nerdexam
Microsoft

70-647 · Question #124

Your company has a main office and 10 branch offices. The network consists of one Active Directory domain. All domain controllers run Windows Server 2008 R2 and are located in the main office. You…

The correct answer is C. Enable the read-only domain controller (RODC) option. See the full explanation below for the reasoning.

Question

Your company has a main office and 10 branch offices. The network consists of one Active Directory domain. All domain controllers run Windows Server 2008 R2 and are located in the main office. You plan to deploy one Windows Server 2008 R2 domain controller in each branch office. You are concerned that the branch offices will fail to provide adequate security for the new domain controllers. You need to recommend a security solution to meet the following requirements:

  • Prevent any unauthorized user from accessing user passwords when the

server is running.

  • Prevent any unauthorized user from accessing user passwords either

locally or over the network on each branch office domain controller. Which configuration should you recommend for each branch office domain controller?

Options

  • AEnable an IPsec policy.
  • BEnable Windows Firewall.
  • CEnable the read-only domain controller (RODC) option.
  • DEnable Windows BitLocker Drive Encryption (BitLocker).

How the community answered

(31 responses)
  • A
    10% (3)
  • B
    3% (1)
  • C
    84% (26)
  • D
    3% (1)

Community Discussion

No community discussion yet for this question.

Full 70-647 Practice