Which of the following options would you choose to accomplish this task?

You are an Enterprise administrator for contoso.com. The company consists of a head office and a branch office. The corporate network of the company consists of a single Active Directory domain. All the servers on the network run Windows Server 2008 and all client computers run Windows Vista.
The branch office contains 50 Windows Server 2008 member servers. The Active Directory contain an organizational unit (OU) called BranchOU to keep the computer objects for the servers in the Branch office.
A global group called Branch-adm also exists in the AD to keep the user accounts for the administrators in the branch office. The administrators on the corporate network manage all the servers in the Branch office.
However, you now want to ensure that the members of Branch-adm group can Stop and start services and change registry settings on the member servers of the branch office. Which of the following options would you choose to accomplish this task?

You are an Enterprise administrator for contoso.com. The company consists of a head office and a branch office. The corporate network of the company consists of a single Active Directory domain. All the servers on the network run Windows Server 2008 and all client computers run Windows Vista.
The branch office contains 50 Windows Server 2008 member servers. The Active Directory contain an organizational unit (OU) called BranchOU to keep the computer objects for the servers in the Branch office.
A global group called Branch-adm also exists in the AD to keep the user accounts for the administrators in the branch office. The administrators on the corporate network manage all the servers in the Branch office.
However, you now want to ensure that the members of Branch-adm group can Stop and start services and change registry settings on the member servers of the branch office. Which of the following options would you choose to accomplish this task?

A.
Assign Full Control permissions on the BranchOU to the Branch-adm group.

B.
Add the Branch-adm group to the Power Users local group on each server in the Branch office.

C.
Assign the Branch-adm group change permissions to the BranchOU and to all child objects.

D.
Add the Branch-adm group to the Administrators local group on each server in the Branch office.

E.
None of the above

Explanation:

To ensure that the members of add the Branch-adm group can Stop and start services and change registry settings on the member servers of the branch office, you need to add the Branch-adm group to the Administrators local group on each server in the Branch office.
‘Administrators’ is a local group that provides full administrative access to an individual computer or a single domain, depending on its location. Because this account has complete access, you should be very careful about adding users to this group. To make someone an administrator for a local computer or domain, all you need to do is make that person a member of this group. Only members of the Administrators group can modify this account.
http://www.windowsecurity.com/articles/Securing-Local-Administrators-Group-Every-Desktop.html



Leave a Reply 0

Your email address will not be published. Required fields are marked *