Skip to content

70-744 Securing Windows Server Practice Questions

Prepare for 70-744 with more than an answer.

162 questions in the full set20 sample questionsUpdated Aug 11, 2025
Exam fee
$165 USD
Level
Professional
Valid for
2 years (certification was valid for 2 years from January 31, 2021 retirement date, after which it moved to inactive section of transcript)
Domains covered on the exam 6
  1. Implement Server Hardening Solutions27.5%
  2. Secure a Virtualization Infrastructure7.5%
  3. Secure a Network Infrastructure12.5%
  4. Manage Privileged Identities27.5%
  5. Implement Threat Detection Solutions17.5%
  6. Implement Workload-Specific Security7.5%
  1. 1

    A company has a file server that hosts sensitive financial data. The security policy requires that all network traffic to and from the file share must be encrypted. Additionally, to prevent man-in-the-middle attacks, the integrity of every SMB packet must be verified. Which two actions must be performed to meet these requirements for a specific share named 'FinanceData'?

    Show answer details

    Correct answer: A, C

    This option enables SMB 3.x encryption specifically for the selected share, ensuring that all data in transit to and from this share is encrypted.

    This Group Policy setting enforces SMB signing on the server, which validates the integrity of each packet and protects against man-in-the-middle attacks. This meets the second requirement of the security policy.

  2. 2

    You are auditing PowerShell activity on a critical server. You need to capture the full content of every script executed, including scripts, commands, and script blocks, for forensic analysis. Which PowerShell logging feature must be enabled via Group Policy to achieve this?

    Show answer details

    Correct answer: C

    PowerShell Transcription creates a unique, detailed text file log of every PowerShell session. It captures all input commands and all console output, providing a complete 'transcript' of the session, which is ideal for deep forensic analysis. Module logging and Script Block logging capture specific events, but Transcription provides the most complete record of the session activity.

  3. 3

    You are deploying a new Hyper-V cluster that will host virtual machines containing sensitive intellectual property. You plan to use BitLocker to encrypt the Clustered Shared Volumes (CSVs). To allow the cluster nodes to automatically unlock the encrypted CSVs upon startup without manual intervention, you must use a specific BitLocker feature. Which feature should you implement?

    Show answer details

    Correct answer: B

    For clustered volumes like CSVs, the Active Directory-Based Protector is the designed solution. It allows BitLocker to use the cluster's computer object (Cluster Name Object or CNO) in Active Directory as a key protector. This enables any node in the cluster to automatically unlock the volume as long as it can authenticate to AD, facilitating seamless failover and startup.

  4. 4

    You are securing a Nano Server deployment using Desired State Configuration (DSC). You need to apply a set of firewall rules defined in a security baseline. Which built-in DSC resource would you use in your configuration script to manage Windows Firewall rules on the Nano Server?

    Show answer details

    Correct answer: B

    The NetFirewallRule is the correct DSC resource for managing individual firewall rules. The older Firewall resource is used for managing profile settings (e.g., enabling or disabling the firewall for the Domain profile) but not for creating specific rules like allowing a certain port.

  5. 5

    You are configuring OMS Log Analytics to collect security event logs from your on-premises domain controllers. The domain controllers do not have direct internet access. What component must be deployed to facilitate the collection of logs and forward them to the OMS workspace?

    graph TD subgraph On-Premises DC1[Domain Controller 1] DC2[Domain Controller 2] OMS_GW(OMS Gateway) end subgraph Cloud["Azure Cloud"] OMS_WS[(OMS Workspace)] end DC1 --> OMS_GW DC2 --> OMS_GW OMS_GW -->|HTTPS| OMS_WS

    Show answer details

    Correct answer: C

    The OMS Gateway (now Log Analytics Gateway) is designed for this exact scenario. It acts as an HTTP forward proxy, collecting data from agents on servers without internet access and sending it to the Log Analytics workspace in Azure. The agents on the DCs are configured to send their data to the gateway instead of directly to the internet.

  6. 6

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this sections, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory forest named contoso.com. All servers run Windows Server 2016. The forest contains 2,000 client computers that runWindows 10. All client computers are deployed from a customized Windows image.You need to deploy 10 Privileged Access Workstations (PAWs). The solution must ensure that administrators can access several client applications used by all users.Solution: You deploy 10 physical computers and configure them as PAWs. You deploy 10 additional computers and configure them by using the customizedWindows image.Does this meet the goal? A.YesB.No

    Show answer details

    Correct answer: A

  7. 7

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this sections, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory forest named contoso.com. All servers run Windows Server 2016. The forest contains 2,000 client computers that runWindows 10. All client computers are deployed from a customized Windows image.You need to deploy 10 Privileged Access Workstations (PAWs). The solution must ensure that administrators can access several client applications used by all users.Solution: You deploy 10 physical computers and configure each one as a virtualization host. You deploy the operating system on each host by using the customized Windows image. On each host, you create a guest virtual machine and configure the virtual machine as a PAW.Does this meet the goal? A.YesB.No

    Show answer details

    Correct answer:

  8. 8

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this sections, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory forest named contoso.com. All servers run Windows Server 2016. The forest contains 2,000 client computers that runWindows 10. All client computers are deployed from a customized Windows image.You need to deploy 10 Privileged Access Workstations (PAWs). The solution must ensure that administrators can access several client applications used by all users.Solution: You deploy one physical computer and configure it as Hyper-V host that runs Windows Server 2016. You create 10 virtual machines and configure each one as a PAW.Does this meet the goal? A.YesB.No

    Show answer details

    Correct answer:

  9. 9

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this sections, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contain an Active Directory domain named contoso.com. The domain contains a computer named Computer1 that runs Windows 10. Computer1 connects to a home network and a corporate network.The corporate network uses the 172.16.0.0/24 address space internally.Computer1 runs an application named App1 that listens to port 8080.You need to prevent connections to App1 when Computer1 is connected to the home network.Solution: From Group Policy Management, you create an AppLocker rule.Does this meet the goal? A.YesB.No

    Show answer details

    Correct answer:

  10. 10

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this sections, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contain an Active Directory domain named contoso.com. The domain contains a computer named Computer1 that runs Windows 10. Computer1 connects to a home network and a corporate network.The corporate network uses the 172.16.0.0/24 address space internally.Computer1 runs an application named App1 that listens to port 8080.You need to prevent connections to App1 when Computer1 is connected to the home network.Solution: From Group Policy Management, you create software restriction policy.Does this meet the goal? A.YesB.No

    Show answer details

    Correct answer:

Create an account to continue.