PrepAway - Latest Free Exam Questions & Answers

You need to prevent DNS records from replicating to RODC1

Your company has a main office and a branch office.
The network contains an Active Directory domain named contoso.com. The DNS zone for
contoso.com is configured as an Active Directory-integrated zone and is replicated to all
domain controllers in the domain.
The main office contains a writable domain controller named DC1. The branch office
contains a read- only domain controller (RODC) named RODC1. All domain controllers run
Windows Server 2008 R2 and are configured as DNS servers.
You uninstall the DNS server role from RODC1.
You need to prevent DNS records from replicating to RODC1.
What should you do?

PrepAway - Latest Free Exam Questions & Answers

A.
Modify the replication scope for the contoso.com zone.

B.
Flush the DNS cache and enable cache locking on RODC1.

C.
Configure conditional forwarding for the contoso.com zone.

D.
Modify the zone transfer settings for the contoso.com zone.

Explanation:
http://technet.microsoft.com/en-us/library/cc754916.aspx
Change the Zone Replication Scope
You can use the following procedure to change the replication scope for a zone. Only Active
Directory Domain Services (AD DS)–integrated primary and stub forward lookup zones can
change their replication scope.
Secondary forward lookup zones cannot change their replication scope.
http://technet.microsoft.com/en-us/library/cc772101.aspx
Understanding DNS Zone Replication in Active Directory Domain Services
You can store Domain Name System (DNS) zones in the domain or application directory
partitions of Active
Directory Domain Services (AD DS). A partition is a data structure in AD DS that
distinguishes data for different replication purposes.
The following table describes the available zone replication scopes for AD DS-integrated
DNS zone data.

When you decide which replication scope to choose, consider that the broader the
replication scope, the greater the network traffic caused by replication. For example, if you
decide to have AD DS–integrated DNS zone data replicated to all DNS servers in the forest,
this will produce greater network traffic than replicating the DNS zone data to all DNS
servers in a single AD DS domain in that forest.
AD DS-integrated DNS zone data that is stored in an application directory partition is not
replicated to the global catalog for the forest. The domain controller that contains the global
catalog can also host application directory partitions, but it will not replicate this data to its
global catalog.
AD DS-integrated DNS zone data that is stored in a domain partition is replicated to all
domain controllers in its AD DS domain, and a portion of this data is stored in the global
catalog. This setting is used to support Windows 2000.
If an application directory partition’s replication scope replicates across AD DS sites,
replication will occur with the same intersite replication schedule as is used for domain
partition data.
By default, the Net Logon service registers domain controller locator (Locator) DNS resource
records for the application directory partitions that are hosted on a domain controller in the
same manner as it registers domain controller locator (Locator) DNS resource records for
the domain partition that is hosted on a domain controller.


Leave a Reply