Skip to main content
Теґи
Answer confirmed
Question

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains the following resources:

  • User1: A user in a domain named us.contoso.com
  • User2: A user in a domain named europe.contoso.com
  • Server1: A computer in the us.contoso.com domain
  • Server2: A computer in the europe.contoso.com domain

You need to ensure that User1 and User2 can access file shares on Server1 and Server2. The solution must minimize administrative effort.

Which type of group should you create?

Proposed answer
  • domain-local
  • global
  • local
  • universal
Correct answer
  • Incorrect - A domain-local group is incorrect because it can only be used on servers in the local domain.
  • Incorrect - A global group is incorrect because members can only be from the local domain.
  • Incorrect - A local group is incorrect because it is not stored in AD DS.
  • Correct - A universal group is correct because it can contain users from anywhere in the forest.

Define users, groups, and computers - Training | Microsoft Learn