nerdexam
Microsoft

70-647 · Question #28

70-647 Question #28: Real Exam Question with Answer & Explanation

The correct answer is B. Replace branch office domain controllers with Windows Server 2008 read-only domain. To ensure that only minimum numbers of user passwords are stored on the branch office domain controllers, you need to replace branch office domain controllers with Windows Server 2008 read- only domain controllers (RODCs) because an RODC can be configured to store only the passwo

Question

Your company has one main office and eight branch offices. Each branch office has one server and 20 client computers. The network consists of one Active Directory domain. All main office domain controllers run Windows Server 2008. All branch office servers are configured as domain controllers and run Windows Server 2003 Service Pack 1 (SP1). You need to implement a security solution for the branch offices to meet the following requirements: The number of user passwords stored on branch office domain controllers must be minimized. All files stored on the branch office domain controller must be protected in the event of an offline attack. What should you do?

Options

  • AUpgrade branch office domain controllers to Windows Server 2008.
  • BReplace branch office domain controllers with Windows Server 2008 read-only domain
  • CReplace branch office domain controllers with Windows Server 2008 read-only domain
  • DAdd the branch office domain controller computer accounts to the read-only domain

Explanation

To ensure that only minimum numbers of user passwords are stored on the branch office domain controllers, you need to replace branch office domain controllers with Windows Server 2008 read- only domain controllers (RODCs) because an RODC can be configured to store only the passwords of specified users and computers. This limitation reduces the risks in case an RODC To ensure that all files stored on the domain controller must be protected from any kind of an offline attack, you need to use Windows BitLocker Drive Encryption. BitLocker allows you to encrypt all data stored on the Windows operating system volume and use the security of using a Trusted Platform Module (TPM) that helps protect user data and to ensure that a computer running Windows Server Vista or Server 2008 have not been tampered with while the system was 6866df4b253c1033.mspx?mfr=true

Community Discussion

No community discussion yet for this question.

Full 70-647 Practice