QuestionQ16

Deploy and manage AD DS

Your network includes an Active Directory Domain Services (AD DS) forest.

The forest has a parent domain named contoso.com and a child domain named corp.contoso.com. Both domains have domain controllers with the DNS Server role installed. Some domain controllers in contoso.com do not have the DNS Server role installed.

The DNS zone for contoso.com is Active Directory-integrated, uses secure dynamic updates, and replicates to all DNS servers in the forest.

You need to change the zone to meet these requirements:

  • Prevent the DNS servers in corp.contoso.com from receiving contoso.com zone data.
  • Minimize Active Directory replication traffic.

What should you do?

Explanation

An Active Directory-integrated DNS zone can replicate to DNS servers on domain controllers within a single AD DS domain. Selecting the contoso.com-domain DNS-server scope prevents DNS servers in corp.contoso.com from receiving the zone and avoids replicating zone data to contoso.com domain controllers that do not host DNS, minimizing Active Directory replication traffic.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!