AZ-802 Exam Question 121

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains the domain controllers shown in the following exhibit, including a read-only domain controller named RODC1.
You need to ensure that if an attacker compromises the computer account of RODC1, the attacker cannot view the Employee-Number AD DS attribute. Which partition should you modify?
  • AZ-802 Exam Question 122

    Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains five servers that run Windows Server. The network also contains two workgroup servers that run Windows Server. You need to implement a connection security rule between the member servers and the workgroup servers. Which authentication method should you use?
  • AZ-802 Exam Question 123

    Your network contains an on-premises Active Directory Domain Services (AD DS) domain.
    The domain contains the servers shown in the following table.
    Server1 has the connection security rule as shown in the Server1 exhibit. (Click the Server1 tab.) Server2 has the connection security rule as shown in the Server2 exhibit. (Click the Server2 tab.) Server1 has the inbound firewall rules as shown in the Server1 inbound rules exhibit. (Click the Server1 inbound rules tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No.

    Exhibit

    Exhibit

    Exhibit

    Exhibit

    Exhibit

    AZ-802 Exam Question 124

    You have 10 servers that run Windows Server in a workgroup. You need to configure the servers to encrypt all the network traffic between the servers. The solution must be as secure as possible. Which authentication method should you configure in a connection security rule?
  • AZ-802 Exam Question 125

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. You need to identify which server is the PDC emulator for the domain. Solution: From a command prompt, you run netdom.exe query fsmo. Does this meet the goal?