nerdexam
Microsoft

70-648 · Question #67

Your network contains two Active Directory forests named contoso.com and adatum.com. Active Directory Rights Management Services (AD RMS) is deployed in contoso.com. An AD RMS trusted user domain…

The correct answer is A. Configure trusted e-mail domains. For each trusted user domain, you must specify which e-mail domains are trusted. It is an important security step to configure e-mail domains, otherwise it may be possible for a user from a trusted user domain to impersonate an internal user. A forest trust would have been…

enhanced security implementations

Question

Your network contains two Active Directory forests named contoso.com and adatum.com. Active Directory Rights Management Services (AD RMS) is deployed in contoso.com. An AD RMS trusted user domain (TUD) exists between contoso.com and adatum.com. From the AD RMS logs, you discover that some clients that have IP addresses in the adatum.com forest are authenticating as users from contoso.com. You need to prevent users from impersonating contoso.com users. What should you do?

Options

  • AConfigure trusted e-mail domains.
  • BEnable lockbox exclusion in AD RMS.
  • CCreate a forest trust between adatum.com and contoso.com.
  • DAdd a certificate from a third-party trusted certification authority (CA).

How the community answered

(21 responses)
  • A
    86% (18)
  • B
    5% (1)
  • D
    10% (2)

Explanation

For each trusted user domain, you must specify which e-mail domains are trusted. It is an important security step to configure e-mail domains, otherwise it may be possible for a user from a trusted user domain to impersonate an internal user. A forest trust would have been needed to setup the RMS environment in the first place. If you have enabled exclusion based on lockbox version, clients that are using a version of the lockbox software that is earlier than the specified version cannot acquire rights account certificates or use licenses because their requests will be denied. Microsoft 70-648 Exam

Topics

#AD RMS#trusted user domain#trusted email domains#identity impersonation prevention

Community Discussion

No community discussion yet for this question.

Full 70-648 Practice