Where can I find accurate and the latest study guide for the Microsoft 70-742? It’s here! 70-742 study guide: latest Microsoft 70-742 practice questions, latest Microsoft 70-742 pdf dumps, Microsoft 70-742 exam video learning. Are you looking for a Exam 70–742 and you want to get help, then https://www.pass4itsure.com/70-742.html 70-742 dumps is the best.

Best questions to prepare for the Microsoft MCSA 70-742 study guide

Vendor: Microsoft
Certifications: MCSA: Windows Server 2016
Exam Code: 70-742
Exam Name: Identity with Windows Server 2016

QUESTION 1
Your network contains an Active Directory domain named contoso.com.
You deploy a standalone root certification authority (CA) named CA1.
You need to autoenroll domain computers for certificates by using a custom certificate template.
What should you do first?
A. Modify the Policy Module for CA1.
B. Modify the Exit Module for CA1.
C. Install a standalone subordinate CA.
D. Install an enterprise subordinate CA.
Correct Answer: D
You can\\’t create templates or configure auto-enrollment on a standalone CA.


QUESTION 2
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
Your network contains an Active Directory domain named contoso.com.
A user named User1 is in an organizational unit (OU) named OU1.
You need to enable User1 to sign in as [email protected].
You need a list of groups to which User1 is either a direct member or an indirect member.
Solution: From Windows PowerShell, you run Set -Aduser User1 -UserPricncipalName [email protected].
Does this meet the goal?
A. Yes
B. No
Correct Answer: B

QUESTION 3
Your network contains an Active Directory domain named contoso.com.
Domain users use smart cards to sign in to their client computer.
Some users report that it takes a long time to sign in to their computer and that the logon attempt times out, so they
must restart the sign in process.
You discover that the issues to checking the certificate revocation list (CRL) of the smart card certificates.
You need to resolve the issue without diminishing the security of the smart card logons.
What should you do?
A. From the properties of the smart card\\’s certificate template, modify the Request Handling settings.
B. From the properties of the smart card\\’s certificate template, modify the Issuance Requirements settings.
C. Deactivate certificate revocation checks on the computers.
D. Implement an Online Certification Status Protocol (OCSP) responder.
Correct Answer: D


QUESTION 4
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
Your network contains an Active Directory domain named contoso.com.
The user account for a user named User1 is in an organizational unit (OU) named OU1.
You need to enable User1 to sign in as [email protected].
Solution: From Active Directory Users and Computers, you set the E-mail property of User1 to [email protected].
Does this meet the goal?
A. Yes
B. No
Correct Answer: B

QUESTION 5
DRAG DROP
You network contains an Active Directory forest. The forest contains an Active Directory Federation Services (AD FS)
deployment.
The AD FS deployment contains the following:
*
An AD FS server named server1.contoso.com that runs Windows Server 2016
*
A Web Application Proxy used to publish AD FS
*
A LIPN that uses the contoso.com suffix
*
A namespace named adfs.contoso.com
You create a Microsoft Office 365 tenant named contoso.onmicrosoft.com. You use Microsoft Azure Active Directory
Connect (AD Connect) to synchronize all of the users and the UPNs from the contoso.com forest to Office 365.
You need to configure federation between Office 365 and the on-premises deployment of Active Directory.
Which three commands should you run in sequence from Server1? To answer, move the appropriate commands from
the list of commands to the answer area and arrange them in the correct order.
Select and Place:

Easyhometraining 70-742 exam questions-q5

Correct Answer:

Easyhometraining 70-742 exam questions-q5-2

QUESTION 6
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
Your network contains an Active Directory forest. The forest contains a domain named contoso.com. The domain
contains three domain controllers.
A domain controller named lon-dc1 fails. You are unable to repair lon-dc1.
You need to prevent the other domain controllers from attempting to replicate to lon-dc1.
Solution: From Active Directory Sites and Trusts, you transfer the operations master roles from lon-dc1.
Does this meet the goal?
A. Yes
B. No
Correct Answer: B

QUESTION 7
You have an enterprise certification authority (CA) named ContosoCA. Recovery agents are configured for ContosoCA.
You duplicate the User certificate template and name it Cont_User. You plan to issue the certificates based on
Cont_User to provide users with the ability to encrypt email messages and files.
You need to ensure that the recovery agents can access any user-encrypted files and email messages if the users lose
their certificate.
What should you do?
A. Modify the Recovery Agents settings for ContosoCA.
B. Issue a certificate based on a key recovery agent certificate.
C. Modify the Request Handling settings for Cont_User.
D. On ContosoCA, configure the Key Recovery Agent template as a certificate template to issue.
Correct Answer: C

QUESTION 8
Your network contains an Active Directory domain named contoso.com. The domain contains a member server named
Server1 and a domain controller named DC1. Both servers run Windows Server 2016. Server1 is used to perform
administrative tasks, including managing Group Polices.
After maintenance is performed on DC1, you open a Group Policy object (GPO) from Server1 as shown in the exhibit.

Easyhometraining 70-742 exam questions-q8

You need to be able to view all of the Administrative Templates settings in GPO1. What should you do?
A. From File Explorer, copy the administrative templates from \\contoso.com\SYSVOL\contoso.com\Policies to the
PolicyDefinitions folder on Server1.
B. From File Explorer, delete \\contoso.com\SYSVOL\contoso.com\Policies\PolicyDefinitions.
C. From File Explorer, delete the PolicyDefinitions folder from Server1.
D. From Group Policy Management, configure WMI Filtering for GPO1.
Correct Answer: B

QUESTION 9
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
Your network contains the Active Directory forests and domains shown in the following table:

Easyhometraining 70-742 exam questions-q9

A two-way forest trust exists between ForestA and ForestB.
Each domain in ForestB contains user accounts that are used to manage servers.
You need to ensure that the user accounts used to manage the servers in ForestB are members of the Server
Operators in ForestA.
Solution: In each domain in ForestB, you create a global group that contains the user accounts of the respective
domain. You create a universal group in DomainBRoot. You add the new global groups to the new universal group. You
modify
the membership of the Server Operators in ForestA.
Does this meet the goal?
A. Yes
B. No
Correct Answer: A
References: https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directorysecurity-groups#bkmk-serveroperators

QUESTION 10
Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may
be correct for more than one question in the series. Each question is independent of the other questions in this series.
Information and details provided in a question apply only to that question.
Your network contains an Active Directory domain named contoso.com. The domain contains 5,000 user accounts.
You have a Group Policy object (GPO) named DomainPolicy that is linked to the domain and a GPO named DCPolicy
that is linked to the Domain Controllers organizational unit (OU).
You need to use the application control policy settings to prevent several applications from running on the network.
What should you do?
A. From the Computer Configuration node of DCPolicy, modify Security Settings.
B. From the Computer Configuration node of DomainPolicy, modify Security Settings.
C. From the Computer Configuration node of DomainPolicy, modify Administrative Templates.
D. From the User Configuration node of DCPolicy, modify Security Settings.
E. From the User Configuration node of DomainPolicy, modify Folder Redirection.
F. From user Configuration node of DomainPolicy, modify Administrative Templates.
G. From Preferences in the User Configuration node of DomainPolicy, modify Windows Settings.
H. From Preferences in the Computer Configuration node of DomainPolicy, modify Windows Settings.
Correct Answer: B

QUESTION 11
Your network contains an Active Directory domain named conIoso.com. The domain contains a server named
Server1 that runs Windows Server 2016. All domain joined computers have Fast logon Optimization enabled You need
to ensure that the next time a user signs in to Server1, the user-targeted Group Policy objects [GPOs) are processed
fully
before the user gains access to the desktop.
What should you run on Server1?
A. secedit with the/configure switch
B. gpupdate with the /Sync switch
C. Invoke-GPupdate with the -Boot switch
D. gpupddte with the /wait switch
Correct Answer: D

QUESTION 12
Your network contains two network domains sales.fabrikam.com, and contoso.com,
You recently added a site named Europe.
The forest contains four users who are members of the groups shown in the following table.

Easyhometraining 70-742 exam questions-q12

You need to create a Group Policy object (GPO) named GP01 and to link GPO1 to the Europe site.
Which users can perform each task? To answer, select the appropriate options in the answer area. NOTE: Each correct
selection is worth one point
Hot Area:

Easyhometraining 70-742 exam questions-q12-2

Correct Answer:

Easyhometraining 70-742 exam questions-q12-3

QUESTION 13
Your network contains an Active Directory forest named contoso.com. The forest contains three domains named
contoso.com, corp.contoso.com, and ext.contoso.com. The forest contains three Active Directory sites named Site1,
Site2, and Site3.
You have the three administrators as described in the following table.

Easyhometraining 70-742 exam questions-q13

You create a Group Policy object (GPO) named GPO1. Which administrator or administrators can link GPO1 to Site2?
A. Admin1 and Admin2 only
B. Admin1, Admin2, and Admin3
C. Admin3 only
D. Admin1 and Admin3 only
Correct Answer: D
To link an existing GPO to a site, domain, or OU, you must have Link GPOs permission on that site, domain, or OU. By
default, only domain administrators and enterprise administrators have this privilege for domains and OUs. Enterprise
administrators and domain administrators of the forest root domain have this privilege for sites.
References: https://technet.microsoft.com/en-us/library/cc732979(v=ws.11).aspx

Study guide: Microsoft 70-742 pdf dumps free download

[100% free] Microsoft 70-742 pdf dumps https://drive.google.com/file/d/1jORV37MWW45flbJ2bfcVm4b0WRQPQevS/view?usp=sharing

Microsoft 70-742 study guide video

70-742 study guide for the Microsoft 70-742 by Pass4itsure

Pass4itsure-Reason-for-selection

Exam preparation tips

70-742 study guide: For many people, exams are the most stressful. With so much effort around the results, there may be a higher degree of pressure to execute effectively. Here are some exam preparation tips to make you stand out in the exam.

Pass4itsure tips

Latest discount code “2020PASS” – Pass4itsure

The latest discount code “2020PASS” is provided below.

Pass4itsure-discount-code-2020

12% off discount, pass the exam, come soon!

Summarize:

Microsoft 70-742 dumps with valid 70-742 exam questions and answers in PDF is reliable 70-742 dumps 70-742 study guide to prepare and pass exam with high grades in only first take.

Download Your Microsoft 70-742 Dumps Study Guide Here: https://www.pass4itsure.com/70-742.html