70-742 Identity with Windows Server Practice Questions
Prepare for 70-742 with more than an answer.
- 1
You have recently installed a standalone root certification authority (CA). You are then informed that computers in your company’s Active Directory domain must be autoenrolled for certificates via a custom certificate template.
You want to make sure that this requirement is met.
Solution: You start by installing an enterprise subordinate CA.Does the solution meet the goal?
Show answer details
Correct answer: B
A standalone certification authority cannot create custom certificate templates or configure autoenrollment for domain computers. Autoenrollment functionality requires an enterprise CA that is integrated with Active Directory to publish certificate templates and enable Group Policy-based enrollment. Standalone CAs operate independently without Active Directory integration, limiting them to manual certificate issuance and basic template management. To achieve the goal of autoenrollment with custom templates, the organization must deploy an enterprise subordinate CA under the standalone root CA, which would provide the necessary Active Directory integration while maintaining the security benefits of the standalone root architecture.
- 2
Your company has a Group Policy object (GPO) linked to their domain. They also have a GPO linked to the Domain Controllers OU.
You are required to make sure that domain controllers can be backed up by the Backup Operators group members.
Solution: You modify Security Settings via the User Configuration node of the GPO linked to the Domain Controllers OU.Does the solution meet the goal?
Show answer details
Correct answer: A
Modifying the Group Policy object linked to the Domain Controllers OU is the correct approach to enable backup operations for domain controllers. The Backup Operators group requires specific user rights assignments including "Back up files and directories" and "Restore files and directories" to perform domain controller backups. These permissions must be applied at the Domain Controllers OU level since domain controllers have unique security requirements that differ from regular domain computers. Applying the GPO at the domain level would be insufficient as it would not override the default domain controller security policies.
