Your network consists of a single Active Directory forest. The forest functional level is Windows Server 2008
R2.
The forest contains two domains named contoso.com and na.contoso.com. The contoso.com contains a user
named User1. The na.contoso.com contains an organizational unit (OU) named Security.
You need to give User1 administrative rights so that he can manage Group Policies for the Security OU.
You want to achieve this goal while meeting the following requirements:
User1 must be able to create and configure Group Policies in na.contoso.com.
User1 must be able to link Group Policies to the Security OU.
User1 must be granted the least administrative rights necessary to achieve the goal.
What should you do?
A.
Add User1 to the Administrators group for na.contoso.com.
B.
Add User1 to the Group Policy Creator Owners group in contoso.com. Modify the permissions on the
Security OU.
C.
Run the Delegation of Control Wizard on the Security OU. In the Group Policy Management Console,
modify the permissions of the Group Policy Objects container in the na.contoso.com domain.
D.
Run the Delegation of Control Wizard on na.contoso.com. In the Group Policy Management Console,
modify the permissions of the Group Policy Objects container in the contoso.com domain.
Explanation:
GROUP POLICY DELEGATION
1. Active Directory Users and Computers console
2. Group Policy Management console
http://technet.microsoft.com/en-us/library/cc732524.aspx