2026 New 70-742 Exam Dumps with PDF and VCE Free: https://www.surepassexam.com/70-742-exam-dumps.html

Master the content and be ready for exam day success quickly with this . We guarantee it!We make it a reality and give you real in our Microsoft 70-742 braindumps. Latest 100% VALID at below page. You can use our Microsoft 70-742 braindumps and pass your exam.

Microsoft 70-742 Free Dumps Questions Online, Read and Test Now.

NEW QUESTION 1
Your network contains an Active Directory domain named contoso.com. The domain contains a user named User1 and an organizational unit (OU) named OU1.
You create a Group Policy object (GPO) named GPO1. You need to ensure that User1 can link GPO1 to OU1. What should you do?

  • A. Modify the security setting of User1.
  • B. Add User1 to the Group Policy Creator Owner group.
  • C. Modify the security setting of OU1.
  • D. Modify the security setting of GPO1.

Answer: D

NEW QUESTION 2
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2021. The Computer account for Server1 is in organizational unit (OU) named OU1.
You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1.
You need to add a domain user named user1 to the local Administrators group on Server1.
Solution: From the Computer Configuration node of GPO1, you configure the local Users and Groups preference.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: A

NEW QUESTION 3
Your network contains an Active Directory domain named contoso.com.
You open Group Policy Management as shown in the Group Policy Management exhibit. (Click the Exhibit button.)
70-742 dumps exhibit
A user named User1 is in OU1. A computer named Computer2 is in OU2.
The settings of GPO1 are configured as shown in the GPO1 exhibit. (Click the Exhibit button.)
70-742 dumps exhibit
The settings of GPO2 are configured as shown in the GPO2 exhibit. (Click the Exhibit button.)
70-742 dumps exhibit
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
70-742 dumps exhibit

    Answer:

    Explanation: 70-742 dumps exhibit

    NEW QUESTION 4
    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
    Your network contains an Active Directory forest named contoso.com. The forest contains a member server named Server1 that runs Windows Server 2021. All domain controllers run Windows Server 2012 R2.
    Contoso.com has the following configuration. PS C:> (Get-ADForest).ForestMode Windows2008R2Forest
    PS C:> (Get-ADDomain).DomainMode Windows2008R2Domain
    PS C:>
    You plan to deploy an Active Directory Federation Services (AD FS) farm on Server1 and to configure device registration.
    You need to configure Active Directory to support the planned deployment. Solution: You run adprep.exe from the Windows Server 2021 installation media. Does this meet the goal?

    • A. Yes
    • B. No

    Answer: A

    Explanation: Device Registration requires Windows Server 2012 R2 forest schema.

    NEW QUESTION 5
    You deploy a new certification authority (CA) to a server that runs Windows Server 2021. You need to configure the CA to support recovery of certificates.
    What should you do first?

    • A. Modify the extensions of the OCSP Response Signing template
    • B. Modify the Recovery Agents settings from the properties of the CA.
    • C. Assign the Request Certificates permission to the user account that will be responsible for recovering certificates.
    • D. Configure the Key Recovery Agent template as a certificate template to issue.

    Answer: A

    NEW QUESTION 6
    You network contains an Active Directory domain named contoso.com. The domain contains 1,000 desktop computers and 500 laptops. An organizational unit (OU) named OU1 contains the computer accounts for the desktop computers and the laptops.
    You create a Windows PowerShell script named Script1.ps1 that removes temporary files and cookies. You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1.
    You need to run the script once weekly only on the laptops. What should you do?

    • A. In GPO1, create a File preference that uses item-level targeting.
    • B. In GPO1, create a Scheduled Tasks preference that uses item-level targeting.
    • C. In GPO1, configure the File System security polic
    • D. Attach a WMI filter to GPO1.
    • E. In GPO1, add Script1.ps1 as a startup scrip
    • F. Attach a WMI filter to GPO1.

    Answer: B

    NEW QUESTION 7
    Your network contains an Active Directory domain named contoso.com. The domain contains an administrative workstation named WKS1 that runs Windows 10.
    You have a Group Policy object (GPO) named GPO1.
    You download a custom administrative template that contains the following files:
    You need to ensure that you can configure GPO1 by using the settings in the new administrative template. To where should you copy each file? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.
    70-742 dumps exhibit

      Answer:

      Explanation: References:
      https://support.microsoft.com/en-us/help/918239/how-to-write-custom-adm-and-admx-administrative-template-f

      NEW QUESTION 8
      Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
      After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
      Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2021. The computer account for Server1 is in organizational unit (OU) named OU1.
      You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1.
      You need to add a domain user named User1 to the local Administrators group on Server1. Solution: From a domain controller, you run the Set-AdComputer cmdlet.
      Does this meet the goal?

      • A. Yes
      • B. No

      Answer: B

      NEW QUESTION 9
      Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.
      Start of repeated Scenario:
      You work for a company named Contoso, Ltd.
      The network contains an Active Directory forest named contoso.com. A forest trust exists between contoso.com and an Active Directory forest named adatum.com.
      The contoso.com forest contains the objects configured as shown in the following table. Scenario:
      Refer to following table:
      70-742 dumps exhibit
      Group1 and Group 2 contain only user accounts.
      Contoso hires a new remote user named User3. User3 will work from home and will use a computer named Computed that runs Windows 10. Computed is currently in a workgroup.
      An administrator named Admin1 is a member of the Domain Admins group in the contoso.com domain. From Active Directory Users and Computers, you create an organizational unit (OU) named OU1 in the
      contoso.com domain, and then you create a contact named Contact1 in OU1,
      An administrator of the adatum.com domain runs the Set-ADUser cmdlet to configure a user named User1 to have a user logon name of User1@litwareinc.com.
      End of Scenario:
      Admin1 attempts to delete OU1 and receives an error message. You need to ensure that Admin1 can delete OU1. What should you do first?

      • A. Delete Contact1.
      • B. Add Admin1 to the Enterprise Admins group.
      • C. Modify the Object settings for OU1.
      • D. Disable the Active Directory Recycle Bin.

      Answer: C

      NEW QUESTION 10
      Your network contains an Active Directory forest named contoso.com.
      Your company has a custom application named ERP1. ERP1 uses an Active Directory Lightweight Directory Services (AD LDS) server named Server1 to authenticate users.
      You have a member server named Server2 that runs Windows Server 2021. You install the Active Directory Federation Services (AD FS) server role on Server2 and create an AD FS farm.
      You need to configure AD FS to authenticate users from the AD LDS server.
      Which cmdlets should you run? To answer, select the appropriate options in the answer area.
      70-742 dumps exhibit

        Answer:

        Explanation: To configure your AD FSfarm to authenticate users from an LDAP directory, you can complete the following steps:
        Step 1: New-AdfsLdapServerConnection
        First, configure a connection to your LDAP directory using the New-AdfsLdapServerConnection cmdlet:
        $DirectoryCred = Get-Credential
        $vendorDirectory = New-AdfsLdapServerConnection –HostName dirserver –Port 50000–SslMode None
        –AuthenticationMethod Basic –Credential $DirectoryCred
        Step 2 (optional):
        Next, you can perform the optional step of mapping LDAP attributes to the existing AD FS claims using the New-AdfsLdapAttributeToClaimMapping cmdlet.
        Step 3: Add-AdfsLocalClaimsProviderTrust
        Finally, you must register the LDAP store with AD FS as a local claims provider trust using the Add-AdfsLocalClaimsProviderTrust cmdlet:
        Add-AdfsLocalClaimsProviderTrust –Name “Vendors” –Identifier “urn:vendors” –Type L References: https://technet.microsoft.com/en-us/library/dn823754(v=ws.11).aspx

        NEW QUESTION 11
        Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
        After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
        You deploy a new Active Directory forest.
        You need to ensure that you can create a group Managed Service Account (gMSA) for multiple member servers.
        Solution: You configure Kerberos constrained delegation on the computer account of each member server. Does this meet the goal?

        • A. Yes
        • B. No

        Answer: B

        NEW QUESTION 12
        Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
        After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
        You network contains an Active Directory forest named contoso.com. The forest contains an Active Directory Rights Management Services (AD RMS) deployment.
        Your company establishes a partnership with another company named Fabrikam, Inc. The network of Fabrikam contains an Active Directory forest named fabrikam.com and an AD RMS deployment.
        You need to ensure that the users in contoso.com can access rights protected documents sent by the users in fabrikam.com.
        Solution: From AD RMS in contoso.com, you configure fabrikam.com as a trusted user domain. Does this meet the goal?

        • A. Yes
        • B. No

        Answer: B

        Explanation: Contoso would need to be the Trusted User Domain.

        NEW QUESTION 13
        Your network contains an Active Directory domain named contoso.com.
        You have an organizational unit (OU) named TestOU that contains test computers.
        You need to enable a technician named Tech1 to create Group Policy objects (GPOs) and to link the GPOs to TestOU. The solution must use the principle of least privilege.
        Which two actions should you perform? Each correct answer presents part of the solution.

        • A. Add Tech1 to the Group Policy Creator Owners group.
        • B. From Group Policy Management, modify the Delegation settings of the TestOU OU.
        • C. Add Tech1 to the Protected Users group.
        • D. From Group Policy Management, modify the Delegation settings of the contoso.com container.
        • E. Create a new universal security group and add Tech1 to the group.

        Answer: AB

        NEW QUESTION 14
        Your network contains an Active Directory domain named contoso.com. You discover that users can use passwords that contain only numbers.
        You need to ensure that all the user passwords in the domain contain at least three of the following types of characters:
        • Numbers
        • Uppercase letters
        • Lowercase letters
        • Special characters What should you do?

        • A. the Default Domain Policy
        • B. the local policy on each client computer
        • C. the Default Domain Controllers Policy
        • D. the local policy on each domain controller

        Answer: A

        NEW QUESTION 15
        Your network contains an Active Directory forest named contoso.com. The forest contains an enterprise root certification authority (CA) on a server that runs Windows Server 2021.
        You plan to create and issue a custom subordinate CA template.
        You need to prevent subordinate CAs from issuing subordinate certificates. What should you configure in the template?

        • A. the Request Handling settings
        • B. the Cryptography settings
        • C. the Basic Constraints extension
        • D. the Security settings

        Answer: D

        NEW QUESTION 16
        Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.
        Start of repeated scenario.
        Your network contains an Active Directory domain named contoso.com. The domain contains a single site named Site1. All computers are in Site1.
        The Group Policy objects (GPOs) for the domain are configured as shown in the exhibit. (Click the Exhibit button.)
        70-742 dumps exhibit
        The relevant users and client computer in the domain are configured as shown in the following table.
        70-742 dumps exhibit
        End of repeated scenario.
        You are evaluating what will occur when you remove the Authenticated Users group from the Security Filtering settings of A5.
        Which GPO or GPOs will apply to User1 when the user signs in to Computer1 after Security Filtering is configured?

        • A. A1 and A7 only
        • B. A3 and A1 only.
        • C. A3, A1, A6 and A7
        • D. A7 only

        Answer: A

        Thanks for reading the newest 70-742 exam dumps! We recommend you to try the PREMIUM Surepassexam 70-742 dumps in VCE and PDF here: https://www.surepassexam.com/70-742-exam-dumps.html (222 Q&As Dumps)