You need to configure the forest trust to meet the new security policy requirement
Your company has two Active Directory forestsas shown in the following table.
The forests are connectedby using a two-way forest trust.
Eachtrust directionis configured with forest-wide authentication.
The new security policyof the company prohibits users fromthe eng.fabrikam.comdomain to access
resources inthe contoso.comdomain.
You need to configure the forest trust to meet the new security policy requirement.
What should you do?
You need to configure AD RMS so that users are able to protect their documents
Your company has an Active Directory Rights Management Services (AD RMS) server.
Usershave Windows Vista computers.
An Active Directory domainis configuredat the Windows Server 2003 functional level.
You need to configure AD RMS so that users are able to protect their documents.
What should you do?
You need to prevent members of the TempWorkers group from accessing the confidential data on the file servers
Your company has an Active Directory domain.
All consultants belongto a global groupnamed TempWorkers.
The TempWorkers groupis not nested in any other groups.
You move the computer objectsof three file serversto a new organizational unitnamed SecureServers.
These file servers contain only confidential data in shared folders.
You need to prevent members of the TempWorkers group from accessing the confidential data on the
file servers.
You must achieve this goal without affecting access to other domain resources.
What should you do?
You need to create a password policy for the engineering department that is different from your domain passwor
Your network consists of a single Active Directory domain.
User accountsfor engineering departmentare located in an OUnamed Engineering.
You need to create a password policy for the engineering department that is different from your domain
password policy.
What should you do?
You need to configure DNS to allow only secure dynamic updates
Your network contains an Active Directory domain.
The domain contains two domain controllers named DC1and DC2.
DC1 hostsa standard primary DNS zonefor the domain.
Dynamic updates are enabled on the zone.
DC2 hostsa standard secondary DNS zonefor the domain.
You need to configure DNS to allow only secure dynamic updates.
What should you do first?
You need to prevent the domain controller from registering Host (A) records for the 10.10.10.5 IP address
Your network contains a domain controllerthat has two network connectionsnamed Internaland Private.
Internalhas an IP address of 192.168.0.20.
Privatehas an IP address of 10.10.10.5.
You need to prevent the domain controller from registering Host (A) records for the 10.10.10.5 IP
address.
What should you do?
You need to ensure that the computers in nwtraders.com can update their Host (A) records on any of the DNS ser
Your network contains an Active Directoryforest named contoso.com.
You plan to adda new domainnamed nwtraders.com to the forest.
All DNS servers are domain controllers.
You need to ensure that the computers in nwtraders.com can update their Host (A) records on any of
the DNS servers in the forest.
What should you do?
You need to prevent the non-domain member computers from registering records in the contoso.com zone
Your network containsan Active Directory domainnamed contoso.com.
The domain contains a domain controllernamed DC1.
DC1 hosts a standard primary zone for contoso.com.
You discover that non-domain member computers register records in the contoso.com zone.
You need to prevent the non-domain member computers from registering records in the contoso.com
zone.
All domain member computers must be allowed to register records in the contoso.com zone.
What should you do first?
You need to ensure that you can resolve names by using the GlobalNames zone
Your network contains an Active Directory domainnamed contoso.com.
You createa GlobalNames zone.
You addan alias (CNAME) resource recordnamed Server1 to the zone.
The target host of the recordis server2.contoso.com.
When you ping Server1, you discover that the name fails to resolve.
You successfully resolve server2.contoso.com.
You need to ensure that you can resolve names by using the GlobalNames zone.
What should you do?
You need to prevent DNS records from replicating to RODC1
Your company has a main officeand a branch office.
The network contains an Active Directory domainnamed contoso.com.
The DNS zonefor contoso.comis configured as an Active Directory-integrated zoneand is replicated to
all domain controllers in the domain.
The main office contains a writable domain controllernamed DC1.
The branch office contains a read-only domain controller (RODC)named RODC1.
All domain controllersrun Windows Server 2008 R2and are configured as DNS servers.
You uninstall the DNS server role from RODC1.
You need to prevent DNS records from replicating to RODC1.
What should you do?