70-246 · Question #1
Your company has a private cloud that contains two Active Directory forests named contoso.com and adatum.com. The contoso.com network and the adatum.com network are separated by a firewall. No…
The correct answer is A. A server certificate on the gateway server in contoso.com E. A gateway server in contoso.com F. A server certificate on the management server in adatum.com. When System Center 2012 Operations Manager is deployed in adatum.com and must monitor servers in an untrusted forest (contoso.com) across a firewall, a Gateway Server must be placed inside contoso.com (Answer E). The Gateway Server acts as a proxy, concentrating all…
Question
Your company has a private cloud that contains two Active Directory forests named contoso.com and adatum.com. The contoso.com network and the adatum.com network are separated by a firewall. No trusts exist between the forests. You deploy System Center 2012 Operations Manager to adatum.com. You install agents on 100 servers in both forests. You need to ensure that you can monitor all 100 servers. The solution must minimize the traffic between the two networks. What should you install? (Each correct answer presents part of the solution. Choose all that apply.)
Options
- AA server certificate on the gateway server in contoso.com
- BA gateway server in adatum.com
- CA server certificate on the gateway server in adatum.com
- DClient certificates on all of the servers in adatum.com
- EA gateway server in contoso.com
- FA server certificate on the management server in adatum.com
- GClient certificates on all of the servers in contoso.com
How the community answered
(34 responses)- A71% (24)
- B3% (1)
- C9% (3)
- D15% (5)
- G3% (1)
Explanation
When System Center 2012 Operations Manager is deployed in adatum.com and must monitor servers in an untrusted forest (contoso.com) across a firewall, a Gateway Server must be placed inside contoso.com (Answer E). The Gateway Server acts as a proxy, concentrating all agent-to-management-server traffic into a single encrypted channel across the firewall - this is how traffic is minimized. Because no Active Directory trust exists between the two forests, Kerberos cannot be used across the firewall; instead, mutual certificate authentication is required. The Gateway Server in contoso.com needs a server certificate (Answer A) so the management server can authenticate it, and the management server in adatum.com needs its own server certificate (Answer F) for the gateway to authenticate it. Agents in contoso.com connect to the gateway server within their own forest using Kerberos, so they do NOT need individual client certificates (eliminating G). There is no need for a gateway server in adatum.com (eliminating B) because the management server is already there and agents in that forest use Kerberos natively.
Topics
Community Discussion
No community discussion yet for this question.