Your network contains an Active Directory forest named contoso.com. The forest contains
five domains. All domain controllers run Windows Server 2012 R2.
The contoso.com domain contains two user accounts named Admin1 and Admin2.
You need to ensure that Admin1 and Admin2 can configure hardware and services on all of
the member servers in the forest. The solution must minimize the number of privileges
granted to Admin1 and Admin2.
Which built-in groups should you use?
A.
Administrators local groups
B.
Administrators domain local groups
C.
Domain Admins global groups
D.
Server Operators global groups
Says “servers in the forest”….is this true answer ?
0
0
I believe if you set those accounts to be members of local Administrators group via forest wide GPO then yes A is correct. Domain admins are valid for domain only unless oyu set tehm to forest domain but then they have too much permissions, Server Operators – too much permissions and Administrators Domain local you would have to configure multiple times as domain local group scope doens´t get inherited to child domains.
0
0
Domain admins global groups
0
0
I think its A. The key to this question is “The solution must minimize the number of privileges
granted” not “You must achieve this goal by using the minimum amount of administrative effort”, if it was the second one then C would be the correct answer.
0
0