Self-learning and self-evaluation functions
Our Securing Windows Server 2016 (070-744 Deutsch Version) qualification test guide boosts the self-learning and self-evaluation functions so as to let the clients understand their learning results and learning process, then find the weak links to improve them. Through the self-learning function the learners can choose the learning methods by themselves and choose the contents which they think are important. Through the self-evaluation function the learners can evaluate their mastery degree of our 070-744 Deutsch test materials and their learning process. The two functions can help the learners adjust their learning arrangements and schedules to efficiently prepare the exam. The clients can record their self-learning summary and results into our software and evaluate their learning process, mastery degrees and learning results in our software. According their learning conditions of our 070-744 Deutsch certification guide they can change their learning methods and styles.
Skills measured
- Secure a Virtualization Infrastructure (5-10%)
- Implement Threat Detection Solutions (15-20%)
- Secure a Network Infrastructure (10-15%)
- Implement Workload-Specific Security (5-10%)
- Implement Server Hardening Solutions (25-30%)
- Manage Privileged Identities (25-30%)
Microsoft 70-744 Exam Syllabus Topics:
| Topic | Details |
|---|---|
Implement Server Hardening Solutions (25-30%) | |
| Configure disk and file encryption | -This objective may include but is not limited to: Determine hardware and firmware requirements for secure boot and encryption key functionality; deploy BitLocker encryption; deploy BitLocker without a Trusted Platform Module (TPM); deploy BitLocker with a TPM only; configure the Network Unlock feature; configure BitLocker Group Policy settings; enable Bitlocker to use secure boot for platform and BCD integrity validation; configure BitLocker on Cluster Shared Volumes (CSVs) and Storage Area Networks (SANs); implement BitLocker Recovery Process using self-recovery and recovery password retrieval solutions; configure Bitlocker for virtual machines (VMs) in Hyper-V; determine usage scenarios for Encrypting File System (EFS); configure the EFS recovery agent; manage EFS and BitLocker certificates, including backup and restore |
| Implement malware protection | -This objective may include but is not limited to: Implement antimalware solution with Windows Defender; integrate Windows Defender with WSUS and Windows Update; configure Windows Defender using Group Policy; configure Windows Defender scans using Windows PowerShell; implement AppLocker rules; implement AppLocker rules using Windows PowerShell; implement Control Flow Guard; implement Code Integrity (Device Guard) Policies; create Code Integrity policy rules; create Code Integrity file rules |
| Protect credentials | -This objective may include but is not limited to: Determine requirements for implementing Credential Guard; configure Credential Guard using Group Policy, WMI, command prompt, and Windows PowerShell; implement NTLM blocking |
| Create security baselines | -This objective may include but is not limited to: Install and configure Microsoft Security Compliance Toolkit; create, view, and import security baselines; deploy configurations to domain and non-domain joined servers |
Secure a Virtualization Infrastructure (5-10%) | |
| Implement a Guarded Fabric solution | -This objective may include but is not limited to: Install and configure the Host Guardian Service (HGS); configure Admin-trusted attestation; configure TPM-trusted attestation; configure the Key Protection Service using HGS; migrate Shielded VMs to other guarded hosts; troubleshoot guarded hosts |
| Implement Shielded and encryption-supported VMs | -This objective may include but is not limited to: Determine requirements and scenarios for implementing Shielded VMs; create a shielded VM using only a Hyper-V environment; enable and configure vTPM to allow an operating system and data disk encryption within a VM; determine requirements and scenarios for implementing encryption-supported VMs; troubleshoot Shielded and encryption-supported VMs |
Secure a Network Infrastructure (10-15%) | |
| Configure Windows Firewall | -This objective may include but is not limited to: Configure Windows Firewall with Advanced Security; configure network location profiles; configure and deploy profile rules; configure firewall rules for multiple profiles using Group Policy; configure connection security rules using Group Policy, the GUI management console, or Windows PowerShell; configure Windows Firewall to allow or deny applications, scopes, ports, and users using Group Policy, the GUI management console, or Windows PowerShell; configure authenticated firewall exceptions; import and export settings |
| Implement a Software Defined Datacenter Firewall | -This objective may include but is not limited to: Determine requirements and scenarios for Datacenter Firewall implementation with Software Defined Networking; determine usage scenarios for Datacenter Firewall policies and network security groups; Configure Datacenter Firewall Access Control Lists |
| Secure network traffic | -This objective may include but is not limited to: Configure IPsec transport and tunnel modes; configure IPsec authentication options; configure connection security rules; implement isolation zones; implement domain isolation; implement server isolation zones; determine SMB 3.1.1 protocol security scenarios and implementations; enable SMB encryption on SMB Shares; configure SMB signing via Group Policy; disable SMB 1.0; secure DNS traffic using DNSSEC and DNS policies; install and configure Microsoft Message Analyzer (MMA) to analyze network traffic |
Manage Privileged Identities (25-30%) | |
| Implement Just-In-Time (JIT) Administration | -This objective may include but is not limited to: Create a new administrative (bastion) forest in an existing Active Directory environment using Microsoft Identity Manager (MIM); configure trusts between production and bastion forests; create shadow principals in bastion forest; configure the MIM Web portal; request privileged access using the MIM Web portal; determine requirements and usage scenarios for Privileged Access Management (PAM) solutions; create and Implement MIM policies; implement Just-in-Time administration principals using time-based policies; request privileged access using Windows PowerShell |
| Implement Just-Enough-Administration (JEA) | -This objective may include but is not limited to: Enable a JEA solution on Windows Server 2016; create and configure session configuration files; create and configure role capability files; create a JEA endpoint; connect to a JEA endpoint on a server for administration; view logs; download WMF 5.1 to a Windows Server 2008 R2; configure a JEA endpoint on a server using Desired State Configuration (DSC) |
| Implement Privileged Access Workstations (PAWs) and User Rights Assignments | -This objective may include but is not limited to: Implement a PAWS solution; configure User Rights Assignment group policies; configure security options settings in Group Policy; enable and configure Remote Credential Guard for remote desktop access; Implement an Enhanced Security Administrative Environment (ESAE) administrative forest design approach; Determine usage scenarios and requirements for implementing ESAE forest design architecture to create a dedicated administrative forest |
| Implement Local Administrator Password Solution (LAPS) | -This objective may include but is not limited to: Install and configure the LAPS tool; secure local administrator passwords using LAPS; manage password parameters and properties using LAPS |
Implement Threat Detection Solutions (15-20%) | |
| Configure advanced audit policies | -This objective may include but is not limited to: Determine the differences and usage scenarios for using local audit policies and advanced auditing policies; implement auditing using Group Policy and AuditPol.exe; implement auditing using Windows PowerShell; create expression-based audit policies; configure the Audit PNP Activity policy; configure the Audit Group Membership policy; enable and configure Module, Script Block, and Transcription logging in Windows PowerShell |
| Install and configure Microsoft Advanced Threat Analytics (ATA) | -This objective may include but is not limited to: Determine usage scenarios for ATA; determine deployment requirements for ATA; install and configure ATA Gateway on a dedicated server; install and configure ATA Lightweight Gateway directly on a domain controller; configure alerts in ATA Center when suspicious activity is detected; review and edit suspicious activities on the attack time line |
| Determine threat detection solutions using Operations Management Suite (OMS) | -This objective may include but is not limited to: Determine usage and deployment scenarios for OMS; determine security and auditing functions available for use; determine Log Analytics usage scenarios |
Implement Workload-Specific Security (5-10%) | |
| Secure application development and server workload infrastructure | -This objective may include but is not limited to: Determine usage scenarios, supported server workloads, and requirements for deployments; determine usage scenarios and requirements for Windows Server and Hyper-V containers; install and configure containers |
| Implement a secure file services infrastructure and Dynamic Access Control (DAC) | -This objective may include but is not limited to: Install the File Server Resource Manager (FSRM) role service; configure quotas; configure file screens; configure storage reports; configure file management tasks; configure File Classification Infrastructure (FCI) using FSRM; implement work folders; configure file access auditing; configure user and device claim types; implement policy changes and staging; perform access-denied remediation; create and configure Central Access rules and policies; create and configure resource properties and lists |
Reference: https://www.microsoft.com/en-us/learning/exam-70-744.aspx
The benefit in Obtaining the 70-744 Exam Certification
- Candidates will get in-depth knowledge by completing the courses along with the access to revision materials for 6 months upon completion means they will have a wider skill set when it comes to the various technologies and systems than an uncertified professional. Certified Professional in this particular skill set is 74% more efficient when it comes to completing their tasks in a timely well-executed manner.
- Becoming a Microsoft Certified System Engineer means one thing you are worth more to the company and therefore more to yourself in the form of an upgraded pay package. On average a Microsoft Certified System Engineer member of staff is estimated to be worth 30% more to a company than their uncertified professionals.
- Organization owners invest a lot in their employees when it comes to their training with the goal of making them quicker, more efficient, and more knowledgeable about their role. Certified Professional will reduce the time he spends on tasks, meaning he can get more done this could help reduce company downtime when repairing faults on a system or fixing hardware problems.
- When Candidates applying for a job or looking to promotion in their current position, a Microsoft Certified System Engineer certification in the field in which Candidates are applying will put you at the top of the list and make them a desirable candidate for employers.
- After completion of Microsoft Certified System Engineer Certification candidates receive official confirmation from Microsoft that you are now fully certified in their chosen field. This can be now added to their CV, cover letters and job applications.
Simple language
The language of our Securing Windows Server 2016 (070-744 Deutsch Version) qualification test guide is simple. The learners may come from many social positions and their abilities to master our 070-744 Deutsch test materials are varied. Based on this consideration we apply the most simple and easy-to-be-understood language to help the learners no matter he or she is the students or the in-service staff, the novice or the experienced employee which have worked for many years. 070-744 Deutsch certification guide use the simple language to explain the answers and detailed knowledge points and the concise words to show the complicated information about the 070-744 Deutsch test materials. The language is also refined to simplify the large amount of information. So the learners have no obstacles to learn our 070-744 Deutsch certification guide.
Any electronic equipment available on the APP online version
Our 070-744 Deutsch test materials boost three versions and they include the PDF version, PC version and the APP online version. The clients can use any electronic equipment on it. If only the users' equipment can link with the internet they can use their equipment to learn our Securing Windows Server 2016 (070-744 Deutsch Version) qualification test guide. They can use their cellphones, laptops and tablet computers to learn our 070-744 Deutsch study materials. The great advantage of the APP online version is if only the clients use our 070-744 Deutsch certification guide in the environment with the internet for the first time on any electronic equipment they can use our 070-744 Deutsch test materials offline later. So the clients can carry about their electronic equipment available on their hands and when they want to use them to learn our Securing Windows Server 2016 (070-744 Deutsch Version) qualification test guide they can take them out at any time and learn offline. So the clients can break through the limits of the time, equipment, place and environment and learn our 070-744 Deutsch certification guide at their own wills. This is an outstanding merit of the APP online version.
The clients at home and abroad strive to buy our 070-744 Deutsch test materials because they think our products are the best study materials which are designed for preparing the test Microsoft certification. They trust our 070-744 Deutsch certification guide deeply not only because the high quality and passing rate of our Securing Windows Server 2016 (070-744 Deutsch Version) qualification test guide but also because our considerate service system. They treat our 070-744 Deutsch study materials as the magic weapon to get the Microsoft certificate and the meritorious statesman to increase their wages and be promoted. You may be not quite familiar with our 070-744 Deutsch test materials and we provide the detailed explanation of our 070-744 Deutsch certification guide as follow for you have an understanding before you decide to buy.
Certification Path
There is no prerequisite for this Microsoft 70-744 exam.








