Microsoft 70-744 Securing Windows Server 2016 Online Training
Microsoft 70-744 Online Training
The questions for 70-744 were last updated at Nov 23,2024.
- Exam Code: 70-744
- Exam Name: Securing Windows Server 2016
- Certification Provider: Microsoft
- Latest update: Nov 23,2024
Your network contains an Active Directory domain named contoso.com. You create a Microsoft Operations Management Suite (OMS) workspace. You need to connect several computers directly to the workspace.
Which two pieces of information do you require? Each correct answer presents part of the solution.
- A . the ID of the workspace
- B . the name of the workspace
- C . the URL of the workspace
- D . the key of the workspace
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1.
Server1 is configured as shown in the following table.
You plan to create a pilot deployment of Microsoft Advanced Threat Analytics (ATA). You need to install the ATA Center on Server1.
What should you do first?
- A . Install Microsoft Security Compliance Manager (SCM).
- B . Obtain an SSL certificate.
- C . Assign an additional IPv4 address.
- D . Remove Server1 from the domain.
Your network contains an Active Directory domain named contoso.com. The domain contains five file servers that run Windows Server 2016. You have an organizational unit (OU) named Finance that contains all of the servers.
You create a Group Policy object (GPO) and link the GPO to the Finance OU. You need to ensure that when a user in the finance department deletes a file from a file server, the event is logged. The solution must log only users who have a manager attribute of Ben Smith.
Which audit policy setting should you configure in the GPO?
- A . File system in Global Object Access Auditing
- B . Audit Detailed File Share
- C . Audit Other Account Logon Events
- D . Audit File System in Object Access
Your network contains an Active Directory domain named contoso.com. The domain contains a server
named Server1 that runs Windows Server 2016. You have an organizational unit (OU) named Administration that contains the computer account of Server1.
You import the Active Directory module to Server1. You create a Group Policy object (GPO) named GPO1. You link GPO1 to the Administration OU. You need to log an event each time an Active Directory cmdlet is executed successfully from Server1.
What should you do?
- A . From Advanced Audit Policy in GPO1, configure auditing for directory service changes.
- B . Run the(Get-Module ActiveDirectory).LogPipelineExecutionDetails = $falsecommand.
- C . Run the(Get-Module ActiveDirectory).LogPipelineExecutionDetails = $truecommand.
- D . From Advanced Audit Policy in GPO1, configure for other privilege use events.
- E . From Administrative Templates in GPO1, configure an Event Logging policy.
HOTSPOT
Your network contains an Active Directory domain named adatum.com. The domain contains a file server named Server1 that runs Windows Server 2016. You have an organizational unit (OU) named OU1 that contains Server1. You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1. A user named User1 is a member of group named Group1.
The properties of User1 are shown in the User1 exhibit. (Click the Exhibit button.)
User1 has permissions to two files on Server1 configured as shown in the following table.
From Auditing Entry for Global File SACL, you configure the advanced audit policy settings in GPO1 as shown in the SACL exhibit. (Click the Exhibit button.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Your network contains an Active Directory domain named contoso.com. You are deploying Microsoft Advanced Threat Analytics (ATA) to the domain. You install the ATA Center on server named Server1 and the ATA Gateway on a server named Server2. You need to ensure that Server2 can collect NTLM authentication events.
What should you configure?
- A . the domain controllers to forward Event ID 4776 to Server2
- B . the domain controllers to forward Event ID 1000 to Server1
- C . Server2 to forward Event ID 1026 to Server1
- D . Server1 to forward Event ID 1000 to Server 2
Your network contains an Active Directory forest named contoso.com. The network is connected to the Internet. You have 100 point-of-sale (POS) devices that run Windows 10. The devices cannot access the Internet. You deploy Microsoft Operations Management Suite (OMS). You need to use OMS to collect and analyze data from the POS devices.
What should you do first?
- A . Deploy Windows Server Gateway to the network.
- B . Install the OMS Log Analytics Forwarder on the network.
- C . Install Microsoft Data Management Gateway on the network.
- D . Install the Simple Network Management Protocol (SNMP) feature on the devices.
- E . Add the Microsoft NDIS Capture service to the network adapter of the devices.
HOTSPOT
You plan to deploy three encrypted virtual machines that use Secure Boot.
The virtual machines will be configured as shown in the following table.
How should you protect each virtual machine? To answer, select the appropriate options in the answer area.
HOTSPOT
Your network contains two Active Directory forests named contoso.com and adatum.com. Contoso.com contains a Hyper-V host named Server1. Server1 is a member of a group named HyperHosts. Adatum.com contains a server named Server2. Server1 and Server2 run Windows Server 2016.
Contoso.com trusts adatum.com.
You plan to deploy shielded virtual machines to Server1 and to configure Admin-trusted attestation on Server2.
Which component should you install and which cmdlet should you run on Server2? To answer, select the appropriate options in the answer area.
Your network contains an Active Directory forest named contoso.com. The forest functional level is Windows Server 2012. The forest contains a single domain. The domain contains multiple Hyper-V hosts.
You plan to deploy guarded hosts.
You deploy a new server named Server22 to a workgroup.
You need to configure Server22 as a Host Guardian Service server.
What should you do before you initialize the Host Guardian Service on Server22?
- A . Install the Active Directory Domain Services server role on Server22.
- B . Obtain a certificate.
- C . Raise the forest functional level.
- D . Join Server22 to the domain.