exam questions

Exam 70-742 All Questions

View all questions & answers for the 70-742 exam

Exam 70-742 topic 1 question 80 discussion

Actual exam question from Microsoft's 70-742
Question #: 80
Topic #: 1
[All 70-742 Questions]

Your network contains an Active Directory forest named contoso.com.
A partner company has a forest named fabrikam.com. Each forest contains one domain.
You need to provide access for a group named Research in fabrikam.com to resources in contoso.com. The solution must use the principle of least privilege.
What should you do?

  • A. Create an external trust from fabrikam.com to contoso.com. Enable Active Directory split permissions in fabrikam.com.
  • B. Create an external trust from contoso.com to fabrikam.com. Enable Active Directory split permissions in contoso.com.
  • C. Create a one-way forest trust from contoso.com to fabrikam.com that uses selective authentication.
  • D. Create a one-way forest trust from fabrikam.com to contoso.com that uses selective authentication.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
paprda
Highly Voted 5 years, 10 months ago
We have resources in contoso.com and a group in fabrikam.com. The domain/forest that holds the resources needs to trust the domain that holds the users/groups. The TRUSTING forest creates the trust towards the TRUSTED forest. So in this case, contoso needs to trust fabrikam. We create a trust from contoso to fabrikam, stating that specific users (selective authentication) in fabrikam are trusted to resources in contoso. You then use ACL’s in contoso to determine which resources those are.
upvoted 25 times
...
Strolokey
Highly Voted 4 years, 10 months ago
More like an english test...
upvoted 11 times
Yebubbleman
4 years, 5 months ago
I was seriously thinking the exact same thing.
upvoted 1 times
...
...
lofzee
Most Recent 4 years, 5 months ago
we need to trust them to access resources in our domain. C
upvoted 2 times
...
jam7272
4 years, 8 months ago
Contoso has to TRUST Fabrikam. Trust is outgoing... 'we trust them'
upvoted 2 times
...
Davar39
4 years, 8 months ago
Resource holding domain/forest = Trusting Users/Group holding domain/forest = Trusted Since the solution must use the principle of least privilege We only need to create a one way trust from Trusting(contoso.com) to Trusted(fabrikam.com).
upvoted 1 times
...
Kamikazekiller
4 years, 11 months ago
Answer is: C. Create a one-way forest trust from contoso.com to fabrikam.com that uses selective authentication.
upvoted 2 times
...
coleman
5 years, 6 months ago
the answer is correct https://technet.microsoft.com/en-us/library/cc794713.apsx When you create a new trust in an existing forest in Active Directory Domain Services (AD DS), all communications over that trust are tightly secured. The default security configuration of Selective Authentication mode of a forest trust is to prevent all users of fabrikam.com to access any resources in contoso.com, this adheres the Principal of least privilege. I.T. administrators of contoso,com must later implement a few "allow" permissions for the Research group in the fabrikam.com forest to access part of the resources in contoso.com.
upvoted 6 times
...
panda
5 years, 8 months ago
For more detail, to create this trust relationship the settings are needed in both the trust domain and the trusted domin. In the trust domin "One-way:outgoing" should be set and int the trusted domin "One-way:incoming" should be set.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...