[Free] 2018(May) EnsurePass Braindumps Microsoft 70-742 Dumps with VCE and PDF 31-40

Ensurepass.com : Ensure you pass the IT Exams
2018 May Microsoft Official New Released 70-742
100% Free Download! 100% Pass Guaranteed!

Identity with Windows Server 2016

Question No: 31

Your network contains an Active Directory domain named contoso.com. You discover that users can use passwords that contain only numbers.

You need to ensure that all the user passwords in the domain contain at least three of the following types of characters:

  • Numbers

  • Uppercase letters

    Ensurepass 2018 PDF and VCE

  • Lowercase letters

  • Special characters What should you do?

  1. the Default Domain Policy

  2. the local policy on each client computer

  3. the Default Domain Controllers Policy

  4. the local policy on each domain controller

Answer: B

Question No: 32

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named Server1.

You recently restored a backup of the Active Directory database from Server1 to an alternate Location.

The restore operation does not interrupt the Active Directory services on Server1.

You need to make the Active Directory data in the backup accessible by using Lightweight Directory Access Protocol (LDAP).

Which tool should you use?

  1. Dsadd quota

  2. Dsmod

  3. Active Directory Administrative Center

  4. Dsacls

  5. Dsamain

  6. Active Directory Users and Computers

    Ensurepass 2018 PDF and VCE

  7. Ntdsutil

  8. Group Policy Management Console

Answer: E

Question No: 33 DRAG DROP

Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server 2016.

Server1 has IP Address Management (IPAM) installed. Server2 has Microsoft System Center 2016 Virtual Machine Manager (VMM) installed.

You need to integrate IPAM and VMM.

Which types of objects should you create on each server? To answer, drag the appropriate object types to the correct servers. Each object type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

Ensurepass 2018 PDF and VCE

Answer:

Ensurepass 2018 PDF and VCE

Explanation:

Ensurepass 2018 PDF and VCE

Ensurepass 2018 PDF and VCE

Server 1 (IPAM): Access Policy

VMM must be granted permission to view and modify IP address space in IPAM, and to perform remote management of the IPAM server. VMM uses a 鈥淩un As鈥?account to provide these permissions to the IPAM network service plugin. The 鈥淩un As鈥?account must be configured with appropriate permission on the IPAM server.

To assign permissions to the VMM user account

In the IPAM server console, in the upper navigation pane, click ACCESS CONTROL, right- click Access Policies in the lower navigation pane, and then click Add AccessPolicy.

Etc.

Server 2 (VMM) #1: Network Service Server 2 (VMM) #2: Run As Account

Perform the following procedure using the System Center VMM console. To configure VMM (see step 1-3, step 6-7)

Ensurepass 2018 PDF and VCE

Ensurepass 2018 PDF and VCE

Etc.

References: https://technet.microsoft.com/en-us/library/dn783349(v=ws.11).aspx

Question No: 34

Your network contains an Active Directory forest named contoso.com. The forest contains three domains named contoso.com, corp.contoso.com, and ext.contoso.com. The forest contains three Active Directory sites named Site1, Site2, and Site3.

You have the three administrators as described in the following table.

Ensurepass 2018 PDF and VCE

Ensurepass 2018 PDF and VCE

You create a Group Policy object (GPO) named GPO1. Which administrator or administrators can link GPO1 to Site2?

  1. Admin1 and Admin2 only

  2. Admin1, Admin2, and Admin3

  3. Admin3 only

  4. Admin1 and Admin3 only

Answer: D Explanation:

References:

https://technet.microsoft.com/en-us/library/cc732979(v=ws.11).aspx

Question No: 35 HOTSPOT

Your network contains an Active Directory domain named contoso.com. Some user accounts in the domain have the P.O. Box attribute set.

You plan to remove the value of the P.O. Box attribute for all of the users by using Ldifde. You have a user named User1 who is located in the Users container.

How should you configure the LDIF file to remove the value of the P.O. Box attribute for User1? To answer, select the appropriate options in the answer area.

Ensurepass 2018 PDF and VCE

Ensurepass 2018 PDF and VCE

Answer:

Ensurepass 2018 PDF and VCE

Question No: 36

Ensurepass 2018 PDF and VCE

Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question is independent of the other questions in this series. Information and details provided in a question apply only to that question.

Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1 that runs Windows Server 2016.

You need to create a snapshot of the Active Directory database on DC1. Which tool should you use?

  1. Dsadd quota

  2. Dsmod

  3. Active Directory Administrative Center

  4. Dsacls

  5. Dsmain

  6. Active Directory Users and Computers

  7. Ntdsutil

  8. Group Policy Management Console

Answer: E

Question No: 37

Your company has a marketing department and a security department.

The network contains an Active Directory domain named contoso.com. The domain contains an enterprise certification authority (CA).

You have two organizational units (OUs) named MKT_UsersOU and MKT_ComputersOU. MKT_UsersOU contains the user accounts for the users in the marketing department.

MKT_ComputersOU contains the computer accounts for the computers in the marketing department.

A Group policy object (GPO) named GPO1 is linked to MKT_UsersOU. A GPO named GPO2 linked to MKT_ComputersOU.

Ensurepass 2018 PDF and VCE

You plan to deploy a web application for the marketing department users. The application will require certificates for authentication.

The security department configures the CA to support the planned deployment.

You need to ensure that the web application can authenticate the marketing department users.

What should you do?

  1. From the User Configuration node of GPO1, create an Internet Setting preference.

  2. From the User Configuration node of GPO1, configure the Certificate Services Client – Auto enrollment settings.

  3. From the Computer Configuration node of GPO2, configure the Certificate Services Client – Certificate Enrollment Policy settings.

  4. From the Computer Configuration node of GPO2, create the Automatic Certificate Request Settings.

Answer: A

Question No: 38

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a server named Web1 that runs Windows Server 2016.

You need to list all the SSL certificates on Web1 that will expire during the next 60 days. Solution: You run the following command.

Get-ChildItem Cert:\LocalMachine\Trust |? { $_.NotAfter -It (Get-Date).AddDays( 60 ) }

Ensurepass 2018 PDF and VCE

Does this meet the goal?

  1. Yes

  2. No

Answer: A

Question No: 39

You network contains an Active Directory domain named contoso.com. The domain contains an enterprise certification authority (CA) named CA1.

You have a test environment that is isolated physically from the corporate network and the Internet.

You deploy a web server to the test environment. On CA1, you duplicate the Web Server template, and you name the template Web_Cert_Test.

For the web server, you need to request a certificate that does not contain the revocation information of CA1.

What should you do first?

  1. From the properties of CA1, allow certificates to be published to the file system.

  2. From the properties of CA1, select Restrict enrollment agents, and then add Web_Cert_Test to the restricted enrollment agent.

  3. From the properties of Web_Cert_Test, assign the Enroll permission to the guest account.

  4. From the properties of Web_Cert_Test, set the Compatibility setting of CA1 to Windows Server 2016.

Answer: D

Question No: 40

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some

Ensurepass 2018 PDF and VCE

question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You deploy a new Active Directory forest.

You need to ensure that you can create a group Managed Service Account (gMSA) for multiple member servers.

Solution: You configure Kerberos constrained delegation on the computer account of each domain controller.

Does this meet the goal?

  1. Yes

  2. No

Answer: B

100% Ensurepass Free Download!
Download Free Demo:70-742 Demo PDF
100% Ensurepass Free Guaranteed!
Download 2018 EnsurePass 70-742 Full Exam PDF and VCE

EnsurePass ExamCollection Testking
Lowest Price Guarantee Yes No No
Up-to-Dated Yes No No
Real Questions Yes No No
Explanation Yes No No
PDF VCE Yes No No
Free VCE Simulator Yes No No
Instant Download Yes No No

Leave a Reply

Your email address will not be published. Required fields are marked *