo1 to the privileged user accounts and the domain controllers.
Answer: ADE
NEW QUESTION 4
Your company has a main office and three branch offices.
The network contains an Active Directory domain named contoso.com.
The main office contains three domain controllers. Each branch office contains one domain controller.
You discover that new settings in the Default Domain Policy are not applied in one of the branch offices, but all other Group Policy objects (GPOs} are applied.
You need to check the replication of the Default Domain Policy for the branch office. What should you do from a domain controller in the main office?
- A. From a command prompt, run dcdiag.exe.
- B. From Group Policy Management, click Default Domain Policy under Contoso.com, and then open theDetails tab.
- C. From Group Policy Management, click Default Domain Policy under Contoso.com, and then open theScope tab.
- D. From a command prompt, run repadmin.exe.
Answer: D
NEW QUESTION 5
You network contains an Active Directory domain named contoso.com. The domain contains an enterprise certification authority (CA) named CA1.
You have a test environment that is isolated physically from the corporate network and the Internet.
You deploy a web server to the test environment. On CA1, you duplicate the Web Server template, and you name the template Web_Cert_Test.
For the web server, you need to request a certificate that does not contain the revocation information of CA1. What should you do first?
- A. From the properties of CA1, allow certificates to be published to the file system.
- B. From the properties of CA1, select Restrict enrollment agents, and then add Web_Cert_Test to the restricted enrollment agent.
- C. From the properties of Web_Cert_Test, assign the Enroll permission to the guest account.
- D. From the properties of Web_Cert_Test, set the Compatibility setting of CA1 to Windows Server 2021.
Answer: D
NEW QUESTION 6
Note: This question is part of a series of questions that use the same or similar answer choice. An answer choice may be correct for more than one question in the series. Each question is Independent of the other questions in this series. Information and details provided in a question apply only to that question.
Your network contains an Active Directory domain named contoso.com. The domain functional level is Windows Server 2012 R2.
Your company hires 3 new security administrators to manage sensitive user data. You create a user account named Secunty1 for the security administrator.
You need to ensure that the password for Secunty1 has at least 12 characters and is modified every 10 days. The solution must apply to Security 1 only.
Which tool should you use?
- A. Dsadd quota
- B. Dsmod
- C. Active Directory Administrative Center
- D. Dsacis
- E. Dsamain
Answer: C
Explanation: Using Fine-Grained Password Policies you specify multiple password policies in a single domain and apply different restrictions for password and account lockout policies to different sets of users in a domain. You can apply stricter settings to privileged accounts and less strict settings to the accounts of other users.To enable Fine-Grained Password Policies (FGPP), you need to open the Active Directory Administrative Center (ADAC)https://blogs.technet.microsoft.com/canitpro/2013/05/29/step-by-step-enabling-and-using-fine-grained-
NEW QUESTION 7
Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.
Start of repeated Scenario
You work for a company named Contoso, Ltd.
The network contains an Active Directory forest named contoso.com. A forest trust exists between contoso.com and an Active Directory forest named adatum.com.
The contoso.com forest contains the objects configured as shown in the following table.
Group 1 and Group2 contain only user accounts.
Contoso hires a new remote user named User3. User3 will work from home and will use a computer named
Computer3 that runs Windows 10. Computer3 is currently in a workgroup.
An administrator named Admin1 is a member of the Domain Admins group in the contoso.com domain. From Active Directory Users and Computers, you create an organizational unit (OU) named OU1 in the
contoso.com domain, and then you create a contact named Contact1 in OU1.
An administrator of the adatum.com domain runs the Set-ADUser cmdlet to configure a user named User1 to have a user logon name of user1@litwareinc.com.
End of repeated scenario
You need to ensure that Admin1 can convert Group1 to a global group. What should you do?
- A. Add Admin1 to the Enterprise Admin group.
- B. Remove all the member from Group1.
- C. Modify the Security settings of Group1.
- D. Convert Group1 to a universal security group.
Answer: B
NEW QUESTION 8
Your network contains an Active Directory forest. The forest contains two domains named litwareinc.com and contoso.com. The contoso.com domain contains two domain controllers named LON-DC01 and LON-DC02. The domain controllers are located in a site named London that is associated to a subnet of 192.168.10.0/24.
You discover that LON-DC02 is not a global catalog server. You need to configure LON-DC02 as a global catalog server.
What should you do?
- A. From Active Directory Sites and Services, modify the NTDS Settings object of the London site.
- B. From Windows Power Shell, run the Enable-ADOptionalFeature cmdlet.
- C. From the properties of the LON-DC02 computer account in Active Directory Users and Computers modify the NTDS settings.
- D. From the properties of the LON-DC02 computer account in Active Directory Users and Computers, modify the City attribute.
Answer: C
NEW QUESTION 9
Your network contains an Active Directory domain named adatum.com. The domain contains a security group named G_Research and an organizational unit (OU) named OU_Research.
All the users in the research department are members of G_Research and their user accounts are in OU_Research.
You need to ensure that all the research department users change their password every 28 days and enforce a complex password that is characters long.
What should you do?
- A. From Group Policy Management, create and link a Group Policy object (GPO) to the domai
- B. Modify the password policy in the GPO Filter the GPO to apply to G_Research only.
- C. From Active Directory Administrative Center, create a new Password Settings object (PSO).
- D. From Active Directory Users and Computers, modify the properties of the Password Settings Container.
- E. From Group Policy Management, create and link a Group Policy object (GPO) to OU_Researc
- F. Modify the password policy in the GPO.
Answer: C
NEW QUESTION 10
You have a server named Server1 that runs Windows Server 2021. Server1 has the Windows Application Proxy role service installed.
You need to publish Microsoft Exchange ActiveSync services by using the Publish New Application Wizard. The ActiveSync services must use preauthentication.
How should you configure Server1? To answer, select the appropriate options in the answer area.
Answer:
Explanation: 
NEW QUESTION 11
Your network contains an Active Directory forest named contoso.com. The forest contains 10 domains. The root domain contains a global catalog server named DC1.
You remove the global catalog server role from DC1.
You need to decrease the size of the Active Directory database on DC1.
Solution:You stop the NTDS service on DC1. You run ntdsutil.exe, use the metadata cleanup option, and then start the NTDS
Does this meet the goal?
- A. Yes
- B. No
Answer: B
Explanation: You need to run ntdsutil.exe with the ‘compact to’ option. References:
https://theitbros.com/active-directory-database-compact-defrag/
NEW QUESTION 12
Your network contains an Active directory domain named conloso.com. The domain has an enterprise certification authority (CA).
You duplicate the Basic EFS template, and you name the template Template1. You configure the CA to issue Template1.
Users are configured to obtain a new certificate automatically when they sign in to a computer in the domain. You need to enable the users to automatically obtain a certificate based on Template1.
What should you modify?
- A. the Security settings for Template1
- B. the Request Handling properties for the CA
- C. the Publication Settings for the CA
- D. the Request Handling properties for Template1
Answer: A
NEW QUESTION 13
Your network contains an Active Directory forest named contoso.com. They connect to the forest by using ldp.exe and receive the output as shown in the following exhibit.
Use drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Answer:
Explanation: 
NEW QUESTION 14
You are deploying a web application named WebApp1 to your internal network. WebApp1 is hosted on a server named Web1 that runs Windows Server 2021.
You deploy an Active Directory Federation Services (AD FS) infrastructure and a Web Application Proxy to provide access to WebApp1 for remote users.
You need to ensure that Web1 can authenticate the remote users. What should you do?
- A. Publish WebApp1 by using pass-through preauthentication.
- B. Publish WebApp 1 as a Remote Desktop Gateway (RD Gateway) application in the Web Application Proxy.
- C. Publish WebApp1 by using AD FS preauthentication.
- D. Publish WebApp1 by using client certificate preauthentication.
Answer: A
NEW QUESTION 15
Your network contains an Active Directory forest named contoso.com. The forest contains three domains named contoso.com, corp.contoso.com, and ext.contoso.com. The forest contains three Active Directory sites named Site1, Site2, and Site3.
You have the three administrators as described in the following table.
You create a Group Policy object (GPO) named GPO1.
Which administrator or administrators can link GPO1 to Site2?
- A. Admin1 and Admin2 only
- B. Admin1, Admin2, and Admin3
- C. Admin3 only
- D. Admin1 and Admin3 only
Answer: D
Explanation: References:
https://technet.microsoft.com/en-us/library/cc732979(v=ws.11).aspx
NEW QUESTION 16
Your company has a testing environment that contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2021. Server1 has IP Address Management (IPAM) installed. IPAM has the following configuration.
The IPAM Overview page from Server Manager is shown in the IPAM Overview exhibit. (Click the Exhibit button.)
The group policy configurations are shown in the GPO exhibit. (Click the Exhibit button.) For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Answer:
Explanation: No domains have been selected in the “Configure Server Discovery” option. Therefore, no automatic discovery will take place. Manual addition of a server will also fail because IPAM needs a domain configured for server verification.
P.S. Easily pass 70-742 Exam with 222 Q&As Certleader Dumps & pdf Version, Welcome to Download the Newest Certleader 70-742 Dumps: https://www.certleader.com/70-742-dumps.html (222 New Questions)