70-744 Exam Details

  • Exam Code
    :70-744
  • Exam Name
    :Securing Windows Server 2016
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :258 Q&As
  • Last Updated
    :Feb 16, 2021

Microsoft 70-744 Online Questions & Answers

  • Question 111:

    You have a Hyper-V host named Server1 that runs Windows Server 2016. Server1 hosts the virtual machines configured as shown in the following table.

    All the virtual machines have two volumes named C and D.

    You plan to implement BitLocker Drive Encryption (BitLocker) on the virtual machines.

    Which virtual machines can have their volumes protected by using BitLocker? Choose Two.

    A. Virtual machines that can have volume C protected by using BitLocker and a Trusted Platform Module (TPM) protector: VM3 only
    B. Virtual machines that can have volume C protected by using BitLocker and a Trusted Platform Module (TPM) protector: VM1 and VM3 only
    C. Virtual machines that can have volume C protected by using BitLocker and a Trusted Platform Module (TPM) protector: VM2 and VM3 only
    D. Virtual machines that can have volume C protected by using BitLocker and a Trusted Platform Module (TPM) protector: VM2 and VM4 only
    E. Virtual machines that can have volume C protected by using BitLocker and a Trusted Platform Module (TPM) protector: VM2, VM3 and VM4 only
    F. Virtual machines that can have volume C protected by using BitLocker and a Trusted Platform Module (TPM) protector: VM1, VM2, VM3 and VM4
    G. Virtual machines that can have volume D protected by using BitLocker: VM3 only
    H. Virtual machines that can have volume D protected by using BitLocker: VM1 and VM3 only
    I. Virtual machines that can have volume D protected by using BitLocker: VM2 and VM3 only
    J. Virtual machines that can have volume D protected by using BitLocker: VM2 and VM4 only

  • Question 112:

    Your network contains several secured subnets that are disconnected from the Internet.

    One of the secured subnets contains a server named Server1 that runs Windows Server 2016.

    You implement Log Analytics in Microsoft Operations Management Suite (OMS) for the servers that connect to the Internet.

    You need to ensure that Log Analytics can collect logs from Server1.

    Which two actions should you perform? Each correct answer presents part of the solution.

    A. Install the OMS Log Analytics Forwarder on a server that has Internet connectivity.
    B. Create an event subscription on a server that has Internet connectivity.
    C. Create a scheduled task on Server1.
    D. Install the OMS Log Analytics Forwarder on Server1.
    E. Install Microsoft Monitoring Agent on Server1.

  • Question 113:

    HOTSPOT

    You have Hyper-V hosts that each has a Software Defined Networking (SDN) deployment. The network uses a virtual subnet of 192.168.0.0/24.

    You create an access control list (ACL) and apply the ACL to the virtual subnets shown in the following table.

    Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the table.

    NOTE: Each correct selection is worth one point.

    Hot Area:

  • Question 114:

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while

    others might not have a correct solution.

    After you answer a question in this sections, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

    You manage a file server that runs Windows Server 2016. The file server contains the volumes configured as shown in the following table.

    You need to encrypt DevFiles by using BitLocker Drive Encryption (ButLocker).

    Solution: You run the Enable-BitLocker cmdlet.

    Does this meet the goal?

    A. Yes
    B. No

  • Question 115:

    Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is

    exactly the same in each question in this series.

    Your network contains an Active Directory domain named contoso.com. The functional level of the forest and the domain is Windows Server 2008 R2.

    The domain contains the servers configured as shown in the following table.

    All servers run Windows Server 2016. All client computers run Windows 10.

    You have an organizational unit (OU) named Marketing that contains the computers in the marketing department You have an OU named Finance that contains the computers in the finance department You have an OU named AppServers

    that contains application servers. A Group Policy object (GPO) named GP1 is linked to the Marketing OU. A GPO named GP2 is linked to the AppServers OU.

    You install Windows Defender on Nano1.

    End of repeated scenario

    You need to ensure that the marketing department computers validate DNS responses from adatum.com.

    Which setting should you configure in the Computer Configuration node of GP1?

    A. TCPIP Settings from Administrative Templates
    B. Connection Security Rule from Windows Settings
    C. DNS Client from Administrative Templates
    D. Name Resolution Policy from Windows Settings

  • Question 116:

    HOTSPOT

    Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2016.

    A user named User1 is a member of the local Administrators group.

    Server1 has the AppLocker rules configured as shown in the exhibit. (Click the Exhibit button.)

    Exhibit:

    Rule1 and Rule2 are configured as shown in the following table.

    You verify that User1 is unable to run App2.exe on Server1.

    Which changes will allow User1 to run D:\Folder1\Program.exe and D:\Folder2\App2.exe? To answer select the appropriate options in the answer area.

    Hot Area:

  • Question 117:

    You have a server named Server1 that runs Windows Server 2016. Server1 has the Windows Server Update Services server role installed.

    Windows Server Update Services (WSUS) updates for Server1 are stored on a volume named D. The hard disk that contains volume D fails.

    You replace the hard disk. You recreate volume D and the WSUS folder hierarchy in the volume.

    You need to ensure that the updates listed in the WSUS console are available in the WSUS folder. What should you run?

    A. wsusutil.exe /import
    B. wsusutil.exe /reset
    C. Set-WsusServerSynchronization
    D. Invoke-WsusServerCleanup

  • Question 118:

    Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2016.

    You have an organizational unit (OU) named Administration that contains the computer account of Server1.

    You import the Active Directory module to Server1.

    You create a Group Policy object (GPO) named GPO1. You link GPO1 to the Administration OU.

    You need to log an event each time an Active Directory cmdlet is executed successfully from Server1.

    What should you do?

    A. From Advanced Audit Policy in GPO1, configure auditing for directory service changes.
    B. Run the Add-NetEventProvider-Name "Microsoft-Active-Directory" -MatchAnyKeyword PowerShell command
    C. From Advanced Audit Policy in GPO1, configure auditing for other privilege use events.
    D. From Administrative Templates in GPO1, configure a Windows PowerShell policy.

  • Question 119:

    Your network contains an Active Directory domain named contoso.com.

    The domain contains a member server named Servers that runs Windows Server 2016.

    You need to configure Servers as a Just Enough Administration (JEA) endpoint.

    Which two actions should you perform? Each correct answer presents part of the solution.

    A. Create and export a Windows PowerShell session.
    B. Deploy Microsoft Identity Manager (MIM) 2016
    C. Create a maintenance Role Capability file
    D. Generate a random Globally Unique Identifier (GUID)
    E. Create and register a session configuration file.

  • Question 120:

    You have the servers configured as shown in the following table.

    You purchase a Microsoft Azure subscription, and you create three Microsoft Operations Management Suite (OMS) workspaces named Workspace1, Workspace2, and Workspace3 You need to deploy Microsoft Monitoring Agent to the

    servers to meet the following requirements:

    -Antimalware data from all the servers must be visible in Workspace1.

    -Security and audit data from the domain controllers and the virtualization hosts must be visible in Workspace2.

    -System update data from all the servers in all the workgroups must be visible in Workspaceand

    How many OMS agents should you deploy?

    A. 10
    B. 33
    C. 73
    D. 45

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-744 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.