nerdexam
Microsoft

70-647 · Question #14

Your company has one main office and 20 branch offices. Each office is configured as an Active Directory site. The network consists of one Active Directory domain. All servers run Windows Server…

The correct answer is C. Create a Group Policy object (GPO) that applies to all branch office domain controllers and. To deploy domain controllers in the branch offices and make sure that the client computers in each branch office must attempt to authenticate to the domain controller at their local site first and the authentication to a main office domain controller must only occur if a local…

Planning and Implementing Servers

Question

Your company has one main office and 20 branch offices. Each office is configured as an Active Directory site. The network consists of one Active Directory domain. All servers run Windows Server 2008 R2 and all client computers run Windows 7. The main office contains three domain controllers. You need to deploy one domain controller in each branch office to meet the following requirements:

  • Authentication to a main office domain controller must only occur if

a local domain controller fails.

  • Client computers in the main office must not authenticate to a domain

controller office.

  • Client computers in a branch office must not authenticate to a domain

controller in another branch office.

  • Client computers in each branch office must attempt to authenticate

to the domain controller at their local site first. What should you do first?

Options

  • AAssociate the IP subnet of each branch office to the Active Directory site of the main office.
  • BSelect the read-only domain controller (RODC) option and the Global Catalog option when
  • CCreate a Group Policy object (GPO) that applies to all branch office domain controllers and
  • DConfigure only the main office domain controllers as global catalog servers.

How the community answered

(46 responses)
  • A
    7% (3)
  • B
    11% (5)
  • C
    80% (37)
  • D
    2% (1)

Explanation

To deploy domain controllers in the branch offices and make sure that the client computers in each branch office must attempt to authenticate to the domain controller at their local site first and the authentication to a main office domain controller must only occur if a local domain controller fails and to meet other specified requirements, you need to create a Group Policy object (GPO) for all branch office domain controllers to control the registration of DNS service location (SRV) records. SRV records are used by Windows Server to locate domain controllers in specific domains, domain controllers in the same site, global catalogue servers, and key distribution centers. Reference: DNS Service Records and Locating Domain Controllers

Topics

#site coverage#authentication failover#Group Policy#branch office domain controllers

Community Discussion

No community discussion yet for this question.

Full 70-647 Practice