Your network contains an Active Directory forest named contoso.com. The forest functional level is Windows
Server 2012.
All servers run Windows Server 2016.
You create a new bastion forest named admin.contoso.com.
The forest functional level of admin.contoso.com is Windows Server 2012 R2.
You need to implement a Privileged Access Management (PAM) solution.
Which two actions should you perform? Each correct answer presents part of the solution.
A.
Raise the forest functional level of contoso.com.
B.
Deploy Microsoft Identity Management (MIM) 2016 to contoso.com.
C.
Configure contoso.com to trust admin.contoso.com.
D.
Deploy Microsoft Identify Management (MIM) 2016 to admin.contoso.com.
E.
Raise the forest functional level of admin.contoso.com.
F.
Configure admin.contoso.com to trust contoso.com.
Explanation:
https://docs.microsoft.com/en-us/microsoft-identity-manager/pam/deploy-pam-with-windows-server-2016
https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/windows-server-2016-functional-levelsFor the bastion forest which deploys MIM, you should raise the Forest Functional Level to “Windows Server
2016″, E is correct.