nerdexam
Microsoft

70-648 · Question #63

Your network contains an Active Directory domain named contoso.com. The network has a branch office site that contains a read-only domain controller (RODC) named RODC1. RODC1 runs Windows Server…

The correct answer is C. Add the user's user account to the built-in Allowed RODC Password Replication Group on RODC1. To facilitate the management of PRP, Windows Server 2008 R2 creates two domain local security groups in the Users container of Active Directory. The first group, Allowed RODC Password Replication Group, is added to the Allowed List of each new RODC. By default, the group has no…

Configuring Active Directory Infrastructure

Question

Your network contains an Active Directory domain named contoso.com. The network has a branch office site that contains a read-only domain controller (RODC) named RODC1. RODC1 runs Windows Server 2008 R2. A user logs on to a computer in the branch office site. You discover that the user's password is not stored on RODC1. You need to ensure that the user's password is stored on RODC1 when he logs on to a branch office site computer. What should you do?

Options

  • AModify the RODC's password replication policy by removing the entry for the Allowed RODC Password
  • BModify the RODC's password replication policy by adding RODC1's computer account to the list of allowed
  • CAdd the user's user account to the built-in Allowed RODC Password Replication Group on RODC1.
  • DAdd RODC1's computer account to the built-in Allowed RODC Password Replication Group on RODC1.

How the community answered

(57 responses)
  • A
    18% (10)
  • B
    7% (4)
  • C
    70% (40)
  • D
    5% (3)

Explanation

To facilitate the management of PRP, Windows Server 2008 R2 creates two domain local security groups in the Users container of Active Directory. The first group, Allowed RODC Password Replication Group, is added to the Allowed List of each new RODC. By default, the group has no members. Therefore, by default, a new RODC will not cache any user's credentials. If you have users whose credentials you want to be cached by all domain RODCs, add those users to the Allowed RODC Password Replication Group. Reference: MS Press - Self-Paced Training Kit (Exam 70-640) (2nd Edition, July 2012) pages 416-417

Topics

#RODC#password replication policy#Allowed RODC Password Replication Group#branch office authentication

Community Discussion

No community discussion yet for this question.

Full 70-648 Practice