Question 21

You need to meet the technical requirements for User1. The solution must use the principle of least privilege.
What should you do?
  • Question 22

    Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.
    You need to identify which server is the PDC emulator for the domain.
    Solution: From Active Directory Sites and Services, you right-click Default-First-Site-Name in the console tree, and then select Properties.
    Does this meet the goal?
  • Question 23

    Your network contains a single-domain Active Directory Domain Services (AD DS) forest named conto.com. The forest contains the servers shown in the following exhibit table.

    You plan to install a line-of-business (LOB) application on Server1. The application will install a custom windows services.
    A new corporate security policy states that all custom Windows services must run under the context of a group managed service account (gMSA). You deploy a root key.
    You need to create, configure, and install the gMSA that will be used by the new application.
    Which two actions should you perform? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.
  • Question 24

    What should you implement for the deployment of DC3?
  • Question 25

    You have a server named Server1 that has Windows Admin Center installed. The certificate used by Windows Admin Center was obtained from a certification authority (CA).
    The certificate expires.
    You need to replace the certificate.
    Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.