nerdexam
Microsoft

70-647 · Question #15

Your network consists of one Active Directory domain that contains only domain controllers that run Windows Server 2003. Your company acquires another company. You need to provide user accounts for…

The correct answer is D. Upgrade all domain controllers to Windows Server 2008. To support multiple account lockout policies, you need to upgrade all domain controllers to Windows Server 2008. In Microsoft?Windows 2000 and Windows Server 2003 Active Directory domains, you could apply only one password and account lockout policy. In Windows Server 2008, you…

Planning and Implementing Security

Question

Your network consists of one Active Directory domain that contains only domain controllers that run Windows Server 2003. Your company acquires another company. You need to provide user accounts for the employees of the newly acquired company. The solution must support multiple account lockout policies. What should you do?

Options

  • AImplement Authorization Manager.
  • BImplement Active Directory Federation Services (AD FS).
  • CUpgrade one domain controller to Windows Server 2008.
  • DUpgrade all domain controllers to Windows Server 2008.

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    15% (7)
  • C
    8% (4)
  • D
    75% (36)

Explanation

To support multiple account lockout policies, you need to upgrade all domain controllers to Windows Server 2008. In Microsoft?Windows 2000 and Windows Server 2003 Active Directory domains, you could apply only one password and account lockout policy. In Windows Server 2008, you can use fine-grained password policies to specify multiple password policies and apply different password restrictions and account lockout policies to different sets of users within a Next you need to raise the functional level of the domain to Windows Server 2008 because Windows Server 2003 functional level does not support Windows Server 2008 domain controllers. ade35f8978ea1033.mspx?mfr=true c600f723b31f1033.mspx?mfr=true

Topics

#fine-grained password policy#account lockout#domain functional level#Windows Server 2008

Community Discussion

No community discussion yet for this question.

Full 70-647 Practice