AZ-800 · Question #11
Case Study 2 - Contoso, Ltd Overview Contoso, Ltd. is a company that has a main office in Seattle and two branch offices in Los Angeles and Montreal. Existing Environment AD DS Environment The…
The correct answer is D. Create a delegation on OU3. Creating a delegation on OU3 (D) is the correct and most precise solution. Active Directory delegation allows you to grant a user or group specific administrative permissions (such as 'Create, delete, and manage user accounts') scoped only to a particular OU - in this case OU3…
Question
Case Study 2 - Contoso, Ltd Overview Contoso, Ltd. is a company that has a main office in Seattle and two branch offices in Los Angeles and Montreal. Existing Environment AD DS Environment The network contains an on premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com. The forest contains the domain controllers shown in the following table. All the domain controllers are global catalog servers. Server infrastructure The network contains the servers shown in the following table. A server named Server4 runs Windows Server and is in a workgroup. Windows Firewall on Server4 uses the private profile. Server2 hosts three virtual machines named VM1, VM2, and VM3. VM3 is a file server that stores data in the volumes shown in the following table. Group Policies The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table. Existing Identities The forest contains the users shown in the following table. The forest contains the groups shown in the following table. Current Problems When an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out, another administrator can connect to the console session as the currently signed in user. Requirements Technical Requirements Contoso identifies the following technical requirements:
Change the replication schedule for all site links to 30 minutes. Promote Server1 to a domain controller in canada.contoso.com. Install and authorize Server3 as a DHCP server. Ensure that User1 can manage the membership of all the groups in Contoso\OU3. Ensure that you can manage Server4 from Server1 by using PowerShell remoting. Ensure that you can run virtual machines on VM1. Force users to provide credentials when they connect to VM2. On VM3, ensure that Data Deduplication on all volumes is possible. Question You need to meet the technical requirements for User1. The solution must use the principle of least privilege. What should you do?
Exhibits
Options
- AAdd Users1 to the Server Operators group in contoso.com.
- BCreate a delegation on contoso.com.
- CAdd Users1 to the Account Operators group in contoso.com.
- DCreate a delegation on OU3.
How the community answered
(42 responses)- A10% (4)
- B2% (1)
- C5% (2)
- D83% (35)
Explanation
Creating a delegation on OU3 (D) is the correct and most precise solution. Active Directory delegation allows you to grant a user or group specific administrative permissions (such as 'Create, delete, and manage user accounts') scoped only to a particular OU - in this case OU3. This follows the principle of least privilege. Adding Users1 to the Server Operators group (A) grants broad server administration rights across the entire domain. Adding to Account Operators (C) grants the ability to manage accounts and groups domain-wide, which is far too permissive. Creating a delegation on contoso.com (B) would grant rights across the entire domain, not just OU3.
Topics
Community Discussion
No community discussion yet for this question.





