PrepAway - Latest Free Exam Questions & Answers

You need to configure the RODC to store only the passwords of users in the remote site

Your network contains an Active Directory forest. The forest contains an Active Directory site for a remote
office. The remote site contains a read-only domaincontroller (RODC).
You need to configure the RODC to store only the passwords of users in the remote site.
What should you do?

PrepAway - Latest Free Exam Questions & Answers

A.
Create a Password Settings object (PSO).

B.
Modify the Partial-Attribute-Set attribute of theforest.

C.
Add the user accounts of the remote site users tothe Allowed RODC Password Replication Group.

D.
Add the user accounts of users who are not in theremote site to the Denied RODC Password Replication
Group.

Explanation:
Reference:
http://technet.microsoft.com/en-us/library/cc730883.aspx
Password Replication Policy Allowed and Denied lists
Two new built-in groups are introduced in Windows Server 2008 Active Directory domains to support RODC
operations. These are the Allowed RODC Password Replication Groupand Denied RODC Password
Replication Group.
These groups help implement a default Allowed List and Denied List for the RODC Password Replication
Policy. By default, the two groups are respectivelyadded to the msDS-RevealOnDemandGroup and msDS-NeverRevealGroup Active Directory attributes mentioned earlier.


Leave a Reply