Microsoft 70-744 Exam Practice Questions (P. 3)
- Full Access (205 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #11
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this sections, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com. The domain contains multiple Hyper-V hosts.
You need to deploy several critical line-of-business applications to the network to meet the following requirements:
✑ The resources of the applications must be isolated from the physical host.
✑ Each application must be prevented from accessing the resources of the other applications.
✑ The configurations of the applications must be accessible only from the operating system that hosts the application.
Solution: You deploy a separate Hyper-V container for each application.
Does this meet the goal?
After you answer a question in this sections, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com. The domain contains multiple Hyper-V hosts.
You need to deploy several critical line-of-business applications to the network to meet the following requirements:
✑ The resources of the applications must be isolated from the physical host.
✑ Each application must be prevented from accessing the resources of the other applications.
✑ The configurations of the applications must be accessible only from the operating system that hosts the application.
Solution: You deploy a separate Hyper-V container for each application.
Does this meet the goal?
- AYes
- BNo
Correct Answer:
A
References:
https://docs.microsoft.com/en-us/virtualization/windowscontainers/about/
A
References:
https://docs.microsoft.com/en-us/virtualization/windowscontainers/about/
send
light_mode
delete
Question #12
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this sections, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com. The domain contains multiple Hyper-V hosts.
You need to deploy several critical line-of-business applications to the network to meet the following requirements:
✑ The resources of the applications must be isolated from the physical host.
Each application must be prevented from accessing the resources of the other applications.

✑ The configurations of the applications must be accessible only from the operating system that hosts the application.
Solution: You deploy one Windows container to host all of the applications.
Does this meet the goal?
After you answer a question in this sections, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com. The domain contains multiple Hyper-V hosts.
You need to deploy several critical line-of-business applications to the network to meet the following requirements:
✑ The resources of the applications must be isolated from the physical host.
Each application must be prevented from accessing the resources of the other applications.

✑ The configurations of the applications must be accessible only from the operating system that hosts the application.
Solution: You deploy one Windows container to host all of the applications.
Does this meet the goal?
- AYes
- BNo
Correct Answer:
B
References:
https://docs.microsoft.com/en-us/virtualization/windowscontainers/about/
B
References:
https://docs.microsoft.com/en-us/virtualization/windowscontainers/about/
send
light_mode
delete
Question #13
Your network contains an Active Directory domain named contoso.com. The domain contains 1,000 client computers that run Windows 10.
A security audit reveals that the network recently experienced a Pass-the-Hash attack. The attack was initiated from a client computer and accessed Active
Directory objects restricted to the members of the Domain Admins group.
You need to minimize the impact of another successful Pass-the-Hash attack on the domain.
What should you recommend?
A security audit reveals that the network recently experienced a Pass-the-Hash attack. The attack was initiated from a client computer and accessed Active
Directory objects restricted to the members of the Domain Admins group.
You need to minimize the impact of another successful Pass-the-Hash attack on the domain.
What should you recommend?
- AInstruct all users to sign in to a client computer by using a Microsoft account.
- BMove the computer accounts of all the client computers to a new organizational unit (OU). Remove the permissions to the new OU from the Domain Admins group.
- CInstruct all administrators to use a local Administrators account when they sign in to a client computer.
- DMove the computer accounts of the domain controllers to a new organizational unit (OU). Remove the permissions to the new OU from the Domain Admins group.
Correct Answer:
C
References:
https://en.wikipedia.org/wiki/Pass_the_hash#Mitigations
C
References:
https://en.wikipedia.org/wiki/Pass_the_hash#Mitigations
send
light_mode
delete
Question #14
Your network contains an Active Directory forest named contoso.com. The forest functional level is Windows Server 2012. All servers run Windows Server 2016.
You create a new bastion forest named admin.contoso.com. The forest functional level of admin.contoso.com is Windows Server 2012 R2.
You need to implement a Privileged Access Management (PAM) solution.
Which two actions should you perform? Each correct answer presents part of the solution.
You create a new bastion forest named admin.contoso.com. The forest functional level of admin.contoso.com is Windows Server 2012 R2.
You need to implement a Privileged Access Management (PAM) solution.
Which two actions should you perform? Each correct answer presents part of the solution.
- ARaise the forest functional level of admin.contoso.com.
- BDeploy Microsoft Identify Management (MIM) 2016 to admin.contoso.com.
- CConfigure contoso.com to trust admin.contoso.com.
- DDeploy Microsoft Identity Management (MIM) 2016 to contoso.com.
- ERaise the forest functional level of contoso.com.
- FConfigure admin.contoso.com to trust contoso.com.
Correct Answer:
BC
References:
https://docs.microsoft.com/en-us/microsoft-identity-manager/pam/hardware-software-requirements https://docs.microsoft.com/en-us/microsoft-identity-manager/pam/planning-bastion-environment
BC
References:
https://docs.microsoft.com/en-us/microsoft-identity-manager/pam/hardware-software-requirements https://docs.microsoft.com/en-us/microsoft-identity-manager/pam/planning-bastion-environment
send
light_mode
delete
Question #15
Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server
2016.
Server1 is configured as a domain controller.
You configure Server1 as a Just Enough Administration (JEA) endpoint. You configure the required JEA rights for a user named User1.
You need to tell User1 how to manage Active Directory objects from Server2.
What should you tell User1 to do first on Server2?
2016.
Server1 is configured as a domain controller.
You configure Server1 as a Just Enough Administration (JEA) endpoint. You configure the required JEA rights for a user named User1.
You need to tell User1 how to manage Active Directory objects from Server2.
What should you tell User1 to do first on Server2?
- AFrom a command prompt, runntdsutil.exe.
- BFrom Windows PowerShell, run the Import-Module cmdlet.
- CFrom Windows PowerShell, run the Enter-PSSession cmdlet.
- DInstall the management consoles for Active Directory, and then launch Active Directory Users and Computers.
Correct Answer:
C
References:
https://blogs.technet.microsoft.com/privatecloud/2014/05/14/just-enough-administration-step-by-step/
C
References:
https://blogs.technet.microsoft.com/privatecloud/2014/05/14/just-enough-administration-step-by-step/
send
light_mode
delete
All Pages