Your company has a main office, three regional offices, and six branch offices. The network links are
configured as shown in the exhibit. (Click the Exhibit button.)
The network consists of one Active Directory domain. You create an Active Directory site for each
office. You create a site link for each wide area network (WAN) link. The Bridge all site links option is
disabled. You need to plan the deployment of domain controllers. The solution must meet the
following requirements. Windows PowerShell must be installed on all domain controllers in each
regional office. Domain user account passwords stored on the domain controllers must be protected
if a branch office domain controller is stolen. What should you do?
A.
In each branch office and in each regional office, install a Server Core installation of Windows
Server 2008 and configure a writable domain controller.
B.
In each branch office and in each regional office, install a full installation of Windows Server 2008
and configure a read-only domain controller (RODC).
C.
In each branch office, install a Server Core installation of Windows Server 2008 and configure a
read-only domain controller (RODC). In each regional office, install a full installation of Windows
Server 2008 and configure a writable domain controller.
D.
In each branch office, install a full installation of Windows Server 2008 and configure a read-only
domain controller (RODC). In each regional office, install a Server Core installation of Windows
Server 2008 and configure a writable domain controller.
Explanation:
To ensure that the domain user account passwords stored on the domain controllers must be
protected if a branch office domain controller is stolen, you need to install a Server Core installation
of Windows Server 2008 and configure it as a read-only domain controller (RODC) in each branch
office. The Server Core installation of Windows Server 2008 will install only limited services on the
RODC, which will store passwords. This installation will be very secure. A Server Core installation
provides a minimal environment for running specific server roles, which reduces the maintenance
and management requirements and the attack surface for those server roles. Next you can install a
full installation of Windows Server 2008 and configure it as a writable domain controller in each
regional office firstly because for RODCs to work you need to configure writable domain controllers
from where data replication can happen and secondly you need to install them because you need to
install Windows PowerShell on all domain controllers in each regional office.
Server Management / Windows PowerShell
http://www.microsoft.com/windowsserver2008/en/us/server-management.aspx
Server Core Installation Option of Windows Server 2008 Step-By-Step Guide
http://technet2.microsoft.com/windowsserver2008/en/library/47a23a74-e13c-46de-8d30-
ad0afb1eaffc1033.mspx?mfr=true