nerdexam
Microsoft

70-648 · Question #58

As the Company administrator you had installed a read-only domain controller (RODC) server at remote location. The remote location doesn't provide enough physical security for the server. What…

The correct answer is B. Add administrative accounts to the domain Allowed RODC Password Replication group. The Allowed RODC Password Replication group in AD contains the accounts of users whose passwords are allowed to replicate with AD.

Configuring Active Directory Infrastructure

Question

As the Company administrator you had installed a read-only domain controller (RODC) server at remote location. The remote location doesn't provide enough physical security for the server. What should you do to allow administrative accounts to replicate authentication information to Read-Only Domain Controllers?

Options

  • ARemove any administrative accounts from RODC's group
  • BAdd administrative accounts to the domain Allowed RODC Password Replication group
  • CSet the Deny on Receive as permission for administrative accounts on the RODC computer account
  • DConfigure a new Group Policy Object (GPO) with the Account Lockout settings enabled. Link the GPO
  • ENone of the above

How the community answered

(38 responses)
  • A
    11% (4)
  • B
    82% (31)
  • C
    3% (1)
  • E
    5% (2)

Explanation

The Allowed RODC Password Replication group in AD contains the accounts of users whose passwords are allowed to replicate with AD.

Topics

#RODC#Allowed RODC Password Replication Group#branch office security#password replication policy

Community Discussion

No community discussion yet for this question.

Full 70-648 Practice