70-647 · Question #37
Your company named Contoso, Ltd. and another company named Fabrikam, Inc. establish a partnership. The Contoso network consists of one Active Directory forest named contoso.com. The Fabrikam network…
The correct answer is C. Deploy Active Directory Federation Services (AD FS). To prepare an environment for the users of contoso.com so that the users from Contoso.com can protect their confidential files from being accessed by unauthorized users while they share their files, you need to deploy Active Directory Federation Services (AD FS) and Active…
Question
Your company named Contoso, Ltd. and another company named Fabrikam, Inc. establish a partnership. The Contoso network consists of one Active Directory forest named contoso.com. The Fabrikam network consists of one Active Directory forest named fabrikam.com. Users from contoso.com plan to share files with users from fabrikam.com. You need to prepare the environment so that users from contoso.com can protect confidential files from being copied or forwarded to unauthorized users. What should you do?
Options
- ACreate a one-way forest trust from Contoso.
- BCreate a one-way forest trust from Fabrikam.
- CDeploy Active Directory Federation Services (AD FS).
- DDeploy Active Directory Federation Services (AD FS).
How the community answered
(23 responses)- A13% (3)
- B4% (1)
- C74% (17)
- D9% (2)
Explanation
To prepare an environment for the users of contoso.com so that the users from Contoso.com can protect their confidential files from being accessed by unauthorized users while they share their files, you need to deploy Active Directory Federation Services (AD FS) and Active Directory Rights Management Services (AD RMS) on the Contoso.com network You can use Active Directory Federation Services (ADFS) to enable efficient and secure online transactions between Partner organizations that are joined by federation trust relationships. AD RMS helps you to prevent sensitive information--such as financial reports, product specifications, customer data, and confidential e-mail messages--from intentionally or accidentally getting into the wrong hands. You can use AD RMS on applications running on Windows or other operating systems to help safeguard sensitive information. Rights-protected documents of any kind can be set up for time-restricted access--and after that author-defined period of time has elapsed, the files can no longer be opened as the "use license" will have expired. The identity federation support role service is an optional role service in AD RMS that allows federated identities to consume rights-protected content by using Active Directory Federation be29352afaca1033.mspx?mfr=true 15b156a0b4e01033.mspx?mfr=true
Topics
Community Discussion
No community discussion yet for this question.