nerdexam
Microsoft

70-648 · Question #69

Your network contains a single Active Directory domain. Active Directory Rights Management Services (AD RMS) is deployed on the network. A user named User1 is a member of only the AD RMS Enterprise…

The correct answer is C. Domain Admins. To register the SCP you must be a member of the local AD RMS Enterprise Administrators group and the Active Directory Domain Services (AD DS) Enterprise Admins group, or you must have Microsoft 70-648 Exam been given the appropriate authority. connectionpoint.aspx MY NOTE…

enhanced security implementations

Question

Your network contains a single Active Directory domain. Active Directory Rights Management Services (AD RMS) is deployed on the network. A user named User1 is a member of only the AD RMS Enterprise Administrators group. You need to ensure that User1 can change the service connection point (SCP) for the AD RMS installation. The solution must minimize the administrative rights of User1. To which group should you add User1?

Options

  • AAD RMS Auditors
  • BAD RMS Service Group
  • CDomain Admins
  • DSchema Admins

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    6% (2)
  • C
    77% (27)
  • D
    11% (4)

Explanation

To register the SCP you must be a member of the local AD RMS Enterprise Administrators group and the Active Directory Domain Services (AD DS) Enterprise Admins group, or you must have Microsoft 70-648 Exam been given the appropriate authority. connectionpoint.aspx MY NOTE: Based on this article, I would think this should be Enterprise Admins, but that's not achoice. So we have to use elimination. Per the article below, neither of the "AD RMS" groupsprovide the feature we need, and Schema Admins is only needed for updating the schema (whichwould be done when RMS is first deployed). That leaves is with the Domain Admins group. AD RMS Auditors Members of this group can only access the reports feature in the AD RMS console. (...) There is also the AD RMS Service Group. Members of this group act as the AD RMS service account. During the installation of AD RMS, the user account designated as the service account is automatically added to this group.

Topics

#AD RMS#service connection point#Domain Admins#least privilege administration

Community Discussion

No community discussion yet for this question.

Full 70-648 Practice