nerdexam
Microsoft

70-647 · Question #50

Your network contains one Active Directory forest that has a root domain and three child domains. All domain controllers run Windows Server 2003 Service Pack 1 (SP1). Each domain has a different…

The correct answer is D. Upgrade the forest root domain to Windows Server 2008. To reduce the number of domains from the forest without loosing existing user account attributes and existing password policies, you need to Use the Active Directory Migration Tool (ADMT) to migrate user accounts that contain SID history from the child domains to the forest…

Planning and Implementing Servers

Question

Your network contains one Active Directory forest that has a root domain and three child domains. All domain controllers run Windows Server 2003 Service Pack 1 (SP1). Each domain has a different password policy. The domain is configured as shown in the exhibit. (Click the Exhibit button.) You plan to reduce the number of domains in the forest. You need to plan the restructuring of the forest to meet the following requirements:

  • Maintain all existing password policies.
  • Maintain all existing user account attributes.

What should you include in your plan?

Exhibit

70-647 question #50 exhibit

Options

  • AUpgrade all domains to Windows Server 2008.
  • BUpgrade all domains to Windows Server 2008 and enable SID history.
  • CUpgrade the forest root domain to Windows Server 2008.
  • DUpgrade the forest root domain to Windows Server 2008.

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    5% (2)
  • C
    12% (5)
  • D
    80% (33)

Explanation

To reduce the number of domains from the forest without loosing existing user account attributes and existing password policies, you need to Use the Active Directory Migration Tool (ADMT) to migrate user accounts that contain SID history from the child domains to the forest root domain. Remove the child domains SID history enables you to maintain user access to resources during the process of restructuring Active Directory domains. When you migrate an object to another domain, the object is assigned a new SID. Because you assign permissions to objects based on SIDs, when the SID changes, the user loses access to that resource until you can reassign permissions. When you use ADMT to migrate objects between domains, the SID history is automatically retained. In this way, the SID from the source domain remains as an attribute of the object after the object is migrated to the target domain. Enable fine-grained password policies to keep existing password policies. 3d76-7d56-44d6-ad25- a95bf0be5516/15_CHAPTER_12_Restructuring_Active_Directory_Domains_Within_a_Forest.do c+reduce+the+number+of+domains+ADMT&hl=en&ct=clnk&cd=10&gl=in

Topics

#fine-grained password policy#domain consolidation#SID history#ADMT migration

Community Discussion

No community discussion yet for this question.

Full 70-647 Practice