70-648 · Question #67
Your network contains two Active Directory forests named contoso.com and adatum.com. Active Directory Rights Management Services (AD RMS) is deployed in contoso.com. An AD RMS trusted user domain…
The correct answer is A. Configure trusted e-mail domains. For each trusted user domain, you must specify which e-mail domains are trusted. It is an important security step to configure e-mail domains, otherwise it may be possible for a user from a trusted user domain to impersonate an internal user. A forest trust would have been…
Question
Your network contains two Active Directory forests named contoso.com and adatum.com. Active Directory Rights Management Services (AD RMS) is deployed in contoso.com. An AD RMS trusted user domain (TUD) exists between contoso.com and adatum.com. From the AD RMS logs, you discover that some clients that have IP addresses in the adatum.com forest are authenticating as users from contoso.com. You need to prevent users from impersonating contoso.com users. What should you do?
Options
- AConfigure trusted e-mail domains.
- BEnable lockbox exclusion in AD RMS.
- CCreate a forest trust between adatum.com and contoso.com.
- DAdd a certificate from a third-party trusted certification authority (CA).
How the community answered
(21 responses)- A86% (18)
- B5% (1)
- D10% (2)
Explanation
For each trusted user domain, you must specify which e-mail domains are trusted. It is an important security step to configure e-mail domains, otherwise it may be possible for a user from a trusted user domain to impersonate an internal user. A forest trust would have been needed to setup the RMS environment in the first place. If you have enabled exclusion based on lockbox version, clients that are using a version of the lockbox software that is earlier than the specified version cannot acquire rights account certificates or use licenses because their requests will be denied. Microsoft 70-648 Exam
Topics
Community Discussion
No community discussion yet for this question.