Identity with Windows Server Free Sample Questions

4 free sample questions48 in the full practice test

Try simulator

70-742 Sample Questions

  1. Question 1

    Your company has a Group Policy object (GPO) linked to their domain. They also have a GPO linked to the Domain Controllers OU.
    You are required to make sure that domain controllers can be backed up by the Backup Operators group members.
    Solution: You modify Security Settings via the User Configuration node of the GPO linked to the Domain Controllers OU.

    Does the solution meet the goal?

    Answer and explanation

    Correct answer: A

    Modifying the Group Policy object linked to the Domain Controllers OU is the correct approach to enable backup operations for domain controllers. The Backup Operators group requires specific user rights assignments including "Back up files and directories" and "Restore files and directories" to perform domain controller backups. These permissions must be applied at the Domain Controllers OU level since domain controllers have unique security requirements that differ from regular domain computers. Applying the GPO at the domain level would be insufficient as it would not override the default domain controller security policies.

  2. Question 2

    Your company’s Active Directory domain has its domain functional level set to Windows Server 2012 R2.
    You have been tasked with securing a number of high-privilege user accounts to block authentication via NTLM, and to verify authentication request to any resources using Kerberos.

    Solution: You configure the users to be members of the Protected Users group.
    Does the solution meet the goal?

    Answer and explanation

    Correct answer: B

    Adding high-privilege user accounts to the Protected Users security group is the correct solution for blocking NTLM authentication and requiring Kerberos verification. The Protected Users group, available with Windows Server 2012 R2 domain functional level, automatically enforces several security restrictions including blocking NTLM authentication, preventing DES and RC4 encryption, disabling Kerberos delegation, and limiting credential caching. This group provides enhanced security for sensitive accounts without requiring complex Group Policy configurations. Reference: https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directory-security-groups

Register free to unlock 2 more sample questions

Lifetime One

Own this practice test forever.

$46.31
$43.99
one-time
  • Full access to 48 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon