Microsoft Exam Questions

You work as an administrator at Contoso.com. The Contoso.com network consists of a single domain nam

You work as an administrator at Contoso.com. The Contoso.com network consists of a single domain named Contoso.com. All servers in the Contoso.com domain, including domain controllers, have Windows Server 2012 R2 installed.

You have created and l

inked a new Group Policy object (GPO) to an organizational unit (OU), named ENSUREPASSServ, which host the computer accounts for servers in the Contoso.com domain.

You have been tasked with adding a group to a local group on all servers in the Contoso.com

domain. This group should not, however, be removed from the local group.

Which of the following actions should you take?

A. You should consider adding a restricted group.

B. You should consider adding a global group.

C. You should consider adding a user

group.

D. You should consider adding a server group.

Explanation:

Restricted groups in Group policies are a simple way of delegating permissions or group membership centrally to any domain computer or server. Using restricted groups it is

easier to enforce the lowest possible permissions to any given account.

Computer Configuration\Windows Settings\Security Settings\Restricted Groups

Restricted groups allow an administrator to define two properties for security-sensitive groups (that is, -r

estricted- groups). The two properties are Members and Member Of.

The Members list defines who should and should not belong to the restricted group.

The Member Of list specifies which other groups the restricted group should belong to. When a restricted Gr

oup Policy is enforced, any current member of a restricted group that is not on the Members list is removed.