exam questions

Exam 70-740 All Questions

View all questions & answers for the 70-740 exam

Exam 70-740 topic 1 question 81 discussion

Actual exam question from Microsoft's 70-740
Question #: 81
Topic #: 1
[All 70-740 Questions]

HOTSPOT -
Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named Server1 and a member server named
Server2.
Server1 has the DNS Server role installed. Server2 has IP Address Management IPAM installed
The IPAM server retrieves zones from Server1 as shown in the following table:

The IPAM Server has one access policy configured as shown in the exhibit.

For each of the following statements, select Yes, if the statement is true. Otherwise, select No.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
IPAM DNS Administrator role with a Global access scope means the user can do anything on any DNS server managed by IPAM.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Ledance
Highly Voted 5 years, 5 months ago
70-742
upvoted 6 times
...
KING_C
Highly Voted 4 years, 11 months ago
Box 1: Yes - As a member of the IPAM DNS Administrator Role of the ADatum zone, User1 can add DNS records to it. Box 2: Yes - As a member of the DNS Record Administrator Role of the Fabrikam zone, User1 can add DNS records to it. Box 3: No - DNS Record Administrators cannot delete zones, only administer DNS records. References: https://technet.microsoft.com/en-us/library/hh831353(v=ws.11).aspx
upvoted 6 times
...
simocb
Most Recent 4 years, 4 months ago
I Agree with YES-YES-NO
upvoted 1 times
...
SalmanAhmed
4 years, 4 months ago
User1 can perform all the 3 tasks, as user1 is granting the role IPAM DNS Administrator Role on the Global scope.
upvoted 1 times
...
Tenshi
4 years, 8 months ago
Y - Y - Y IPAM DNS Administrator role with a Global access scope means the user can do anything on any DNS server managed by IPAM. Fabrikam zone is \global\scope1. The user is DNS Record Administrator on \global\scope2... But this is 741 question.
upvoted 1 times
alexnt
4 years, 7 months ago
This means that he cannot delete the fabrikam.com zone (I'm talking for the 741 question) Y-Y-N ???
upvoted 1 times
...
...
alexnt
4 years, 9 months ago
I have a question: In 70-741 there is the same question with only difference that on the table "Fabrikam.com" Zone has access scope "Global\Scope2". What is the answer in this situation?
upvoted 1 times
alexnt
4 years, 9 months ago
This is what I mean https://www.examtopics.com/exams/microsoft/70-743/view/10/
upvoted 1 times
...
...
LeonSKennedy
4 years, 10 months ago
YES YES NO *** Since Server 2016, the DNS can be managed through IPAM. And the DNS Administrator role does have permission to create DNS records. *** Box 1: Yes As a member of the IPAM DNS Administrator Role of the ADatum zone, User1 can add DNS records to it. Box 2: Yes As a member of the DNS Record Administrator Role of the Fabrikam zone, User1 can add DNS records to it. Box 3: No DNS Record Administrators cannot delete zones, only administer DNS records Source: https://docs.microsoft.com/en-us/windows-server/networking/technologies/ipam/view-roles-and-role-permissions
upvoted 2 times
...
Voldemort
4 years, 10 months ago
70-742 question.
upvoted 1 times
...
TooManyExams
5 years, 3 months ago
Tested this on a single zone Moved zone to Global\Test access scope Made user DNS administrator at global Made user DNS record administrator at global\test Logged on as that user and deleted the zone. So Permissions do not appear to be most restrictive, but cumulative. Whether or not the zone is configured for dynamic updates is irrelevant - as we have not got dynamic updates coming from a computer.
upvoted 1 times
darfinx
5 years, 2 months ago
So which options true? Yes,yes,no?
upvoted 1 times
khalid86
5 years, 1 month ago
Yes, Yes, Yes
upvoted 1 times
...
...
...
glukken
5 years, 4 months ago
The user1 is IPAM DNS Administrator on the Global level, so he/she can do anything...
upvoted 5 times
...
davidtld
5 years, 4 months ago
User 1 has Admin permissions for ADATUM zone (secured but user1 is DNS ADMIN). You don't need permission for Fabrikam Zone (none)
upvoted 1 times
...
Person
5 years, 7 months ago
I think the third option is No. User1 have "DNS Record Administrator" on Scope2 (zone Fabrikam.com). Although User1 has IPAM DNS Administer Role, the most restrictive permission is applied. The permission "DNS Record Administrator" can't permit delete zone. So, for me The correct answer is Yes, Yes, No.
upvoted 4 times
Frits
5 years, 6 months ago
In the example User1 is "DNS Record Administrator" on Scope1, not 2. So my guess is that he cant even add a record on that zone.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago