Question 1
Q1A system administrator is deploying a Read-Only Domain Controller (RODC) at a remote branch office for Contoso, Ltd. To ensure branch users can authenticate locally during WAN outages, the administrator configures the Password Replication Policy (PRP). A member of the Helpdesk staff, User1, is added to the Allowed RODC Password Replication Group. However, User1 is also a member of the built-in Denied RODC Password Replication Group. When User1 attempts to authenticate at the branch office during a WAN failure, authentication fails. What is the cause of this behavior?
Show answer & explanation
Correct answer: B
In Active Directory Domain Services, evaluation of the RODC Password Replication Policy (PRP) follows strict precedence where explicit Deny rules supersede Allow rules. The Denied RODC Password Replication Group is specifically designed to protect administrative and sensitive accounts from having their credentials stored in branch offices with limited physical security. Because User1 is a member of the Denied group, their credentials are never cached locally on the RODC, causing authentication to fail when the WAN link is unavailable.