70-663 · Question #191
A company named Contoso Ltd. has three offices. Each office is configured as an Active Directory site and contains multiple Exchange servers. Each office has a team of network support technicians…
The correct answer is A. Three custom scopes and three management role groups D. Three custom scopes, three management roles, and three Active Directory security groups. 1- The scope should be different as each support team will be managing their exchange server at 2- management role is determining what kind of permission "roles" to manage Exchange. 3- To apply scope there must be a security group. To get a basic understanding of how this is…
Question
A company named Contoso Ltd. has three offices. Each office is configured as an Active Directory site and contains multiple Exchange servers. Each office has a team of network support technicians. You are designing an Exchange organization for Contoso. All servers in the organization will have Exchange Server 2010 Service Pack 1 (SP1) installed. You need to implement a security solution to ensure that the team of network support technicians can manage the Exchange servers in its respective office only. Which of the following solutions is the best recommendation? (More than one answer choice may achieve the goal. Select the BEST answer.)
Options
- AThree custom scopes and three management role groups
- BOne management role and three Active Directory security groups
- COne custom scope and one management role group
- DThree custom scopes, three management roles, and three Active Directory security groups
How the community answered
(25 responses)- A84% (21)
- B4% (1)
- C12% (3)
Explanation
1- The scope should be different as each support team will be managing their exchange server at 2- management role is determining what kind of permission "roles" to manage Exchange. 3- To apply scope there must be a security group. To get a basic understanding of how this is going to work, a quick description of the RBAC components used in the upcoming example will be helpful: Management Role-this is just a container for a group of Exchange Management Shell cmdlets. For example, the Mail Recipient Creation role contains only the cmdlets required to view, create and delete recipients. Management Role Entry - this is an Exchange Management Shell cmdlet or custom script. Management roles are made up of management role entries. Management Role Group-this is an Active Directory universal security group that contains the user accounts that can be assigned to a role. Management Role Scope-this can be used to filter the type of objects that can be managed, and where they can be managed in Active Directory. Management Role Assignment-this links a management scope to a management role.
Topics
Community Discussion
No community discussion yet for this question.