Testlet: Tailspin Toys
You are planning for the IT integration of TailspinToys and Wingtip Toys.
The company has decided on the following name resolution requirements:
Name resolution for Internet-based resources must continue to operate by using the same DNS servers as
prior to the merger.
The existing connectivity between Tailspin Toys andWingtip Toys must be used for all network
communication.
The documented name resolution goals must be met.
You need to provide a name resolution solution thatmeets the requirements.
What should you recommend? (Choose all that apply.)\r\n
General Background
You are the Windows Server Administrator for Tailspin Toys. Tailspin Toys has a main office and a
manufacturing office.
Tailspin Toys recently acquired Wingtip Toys and isin the beginning stages of Merging the IT environments.
Wingtip Toys has a main office and a sales office.
Technical Background
The companies use the network subnets indicated in the following table:
The Tailspin Toys network and the Wingtip Toys are connected by a point-to-point dedicated 45 Mbps
circuit that terminates in the main offices.
The current Tailspin Toys server topology is shown in the following table:
The Tailspin Toys environment has the following characteristics:
All servers are joined to the tailspintoys.com domain
In the Default Domain Policy, the Retain old eventsGroup Policy setting is enabled.
An Active Directory security group named “Windows System Administrators” is used to control all files
and folders on TT-PRINT01
A Tailspin Toys administrator named Marx has been delegated rights to multiple Organizational Units
(OUs) and object in the tailspintoys.com domain.
Tailspin Toys developers use Hyper-V Virtual Machines (VM’s) for development. There are 10
development VM’s named TT-DEV01 to TT-DEV20
The current Wingtip Toys server topology is shown in the following table:
All servers in the Wingtip Toys environment are joined to the wingtiptoys.com domain.
Infrastructure Services
You must ensure that the following infrastructure services requirements are met:
All domain zones must be stored as Active Directory-integrated zones.
Only DNS servers located in the Tailspin Toys main offices may communicate with the DNS servers at
Wingtip Toys.
Only DNS servers located in the Wingtip Toys main offices may communicate with the DNS servers at
Tailspin Toys
All tailspintoys.com resources must be resolved from the Wingtip Toys offices.
All wingtiptoys.com resources must be resolved fromthe Tailspin toys offices.
Certificates must be distributed automatically to all Tailspin Toys and Wingtip Toys computers.
Delegated Administration
You must ensure that the following delegated administration requirements are met:
Tailspin Toys IT security administrators must be able to create, modify and delete user objects in the
wingtip.com domain.
Members of the Domain Admins Group in the tailspintoys.com domain must have full access to the
wingtiptoys.com Active Directory environment.
A delegation policy must grant minimum access rights and simplify the process of delegating rights.
Minimum permissions must always be delegated to ensure that the least privilege is granted for a job
task.
Members of the TAILSPINTOYS\Helpdesk group must be able to update drivers and add printer ports
on TT-PRINT01.
Members of the TAILSPINTOYS\Helpdesk group must notbe able to cancel a print job on TT-PRINT01.
Tailspin Toys developers must be able to start,stopand apply snapshots to their development VM’s.
IT Security
Server security must be automated to ensure that newly deployed servers automatically have the same
security configurations as existing servers.
Auditing must be configured to ensure that the deletion of users objects and OUs is logged.
Microsoft Word and Microsoft Excel files must be automatically encrypted when uploaded to the
Confidential documents library on the Tailspin ToysMicrosoft SharePoint site.
Multi factor authentication must control access to Tailspin Toys domain controllers.
All file and folder auditing must capture the reason for access.
All folder auditing must capture all delete actionsfor all existing folders and newly created folders.
New events must be written to the Security event log in the tailspintoys.com domain and retained
indefinitely.
Drive X:\ on the TT-FILE01 must be encrypted by using Windows BitLocker Drive Encryption and must
be automatically unlock.
A.
On TT-DC01, TT-DC02, TT-DC03, and TT-DC04, add forwarders with the IP addresses of 172.16.10.10
and 172.16.10.11.
B.
On TT-DC01, add a conditional forwarder for wingtiptoys.com, use 172.16.10.10 and 172.16.10.11 as the IP
addresses, and then configure it to replicate to all DNS servers in the tailspintoys.com domain.
C.
On TT-DC01, TT-DC02, TT-DC03, and TT-DC04, add a secondary DNS zone for wingtiptoys.com and
specify 172.16.10.10 and 172.16.10.11 as the masterDNS servers.
D.
On WT-DC01 and WT-DC02, add a secondary DNS zone for tailspintoys.com and specify 10.10.10.10 and
10.10.10.11 as the master DNS servers.
E.
On WT-DC01, WT-DC02, WT-DC03, and WT-DC04, add forwarders with the IP addresses of 10.10.10.10
and 10.10.10.11.
F.
On WT-DC01, add a conditional forwarder for tailspintoys.com, use 10.10.10.10 and 10.10.10.11 as the IP
addresses, and configure it to replicate to all DNSservers in the wingtiptoys.com domain.