nerdexam
Microsoft

AZ-800 · Question #219

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains the servers shown in the following table. On Server1, you create a DNS zone named Zone1.com as shown in…

The correct answer is A. Server2 only. Option A is correct because Zone1.com is configured as an Active Directory-integrated zone with a replication scope of "To all DNS servers in this domain" - and Server2 is the only other DNS server that resides in the same AD DS domain as Server1. AD-integrated zones replicate…

Deploy and manage Active Directory Domain Services

Question

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains the servers shown in the following table. On Server1, you create a DNS zone named Zone1.com as shown in the following exhibit. To which DNS servers is Zone1.com replicated?

Exhibits

AZ-800 question #219 exhibit 1
AZ-800 question #219 exhibit 2

Options

  • AServer2 only
  • BServer2 and Server3 only
  • CServer2 and Server4 only
  • DServer2, Server3, and Server4 only
  • EServer2, Server3, Server4, and Server5

How the community answered

(40 responses)
  • A
    73% (29)
  • B
    3% (1)
  • C
    5% (2)
  • D
    13% (5)
  • E
    8% (3)

Explanation

Option A is correct because Zone1.com is configured as an Active Directory-integrated zone with a replication scope of "To all DNS servers in this domain" - and Server2 is the only other DNS server that resides in the same AD DS domain as Server1. AD-integrated zones replicate through AD replication, not traditional zone transfers, so only servers participating in the correct AD partition receive the zone data.

Why the distractors are wrong:

  • B & D (Server3): Server3 is a DNS server in a different domain within the forest. The replication scope "this domain" excludes cross-domain servers unless the scope is set to "entire forest."
  • C & D (Server4): Server4 is a DNS server that is not Active Directory-integrated (e.g., a standalone or non-Windows DNS server), so it cannot receive AD replication data.
  • E (Server5): Server5 does not run the DNS Server role at all, so it is never a replication target regardless of scope.

Memory tip: Think of AD-integrated DNS replication scopes as narrowing rings - Forest (all AD DNS servers everywhere) → Domain (only your domain's AD DNS servers) → Custom partition (specific servers you designate). When the scope is "this domain," only same-domain AD DNS servers are in that ring.

Topics

#DNS zone replication#Active Directory DNS#Server roles#Standard DNS zones

Community Discussion

No community discussion yet for this question.

Full AZ-800 Practice