[Free] 2019(Nov) EnsurePass Microsoft 70-742 Dumps with VCE and PDF 41-50

Get Full Version of the Exam
http://www.EnsurePass.com/70-742.html

Question No.41

HOTSPOT

Note: This question is part of a series of questions that use the same scenario. For you convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.

Start of repeated scenario.

You work for a company named Contoso, Ltd.

The network contains an Active Directory forest named contoso.com. A forest trust exists between contoso.com and an Active Directory forest named adatum.com.

The contoso.com forest contains the objects configured as shown in the following table.

image

Group1 and Group2 contain only user accounts.

Contoso hires a new remote user named User3. User3 will work from home and will use a computer named Computer3 that runs Windows 10. Computer3 is currently in a workgroup.

An administrator named Admin1 is a member of the Domain Admins group in the contoso.com domain.

From Active Directory Users and Computers, you create an organizational unit (OU) named OU1 in the contoso.com domain, and then you create a contact named Contact1 in OU1.

An administrator of the adatum.com domain runs the Set-ADUser cmdlet to configure a user named User1 to have a user logon name of User1@litwareinc.com.

End or repeated scenario.

You need to join Computer3 to the contoso.com domain by using offline domain join. Which command should you use in the contoso.com domain and on Computer3?

To answer, select the appropriate options in the answer area.

image

Correct Answer:

image

Question No.42

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You network contains an Active Directory forest named contoso.com. The forest contains an Active Directory Rights Management Services (AD RMS) deployment.

Your company establishes a partnership with another company named Fabrikam, Inc. The network of Fabrikam contains an Active Directory forest named fabrikam.com and an AD RMS deployment.

You need to ensure that the users in contoso.com can access rights protected documents sent by the users in fabrikam.com.

Solution: From AD RMS in contoso.com, you configure fabrikam.com as a trusted user domain. Does this meet the goal?

  1. Yes

  2. No

Correct Answer: B

Explanation:

Contoso would need to be the Trusted User Domain.

Question No.43

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory forest named contoso.com. The forest contains a member server named Server1 that runs Windows Server 2016. All domain controllers run Windows Server 2012 R2.

Contoso.com has the following configuration. PS C:\gt; (Get-ADForest).ForestMode Windows2008R2Forest

PS C:\gt; (Get-ADDomain).DomainMode Windows2008R2Domain

PS C:\gt;

You plan to deploy an Active Directory Federation Services (AD FS) farm on Server1 and to configure device registration.

You need to configure Active Directory to support the planned deployment. Solution: You run adprep.exe from the Windows Server 2016 installation media. Does this meet the goal?

  1. Yes

  2. No

Correct Answer: A

Explanation:

Device Registration requires Windows Server 2012 R2 forest schema.

Question No.44

HOTSPOT

You have a server named Server1 that runs Windows Server 2016. Server1 has the Web Application Proxy role service installed.

You are publishing an application named App1 that will use Integrated Windows authentication as shown in the following graphic.

image

Use the drop-down menus to select the answer area choice that completes each statement based on the information presented in the graphic.

image

Correct Answer:

image

Question No.45

Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.

Start of repeated scenario.

You work for a company named Contoso, Ltd.

The network contains an Active Directory forest named contoso.com. A forest trust exists between contoso.com and an Active Directory forest named adatum.com.

The contoso.com forest contains the objects configured as shown in the following table.

image

Group1 and Group2 contain only user accounts.

Contoso hires a new remote user named User3. User3 will work from home and will use a computer named Computer3 that runs Windows 10. Computer3 is currently in a workgroup.

An administrator named Admin1 is a member of the Domain Admins group in the contoso.com domain.

From Active Directory Users and Computers, you create an organizational unit (OU) named OU1 in the contoso.com domain, and then you create a contact named Contact1 in OU1.

An administrator of the adatum.com domain runs the Set-ADUser cmdlet to configure a user named User1 to have a user logon name of User1@litwareinc.com.

End or repeated scenario.

You need to ensure that Admin1 can add Group2 as a member of Group3. What should you modify?

  1. Modify the Security settings of Group3.

  2. Modify the group scope of Group3.

  3. Modify the group type of Group3.

  4. Set Admin1 as the manager of Group3.

Correct Answer: B

Question No.46

Your network contains an Active Directory domain named contoso.com.

You have an organizational unit (OU) named TestOU that contains test computers.

You need to enable a technician named Tech1 to create Group Policy objects (GPOs) and to link the GPOs to TestOU. The solution must use the principle of least privilege.

Which two actions should you perform? Each correct answer presents part of the solution.

  1. Add Tech1 to the Group Policy Creator Owners group.

  2. From Group Policy Management, modify the Delegation settings of the TestOU OU.

  3. Add Tech1 to the Protected Users group.

  4. From Group Policy Management, modify the Delegation settings of the contoso.com container.

  5. Create a new universal security group and add Tech1 to the group.

Correct Answer: AB

Question No.47

Your network contains an Active Directory forest named contoso.com

Your company plans to hire 500 temporary employees for a project that will last 90 days.

You create a new user account for each employee. An organizational unit (OU) named Temp contains the user accounts for the employees.

You need to prevent the new users from accessing any of the resources in the domain after 90 days.

What should you do?

  1. Run the Get-ADUser cmdlet and pipe the output to the Set-ADUser cmdlet.

  2. Create a group that contains all of the users in the Temp OU. Create a Password Setting object (PSO) for the new group.

  3. Create a Group Policy object (GPO) and link the GPO to the Temp OU. Modify the Password Policy settings of the GPO.

  4. Run the GET-ADOrganizationalUnit cmdlet and pipe the output to the Set-Date cmdlet.

Correct Answer: A

Question No.48

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You network contains an Active Directory forest named contoso.com. The forest contains an Active Directory Rights Management Services (AD RMS) deployment.

Your company establishes a partnership with another company named Fabrikam, Inc. The network of Fabrikam contains an Active Directory forest named fabrikam.com and an AD RMS deployment.

You need to ensure that the users in contoso.com can access rights protected documents sent by the users in fabrikam.com.

Solution: From AD RMS in fabrikam.com, you configure contoso.com as a trusted publisher domain.

Does this meet the goal?

  1. Yes

  2. No

Correct Answer: B

Explanation:

Contoso needs to trust Fabrikam.

Question No.49

DRAG DROP

You network contains an Active Directory forest. The forest contains an Active Directory Federation Services (AD FS) deployment.

The AD FS deployment contains the following:

An AD FS server named server1.contoso.com that runs Windows Server 2016 A Web Application Proxy used to publish AD FS

A UPN that uses the contoso.com suffix A namespace named adfs.contoso.com

You create a Microsoft Office 365 tenant named contoso.onmicrosoft.com. You use Microsoft Azure Active Directory Connect (AD Connect) to synchronize all of the users and the UPNs from the contoso.com forest to Office 365.

You need to configure federation between Office 365 and the on-premises deployment of Active Directory.

Which three commands should you run in sequence from Server1?

To answer, move the appropriate commands from the list of commands to the answer area and arrange them in the correct order.

image

Correct Answer:

image

Question No.50

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2016.

Server1 has IP Address Management (IPAM) installed. IPAM is configured to use the Group Policy based provisioning method. The prefix for the IPAM Group Policy objects (GPOs) is IP.

From Group Policy Management, you manually rename the IPAM GPOs to have a prefix of IPAM. You need to modify the GPO prefix used by IPAM.

What should you do?

  1. Click Configure server discovery in Server Manager.

  2. Run the Set-IpamConfiguration cmdlet.

  3. Run the Invoke-IpamGpoProvisioning cmdlet.

  4. Click Provision the IPAM server in Server Manager.

Correct Answer: B

Explanation:

The Set-IpamConfiguration cmdlet modifies the configuration for the computer that runs the IPAM server.

The -GpoPrefixlt;Stringgt; parameter specifies the unique Group Policy object (GPO) prefix name that IPAM uses to create the group policy objects. Use this parameter only when the value of the ProvisioningMethod parameter is set to Automatic.

References:

https://technet.microsoft.com/en-us/library/jj590816.aspx

Get Full Version of the Exam
70-742 Dumps
70-742 VCE and PDF