70-647 · Question #104
Your network consists of two Active Directory forests. The Active Directory forests are configured as shown in the following table. (Click the Exhibit) The servers in both forests run Windows Server…
The correct answer is C. Set the authentication scope of the existing forest trust in the fabrikam.com domain to Allow. To ensure that the users in the ContosoSales global group are allowed to access server1.Fabrikam.com you need to assign the Access this computer from the network option to the ContosoSales global group in the local security policy of server1.Fabrikam.com to allow remote users…
Question
Your network consists of two Active Directory forests. The Active Directory forests are configured as shown in the following table. (Click the Exhibit) The servers in both forests run Windows Server 2008. A forest trust exists between the fabrikam.com forest and the contoso.com forest. Fabrikam.com has a server named server1.fabrikam.com. Contoso.com has a global group named ContosoSales. Users in the ContosoSales global group access an application on server1.fabrikam.com. You discover that users from other groups in the contoso.com domain can log on to servers in the fabrikam.com domain. You need to implement an authentication solution to meet the following requirements:
- Users in the ContosoSales global group must be able to access
server1.fabrikam.com.
- Users in the ContosoSales global group must be denied access to all
other servers in the fabrikam.com forest.
- All other users in the contoso.com domain must be able to access only
resources in the contoso.com forest. What should you do?
Options
- AReplace the existing forest trust with an external trust between the contoso.com domain and
- BReplace the existing forest trust with an external trust between the contoso.com domain and
- CSet the authentication scope of the existing forest trust in the fabrikam.com domain to Allow
- DSet the authentication scope of the existing forest trust in the fabrikam.com domain to Allow
How the community answered
(30 responses)- A3% (1)
- B10% (3)
- C83% (25)
- D3% (1)
Explanation
To ensure that the users in the ContosoSales global group are allowed to access server1.Fabrikam.com you need to assign the Access this computer from the network option to the ContosoSales global group in the local security policy of server1.Fabrikam.com to allow remote users to have permission to connect to the remote computer. To ensure that the ContosoSales global group users should not be allowed to access any other server in the Fabrikam.com forest, you need to grant the Allowed to Authenticate permission to the ContosoSales global group on the server1.Fabrikam.com computer object. The Allowed to authenticate on an object allows you to set the selective authentication on an incoming external trust from the external domain. Authentication requests made from one domain to another are successfully routed in order to provide a seamless coexistence of resources across domains. Users can only gain access to resources in other domains after first being authenticated in their own domain. 75f0eacfe94c1033.mspx?mfr=true
Topics
Community Discussion
No community discussion yet for this question.