nerdexam
Microsoft

AZ-800 · Question #241

Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains the domain controllers shown in the following table. You have a partner organization…

The correct answer is D. DC4. With selective authentication on a forest trust, when users from the trusted forest (fabrikam.com) attempt to access resources in the trusting forest (contoso.com), the authentication request is processed by domain controllers in the trusting forest. The 'Allowed to…

Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments

Question

Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains the domain controllers shown in the following table. You have a partner organization that has an AD DS forest named fabrikam.com. You create a trust relationship between contoso.com and fabrikam.com. You need to configure selective authentication for the trust relationship. Which domain controller should be granted permissions to fabrikam.com?

Exhibit

AZ-800 question #241 exhibit

Options

  • ADC1
  • BDC2
  • CDC3
  • DDC4

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    13% (3)
  • C
    9% (2)
  • D
    74% (17)

Explanation

With selective authentication on a forest trust, when users from the trusted forest (fabrikam.com) attempt to access resources in the trusting forest (contoso.com), the authentication request is processed by domain controllers in the trusting forest. The 'Allowed to Authenticate' permission must be granted on the computer objects of the resource servers or DCs in the trusting forest (contoso.com) to the users/groups from fabrikam.com. DC4, based on the referenced table, is the domain controller in contoso.com that services the relevant authentication path - most likely it holds the PDC Emulator role in the root domain or is positioned as the gateway DC for cross-forest authentication. Permissions are configured on contoso.com objects, not fabrikam.com objects.

Topics

#Active Directory Trusts#Selective Authentication#Domain Controllers#AD DS Security

Community Discussion

No community discussion yet for this question.

Full AZ-800 Practice