Question 1
IntermediateDeploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments · Deploy read-only domain controllers (RODCs)
A financial services firm, Woodgrove Bank, is deploying a new Active Directory forest. For security reasons, they need to ensure that the administrator who installs a new Read-Only Domain Controller (RODC) in a branch office cannot use their own credentials to install other domain controllers in the forest. Which approach meets this requirement while adhering to the principle of least privilege?
Answer and explanation
Correct answer: C
This method, known as a staged RODC installation, is the most secure approach. A member of the Domain Admins group pre-creates the RODC account and specifies which user or group has the permission to attach a server to that account. This delegates the exact permission needed without granting excessive rights like Domain Admin membership. The branch administrator can then complete the installation without needing high-level domain credentials.
