Microsoft
AZ-801 · Question #63
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the organizational units (OUs) shown in the following table. [Table: Name, Contents: Dom
Sign in or unlock AZ-801 to reveal the answer and full explanation for question #63. The question stem and answer options stay visible for context.
Secure Windows Server on-premises and hybrid infrastructures
Question
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the organizational units (OUs) shown in the following table. [Table: Name, Contents: Domain Controllers, All the domain controllers in the domain; Domain Servers, All the servers that run Windows Server in the domain; Domain Client Computers, All the client computers that run Windows 10 in the domain; Domain Users, All the users in the domain] In the domain, you create the Group Policy Objects (GPOs) shown in the following table. [Table: Name, IPsec setting: GPO1, Require authentication by using Kerberos V5 for inbound connections; GPO2, Request authentication by using Kerberos V5 for inbound connections; GPO3, Require authentication by using X.509 certificates for inbound connections; GPO4, Request authentication by using X.509 certificates for inbound connections] You need to implement IPsec authentication to ensure that only authenticated computer accounts can connect to the members in the domain. The solution must minimize administrative effort. Which GPOs should you apply to the Domain Controllers OU and the Domain Servers OU? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Unlock AZ-801 to see the answer
You've previewed enough free AZ-801 questions. Unlock AZ-801 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Group Policy#IPsec#Kerberos#Active Directory Security