PrepAway - Latest Free Exam Questions & Answers

Which two actions should you perform?

Your network contains an Active Directory forest named contoso.com.
The forest contains two domains named contoso.com and childl.contoso.com.

The domains contain three domain controllers.
The domain controllers are configured as shown in the following table.

You need to ensure that the KDC support for claims, compound authentication, and kerberos
armoring setting is enforced in both domains.
Which two actions should you perform? (Each correct answer presents part of the solution.
Choose two.)

PrepAway - Latest Free Exam Questions & Answers

A.
Raise the domain functional level of contoso.com.

B.
Raise the domain functional level of child1.contoso.com.

C.
Raise the forest functional level of contoso.com.

D.
Upgrade DC11 to Windows Server 2012 R2.

E.
Upgrade DC1 to Windows Server 2012 R2.

Explanation:
To use claims-based authorization, you need the following:
• Windows Server 2012 must be installed on the file server that hosts
the resources that DAC protects.
• At least one Windows Server 2012 domain controller must be accessible
by the requesting client.
• If you use claims across a forest, you must have a Windows Server
2012 domain controller in each domain.
• If you use device claims, clients must run Windows 8.
A question in the same book indicates:
Identify the minimum domain function level (2003, 2008, 2008 R2, or 2012) for the specified
feature…
KDC support for claims – 2012
So the answer is A and E.
E because you must upgrade the domain controller to 2012 R2 to raise the functional level of the
domain to the necessary level, and A because 2012 domain functional level is required for KDC
support for claims.
Upgrading dc11.child1.contoso.com is not necessary because there is already a Server 2012 R2
server in the child domain (dc10).

2 Comments on “Which two actions should you perform?


Leave a Reply