realexamdumps.com

Thursday, 8 August 2019

Download Microsoft 70-742 Exam Questions - Free 3 Months Updates - Realexamdumps.com

Question: 1

Your company recently deployed a new child domain to an Active Directory forest. You discover that a user modified the Default Domain Policy to configure several Windows components in the child domain. A company policy states that the Default Domain Policy must be used only to configure domain-wide security settings. You create a new Group Policy object (GPO) and configure the settings for the Windows components in the new GPO. You need to restore the Default Domain Policy to the default settings from when the domain was first installed. What should you do?

A. From Group Policy Management, click Starter GPOs, and then click Manage Backups.
B. From a command prompt, run the dcgpofix.exe command.
C. From Windows PowerShell, run the Copy-GPO cmdlet.
D. Run ntdsutil.exe to perform a metadata cleanup and a semantic database analysis.

Answer: B   


Question: 2

You network contains an Active Directory domain named contoso.com. The domain contains 1,000 desktop computers and 500 laptops. An organizational unit (OU) named OU1 contains the computer accounts for the desktop computers and the laptops. You create a Windows PowerShell script named Script1.ps1 that removes temporary files and cookies. You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1. You need to run the script once weekly only on the laptops. What should you do?


A. In GPO1, create a File preference that uses item-level targeting.
B. In GPO1, create a Scheduled Tasks preference that uses item-level targeting.
C. In GPO1, configure the File System security policy. Attach a WMI filter to GPO1.
D. In GPO1, add Script1.ps1 as a startup script. Attach a WMI filter to GPO1.

Answer: B

Question: 3

You deploy a new enterprise certification authority (CA) named CA1. You plan to issue certificates based on the User certificate template. You need to ensure that the issued certificates are valid for two years and support autoenrollment. What should you do first?

A. Run the certutil.exe command and specify the resubmit parameter.
B. Duplicate the User certificate template.
C. Add a new certificate template for CA1 to issue.
D. Modify the Request Handling settings for the CA.

Answer: B   

Question: 4

Your network contains an enterprise root certification authority (CA) named CA1. Multiple computers on the network successfully enroll for certificates that will expire in one year. The certificates are based on a template named Secure_Computer. The template uses schema version 2. You need to ensure that new certificates based on Secure_Computer are valid for three years. What should you do?

A. Modify the Validity period for the certificate template.
B. Instruct users to request certificates by running the certreq.exe command.
C. Instruct users to request certificates by using the Certificates console.
D. Modify the Validity period for the root CA certificate.

Answer: A   

Question: 5

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The domain contains a server named Server1. An administrator named Admin01 plans to configure Server1 as a standalone certification authority (CA). You need to identify to which group Admin01 must be a member to configure Server1 as a standalone A. The solution must use the principle of least privilege. To which group should you add Admin01?

A. Administrators on Server1.
B. Domain Admins in contoso.com
C. Cert Publishers on Server1
D. Key Admins in contoso.com

Answer: A   

Download Microsoft 70-742 Exam Questions - Free 3 Months Updates - Realexamdumps.com

No comments:

Post a Comment