nerdexam
Microsoft

AZ-800 · Question #76

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is B. No. The proposed solution does not meet the requirement to ensure client computers in a new branch office with no domain controllers can reliably locate and authenticate with domain controllers.

Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK. You open a new branch office that contains only client computers. You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1. Solution: You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to Site1. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(49 responses)
  • A
    24% (12)
  • B
    76% (37)

Why each option

The proposed solution does not meet the requirement to ensure client computers in a new branch office with no domain controllers can reliably locate and authenticate with domain controllers.

AYes

The proposed solution is incomplete and does not satisfy the full configuration required for branch office client computers to correctly authenticate against the AD DS forest.

BNoCorrect

Simply modifying DEFAULTIPSITELINK is insufficient because creating a branch office site in AD DS also requires creating a new Site object in Active Directory Sites and Services, associating the branch subnet with that site, and linking it properly so clients use the correct site-aware DC locator process; without these steps, branch clients cannot reliably find the nearest domain controller.

Concept tested: AD DS site and site link configuration for branch offices

Source: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/creating-a-site-design

Topics

#Active Directory Sites#Group Policy Objects (GPO)#DC Locator#Client Authentication

Community Discussion

No community discussion yet for this question.

Full AZ-800 Practice