Microsoft Identity with Windows Server 2016 - 070-742 FREE EXAM DUMPS QUESTIONS & ANSWERS

Your company has a marketing department.
The network contains an Active Directory domain named comoso.com.
The domain contains two top-level organizational units (OUs) named MKT_Comps and MKT_Users.
MKT_Comps contains the computer accounts for the computers in the marketing department. MKT_Users contains the user accounts for the users in the marketing department.
You link a new Group Policy object (GPO) named GPO1 to MKT_Comps.
You need to deploy a VPN connection to all of the users who sign in to the marketing department computers.
The users must be
Correct Answer: A Vote an answer
Your network contains an Active Directory domain named contoso.com. The domain contains a certification authority (CA).
The CA certificate was valid for five years and is about to expire.
You need to ensure that when you renew the CA certificate, the maximum Validity period for the certificate is
10 years.
What should you do before you renew the certificate?
Correct Answer: B Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Your network contains the Active Directory forests and domains shown in the following table.

A two-way forest trust exists between ForestA and ForestB.
Each domain in forestB contains user accounts that are used to manage servers.
You need to ensure that the user accounts used to manage the servers in forestB are members of the Server Operators groups in ForestA.
Solution: In each domain in forestB you add the user to the Server Operatorsd group. You modify the membership of the Server Operators in ForestA.
Does this meet the goal
Correct Answer: A Vote an answer
Your network contains an Active Directory domain. The domain contains a domain controller named DC1 that runs Windows Server 2016.
You start DC1 in Directory Services Restore Mode (DSRM).
You need to compact the Active Directory database on DC1.
Which three action should you perform in sequence?
Correct Answer:

Explanation

https://technet.microsoft.com/en-us/library/cc794920(v=ws.10).aspx
Your network contains an Active directory domain named conloso.com. The domain has an enterprise certification authority (CA).
You duplicate the Basic EFS template, and you name the template Template1. You configure the CA to issue Template1.
Users are configured to obtain a new certificate automatically when they sign in to a computer in the domain.
You need to enable the users to automatically obtain a certificate based on Template1.
What should you modify?
Correct Answer: A Vote an answer
Your network contains an Active Directory domain named contos.com. The domain contains a server named Server1 that runs a server core installation of windows Server 2016. Server is configured as an Active Directory Rights Management Services (AD RMS) server for the domain.
You need to install the identity Federation Support role service on Server1.
What should you don first?
Correct Answer: B Vote an answer
Your network contains an Active Directory domain. The domain contains computer named Comouter1 and an organizational unit (OU) named TestOU. TestOU contains 10 computer accounts that are used for testing. A Group Policy object (GPO) named GPO1 is linked to TestOU.
On Computer1, you modify the User Right Assignment by using the local policy.
You need to apply the User Right Assignment from Computer1 to the 10 test computers.
What should you do?
Correct Answer: C Vote an answer
Your network contains an Active Directory forest named contoso.com
Your company plans to hire 500 temporary employees for a project that will last 90 days.
You create a new user account for each employee. An organizational unit (OU) named Temp contains the user accounts for the employees.
You need to prevent the new users from accessing any of the resources in the domain after 90 days.
What should you do?
Correct Answer: B Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Your network contains an Active Directory domain named contoso.com.
Domain users use smart cards to sign in to their client computer.
Some users report that it takes a long time to sign in to their computer and that the logon attempt times out, so they must restart the sign in process.
You discover that the issues to checking the certificate revocation list (CRL) of the smart card certificates.
You need to resolve the issue without diminishing the security of the smart card logons.
What should you do?
Correct Answer: B Vote an answer
Your network contains an Active Directory domain named adatum.com. The domain contains the servers configured as shown in the following table:

You have a server named Server6 in the perimeter network.
Each server has the local users show in the following table.

The domain contains the users shown in the following table.

You install a Web Application Proxy on Server6.
You need to configure the Web Application proxy on Server6. The solution must use the principle of least privilege.
Which account should you specify in the Web Application Proxy Configuration Wizard? To answer, select the appropriate options in the answer are.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation

The user account used to configure the web application proxy must have local Administrator permission on the WAP server(s), and have access to an account that have local Administrator permissions on the AD FS servers.
References:
http://www.mistercloudtech.com/2015/11/25/how-to-install-and-configure-web-application-proxy-for-adfs/
Your network contains an Active Directory domain named contoso.com.
Some user accounts in the domain have the P.O. Box attribute set.
You plan to remove the value of the P.O. Box attribute for all of the users by using Ldifde.
You have a user named User1 who is located in the Users container.
How should you configure the LDIF file to remove the value of the P.O. Box attribute for User1? To answer, select the appropriate options in the answer area.
Correct Answer:

Explanation
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com.
The user account for a user named User1 is in an organizational unit (OU) named OU1.
You need to enable User1 to sign in as [email protected].
Solution: From Windows PowerShell, you run
Set-ADObject 'CN=User1,OU=OU1,DC=Contoso,DC=com'
-Add @{UserPrincipalName='[email protected]'}
-Remove @ {UserPrincipalName='[email protected]'}.
Does this meet the goal?
Correct Answer: A Vote an answer
0
0
0
10