PrepAway - Latest Free Exam Questions & Answers

What should you modify?

Note: This question is part of a series of questions that use the same scenario. For your convenience, the
scenario is repeated in each question. Each question presents a different goal and answer choices, but the text
of the scenario is exactly the same in each question in this series.Start of repeated scenario.
You work for a company named Contoso, Ltd.
The network contains an Active Directory forest named contoso.com. A forest trust exists between
contoso.com and an Active Directory forest named adatum.com.
The contoso.com forest contains the objects configured as shown in the following table.

Group1 and Group2 contain only user accounts.
Contoso hires a new remote user named User3. User3 will work from home and will use a computer named
Computer3 that runs Windows 10. Computer3 is currently in a workgroup.
An administrator named Admin1 is a member of the Domain Admins group in the contoso.com domain.
From Active Directory Users and Computers, you create an organizational unit (OU) named OU1 in the
contoso.com domain, and then you create a contact named Contact1 in OU1.
An administrator of the adatum.com domain runs the Set-ADUser cmdlet to configure a user named User1 to
have a user logon name of User1@litwareinc.com.
End or repeated scenario.
You need to ensure that Admin1 can add Group2 as a member of Group3.
What should you modify?

PrepAway - Latest Free Exam Questions & Answers

A.
Modify the Security settings of Group3.

B.
Modify the group scope of Group3.

C.
Modify the group type of Group3.

D.
Set Admin1 as the manager of Group3.

One Comment on “What should you modify?

  1. davidcertifier says:

    Group 2 is a Domain Local group. A DL group can only be a member of another DL group.

    So we need to convert Group 3 to DL. This just happens to be a one-step process, since Universal groups are actually more restrictive than DL when it comes to their membership.

    Reference:
    https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directory-security-groups

    According to that, going from Uni to Global should also be a one-click. Anyone tried it in their labs? Or is it still U->DL, DL->G?




    5



    0

Leave a Reply