PrepAway - Latest Free Exam Questions & Answers

Tag: Briefing 70-742 (update September 30th, 2017)

Briefing 70-742: Identity with Windows Server 2016 (update September 30th, 2017)

Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each
question in the series contains a unique solution that might meet the stated goals. Some
question sets might have more than one correct solution, while others might not have a
correct solution. After you answer a question in this section, you will NOT be able to return
to it. As a result, these questions will not appear in the review screen.
You network contains an Active Directory forest named contoso.com. The forest contains an Active
Directory Rights Management Services (AD RMS) deployment. Your company establishes a
partnership with another company named Fabrikam, Inc. The network of Fabrikam contains an
Active Directory forest named fabrikam.com and an AD RMS deployment. You need to ensure that
the users in contoso.com can access rights protected documents sent by the users in fabrikam.com.
Solution: From AD RMS in contoso.com, you configure fabrikam.com as a trusted user domain.

Does this meet the goal?

Which tool should you use?

Note: This question is part of a series of questions that use the same or similar answer
choices. An answer choice may be correct for more than one question in the series. Each
question is independent of the other questions in this series. Information and details
provided in a question apply only to that question.
Your network contains an Active Directory forest named contoso.com. The forest functional level
is Windows Server 2012 R2. You need to ensure that a domain administrator can recover a deleted
Active Directory object quickly. Which tool should you use?

You need to restore the Default Domain Policy to the de…

Your company recently deployed a new child domain to an Active Directory forest. You discover
that a user modified the Default Domain Policy to configure several Windows components in the
child domain. A company policy states that the Default Domain Policy must be used only to
configure domain-wide security settings. You create a new Group Policy object (GPO) and
configure the settings for the Windows components in the new GPO. You need to restore the
Default Domain Policy to the default settings from when the domain was first installed. What should
you do?

Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each
question in the series contains a unique solution that might meet the stated goals. Some
question sets might have more than one correct solution, while others might not have a
correct solution. After you answer a question in this section, you will NOT be able to return
to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com. The domain contains a
server named Server1 that runs Windows Server 2016. The computer account for Server1 is in
organizational unit (OU) named OU1. You create a Group Policy object (GPO) named GPO1 and
link GPO1 to OU1. You need to add a domain user named User1 to the local Administrators group
on Server1.
Solution: From a domain controller, you run the Set-AdComputer cmdlet.
Does this meet the goal?

Which cmdlet should you run?

Your network contains an Active Directory forest named contoso.com. You have an Active Directory
Federation Services (AD FS) farm. The farm contains a server named Server1 that runs Windows
Server 2012 R2. You add a server named Server2 to the farm. Server2 runs Windows Server 2016.
You remove Server1 from the farm. You need to ensure that you can use role separation to manage
the farm. Which cmdlet should you run?

You need to configure the Documents folder of every use…

Note: This question is part of a series of questions that use the same or similar answer
choices. An answer choice may be correct for more than one question in the series. Each
question is independent of the other questions in this series. Information and details
provided in a question apply only to that question.
Your network contains an Active Directory domain named contoso.com. The domain contains 5,000
user accounts. You have a Group Policy object (GPO) named DomainPolicy that is linked to the
domain and a GPO named DCPolicy that is linked to the Domain Controllers organizational unit
(OU). You need to configure the Documents folder of every user to be stored on a server named
FileServer1. What should you do?

which group should you add Admin01?

Your network contains an Active Directory forest named contoso.com. The forest contains several
domains. An administrator named Admin01 installs Windows Server 2016 on a server named
Server1 and then joins Server1 to the contoso.com domain. Admin01 plans to configure Server1
as an enterprise root certification authority (CA). You need to ensure that Admin01 can configure
Server1 as an enterprise CA. The solution must use the principle of least privilege. To which group
should you add Admin01?

You need to ensure that the warning message is not gene…

You have users that access web applications by using HTTPS. The web applications are located
on the servers in your perimeter network. The servers use certificates obtained from an enterprise
root certification authority (CA). The certificates are generated by using a custom template named
WebApps. The certificate revocation list (CRL) is published to Active Directory. When users attempt
to access the web applications from the Internet, the users report that they receive a revocation
warning message in their web browser. The users do not receive the message when they access
the web applications from the intranet. You need to ensure that the warning message is not
generated when the users attempt to access the web applications from the Internet. What should
you do?

Which two actions should you perform?

Your network contains an Active Directory domain named contoso.com. You have an
organizational unit (OU) named TestOU that contains test computers. You need to enable a
technician named Tech1 to create Group Policy objects (GPOs) and to link the GPOs to TestOU.
The solution must use the principle of least privilege. Which two actions should you perform? Each
correct answer presents part of the solution.

Does this meet the goal?

Note: This question is part of a series of questions that present the same scenario. Each
question in the series contains a unique solution that might meet the stated goals. Some
question sets might have more than one correct solution, while others might not have a
correct solution. After you answer a question in this section, you will NOT be able to return
to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory forest named contoso.com. The forest contains a
member server named Server1 that runs Windows Server 2016. All domain controllers run
Windows Server 2012 R2. Contoso.com has the following configuration:
PS C:\\> (Get-ADForest).ForestMode
Windows2008R2Forest
PS C:\\> (Get-ADDomain).DomainMode
Windows2008R2Domain
PS C:\\>
You plan to deploy an Active Directory Federation Services (AD FS) farm on Server1 and to
configure device registration. You need to configure Active Directory to support the planned
deployment.
Solution: You run adprep.exe from the Windows Server 2016 installation media.
Does this meet the goal?


Page 2 of 512345