nerdexam
Microsoft

70-246 · Question #44

The Network Access Account is used by client computers when they cannot use their local computer account to access content on distribution points. For example, this applies to workgroup clients and…

The correct answer is A. You can configure the Network Access Account on a central administration site. Answer A is FALSE. The Network Access Account cannot be configured on a central administration site (CAS). In a Configuration Manager hierarchy, the CAS is an administrative tier and does not serve content directly to clients; it has no distribution points of its own and no…

Implementing a Private Cloud

Question

The Network Access Account is used by client computers when they cannot use their local computer account to access content on distribution points. For example, this applies to workgroup clients and computers from untrusted domains. This account might also be used during operating system deployment when the computer installing the operating system does not yet have a computer account on the domain. Which of the following is FALSE?

Options

  • AYou can configure the Network Access Account on a central administration site.
  • BYou should not grant this account interactive logon rights
  • CWhen Configuration Manager tries to use the computername$ account to download the content
  • DThe Network Access Account is never used as the security context to run programs, install

How the community answered

(32 responses)
  • A
    91% (29)
  • C
    6% (2)
  • D
    3% (1)

Explanation

Answer A is FALSE. The Network Access Account cannot be configured on a central administration site (CAS). In a Configuration Manager hierarchy, the CAS is an administrative tier and does not serve content directly to clients; it has no distribution points of its own and no clients report to it. The Network Access Account is configured at primary sites, which are the sites that directly serve clients and host distribution points. The remaining statements are all TRUE: B is a security best practice (no interactive logon rights prevents misuse if credentials are compromised); C correctly describes that ConfigMgr first attempts to use the computer's machine account (computername$) before falling back to the Network Access Account; and D is a critical security restriction - the Network Access Account is strictly for content access only, never for running programs or installing software.

Topics

#Network Access Account#Configuration Manager#client security context#distribution points

Community Discussion

No community discussion yet for this question.

Full 70-246 Practice