| Author |
70-218 Q of the Day 6/03
|
|
| mrfixit 2003-06-03, 6:02 am |
| Hope this one is a little tougher... 
You are the domain administrator for Jerkware Inc. The company's network consist of three domains.
You are responsible for the ny.jerkware.com domain. The ny.jerkware.com domain contains user accounts for 50 of the employees in the Finance department.
Recently, a shared folder named FinanceA was created in the ny.jerkware.com domain. FinanceA can only be accessed by those 50 employees. FinanceA contains forms used by those 50 employees.
You are directed to create a group on your domain controllers that will allow finance users whose user accounts are in Global Groups from the other Domains to access FinanceA. You must accomplish this goal while minimizing replication overhead.
What should you do?
A)Create a Global Group
Add the appropriate groups from the other domains to the group
Assign the Global Group permissions to FinanceA
B)Create a Domain Local Group
Add the appropriate groups from the other domains to the domain local group
Assign the domain local group permissions to FinanceA
C)Create a Universal Group
Add the appropriate groups from the other domains to the universal group
Assign the universal group permissions to FinanceA
D)Create a Distribution Group
Add the appropriate groups from the other domains to the distribution group
Assign the distribution group permissions to FinanceA
See you tomorrow! | |
| karlisi 2003-06-03, 6:15 am |
| B
the Rule UGLP | |
| enforcer 2003-06-03, 6:18 am |
| Agree B
but what does the P stand for? | |
| karlisi 2003-06-03, 6:30 am |
| Users -> Global groups -> Local groups -> Permissions
 | |
| enforcer 2003-06-03, 6:48 am |
| got the others, just not the P, cheers makes sense, almost makes GULP but not quite, or UGLY  | |
| karlisi 2003-06-03, 6:50 am |
| UGLY? Something new (or you mean what I think...) | |
| enforcer 2003-06-03, 6:56 am |
| Yeah got it the first time  | |
| karlisi 2003-06-03, 7:03 am |
| It was a little technical problem. Only refreshed the page and, big surprise, duplicate post. | |
| enforcer 2003-06-03, 7:05 am |
| OH, we seem to have alot of that happening these days, but they usually happen straight after each other, not 20mins later  | |
| karlisi 2003-06-03, 7:08 am |
| Sometimes strange things happen. Especially with special people (like me  | |
| tetragamon 2003-06-03, 7:25 am |
| I'm going for B but I am concerned about requirement for replication overhead.
Is the local group not being replicated outside the domain something I need to know?
Is this really significant worry? | |
| kklentz 2003-06-03, 12:19 pm |
| B
Reminder tip from my 70-215 study:
A G DL P
(A)ccounts are placed into (G)roups
(G)roups are placed into (D)omain (L)ocal groups
(P)remissions are assigned to (D)omain (L)ocal groups
A => G => DL <= P
Wrote this at the top of my scratch sheet when taking the exam. | |
| cramersaunders 2003-06-04, 4:20 am |
| B | |
| mrfixit 2003-06-04, 6:13 am |
| Guess you ppl know your stuff. 
And the answer is...
quote: You are the domain administrator for Jerkware Inc. The company's network consist of three domains.
You are responsible for the ny.jerkware.com domain. The ny.jerkware.com domain contains user accounts for 50 of the employees in the Finance department.
Recently, a shared folder named FinanceA was created in the ny.jerkware.com domain. FinanceA can only be accessed by those 50 employees. FinanceA contains forms used by those 50 employees.
You are directed to create a group on your domain controllers that will allow finance users whose user accounts are in Global Groups from the other Domains to access FinanceA. You must accomplish this goal while minimizing replication overhead.
What should you do?
B)Create a Domain Local Group
Add the appropriate groups from the other domains to the domain local group
Assign the domain local group permissions to FinanceA
When multiple users need the same level of access to the same resources, it is recommended to create groups, place the users
into groups, and assign permissions to the group rather than to individual user accounts. A Global Group can include only
members from the same domain as the group and is visible on any computer throughout the forest. It is recommended to place
all of the users from a specific domain who need the same level of access to resources throughout the forest into a Global Group. A Domain Local Group can include members from anywhere in the forest and is visible on all computers in the same domain where the Domain Local Group is located. Here we have users from differnt domains requiring access to resources in one of the domains. Therefore, you would create a Global Group in each domain that contains employees who require access to the resources, and place those employees in the Global Group. Then you would create a Domain Local Group in the resource domain, assign it the appropriate permissions for the required files and add the Global Groups to the Domain Local Group.
(Little long on the explanation... ) |
|
|
|