The latest updated Microsoft 70-742 exam dumps and free 70-742 exam practice questions and answers! Latest updates from leads4pass Microsoft 70-742 Dump PDF and 70-742 Dump VCE, leads4pass 70-742 exam questions updated and answers corrected! Get the full Microsoft 70-742 braindumps from leads4pass 70-742 (VCE&PDF)
Latest 70-742 PDF for free
Share the Microsoft 70-742 Dumps PDF for free From leads4pass 70-742 Dumps part of the distraction collected on Google Drive shared by leads4pass
https://drive.google.com/file/d/1W75M5GNLl4qDxXLmMJqVT0xyNEzP2Q8A/
Latest leads4pass 70-742 Youtube
Share the latest Microsoft 70-742 exam practice questions and answers for free from Led4Pass Dumps viewed online by Youtube Videos
The latest updated Microsoft 70-742 Exam Practice Questions and Answers Online Practice Test is free to share from leads4pass (Q1-Q13)
QUESTION 1
DRAG DROP
Your network contains an Active Directory forest. The forest contains an Active Directory Federation Services (AD FS)
deployment.
The AD FS deployment contains the following:
*
An AD FS server named server1.contoso.com that runs Windows Server 2016
*
A Web Application Proxy used to publish AD FS
*
A LIPN that uses the contoso.com suffix
*
A namespace named adfs.contoso.com
You create a Microsoft Office 365 tenant named contoso.onmicrosoft.com. You use Microsoft Azure Active Directory
Connect (AD Connect) to synchronize all of the users and the UPNs from the contoso.com forest to Office 365.
You need to configure federation between Office 365 and the on-premises deployment of Active Directory.
Which three commands should you run in sequence from Server1? To answer, move the appropriate commands from
the list of commands to the answer area and arrange them in the correct order.
Select and Place:
QUESTION 2
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear on the review screen.
Your network contains an Active Directory domain named contoso.com.
The domain contains a server named Server1 that runs Windows Server 2016.
The Computer account for Server1 is in an organizational unit (OU) named OU1.
You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1.
You need to add a domain user named user1 to the local Administrators group on Server1.
Solution: From the Computer Configuration node of GPO1, you configure the Restricted Groups settings.
Does this meet the goal?
A. Yes
B. No
Correct Answer: A
QUESTION 3
Etc.
References: https://technet.microsoft.com/en-us/library/dn783349(v=ws.11).aspx
Your network contains an Active Directory forest named contoso.com. The forest contains an Active Directory
Federation Services (AD FS) farm.
You install Windows Server 2016 on a server named Server2.
You need to configure Server2 as a node in the federation server farm.
Which cmdlets should you run? To answer, select the appropriate options in the answer area.
Hot Area:
QUESTION 4
You have a Nano Server named Nano1 that runs Windows Server 2016. Nano1 is deployed to a virtual machine and is
a member of a workgroup.
You need to join Nano1 to a domain named contoso.com.
Which two commands should you run? To answer, select the appropriate options in the answer area. NOTE: Each
correct selection is worth one point.
Hot Area:
Correct Answer:
https://charbelnemnom.com/2016/11/how-to-add-nano-server-to-a-domain-nanoserver-ws2016/
QUESTION 5
Your network contains an Active Directory forest named contoso.com.
Your company has a custom application named ERP1. ERP1 uses an Active Directory Lightweight Directory Services
(AD LDS) a server named Server1 to authenticate users.
You have a member server named Server2 that runs Windows Server 2016. You install the Active Directory Federation
Services (AD FS) server role on Server2 and create an AD FS farm.
You need to configure AD FS to authenticate users from the AD LDS server.
Which cmdlets should you run? To answer, select the appropriate options in the answer area.
Hot Area:
Correct Answer:
To configure your AD FSfarm to authenticate users from an LDAP directory, you can complete the following steps:
Step 1: New-AdfsLdapServerConnection
First, configure a connection to your LDAP directory using the New-AdfsLdapServerConnection cmdlet: $DirectoryCred
= Get-Credential $vendorDirectory = New-AdfsLdapServerConnection –HostName dirserver –Port 50000–SslMode
None –AuthenticationMethod Basic –Credential $DirectoryCred
Step 2 (optional):
Next, you can perform the optional step of mapping LDAP attributes to the existing AD FS claims using the NewAdfsLdapAttributeToClaimMapping cmdlet.
Step 3: Add-AdfsLocalClaimsProviderTrust
Finally, you must register the LDAP store with AD FS as a local claims provider trust using the AddAdfsLocalClaimsProviderTrust cmdlet: Add-AdfsLocalClaimsProviderTrust –Name “Vendors” –Identifier “urn:vendors”
–Type L
References: https://technet.microsoft.com/en-us/library/dn823754(v=ws.11).aspx
QUESTION 6
Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may
be correct for more than one question in the series. Each question is independent of the other questions in this series.
Information and details provided in a question apply only to that question.
Your network contains an Active Directory domain named contoso.com. The domain contains 5,000 user accounts.
You have a Group Policy object (GPO) named DomainPolicy that is linked to the domain and a GPO named DCPolicy
that is linked to the Domain Controllers organizational unit (OU).
You need to ensure that the members of the Backup Operators group can back up domain controllers.
What should you do?
A. From the Computer Configuration node of DCPolicy, modify Security Settings.
B. From the Computer Configuration node of DomainPolicy, modify Security Settings.
C. From the Computer Configuration node of DomainPolicy, modify Administrative Templates.
D. From the User Configuration node of DCPolicy, modify Security Settings.
E. From the User Configuration node of DomainPolicy, modify Folder Redirection.
F. From user Configuration node of DomainPolicy, modify Administrative Templates.
G. From Preferences in the User Configuration node of DomainPolicy, modify Windows Settings.
H. From Preferences in the Computer Configuration node of DomainPolicy, modify Windows Settings.
Correct Answer: D
QUESTION 7
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and
fabrikam.com. The functional level of the forest and the domains is Windows Server 2008 R2.
You have a global group named Group1 in the contoso.com domain. Group1 contains the user accounts in the
contoso.com.
You need to ensure that you can add the user accounts in the fabrikam.com domain to Group1.
What should you do?
A. Assign the Domain Controllers group in fabrikam.com permissions to Group1.
B. Modify the scope of Group1 to Universal.
C. Raise the domain functional level contoso.com to Windows Server 2016.
D. Raise the domain functional level of fabriakm.com Windows Server 2016.
E. Change Group1 to a distribution group
Correct Answer: B
QUESTION 8
Your network contains an Active Directory forest named contoso.com. The forest contains 10 domains. The root domain
contains a global catalog server named DC1.
You remove the global catalog server role from DC1.
You need to decrease the size of the Active Directory database on DC1.
Solution: You stop the NTDS service on DC1. You run ntdsutil.exe, use the metadata cleanup option, and then start the
NTDS server.
Does this meet the goal?
A. Yes
B. No
Correct Answer: B
You need to run ntdsutil.exe with the `compact to\\’ option.
References: https://theitbros.com/active-directory-database-compact-defrag/
QUESTION 9
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear on the review screen.
You have a server named Web1 that runs Windows Server 2016.
You need to list all the SSL certificates on Web1 that will expire during the next 60 days.
Solution: You run the following command.
Get-ChildItem Cert:\LocalMachine\Trust |? { $_.NotAfter It (Get-Date).AddDays( 60 ) } Does this meet the goal?
A. Yes
B. No
Correct Answer: B
QUESTION 10
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear on the review screen.
Your network contains an Active Directory domain named contoso.com.
A user named User1 is in an organizational unit (OU) named OU1.
You need to enable User1 to sign in as [email protected].
Solution: From Windows PowerShell, you run Set -ADuser User1 -UserPrincipalName [email protected].
Does this meet the goal?
A. Yes
B. No
Correct Answer: B
QUESTION 11
Your network contains an Active Directory forest named contoso.com. The domain contains a server named Server1
that runs Windows Server 2016. The computer account of Server1 is an organizational unit (OU) named OU1. You open
Group Policy Management as shown in the exhibit. (Click the Exhibit button.)
An administrator reports that the settings from GPO1 are not applied to Server1.
You need to ensure that the settings from GPO1 are applied to Server1.
What should you do?
A. Enable the link of GPO1
B. Enforce GPO1
C. Disable Block inheritance
D. Remove the security filtering
Correct Answer: A
If the GPO link is enabled, the settings of the GPO are applied when Group Policy is processed for the site, domain or
OU.
References: https://docs.microsoft.com/en-us/powershell/module/grouppolicy/set-gplink?view=win10-ps
QUESTION 12
DRAG DROP
You are the network administrator for a company named Contoso, Ltd.
Contoso has a partner company named Fabrikam, Inc.
The networks of both companies contain Active Directory forests. The functional level of both forests is Windows 2008.
Both forests have Active Directory Rights Management Services (AD RMS) and Microsoft Exchange Server 2016
installed.
The users in both forests can access AD RMS and Exchange servers.
You need to ensure that the Contoso users can access the rights-protected content of the Fabrikam users. The solution
must minimize changes to the AD RMS clients and must eliminate the need to exchange AD RMS private keys.
Select and Place:
Correct Answer:
QUESTION 13
Your network is isolated from the Internet. The network contains computers that are members of a domain and
computers that are members of a workgroup. All the computers are configured to use internal DNS servers and WINS
servers for
name resolution.
The domain has a certification authority (CA). You run the Get-CACrlDistributionPoint cmdlet and receive the output as
shown in the following exhibit.
Hot Area:
Fulldumps shares the latest updated Microsoft 70-742 exam exercise questions, 70-742 dumps pdf, and Youtube video learning for free.
All exam questions and answers come from the leads4pass exam dump shared part! leads4pass updates throughout the year and shares a portion of your exam questions for free to help you understand the exam content and enhance your exam experience!
Get the full Microsoft 70-742 exam readiness dump questions at https://www.leads4pass.com/70-742.html (pdf&vce)
ps.
Get free Microsoft 70-742 dumps PDF online: https://drive.google.com/file/d/1W75M5GNLl4qDxXLmMJqVT0xyNEzP2Q8A/