nerdexam
Microsoft

70-243 · Question #170

Your network contains three Active Directory forests named contoso.com, fabrikam.com, and litwareinc.com. All of the forests are untrusted. In contoso.com, you have a System Center 2012 R2…

The correct answer is B. Add a Network Access Account for fabrikam.com and litwareinc.com. In a multi-forest environment with no AD trusts, SCCM Network Access Accounts provide the credentials needed for PXE-booted clients in untrusted forests to authenticate to distribution points and retrieve OS deployment content.

Managing Operating System Deployment (OSD)

Question

Your network contains three Active Directory forests named contoso.com, fabrikam.com, and litwareinc.com. All of the forests are untrusted. In contoso.com, you have a System Center 2012 R2 Configuration Manager Service Pack 1 (SP1) deployment. In each forest, you deploy a distribution point that will be used to perform PXE-based operating system deployments. Each distribution point has the same configuration. You discover that the operating system deployments can only be performed in contoso.com. You need to ensure that you can perform the operating system deployments in each forest. The solution must minimize security changes to the Active Directory environment. What should you do?

Options

  • AEstablish a one-way trust relationship from contoso.com to fabrikam.com and from contoso.com to
  • BAdd a Network Access Account for fabrikam.com and litwareinc.com.
  • CEstablish a one-way trust relationship from fabrikam.com to contoso.com and from litwareinc.com
  • DAdd a client push installation account for fabrikam.com and litwareinc.com.

How the community answered

(26 responses)
  • A
    15% (4)
  • B
    73% (19)
  • C
    8% (2)
  • D
    4% (1)

Why each option

In a multi-forest environment with no AD trusts, SCCM Network Access Accounts provide the credentials needed for PXE-booted clients in untrusted forests to authenticate to distribution points and retrieve OS deployment content.

AEstablish a one-way trust relationship from contoso.com to fabrikam.com and from contoso.com to

Establishing a one-way trust from contoso.com to fabrikam.com and litwareinc.com introduces Active Directory trust relationships, which are significant security changes that contradict the stated requirement.

BAdd a Network Access Account for fabrikam.com and litwareinc.com.Correct

The Network Access Account (NAA) supplies credentials that SCCM clients use to access distribution point content when their own machine account lacks the required permissions - a situation that always occurs during PXE boot before domain join. Adding NAAs configured for fabrikam.com and litwareinc.com enables clients in those untrusted forests to download the OS deployment content from their respective distribution points without establishing any Active Directory trust relationships, satisfying the requirement to minimize security changes.

CEstablish a one-way trust relationship from fabrikam.com to contoso.com and from litwareinc.com

Creating trust relationships from fabrikam.com and litwareinc.com to contoso.com also requires Active Directory trust configuration and does not meet the requirement to minimize security changes to the AD environment.

DAdd a client push installation account for fabrikam.com and litwareinc.com.

Client push installation accounts are credentials used specifically for remotely installing the SCCM client agent and play no role in enabling PXE-based OS deployments across untrusted forest boundaries.

Concept tested: SCCM Network Access Account for untrusted forest PXE deployment

Source: https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts#network-access-account

Topics

#PXE deployment#untrusted forests#Network Access Account#cross-forest OSD

Community Discussion

No community discussion yet for this question.

Full 70-243 Practice