70-744 Exam Details

  • Exam Code
    :70-744
  • Exam Name
    :Securing Windows Server 2016
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :258 Q&As
  • Last Updated
    :Feb 16, 2021

Microsoft 70-744 Online Questions & Answers

  • Question 141:

    Your network contains an Active Directory domain named contoso.com.

    You are deploying Microsoft Advanced Threat Analytics (ATA) to the domain.

    You install the ATA Center on server named Server1 and the ATA Gateway on a server named Served.

    You need to ensure that Server2 can collect NTLM authentication events.

    What should you configure?

    A. the domain controllers to forward Event ID 4776 to Server2
    B. the domain controllers to forward Event ID 1000 to Server1
    C. Server2 to forward Event ID 1026 to Server1
    D. Server1 to forward Event ID 1000 to Server2

  • Question 142:

    You manage a guarded fabric in TPM-trusted attestation mode.

    You plan to create a virtual machine template disk for shielded virtual machines.

    You need to create the virtual machine disk that you will use to generate the template.

    How should you configure the disk? To answer, select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

    Hot Area:

  • Question 143:

    You have a guarded fabric that consists of the servers shown in the following table.

    You need to ensure that you can start the shielded virtual machines on the Hyper-V hosts if the Hyper-V hosts cannot connect to the HGS. What should you do?

    A. On Server1, run Set-HgsKeyProtectionConfiguration.
    B. On Server1, Server2, and Server3, configure admin-trusted attestation.
    C. On Server1, run Set-HgsKeyProtectionAttestationSignerCertificatePolicy.
    D. On Server4, and Server5, disable the heartbeat integration service on the shielded virtual machines.

  • Question 144:

    Your network contains an Active Directory domain named contoso.com.

    You install the Windows Server Update Services server role on a member server named Server1. Server1 runs Windows Server 2016.

    You need to ensure that a user named User1 can perform the following tasks:

    1.

    View the Windows Server Update Services (WSUS) configuration.

    2.

    Generate WSUS update reports.

    The solution must use the principle of least privilege.

    What should you do on Server1?

    A. Modify the permissions of the ReportWebService virtual folder from the WSUS Administration website.
    B. Add User1 to the WSUS Reporters local group.
    C. Add User1 to the WSUS Administrators local group.
    D. Run wsusutil.exe and specify the postinstall parameter.

  • Question 145:

    You have a file server named FS1 that runs Windows Server 2016.

    You plan to disable SMB 1.0 on the server.

    You need to verify which computers access FS1 by using SMB 1.0.

    What should you run first?

    A. Debug-FileShare
    B. Set-FileShare
    C. Set-SmbShare
    D. Set-SmbServerConfiguration
    E. Set-SmbClientConfiguration

  • Question 146:

    Your network contains an Active Directory forest named contoso.com. All servers run Windows Server 2016.

    You implement a single-domain administrative forest named admin.contoso.com that has Enhanced Security Administrative Environment (ESAE) deployed.

    You have an administrative user named Admin1 in admin.contoso.com.

    You need to ensure that Admin1 can manage the domain controllers in contoso.com.

    To which group should you add Admin1?

    A. Contoso\\Domain Admins
    B. Admin\\Administrators
    C. Admin\\Domain Admins
    D. Contoso\\Administrators

  • Question 147:

    HOTSPOT

    Your network contains two Active Directory forests named contoso.com and adatum.com. Contoso.com contains a Hyper-V host named Server1. Server1 is a member of a group named HyperHosts. Adatum.com contains a server named

    Server2. Server1 and Server2 run Windows Server 2016.

    Contoso.com trusts adatum.com.

    You plan to deploy shielded virtual machines to Server1 and to configure Admin-trusted attestation on Server2.

    Which component should you install and which cmdlet should you run on Server2? To answer, select the appropriate options in the answer area.

    Hot Area:

  • Question 148:

    You have the servers configured as shown in the following table.

    You purchase a Microsoft Azure subscription, and you create three Microsoft Operations Management Suite (OMS) workspaces named Workspace1, Workspace2, and Workspace3. You need to deploy Microsoft Monitoring Agent to the servers to meet the following requirements:

    1.

    Antimalware data from all the servers must be visible in Workspace1.

    2.

    Security and audit data from the domain controllers and the virtualization hosts must be visible in Workspace2.

    3.

    System update data from all the servers in all the workgroups must be visible in Workspace3. How many OMS agents should you deploy?

    A. 6
    B. 33
    C. 73
    D. 91

  • Question 149:

    Your network contains an Active Directory domain named contoso.com.

    The domain contains two global groups named Group1 and Group2. A user named User1 is a member of Group1.

    You have an organizational unit (OU) named OU1 that contains the computer accounts of computers that contain sensitive data. A Group Policy object (GPO) named GPO1 is linked to OU1. OU1 contains a computer account named

    Computer1.

    GPO1 has the User Rights Assignment configured as shown in the following table.

    You need to prevent User1 from signing in to Computer1. What should you do?

    A. From Default Domain Policy, modify the Allow log on locally user right
    B. On Computer1, modify the Deny log on locally user right.
    C. From Default Domain Policy, modify the Deny log on locally user right
    D. Remove User1 to Group2.

  • Question 150:

    Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1.

    You implement the Host Guardian Service (HGS) configured for admin-trusted attestation.

    You install the Hyper-V server role on Server1.

    You need to add Server1 to the guarded hosts.

    What should you do?

    A. On Server1, install the Host Guardian Hyper-V Support feature and a computer certificate from a trusted certification authority (CA).
    B. On Server1, install the Device Health Attestation server role and a computer certificate from a trusted certification authority (CA).
    C. Install the Host Guardian Hyper-V Support feature on Server1 and add Server1 to a domain security group.
    D. Install the Device Health Attestation server role on Server1 and add Server1 to a domain security group.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-744 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.