exam questions

Exam 70-742 All Questions

View all questions & answers for the 70-742 exam

Exam 70-742 topic 1 question 2 discussion

Actual exam question from Microsoft's 70-742
Question #: 2
Topic #: 1
[All 70-742 Questions]

Note: This question is part of a series of questions that use the same scenario. For your convenience, the scenario is repeated in each question. Each question presents a different goal and answer choices, but the text of the scenario is exactly the same in each question in this series.
Start of repeated scenario.
You work for a company named Contoso, Ltd.
The network contains an Active Directory forest named contoso.com. A forest trust exists between contoso.com and an Active Directory forest named adatum.com.
The contoso.com forest contains the objects configured as shown in the following table.

Group1 and Group2 contain only user accounts.
Contoso hires a new remote user named User3. User3 will work from home and will use a computer named Computer3 that runs Windows 10. Computer3 is currently in a workgroup.
An administrator named Admin1 is a member of the Domain Admins group in the contoso.com domain.
From Active Directory Users and Computers, you create an organizational unit (OU) named OU1 in the contoso.com domain, and then you create a contact named Contact1 in OU1.
An administrator of the adatum.com domain runs the Set-ADUser cmdlet to configure a user named User1 to have a user logon name of [email protected].
End or repeated scenario.
You need to ensure that Admin1 can add Group2 as a member of Group3.
What should you modify?

  • A. Modify the Security settings of Group3.
  • B. Modify the group scope of Group3.
  • C. Modify the group type of Group3.
  • D. Set Admin1 as the manager of Group3.
  • E. Add Admin1 to the Enterprise Admins group
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
A domain local group (group2) can only be a member of another domain local group. Therefore, we need to change the scope of Group3 from Universal to
Domain Local.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
elopez2207
4 years, 5 months ago
other variant: You need to ensure that Admin1 can add Group2 as a member of Group3. What should you modify? A Modify the Security settings of Group3. B Modify the group type of Group2. C Modify the group scope of Group2. D Add Admin1 to the Enterprise-Admins group. ANSWER:C Explanation: Group2 is a domain local group. Group3 is a universal group. Domain local groups can´t be members of universal groups. We need to convert Group2 to a global group.
upvoted 3 times
...
yesboet
4 years, 7 months ago
B is correct
upvoted 1 times
...
Kamikazekiller
4 years, 11 months ago
Answer is: B. Modify the group scope of Group3.
upvoted 1 times
...
ITGEEK
5 years, 4 months ago
Answer is correct. https://blog.stealthbits.com/all-about-agdlp-group-scope-for-active-directory-account-global-domain-local-permissions
upvoted 2 times
...
coleman
5 years, 6 months ago
right .
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...