nerdexam

70-158 · Question #9

Your company network uses Forefront Identity Manager (FIM) 2010 to synchronize user accounts in an Active Directory Domain Services (AD DS) domain. You are implementing Password Change Notification…

The correct answer is A. Select the .dll file of the HR MA extension as the extension name. C. Enable Password Management in the extensions of the HR Data MA. D. Set the Password Synchronization target MA to HR Data in the AD MA. E. Enable password synchronization in Synchronization Service Manager. G. Configure the Directory Partition of the AD MA to Enable this partition as a password synchronization source. Configuring PCNS-based password synchronization in FIM 2010 requires enabling password sync globally, configuring the AD MA as a password source, targeting the HR Data MA, and enabling password management on the HR Data MA with the correct extension DLL.

Submitted by jordan8· Mar 4, 2026Configuring Credential Management

Question

Your company network uses Forefront Identity Manager (FIM) 2010 to synchronize user accounts in an Active Directory Domain Services (AD DS) domain. You are implementing Password Change Notification Service (PCNS). You need to configure the AD Management Agent (AD MA) for password synchronization with PCNS. You also need to ensure that the HR Data MA receives password change notifications. What should you do? (Choose all that apply.)

Options

  • ASelect the .dll file of the HR MA extension as the extension name.
  • BSelect the .dll file of the metaverse extension as the extension name.
  • CEnable Password Management in the extensions of the HR Data MA.
  • DSet the Password Synchronization target MA to HR Data in the AD MA.
  • EEnable password synchronization in Synchronization Service Manager.
  • FCreate the HR Data MA import attribute flow for the resetPassword metaverse attribute.
  • GConfigure the Directory Partition of the AD MA to Enable this partition as a password synchronization source.

How the community answered

(21 responses)
  • A
    67% (14)
  • B
    10% (2)
  • F
    24% (5)

Why each option

Configuring PCNS-based password synchronization in FIM 2010 requires enabling password sync globally, configuring the AD MA as a password source, targeting the HR Data MA, and enabling password management on the HR Data MA with the correct extension DLL.

ASelect the .dll file of the HR MA extension as the extension name.Correct

The HR Data MA extension DLL must be specified as the extension name so that the MA can process password change notifications through its custom password management code.

BSelect the .dll file of the metaverse extension as the extension name.

The metaverse extension DLL is not used for password management on the HR Data MA; the MA's own extension DLL (option A) is required to handle password operations.

CEnable Password Management in the extensions of the HR Data MA.Correct

Enabling Password Management in the HR Data MA extensions is required so that the MA can accept and process inbound password synchronization calls from the synchronization engine.

DSet the Password Synchronization target MA to HR Data in the AD MA.Correct

Setting the Password Synchronization target MA to HR Data in the AD MA configuration establishes the flow path so that password changes captured by the AD MA via PCNS are forwarded to the HR Data MA.

EEnable password synchronization in Synchronization Service Manager.Correct

Enabling password synchronization in Synchronization Service Manager is the global setting that activates the password synchronization infrastructure within FIM, without which no password sync operations will occur.

FCreate the HR Data MA import attribute flow for the resetPassword metaverse attribute.

Creating an import attribute flow for resetPassword is not required for PCNS-based password synchronization, as password sync uses a dedicated password pipeline rather than standard attribute flow rules.

GConfigure the Directory Partition of the AD MA to Enable this partition as a password synchronization source.Correct

Configuring the Directory Partition of the AD MA to enable it as a password synchronization source allows the AD MA to receive PCNS notifications from domain controllers and initiate the password sync flow.

Concept tested: FIM 2010 PCNS password synchronization configuration

Source: https://learn.microsoft.com/en-us/previous-versions/mim/ff608278(v=ws.10)

Topics

#PCNS#Password Synchronization#Management Agents#Metaverse Extensions

Community Discussion

No community discussion yet for this question.

Full 70-158 Practice