70-742 Sample Questions & Answers
Free Identity with Windows Server 2016 practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.
Launch the full 70-742 simulator →Showing 2 of 4 free samples.
- Question 1
Your company’s Active Directory domain has its domain functional level set to Windows Server 2012 R2.
You have been tasked with securing a number of high-privilege user accounts to block authentication via NTLM, and to verify authentication request to any resources using Kerberos.Solution: You configure the users to be members of the Protected Users group.
Does the solution meet the goal?Show answer & explanation
Correct answer: A
Adding high-privilege user accounts to the Protected Users security group is the correct solution for blocking NTLM authentication and requiring Kerberos verification. The Protected Users group, available with Windows Server 2012 R2 domain functional level, automatically enforces several security restrictions including blocking NTLM authentication, preventing DES and RC4 encryption, disabling Kerberos delegation, and limiting credential caching. This group provides enhanced security for sensitive accounts without requiring complex Group Policy configurations. Reference: https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directory-security-groups
- Question 2
Your company’s Active Directory domain includes an Active Directory Rights Management Services (AD RMS) cluster. It also includes a certification authority (CA).
You are required to make sure, in the event that the account used to encrypt AD RMS protected documents is deleted, that the documents can be accessed.
Solution: You create a distribution group.Does the solution meet the goal?
Show answer & explanation
Correct answer: B
Configuring a data recovery agent (DRA) or super user group for AD RMS is the correct approach to ensure content can be accessed even if the original encryption account is compromised or unavailable. AD RMS super users have unrestricted access to all RMS-protected content within the organization, bypassing normal usage rights restrictions. This provides a critical recovery mechanism for business continuity while maintaining the security integrity of the RMS infrastructure. The CA integration ensures proper certificate-based authentication for the recovery process.
Ready for the real thing?
The full 70-742 simulator has every exam-style question, timed mode, and instant scoring.