MCSA 70-741 EXAM mcq questions with answer – Set 2

MCSA 70-741 EXAM mcq questions with answer – Set 2

Important Instructions:

  • Total Number Of Questions : 10
  • Passing Marks : 7
  • Each Question Carry 1 Mark, No Negative Marking.
  • Do Not Refresh The Page.
  • This Is A FREE Online Test, DO NOT Pay Money To Anyone To Attend This Test.
  • Best Of Luck…



#1. You have less DNS zone security after you have used the ConvertTo-DnsServerPrimaryZone PowerShell cmdlet to convert an AD-integrated zone to a file-based DNS zone. Which statement about file-based DNS zones is not correct?

#2. You want to get information about DNS request types and DNS query packet content. What kind of DNS logging do you need to enable to get that information?

#3. Which of the following is part of a Windows Server 2016 stub zone? (Choose two.)

Select all that apply:

#4. You are responsible for the administration of your Windows Server 2016 DNS server, which is installed on a domain controller as an AD-integrated DNS server. Paul, a new employee, also needs full administrative rights for the DNS server. Which security group must he become a member of?

#5. You are managing a Windows Server 2008 R2 domain named pearson.com (productive domain). All domain controllers are Windows Server 2008 R2 with a DNS server role and AD-integrated DNS zones. You want to perform a step-by-step migration from this existing domain to a newly created empty forest root domain (future domain) with the same domain name. You have installed the Windows Server 2016 forest root domain controller of the future domain (including DNS server role with the AD-integrated zone pearson.com). You want to migrate all DNS zone data from the zone pearson.com (productive domain) to the forest root DNS server (future domain) so that this DNS server is authoritative for that zone and DNS data is saved in the Active Directory of the future domain. This has to be done with the least administrative effort. Which configuration steps are the best option?

#6. You have a forest environment with the following domains: pearson.com, eu.pearson.com, usa.pearson.com, pearsonucertify.com, eu.pearsonucertify.com, and usa.pearsonucertify.com. Every domain has two domain controllers with AD-integrated DNS servers. Each DNS server is authoritative for the name resolution in its own domain. You plan to implement additional DNS servers in usa.pearsonucertify.com. DNS servers in usa.pearson.com must automatically know about the new DNS servers in usa.pearsonucertify.com. Which of the following is the best solution to accomplish this?

#7. You want to sign DNS resource records with NSEC3 and RSA/SHA-2. Which Windows server version can use both standards?

#8. You are responsible for managing your DNS environment. You have a UNIX BIND DNS server named BIND1 that is the master authoritative server for the zone pearson.com with TSIG protection enabled. You want to use a Windows Server 2016 DNS server named SEC1 as the secondary DNS server for this zone. You want to use an additional layer of security for zone transfer between BIND1 and SEC1. Which technology enables you to accomplish this?

#9. You want to get information about DNSKEY record behaviors on your Windows Server 2016 DNS server and your zone pearson.com. You use the following PowerShell command: $stat = Get-DnsServerStatistics -ZoneName pearson.com. Now you must use the correct command to get that information you need. Which command do you use?

