|
Question : Gplink / Gpoptions And "permissions", Administrators must be given some GP access, restricted in others
|
|
You are the network administrator for ProzeWarez .com. ProzeWarez has one main office and 11 branch offices. The network consists of a single Active Directory domain named ProzeWarez .com. The domain contains an organizational unit (OU) named BranchOffices. The BranchOffices OU contains an OU for each of the 11 branch offices.
The network administrators who administer the branch offices are members of the BranchOffice Admins global group. You delete (delegate?) full control of all child objects in the BranchOffices OU to the BranchOffice Admins group. ProzeWarez 's written security policy states the following requirements:
Members of the BranchOffice Admins group must have the right to modify the assignment of Group Policy objects (GPOs) for the individual branch office OUs. Members of the BranchOffice Admins group must not be able to block the inheritance of GPOs at the individual branch office OUs. Members of the BranchOffice Admins group must not be able to modify any GPO settings at the BranchOffices OU level.
You need to configure the delegation of the administration of GPOs as defined by the written security policy. You must also ensure that you do not remove more permissions that is necessary from the BranchOffice Admins group.
What should you do?
A. Modify the permissions granted to the BranchOffice Admins group so that the group is denied permission to write the gPOptions attribute at the BranchOffices OU level. Configure the permission to apply to the BranchOffices OU and all child objects.
B. Modify the permissions granted to the BranchOffice Admins group so that the group is granted permission to read and write the gPOptions attribute at the BranchOffices OU level. Configure the permission to apply to child objects of the BranchOffices OU only.
C. In the Group Policy Management Console (GPMC), remove the BranchOffice Admins group from the Permissions tab for the BranchOffices OU. Add the BranchOffice Admins group to the LinkGPOs permission in the Delegation tab for the BranchOffices OU. Configure the permissions to apply the BranchOffice Admins container only.
D. In the Group Policy Management Console (GPMC), remove the BranchOffice Admins group from the Permissions tab for the BranchOffices OU. Add the BranchOffice Admins group to the LinkGPOs permission in the Delegation tab for the BranchOffices OU. Configure the permissions to apply the BranchOffice Admins container and all child containers.
|
Answer : Gplink / Gpoptions And "permissions", Administrators must be given some GP access, restricted in others
|
|
Hi tourajam,
homework.......
|
|
|
|