exam questions

Exam 70-742 All Questions

View all questions & answers for the 70-742 exam

Exam 70-742 topic 1 question 32 discussion

Actual exam question from Microsoft's 70-742
Question #: 32
Topic #: 1
[All 70-742 Questions]

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2016.
The Computer account for Server1 is in organizational unit (OU) named OU1.
You create a Group Policy object (GPO) named GPO1 and link GPO1 to OU1.
You need to add a domain user named User1 to the local Administrators group on Server1.
Solution: From the Computer Configuration node of GPO1, you configure the Restricted Groups settings.
Does this meet the goal?

  • A. Yes
  • B. No
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
coleman
Highly Voted 5 years, 6 months ago
Solution: From the Computer Configuration node of GPO1, you configure the Local Users and Groups preference. or Solution: From the Computer Configuration node of GPO1, you configure the Restricted Groups settings. also correct.
upvoted 14 times
...
Nhan
Highly Voted 5 years, 3 months ago
thats why i said you must add a user to a group then add that group to the restricted group. the scenario indicate that we just add user to the restricted group but did not indicate that we have to take an additional step top competed, the question is poor written and whoever wrote this stupid question should be kick butt
upvoted 7 times
...
lofzee
Most Recent 4 years, 5 months ago
Yes the answer is A. You can Add a restricted group to the GPO, i.e. 'Administrators' and then add members to this group via the GPO. Do a gpupdate /force and the users appear in the group in AD Users and Computers. Remove the user from AD Users and Computers, do another gpupdate /force and the user goes back in there.
upvoted 1 times
...
Kamikazekiller
4 years, 11 months ago
Answer is A-YES
upvoted 2 times
...
Nhan
5 years, 4 months ago
NO the answer is wrong, in the restricted group you can add a group but not a user, user must be added to a group then will be added to the restricted group. I dont think the answer is correct
upvoted 3 times
krj
5 years, 3 months ago
No, the answer is correct. Just add the group Administrators. Add user1 to "Members of this group:". It works, trust me.
upvoted 1 times
GenjamBhai
4 years, 10 months ago
It will overwrite existing users like Domain admins, not just add the user only.
upvoted 1 times
...
...
...
Ozguraydin
5 years, 6 months ago
The answer is YES. https://richardstk.com/2013/11/26/adding-domain-users-to-the-local-administrators-group-using-group-policy/
upvoted 3 times
...
minajahan
5 years, 7 months ago
"Restricted Groups is designed specifically to work with Local Groups. " So answer A is probably correct. https://support.microsoft.com/en-us/help/279301/description-of-group-policy-restricted-groups
upvoted 1 times
...
MrRiver
5 years, 7 months ago
Answer ist Yes it works either way: add restricted group ".\administrators" -> add User1 as Member. This will remove all other members of "administrators Group" except the local default administrators account Other way works ass well add "domain\user1" as restricted group and then at the Members of section add ".\administrators"
upvoted 2 times
...
panda
5 years, 7 months ago
I agree that A is correct. The premise in this case is that you add a domain user to the local Administorators group on which without removing Other users. Becase it does not say that remove any users. To do so , to "This group is a menber of" specify local Administorators group as a domain user of. https://morgansimonsen.com/2008/03/25/working-with-group-policy-restricted-groups-policies-2/
upvoted 3 times
...
Charchar
5 years, 8 months ago
I think the answer is correct. You can apparently do it without removing all other members according to this: https://social.technet.microsoft.com/Forums/windowsserver/en-US/64d9a801-5281-487c-8d14-1b092c0dffcf/group-policy-restricted-groups-how-to-specify-a-local-user-as-member-of-the-administrators?forum=winserverGP
upvoted 2 times
...
Dean
5 years, 8 months ago
If the user to be added is a domain user not a domain admin is the answer then not B?
upvoted 1 times
...
renatovieira
5 years, 8 months ago
Registrited groups will add the domain admin to local group, but will remove all current members.
upvoted 3 times
GenjamBhai
4 years, 10 months ago
B is ok. RG allows adding groups & local accounts to local groups, not individual domain users. Domain users need to be in a domain group which can be added to a local group.
upvoted 1 times
Onolisk
4 years, 7 months ago
individual domain users can be added to restricted groups.
upvoted 4 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...