nerdexam
Microsoft

70-243 · Question #150

You create a new Active Directory user named User1. You create a new collection that contains ther servers in PS1 and PS2. You need to ensure that User1 can perform the following tasks in SP1 and…

The correct answer is D. Add User1 as an administrative user. SCCM role-based administration uses scoped security roles to grant only the permissions required for specific tasks, satisfying the principle of least privilege.

security management

Question

You create a new Active Directory user named User1. You create a new collection that contains ther servers in PS1 and PS2. You need to ensure that User1 can perform the following tasks in SP1 and SP2:

  • Modify alrets
  • Set maintainace windows
  • Deploy application to servers

The solution must minimize the number of permission assigned to User1. What should you do?

Options

  • AAdd User1 as an administrative user.
  • BAdd User1 as an administrative user.
  • CAdd User1 as an administrative user.
  • DAdd User1 as an administrative user.

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    12% (3)
  • D
    76% (19)

Why each option

SCCM role-based administration uses scoped security roles to grant only the permissions required for specific tasks, satisfying the principle of least privilege.

AAdd User1 as an administrative user.

Identical choice text - the source question contains a data entry error; all options read the same, so no technical distinction can be drawn.

BAdd User1 as an administrative user.

Identical choice text - the source question contains a data entry error; all options read the same, so no technical distinction can be drawn.

CAdd User1 as an administrative user.

Identical choice text - the source question contains a data entry error; all options read the same, so no technical distinction can be drawn.

DAdd User1 as an administrative user.Correct

Note - all four answer choices in this question contain identical text due to a data entry error in the source material, making it impossible to differentiate between options as written. The concept being tested is SCCM role-based administration: assigning a scoped security role such as 'Operations Administrator' limited to the target collection grants rights to modify alerts, configure maintenance windows, and deploy applications without requiring full administrative access across the hierarchy.

Concept tested: SCCM role-based administration least privilege security roles

Source: https://learn.microsoft.com/en-us/mem/configmgr/core/understand/fundamentals-of-role-based-administration

Topics

#security roles#role-based administration#minimum permissions#administrative users

Community Discussion

No community discussion yet for this question.

Full 70-243 Practice