AZ-800 · Question #262
You have recently joined Carla company as an administrator. Your team lead is working on AD DS and asks you a few questions to check your existing knowledge. One question he asks is - what kind of…
The correct answer is C. A tree-root trust. When you create a new domain tree in an existing Active Directory forest, a tree-root trust is automatically established between the root domain of the new tree and the forest root domain. This trust is two-way and transitive, allowing all domains in the forest to trust each…
Question
You have recently joined Carla company as an administrator. Your team lead is working on AD DS and asks you a few questions to check your existing knowledge. One question he asks is – what kind of trust relationship is automatically created when you create a new AD DS tree in an existing AD DS forest? What would be your response?
Options
- AA Parent and Child trust
- BAn External trust
- CA tree-root trust
- DA Realm trust
- EA shortcut trust
How the community answered
(28 responses)- C89% (25)
- D7% (2)
- E4% (1)
Explanation
When you create a new domain tree in an existing Active Directory forest, a tree-root trust is automatically established between the root domain of the new tree and the forest root domain. This trust is two-way and transitive, allowing all domains in the forest to trust each other through the trust chain. A Parent-Child trust (option A) is created when adding a child domain within an existing tree (e.g., child.parent.com under parent.com). An External trust (option B) is a manually configured, non-transitive trust to a domain outside the forest. A Realm trust (option D) connects AD DS to a non-Windows Kerberos realm. A Shortcut trust (option E) is manually created to optimize authentication paths between domains in a large forest. Only the tree-root trust applies to the new-tree scenario.
Topics
Community Discussion
No community discussion yet for this question.