单项选择题

Your company has two Active Directory forests as shown in the following table:    
Forest name  Forest functional level  Domain(s)  contoso.com  Windows Server 2008  contoso.com  
fabrikam.com  Windows Server 2008  fabrikam.com  eng.fabrikam.com    
The forests are connected by using a two-way forest trust. Each trust direction is configured with  forest-wide authentication. The new security policy of the company prohibits users from the  eng.fabrikam.com domain to access resources in the contoso.com domain.    
You need to configure the forest trust to meet the new security policy requirement.    
What should you do()

A.Delete the outgoing forest trust in the contoso.com domain.
B.Delete the incoming forest trust in the contoso.com domain.
C.Change the properties of the existing incoming forest trust in the contoso.com domain from Forest-wide authenticat
D.Change the properties of the existing outgoing forest trust in the contoso.com domain to exclude *.eng.fabrikam.com

相关考题

Yourcompany,A.DatumCorporation,hasasingleActiveDirector...


多项选择题

Your company, A. Datum Corporation, has a single Active Directory domain named intranet.adatum.com. The  domain has two domain controllers that run Windows Server 2008 R2 operating system. The  domain controllers also run DNS servers.  
The intranet.adatum.com DNS zone is configured as an Active Directory-integrated zone with the  Dynamic updates setting configured to Secure only. A new corporate security policy requires that  the intranet.adatum.com DNS zone must be updated only by domain controllers or member  servers.  
You need to configure the intranet.adatum.com zone to meet the new security policy requirement.    
Which two actions should you perform()

A.Remove the Authenticated Users account from the Security tab of the intranet.adatum.com DNS zone properties.
B.Assign the SELF Account Deny on Write permission on the Security tab of the intranet.adatum.com DNS zone prop
C.Assign the server computer accounts the Allow on Write All Properties permission on the Security tab of the intrane
D.Assign the server computer accounts the Allow on Create All Child Objects permission on the Security tab of the int