Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft Exam AZ-801 Topic 14 Question 48 Discussion

Actual exam question for Microsoft's AZ-801 exam
Question #: 48
Topic #: 14
[All AZ-801 Questions]

Your network contains an Active Directory Domain Services (AD DS) forest. The forest functional level is Windows Server 2012 R2. The forest contains the domains shown in the following table.

You create a user named Admin1.

You need to ensure that Admin1 can add a new domain controller that runs Windows Server 2022 to the east.contoso.com domain. The solution must follow the principle of least privilege.

To which groups should you add Admin1?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

Denny
6 months ago
I agree with Robt, it makes sense to give Admin1 broader permissions in this scenario to ensure the task can be completed successfully.
upvoted 0 times
...
Robt
7 months ago
I disagree, I believe the answer is D) CONTOSO\Enterprise Admins and CONTOSO/Schema Admins. Admin1 might need higher-level permissions to add a new domain controller.
upvoted 0 times
...
Elden
7 months ago
I think the answer is A) EAST\Domain Admins only. Admin1 only needs permissions in the east.contoso.com domain.
upvoted 0 times
...
Verona
8 months ago
Haha, I can just picture Admin1 trying to add a new domain controller and accidentally deleting the entire forest. Better stick to the least privilege approach, eh?
upvoted 0 times
...
Otis
8 months ago
You know, I was initially leaning towards D, but after thinking it through, I think C is the better option. The Enterprise Admins group might be a bit overkill for this specific task.
upvoted 0 times
...
Kerry
8 months ago
I agree, C seems like the most logical answer. Adding Admin1 to both the Schema Admins and the Domain Admins of the east.contoso.com domain would give them the necessary permissions to carry out the task, while still following the principle of least privilege.
upvoted 0 times
...
Rusty
8 months ago
Hmm, this question is interesting. It's testing our understanding of domain controller deployment and the principle of least privilege. I'm thinking the answer might be C, since the Schema Admins group would be required to add a new domain controller running a newer version of Windows Server, and the Domain Admins would be needed to add it to the east.contoso.com domain.
upvoted 0 times
Yen
8 months ago
Hmm, this question is interesting. It's testing our understanding of domain controller deployment and the principle of least privilege. I'm thinking the answer might be C, since the Schema Admins group would be required to add a new domain controller running a newer version of Windows Server, and the Domain Admins would be needed to add it to the east.contoso.com domain.
upvoted 0 times
...
Jose
8 months ago
C) CONTOSO/Schema Admins and EAST\Domain Admins
upvoted 0 times
...
Queen
8 months ago
A) EAST\Domain Admins only
upvoted 0 times
...
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77