nerdexam
Microsoft

70-243 · Question #38

You have a System Center 2012 Configuration Manager environment running in native mode. You have a perimeter network for your Internet-based site systems. You block the SMB traffic from the…

The correct answer is D. Configure a Site System Installation account. When SMB is blocked from a perimeter network to the intranet and only site-server-initiated transfers are allowed, a Site System Installation Account must be configured for the site server to manage those remote site systems.

Managing Sites and Clients

Question

You have a System Center 2012 Configuration Manager environment running in native mode. You have a perimeter network for your Internet-based site systems. You block the SMB traffic from the perimeter network to your intranet. You configure the site systemsproperties to allow only site server initiated data transfers from the site systems. You need to configure site system communications between the perimeter network and the site server. What should you do?

Options

  • AConfigure the fallback status points.
  • BConfigure a server locator point.
  • CConfigure a Client Connection account.
  • DConfigure a Site System Installation account.

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    14% (6)
  • C
    24% (10)
  • D
    55% (23)

Why each option

When SMB is blocked from a perimeter network to the intranet and only site-server-initiated transfers are allowed, a Site System Installation Account must be configured for the site server to manage those remote site systems.

AConfigure the fallback status points.

Fallback status points provide a communication channel for clients that cannot reach a management point - they do not address the authentication and connectivity requirements between the site server and site systems in a perimeter network.

BConfigure a server locator point.

A server locator point helps clients discover a management point when AD and WINS are unavailable - it does not facilitate site server to site system administrative communication across a blocked perimeter.

CConfigure a Client Connection account.

A Client Connection account is used by Configuration Manager clients to authenticate to site systems when computer account authentication is unavailable - it does not govern site server to site system installation communications.

DConfigure a Site System Installation account.Correct

The Site System Installation Account provides the credentials the site server uses to connect to and install or manage site systems located in the perimeter network. Because SMB is blocked inbound and data transfers are site-server-initiated, the site server must authenticate using this account to push installations and retrieve status from the perimeter site systems; without it, the site server has no way to authenticate across the network boundary.

Concept tested: Site System Installation Account for perimeter network communication

Source: https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts#site-system-installation-account

Topics

#perimeter network#native mode#site system installation account#SMB blocking

Community Discussion

No community discussion yet for this question.

Full 70-243 Practice