nerdexam
Microsoft

70-648 · Question #18

Your company has a main office and a branch office. The branch office has an Active Directory site that contains a read-only domain controller (RODC). A user from the branch office reports that his…

The correct answer is D. Restore network communication between the branch office and the main office. We confirmed the account is not locked out, but the user believes it is. This means he is likely receiving a message indicating that a domain controller could not be contacted. How? Since the branch office has an RODC, it would let him log in if his password was cached. But…

Configuring Active Directory Infrastructure

Question

Your company has a main office and a branch office. The branch office has an Active Directory site that contains a read-only domain controller (RODC). A user from the branch office reports that his account is locked out. From a writable domain controller in the main office, you discover that the user's account is not locked out. You need to ensure that the user can log on to the domain. What should you do?

Options

  • AModify the Password Replication Policy.
  • BReset the password of the user account.
  • CRun the Knowledge Consistency Checker (KCC) on the RODC.
  • DRestore network communication between the branch office and the main office.

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    8% (2)
  • D
    85% (22)

Explanation

We confirmed the account is not locked out, but the user believes it is. This means he is likely receiving a message indicating that a domain controller could not be contacted. How? Since the branch office has an RODC, it would let him log in if his password was cached. But this is not happening, so his account must not be cached, and he is getting directed to a writeable DC. But if he's getting a message that it can't be contacted, then the network link between the 2 offices Microsoft 70-648 Exam The KCC configures replication between DC's and is a fairly automated process. (we would not normally run it manually). Anyhow, there is no sign that replication is not working as the user did not recently change his account. We are only aware that the user's account is reporting a wrong Password Replication Policy allows us to configure who can cache passwords on an RODC, but we're not given any indication that he has not been able to use the RODC previously. Resetting the password would not help, as he did not receive a message indicating that his password had expired.

Topics

#RODC#account lockout#password replication#branch office connectivity

Community Discussion

No community discussion yet for this question.

Full 70-648 Practice