nerdexam
Microsoft

70-648 · Question #70

Your network contains two Active Directory forests named contoso.com and nwtraders.com. Active Directory Rights Management Services (AD RMS) is deployed in each forest. You need to ensure that users…

The correct answer is D. Add a trusted user domain to the AD RMS cluster in the contoso.com domain. It is not necessary to create trust or federation relationships between the Active Directory forests of organizations to be able to share rights-protected information (MY NOTE: This is why we don't need to create an external trust) between separate organizations. AD RMS…

enhanced security implementations

Question

Your network contains two Active Directory forests named contoso.com and nwtraders.com. Active Directory Rights Management Services (AD RMS) is deployed in each forest. You need to ensure that users from the nwtraders.com forest can access AD RMS protected content in the contoso.com forest. What should you do?

Options

  • ACreate an external trust from nwtraders.com to contoso.com.
  • BAdd a trusted user domain to the AD RMS cluster in the nwtraders.com domain.
  • CCreate an external trust from contoso.com to nwtraders.com.
  • DAdd a trusted user domain to the AD RMS cluster in the contoso.com domain.

How the community answered

(34 responses)
  • A
    12% (4)
  • B
    3% (1)
  • C
    3% (1)
  • D
    82% (28)

Explanation

It is not necessary to create trust or federation relationships between the Active Directory forests of organizations to be able to share rights-protected information (MY NOTE: This is why we don't need to create an external trust) between separate organizations. AD RMS provides two types of trust relationships that provide this kind of rights-protected information exchange. A trusted user domain (TUD) allows the AD RMS root cluster to process requests for client licensor certificates or use licenses from users whose rights account certificates (RACs) were issued by a different AD RMS root cluster. You add a trusted user domain by importing the server licensor certificate of the AD RMS cluster to trust. (MY NOTE:We add a TUD to the contoso.com cluster because it is hosting the content - it needs to be able totrust users for nwtraders.com)

Topics

#AD RMS#trusted user domain#cross-forest content access#inter-forest RMS

Community Discussion

No community discussion yet for this question.

Full 70-648 Practice