nerdexam
Microsoft

AZ-800 · Question #315

Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains the users shown in following table. You have a workgroup server named Server1 that…

When a workgroup server is promoted to the first domain controller in a child domain, its local SAM database is replaced by Active Directory, permanently removing all pre-existing local user accounts.

Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments

Question

Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains the users shown in following table. You have a workgroup server named Server1 that runs Windows Server and contains the local users shown in the following table. You promote Server1 to the first domain controller in a new child domain named east.contoso.com. Which users can sign in to Server1 locally?

Exhibit

AZ-800 question #315 exhibit

Options

  • AUser1 only
  • BUser3 only
  • CUser1 and User2 only
  • DUser1 and User3 only
  • EUser3 and User4 only
  • FUser1, User2, User3 and User4

Why each option

When a workgroup server is promoted to the first domain controller in a child domain, its local SAM database is replaced by Active Directory, permanently removing all pre-existing local user accounts.

AUser1 only

User1 only is unlikely correct unless User1 is the only user with a valid domain account in the new or parent domain, since promotion removes local accounts and only domain-authenticated users can sign in to a DC.

BUser3 only

User3 only is incorrect if User3 was a local workgroup account on Server1, because all local SAM accounts are deleted during DC promotion when AD replaces the local SAM.

CUser1 and User2 only

User1 and User2 only would be incorrect if either user was a local workgroup account rather than a domain account, since local accounts do not survive the promotion process.

DUser1 and User3 only

User1 and User3 only is incorrect if User3 was a local account on the workgroup server, as it would have been removed when the SAM was replaced by Active Directory during promotion.

EUser3 and User4 only

User3 and User4 only is incorrect if User3 and User4 were local accounts on the workgroup server, because those accounts are deleted when the server is promoted to a domain controller.

FUser1, User2, User3 and User4

All four users cannot all sign in if any of them were local workgroup accounts that no longer exist after the SAM was replaced by Active Directory during DC promotion.

Concept tested: Effect of DC promotion on local SAM user accounts

Source: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/install-active-directory-domain-services--level-100-

Topics

#Active Directory Domain Services#Domain Controller promotion#Local vs. Domain accounts#User logon

Community Discussion

No community discussion yet for this question.

Full AZ-800 Practice