| Author |
Tue 70-217 Question of the Day
|
|
| wbafrank 2002-07-09, 7:07 pm |
| And today's poser is ....
Q9. Alison is currently implimenting Group Policies in her organization, nefarious.com. Her organization currently has a single domain - ad.nefarious.com.
The Organizational Unit Structure is as follows:
Top Level OUs:
Salem, Fredricksberg, Melbourne.
Second Level OUs:
US (sub OU of Salem)
Int (sub OU of Salem)
Interns (sub OU of Melbourne)
Alison is testing the Group Policies and sets them up in the following manner:
The GPO linked to the domain ad.nefarious.com has
Disable Command Prompt: Enabled
Disable Registry Editing Tools: Enabled
The GPO linked to the Salem OU
Disable Command Prompt: Disabled
Disable Registry Editing Tools: Disabled
GPO linked to the Int OU (sub OU of Salem)
Disable Command Prompt: Enabled.
Disable Registry Editing Tools: Disabled
In addition, she sets all three of the GPOs to No Override. Assuming that no other GPOs have settings that conflict with these, what will be the effective settings for a user in the Int OU when he or she logs into the domain?
A. Command Prompt will be disabled. Registry Editing Tools will be enabled.
B. Command Prompt will be enabled. Registry Editing Tools will be enabled.
C. Command Prompt will be enabled. Registry Editing Tools will be disabled.
D. Command Prompt will be disabled. Registry Editing Tools will be disabled.
Good Luck .... see you tomorrow for the answer!! | |
| Slinky 2002-07-09, 8:55 pm |
| I have to say A. | |
| Zaraspook 2002-07-09, 9:29 pm |
| How about D?  | |
|
| I'll go with D,
Remember, the policy was Disable cmd/reg=enable! | |
| Surender 2002-07-10, 7:12 am |
| d | |
| Slinky 2002-07-10, 10:59 am |
| What am I missing here? The order of execution for the GPOs will be the domain first then the OUs. So the effective settings should be whatever the intern OU GPO sets them to, right? | |
| Slinky 2002-07-10, 11:16 am |
| I got it now. Overlooked the No Override option. Since that is the case the OU policy will not override the domain policy, so the answer is in fact D. | |
| RUSH2112 2002-07-10, 12:31 pm |
| I would say D as well | |
| robertmillar 2002-07-10, 1:16 pm |
| D | |
|
| Yup, "D" would be the answer. | |
| wbafrank 2002-07-11, 9:53 am |
| quote: Originally posted by wbafrank
And today's poser is ....
Q9. Alison is currently implimenting Group Policies in her organization, nefarious.com. Her organization currently has a single domain - ad.nefarious.com.
The Organizational Unit Structure is as follows:
Top Level OUs:
Salem, Fredricksberg, Melbourne.
Second Level OUs:
US (sub OU of Salem)
Int (sub OU of Salem)
Interns (sub OU of Melbourne)
Alison is testing the Group Policies and sets them up in the following manner:
The GPO linked to the domain ad.nefarious.com has
Disable Command Prompt: Enabled
Disable Registry Editing Tools: Enabled
The GPO linked to the Salem OU
Disable Command Prompt: Disabled
Disable Registry Editing Tools: Disabled
GPO linked to the Int OU (sub OU of Salem)
Disable Command Prompt: Enabled.
Disable Registry Editing Tools: Disabled
In addition, she sets all three of the GPOs to No Override. Assuming that no other GPOs have settings that conflict with these, what will be the effective settings for a user in the Int OU when he or she logs into the domain?
A. Command Prompt will be disabled. Registry Editing Tools will be enabled.
B. Command Prompt will be enabled. Registry Editing Tools will be enabled.
C. Command Prompt will be enabled. Registry Editing Tools will be disabled.
D. Command Prompt will be disabled. Registry Editing Tools will be disabled.
And the answer is ....
Correct Answer: D
If multiple GPOs have the No Override option enabled the GPO highest up in the hierarchy will be the one that will apply. In the above example the settings from the domain GPO would be highest in the hierarchy and therefore the command prompt would be disabled as would the registry editing tools. |
|
|
|