Ensurepass.com : Ensure you pass the IT Exams
2018 May Microsoft Official New Released 70-742
100% Free Download! 100% Pass Guaranteed!

Identity with Windows Server 2016

Question No: 101

Your network contains an Active Directory forest named contoso.com. The forest contains a member server named Server1. Server1 has several line-of-business applications. Each application runs as a service that uses the Network Service account. You need to configure the line-of-business applications to run by using a virtual account. What should you do?

  1. From the Services console, modify the Log On properties of the services.

  2. From the Microsoft Application Compatibility Toolkit (ACT), create a shim.

  3. From Windows PowerShell, run the Install-ADScrviceAccount cmdlet.

  4. From Windows PowerShell, run the New-ADServiccAccount cmdlet.

Answer: C

Question No: 102

Your network contains an Active Directory domain named contoso.com.

The user account for a user named User1 is in an organizational unit (OU) named OU1. You need to enable User1 to sign in as user1@adatum.com.

Ensurepass 2018 PDF and VCE

Solution: From Windows PowerShell, You run Set-ADuser User1 -UserPrincipalName User1@Adatum.com.

Does this meet the goal?

  1. Yes

  2. No

Answer: A

Question No: 103

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2016. The Computer account for Server1 is in organizational unit (OU) named OU1.

You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1.

You need to add a domain user named user1 to the local Administrators group on Server1.

Solution: From the Computer Configuration node of GPO1, you configure the local Users and Groups preference.

Does this meet the goal?

  1. Yes

  2. No

Answer: A

Ensurepass 2018 PDF and VCE

Question No: 104

Your network contains an Active Directory domain named contoso.com. The domain contains a Group Policy object (GPO) named GPO1.

You configure the Internet Settings preference in GPO1 as shown in the exhibit. (Click the Exhibit button.)

Ensurepass 2018 PDF and VCE

A user reports that the homepage of Internet Explorer is not set to http://www.contoso.com.

Ensurepass 2018 PDF and VCE

You confirm that the other settings in GPO1 are applied.

You need to configure GPO1 to set the Internet Explorer homepage. What should you do?

  1. Edit the GPO1 preference and press F5.

  2. Modify Security Settings for GPO1.

  3. Modify WMI Filtering for GPO1.

  4. Modify the GPO1 preference to use item-level targeting.

Answer: A Explanation:

The red dotted line under the homepage URL means that setting is disabled. Pressing F5 enables all settings.

Question No: 105

Your network contains an enterprise root certification authority (CA) named CA1.

Multiple computers on the network successfully enroll for certificates that will expire in one year. The certificates are based on a template named Secure_Computer. The template uses schema version 2.

You need to ensure that new certificates based on Secure_Computer are valid for three years.

What should you do?

  1. Modify the Validity period for the certificate template.

  2. Instruct users to request certificates by running the certreq.exe command.

  3. Instruct users to request certificates by using the Certificates console.

  4. Modify the Validity period for the root CA certificate.

Ensurepass 2018 PDF and VCE

Answer: A

Question No: 106

Your network contains an Active Directory domain named contoso.com.

All the accounts of the users in the sales department are in an organizational unit (OU) named SalesOU.

An application named App1 is deployed to the user accounts in SalesOU by using a Group Policy object (GPO) named SalesGPO. You need to set the registry value of

\HKEY_CURRENT_USER\Software\App1\CoIlaboration to 0. Solution: You add a user preference that has an Replace action. Does this meet the goal?

  1. Yes

  2. No

Answer: A

Explanation: https://technet.microsoft.com/en-us/library/cc753092(v=ws.11).aspx

Question No: 107

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You deploy a new Active Directory forest.

Ensurepass 2018 PDF and VCE

You need to ensure that you can create a group Managed Service Account (gMSA) for multiple member servers.

Solution: From Windows PowerShell on a domain controller, you run the Add- KdsRootKey cmdlet.

Does this meet the goal?

  1. Yes

  2. No

Answer: A

Question No: 108

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series.

Information and details provided in a question apply only to that question.

Your network contains an Active Directory domain named contoso.com. The domain contains 5,000 user accounts.

You have a Group Policy object (GPO) named DomainPolicy that is linked to the domain and a GPO named DCPolicy that is linked to the Domain Controllers organizational unit (OU).

You need to force users to change their account password at least every 30 days. What should you do?

  1. From the Computer Configuration node of DCPolicy, modify Security Settings.

  2. From the Computer Configuration node of DomainPolicy, modify Security Settings.

  3. From the Computer Configuration node of DomainPolicy, modify Administrative Templates.

  4. From the User Configuration node of DCPolicy, modify Security Settings.

  5. From the User Configuration node of DomainPolicy, modify Folder Redirection.

  6. From user Configuration node of DomainPolicy, modify Administrative Templates.

    Ensurepass 2018 PDF and VCE

  7. From Preferences in the User Configuration node of DomainPolicy, modify Windows Settings.

  8. From Preferences in the Computer Configuration node of DomainPolicy, modify Windows Settings.

Answer: B

Question No: 109 HOTSPOT

Your network contains an Active Directory domain named contoso.com. The domain contains three servers named Server1, Server2, and Server3 that run Windows Server 2016.

Server1 has IP Address Management (IPAM) installed. Server2 and Server3 have the DHCP Server role installed and have several DHCP scopes configured. The IPAM server retrieves data from Server2 and Server3.

A domain user named User1 is a member of the groups shown in the following table.

Ensurepass 2018 PDF and VCE

On Server1, you create a security policy for User1. The policy grants the IPAM DHCP Scope Administrator Role with the \Global access scope to the user.

Which actions can User1 perform? To answer, select the appropriate options in the answer area.

Ensurepass 2018 PDF and VCE

Ensurepass 2018 PDF and VCE

Answer:

Ensurepass 2018 PDF and VCE

Explanation:

Ensurepass 2018 PDF and VCE

User1 is using Server Manager, not IPAM to perform the administration. Therefore, only the 鈥淒HCP Administrators鈥?permission on Server2 and the 鈥淒HCP Users鈥?permissions on Server3 are applied.

The permissions granted through membership of the 鈥淚PAM DHCP Scope Administrator Role鈥?are not applied when the user is not using the IPAM console.

Question No: 110

Your network contains an Active Directory forest named contoso.com

Ensurepass 2018 PDF and VCE

Your company plans to hire 500 temporary employees for a project that will last 90 days.

You create a new user account for each employee. An organizational unit (OU) named Temp contains the user accounts for the employees.

You need to prevent the new users from accessing any of the resources in the domain after 90 days.

What should you do?

  1. Run the Get-ADUser cmdlet and pipe the output to the Set-ADUser cmdlet.

  2. Create a group that contains all of the users in the Temp OU. Create a Password Setting object (PSO) for the new group.

  3. Create a Group Policy object (GPO) and link the GPO to the Temp OU. Modify the Password Policy settings of the GPO.

  4. Run the GET-ADOrganizationalUnit cmdlet and pipe the output to the Set-Date cmdlet.

Answer: A

100% Ensurepass Free Download!
Download Free Demo:70-742 Demo PDF
100% Ensurepass Free Guaranteed!
70-742 Dumps

EnsurePass ExamCollection Testking
Lowest Price Guarantee Yes No No
Up-to-Dated Yes No No
Real Questions Yes No No
Explanation Yes No No
PDF VCE Yes No No
Free VCE Simulator Yes No No
Instant Download Yes No No