1. Jean says that there are four internal auditors within the forest root domain. There are two inner auditors in each of the child domains. Every set of inside auditors has been positioned in a worldwide group inside each domain. These groups are named IA_Main, IA_East, and IA_West after their respective places. Jean desires all the members of these teams to have the ability to access the identical assets in every area. What is the really useful solution to configure this?
Create a universal group that each one particular person international groups can turn into a member of. It will permit every internal auditor to have access to resources granted to the common group. Choose a reputation for the group that represents all the company, akin to HumongousJA. MCSA
2. The community administrators from the East domain want to know why the option to
create a common group is not obtainable of their domain. What can you tell them?
Common teams are only accessible to domains which have a practical level of Home windows 2000 native or later. When using the mixed useful degree, you can not create universal groups. With a purpose to change the practical stage, all the current Windows NT 4 backup area controllers (BDCs) have to be removed or upgraded. Once the area practical stage is raised, the 2 Windows Server 2003 area controllers will now not replicate the area database to Windows NT 4 BDCs.
3. The network directors from the West domain wish to know why everyone
always recommends inserting international teams into universal teams, as an alternative of just
putting the users straight into the common groups. What should yoti inform them?
Common group membership modifications trigger forest-huge replication. In the event you use world groups within the universal groups as a substitute of users, it's much less likely that there can be membership adjustments to the universal groups. If instead you decided to position users in common teams, each time a consumer was added to, or deleted from, a common group, forest broad replication would happen. In most domains the person accounts are modified extra incessantly than the groups themselves. Once you are able to upgrade all of the area controllers in the forest, you'll increase the area purposeful degree to Home windows Server 2003, which would alleviate this situation and concern. MCSA Examination
4.Jean approves a plan to hire assistants for every area to create and handle person
accounts. How will you give the assistants the quick potential to assist on this means
without making them domain administrators?Place the assistants in the Account Operators group of the domains for which they're expected to be assistants.
5. Two staff have been employed to back up knowledge, keep the Windows Server
2003 domain controllers, and handle printers for the Main_Site. Which Builtin
groups will give these customers the permissions they require to manage the domain
controllers? How do you have to set up their accounts and group memberships?
These users will need permissions assigned to the Backup Operators, Account Operators, and Server Operators. It's best to create a worldwide group particularly for these customers. For instance, create the Maintenance_Main world group. Make that group a member of the Backup Opera?tors, Account Operators, and Server Operator domain native groups. Then place the consumer accounts for these new employees in that new international group.
6. Two security specialists have been contracted to create group policy for the
humongous.com area. They haven't any have to carry out most administrative
duties. How should you assign their group memberships?
Make them a member of the Group Coverage Creator Homeowners domain group.
Exam Objectives on this Chapter:
Plan a user authentication strategy
Delegate permissions of an organizational unit (OU) to a person or security group