exam questions

Exam 70-742 All Questions

View all questions & answers for the 70-742 exam

Exam 70-742 topic 1 question 87 discussion

Actual exam question from Microsoft's 70-742
Question #: 87
Topic #: 1
[All 70-742 Questions]

Your network contains an Active Directory domain named contoso.com.
The domain contains a web application that uses Kerberos authentication.
You change the domain name of the web application.
You need to ensure that the service principal name (SPN) for the application is registered.
Which tool should you use?

  • A. Rdspnf
  • B. Active Directory Users and Computers
  • C. Dnscmd
  • D. Ldifde
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
Note:
There are several versions of this question in the exam. The question has two possible correct answers:
1. Ldifde
2. Setspn
Other incorrect answer options you may see on the exam include the following:
1. Netsh
2. Repladmin
3. Internet Information Services (IIS) Manager
References:
https://blogs.technet.microsoft.com/tristank/2006/05/08/3-simple-rules-to-kerberos-authenticationdelegation-spns/ https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731241(v=ws.11)#spn-format

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Hayemaker
Highly Voted 5 years, 10 months ago
D. Ldifde is the answer
upvoted 12 times
...
Hayemaker
Highly Voted 5 years, 10 months ago
You are right, downvote my previous answer. Found this: The given answer is correct. It used to be setspn. But in Windows 2016, Microsoft now finally acknowledges the method us administrators have been using for years. If you turn on Advanced Features in your ADUC, you can browse to the tab called “Attribute Editor” on every object. Do that on a computer-object. In there, you’ll find a value called “servicePrincipalName”. You can manually add and remove SPNs there. For real-life, learn the format: ServiceName/ComputerName(or FQDN). This can include a port number as well.
upvoted 11 times
dexter56
5 years, 5 months ago
In that way you can't check if a certain spn exists in the domain, you just check the spns of one object. D is still the best answer.
upvoted 3 times
...
...
promaster
Most Recent 4 years, 2 months ago
This can be edited within ADUC under the Attribute Editor tab.
upvoted 1 times
...
Kamikazekiller
4 years, 4 months ago
D. Ldifde is the answer
upvoted 2 times
Kamikazekiller
4 years, 4 months ago
Sorry, the correct answer is B. B. Active Directory Users and Computers
upvoted 1 times
...
...
jelly_baby
4 years, 5 months ago
Correct answer is D. setspn > ldifde > AD UC. Each of the above can be used, however Setspn is the preferred option by Microsoft. If you don't have that answer available, select ldifde. If both are not available, AD UC can be used, but is not a preferred method.
upvoted 4 times
...
panda
5 years ago
Correct answer B and D. This is as same as #Question 8. And conclusion is also.
upvoted 5 times
ve22
4 years, 6 months ago
Thanks!
upvoted 1 times
...
...
Brinu
5 years, 3 months ago
Hello Guys, So I looked up some information Regarding this subject and i have executed them myself on my practice Environment, Option B is a Valid Answer as by enabling 'Show Advanced option' from the Users and Computers and browsing to my attributes/Service Principal Name you should be able to see all the available Values Register. Option D - is also Correct given the following Syntax: ldifde -d "DC=Adatum,DC=com" -l ServicePrincipleName -f C:spn.txt >c:\spn.txt this text file contains all the Service Principle Names. I would understand why it Says B though as LDIFDE is 'The more complex' way to do it or the 'Old School' as there is also an easier command to do this : setspn -l <lon-dc1> ---- So All above are correct Answers.
upvoted 4 times
...
paprda
5 years, 3 months ago
in new test is even variant e:netsh
upvoted 2 times
...
[Removed]
5 years, 5 months ago
Agree. D is the answer
upvoted 3 times
...
skwierzyk
5 years, 10 months ago
Are you sure ? Any explaination?
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago