PrepAway - Latest Free Exam Questions & Answers

You need to prevent DNS records from replicating to RODC1

Your company has a main officeand a branch office.
The network contains an Active Directory domainnamed contoso.com.
The DNS zonefor contoso.comis configured as an Active Directory-integrated zoneand is replicated to
all domain controllers in the domain.
The main office contains a writable domain controllernamed DC1.
The branch office contains a read-only domain controller (RODC)named RODC1.
All domain controllersrun Windows Server 2008 R2and are configured as DNS servers.
You uninstall the DNS server role from RODC1.
You need to prevent DNS records from replicating to RODC1.
What should you do?

PrepAway - Latest Free Exam Questions & Answers

A.
Modify the replication scope for the contoso.com zone.

B.
Flush the DNS cache and enable cache locking on RODC1.

C.
Configure conditional forwarding for the contoso.com zone.

D.
Modify the zone transfer settings for the contoso.com zone.

Explanation:
http://technet.microsoft.com/en-us/library/cc754916.aspx
Change the Zone Replication Scope
You can use the following procedure to change the replication scope for a zone. Only Active Directory Domain
Services (AD DS)–integrated primary and stub forward lookup zones can change their replication scope.
Secondary forward lookup zones cannot change their replication scope.
http://technet.microsoft.com/en-us/library/cc772101.aspx
Understanding DNS Zone Replication in Active Directory Domain Services
You can store Domain Name System (DNS) zones in thedomain or application directory partitions of Active
Directory Domain Services (AD DS). A partition is adata structure in AD DS that distinguishes data for different
replication purposes.
The following table describes the available zone replication scopes for AD DS-integrated DNS zone data.

When you decide which replication scope to choose, consider that the broader the replication scope, the
greater the network traffic caused by replication. For example, if you decide to have AD DS–integratedDNS
zone data replicated to all DNS servers in the forest, this will produce greater network traffic than replicating the
DNS zone data to all DNS servers in a single AD DS domain in that forest.
AD DS-integrated DNS zone data that is stored in anapplication directory partition is not replicated to the global
catalog for the forest. The domain controller that contains the global catalog can also host application directory
partitions, but it will not replicate this data to its global catalog.
AD DS-integrated DNS zone data that is stored in a domain partition is replicated to all domain controllers in its
AD DS domain, and a portion of this data is stored in the global catalog. This setting is used to support
Windows 2000.
If an application directory partition’s replicationscope replicates across AD DS sites, replication will occur with
the same intersite replication schedule as is used for domain partition data.
By default, the Net Logon service registers domain controller locator (Locator) DNS resource records for the
application directory partitions that are hosted ona domain controller in the same manner as it registers domain
controller locator (Locator) DNS resource records for the domain partition that is hosted on a domain controller.


Leave a Reply