70-243 · Question #38
You have a System Center 2012 Configuration Manager environment running in native mode. You have a perimeter network for your Internet-based site systems. You block the SMB traffic from the…
The correct answer is D. Configure a Site System Installation account. When SMB is blocked from a perimeter network to the intranet and only site-server-initiated transfers are allowed, a Site System Installation Account must be configured for the site server to manage those remote site systems.
Question
You have a System Center 2012 Configuration Manager environment running in native mode. You have a perimeter network for your Internet-based site systems. You block the SMB traffic from the perimeter network to your intranet. You configure the site systemsproperties to allow only site server initiated data transfers from the site systems. You need to configure site system communications between the perimeter network and the site server. What should you do?
Options
- AConfigure the fallback status points.
- BConfigure a server locator point.
- CConfigure a Client Connection account.
- DConfigure a Site System Installation account.
How the community answered
(42 responses)- A7% (3)
- B14% (6)
- C24% (10)
- D55% (23)
Why each option
When SMB is blocked from a perimeter network to the intranet and only site-server-initiated transfers are allowed, a Site System Installation Account must be configured for the site server to manage those remote site systems.
Fallback status points provide a communication channel for clients that cannot reach a management point - they do not address the authentication and connectivity requirements between the site server and site systems in a perimeter network.
A server locator point helps clients discover a management point when AD and WINS are unavailable - it does not facilitate site server to site system administrative communication across a blocked perimeter.
A Client Connection account is used by Configuration Manager clients to authenticate to site systems when computer account authentication is unavailable - it does not govern site server to site system installation communications.
The Site System Installation Account provides the credentials the site server uses to connect to and install or manage site systems located in the perimeter network. Because SMB is blocked inbound and data transfers are site-server-initiated, the site server must authenticate using this account to push installations and retrieve status from the perimeter site systems; without it, the site server has no way to authenticate across the network boundary.
Concept tested: Site System Installation Account for perimeter network communication
Source: https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts#site-system-installation-account
Topics
Community Discussion
No community discussion yet for this question.