Your network contains an Active Directory forest. The forest contains one domain named
adatum.com. The domain contains three domain controllers. The domain controllers are
configured as shown in the following table.
DC2 has all of the domain-wide operations master roles. DC3 has all of the forest-wide
operation master roles.
You need to ensure that you can use Password Settings objects (PSOs) in the domain.
What should you do first?
A.
Uninstall Active Directory from DC1.
B.
Change the domain functional level.
C.
Transfer the domain-wide operations master roles.
D.
Transfer the forest-wide operations master roles.
I beleiev answer is (B) raise domain functional level , as 1st DC is windows 2003 and we can assume that the domain functional level is configure as 2003 level.
as part of the prerequeiste to use PSO , we need to have at least domain functional level of 2008
https://technet.microsoft.com/en-us/library/cc770842(v=ws.10).aspx