QuestionQ64

Implementación y administración de Active Directory Domain Services (AD DS) en entornos locales y en la nube

Your network contains three Active Directory Domain Services (AD DS) forests, as shown in the following exhibit.

Question Image

The network includes the users shown in the following table.

Question Image

The network includes the security groups shown in the following table.

Question Image

For each statement, select Yes if it is true. Otherwise, select No.

Yes or No
StatementsYesNo
You can add User1 to Group1.
You can add User2 to Group3.
You can grant Group2 permissions to the resources in the fabrikam.com domain.
Explanation

A domain local group can contain an account from a trusted forest, so User1 from contoso.com can join Group1 in adatum.com. A universal group can contain accounts only from domains in its own forest, so User2 from fabrikam.com cannot join Group3 in contoso.com. Forest trusts create trust between the two forests involved, but they do not implicitly extend to a third forest; contoso.com therefore has no trust relationship with fabrikam.com for assigning Group2 access there.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!