nerdexam
MicrosoftMicrosoft

SC-100 · Question #297

SC-100 Question #297: Real Exam Question with Answer & Explanation

The correct answer is C: the User Rights Assignment security policy settings. To restrict the built-in domain administrator account to interactive sign-ins on domain controllers, you should configure a Group Policy Object (GPO) that modifies the "Deny access to this computer from the network" and "Deny log on through Remote Desktop Services" rights for the

Design security operations, identity, and compliance capabilities

Question

Your network contains an Active Directory Domain Services (AD DS) domain. You need to ensure that the built-in administrator account for the domain can be used only for interactive sign-ins to domain controllers. What should you configure?

Options

  • Athe Protected Users group
  • Bauthentication policies
  • Cthe User Rights Assignment security policy settings
  • Dan authentication policy silo

Explanation

To restrict the built-in domain administrator account to interactive sign-ins on domain controllers, you should configure a Group Policy Object (GPO) that modifies the "Deny access to this computer from the network" and "Deny log on through Remote Desktop Services" rights for the domain administrator account.

Topics

#Active Directory Security#User Rights Assignment#Logon Restrictions#Administrative Account Security

Community Discussion

No community discussion yet for this question.

Full SC-100 PracticeBrowse All SC-100 Questions