nerdexam
Microsoft

70-647 · Question #91

Your company has a main office, three regional offices, and six branch offices. The network links are configured as shown in the exhibit. (Click the Exhibit button.) The network consists of one…

The correct answer is C. In each branch office, install a Server Core installation of Windows Server 2008 and configure. To ensure that the domain user account passwords stored on the domain controllers must be protected if a branch office domain controller is stolen, you need to install a Server Core installation of Windows Server 2008 and configure it as a read-only domain controller (RODC) in…

Planning and Implementing Servers

Question

Your company has a main office, three regional offices, and six branch offices. The network links are configured as shown in the exhibit. (Click the Exhibit button.) The network consists of one Active Directory domain. You create an Active Directory site for each office. You create a site link for each wide area network (WAN) link. The Bridge all site links option is disabled. You need to plan the deployment of domain controllers. The solution must meet the following requirements. Windows PowerShell must be installed on all domain controllers in each regional office. Domain user account passwords stored on the domain controllers must be protected if a branch office domain controller is stolen. What should you do?

Exhibit

70-647 question #91 exhibit

Options

  • AIn each branch office and in each regional office, install a Server Core installation of Windows
  • BIn each branch office and in each regional office, install a full installation of Windows Server
  • CIn each branch office, install a Server Core installation of Windows Server 2008 and configure
  • DIn each branch office, install a full installation of Windows Server 2008 and configure a

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    15% (4)
  • C
    74% (20)
  • D
    4% (1)

Explanation

To ensure that the domain user account passwords stored on the domain controllers must be protected if a branch office domain controller is stolen, you need to install a Server Core installation of Windows Server 2008 and configure it as a read-only domain controller (RODC) in each branch office. The Server Core installation of Windows Server 2008 will install only limited services on the RODC, which will store passwords. This installation will be very secure. A Server Core installation provides a minimal environment for running specific server roles, which reduces the maintenance and management requirements and the attack surface for those server roles. Next you can install a full installation of Windows Server 2008 and configure it as a writable domain controller in each regional office firstly because for RODCs to work you need to configure writable domain controllers from where data replication can happen and secondly you need to install them because you need to install Windows PowerShell on all domain controllers in each regional office. ad0afb1eaffc1033.mspx?mfr=true

Topics

#Server Core#RODC#domain controller deployment#Windows PowerShell

Community Discussion

No community discussion yet for this question.

Full 70-647 Practice