AZ-800 · Question #233
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains the servers shown in the following table. You need to deploy inbound firewall rules to the servers. The…
The correct answer is C. Group Policy Objects (GPOs). Group Policy Objects (GPOs) are the standard, built-in mechanism for centrally deploying Windows Defender Firewall rules to multiple domain-joined servers simultaneously, requiring no additional infrastructure. A single GPO linked to the appropriate OU can target all servers at…
Question
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains the servers shown in the following table. You need to deploy inbound firewall rules to the servers. The solution must minimize administrative effort. What should you use?
Exhibit
Options
- APowerShell Desired State Configuration (DSC)
- Blocal security objects
- CGroup Policy Objects (GPOs)
- DMicrosoft Intune configuration profiles
How the community answered
(28 responses)- A4% (1)
- B4% (1)
- C86% (24)
- D7% (2)
Explanation
Group Policy Objects (GPOs) are the standard, built-in mechanism for centrally deploying Windows Defender Firewall rules to multiple domain-joined servers simultaneously, requiring no additional infrastructure. A single GPO linked to the appropriate OU can target all servers at once, minimizing administrative effort. PowerShell DSC can deploy firewall rules but requires authoring configuration scripts, a pull server or push mechanism, and ongoing maintenance - more overhead. Local security objects require configuring each server individually, which is the opposite of minimizing effort. Microsoft Intune requires devices to be enrolled (typically Azure AD joined), which adds onboarding overhead for on-premises servers.
Topics
Community Discussion
No community discussion yet for this question.
