exam questions

Exam AZ-800 All Questions

View all questions & answers for the AZ-800 exam

Exam AZ-800 topic 7 question 3 discussion

Actual exam question from Microsoft's AZ-800
Question #: 3
Topic #: 7
[All AZ-800 Questions]

You need to meet the technical requirements for User1. The solution must use the principle of least privilege.
What should you do?

  • A. Add Users1 to the Server Operators group in contoso.com.
  • B. Create a delegation on contoso.com.
  • C. Add Users1 to the Account Operators group in contoso.com.
  • D. Create a delegation on OU3.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
prepper666
Highly Voted 1 year, 5 months ago
D is correct
upvoted 8 times
GoforIT21
1 year, 4 months ago
Yeah, doing anything with a scope of contoso.com will violate the principle of least privilege here...
upvoted 4 times
...
...
syu31svc
Most Recent 7 months, 1 week ago
Selected Answer: D
https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/delegating-administration-by-using-ou-objects You can use organizational units (OUs) to delegate the administration of objects, such as users or computers, within the OU to a designated individual or group "principle of least privilege" so answer is D
upvoted 2 times
...
empee1977
9 months, 1 week ago
Selected Answer: D
Create a delegation on OU3 would be the best option to meet the requirement for User1 to manage the membership of all the groups in Contoso\OU3 while following the principle of least privilege. Delegation allows you to assign specific administrative tasks to users or groups without granting them full control over the object.
upvoted 3 times
...
johosofat
1 year ago
Selected Answer: D
the delegation wizzard is pretty easy- bummer for folks that run core ! :-) D is correct granularity is great there
upvoted 2 times
...
Jawad1462
1 year ago
Selected Answer: D
Is the correct answer as we are working with least privileges
upvoted 1 times
...
xrisimix
1 year, 1 month ago
In order to change a "group member", you need to have permissions to change "member of" of affected user or group. So delegation to OU of groups is not enough. B should be correct.
upvoted 1 times
...
WMG
1 year, 3 months ago
Selected Answer: D
When you delegate to an OU you can be extremly granular, so D) is correct. C) Account Operators also has an interesting side effect, it allows Local Login on Domain Controllers. Great for least privilege!
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago