Your network contains two Active Directory forests named contoso.com and dev.contoso.com. The
contoso.com forest contains a domain controller named DC1. The dev.contoso.com forest contains a
domain controller named DC2. Each domain contains an organizational unit (OU) named OU1.
Dev.contoso.com has a Group Policy object (GPO) named GPO1. GPO1 contains 200 settings,
including several settings that have network paths. GPO1 is linked to OU1.
You need to copy GPO1 from dev.contoso.com to contoso.com.
What should you do first on DC2?
A.
From the Group Policy Management console, right-click GPO1 and select Copy.
B.
Run the mtedit.exe command and specify the /Domaintcontoso.com /DC: DC 1 parameter.
C.
Run the Save-NetGpocmdlet.
D.
Run the Backup-Gpocmdlet.
Explanation:
To copy a Group Policy object:
In the GPMC console tree, right-click the GPO that you want to copy, and then click Copy.
To create a copy of the GPO in the same domain as the source GPO, right-click Group Policy objects,
click Paste, specify permissions for the new GPO in the Copy GPO box, and then click OK.
For copy operations to another domain, you may need to specify a migration table.
The Migration Table Editor (MTE) is provided with Group Policy Management Console (GPMC) to
facilitate the editing of migration tables. Migration tables are used for copying or importing Group
Policy objects (GPOs) from one domain to another, in cases where the GPOs include domain-specific
information that must be updated during copy or import.Source WS2008R2: Backup the existing GPOs from the GPMC, you need to ensure that the “Group
Policy Objects” container is selected for the “Backup Up All” option to be available.
Copy a Group Policy Object with the Group Policy Management Console (GPMC)
You can copy a Group Policy object (GPO) either by using the drag-and-drop method or right-click
method.
Applies To: Windows 8, Windows Server 2008 R2, Windows Server 2012
References:
http://technet.microsoft.com/en-us/library/cc785343(v=WS.10).aspx
http://technetHYPERLINK “http://technet.microsoft.com/enus/library/cc733107.aspx#_blank”.microsoft.com/en-us/library/cc733107.aspx
In this case since they are separate Forests the correct process is as follows:
• Backup GPO
• Copy GPO to other Forest
• Create Migration table
• Import GPO Using the Migration Table
Therefore the correct answer would be D
agree with TaSpanja. Correct should be D
yes. the first thing to to is to do backup.
https://technet.microsoft.com/en-za/enus/library/cc733107.aspx
Answer: A
Your link refers to copying to/from the same domain.
The question is talking about 2 different forests.
The answer is D.
Answer=D It cannot be A because the first step=backup the GPO
Export:
In the source domain, right-click the GPO you want to migrate and choose Backup…
Backup to a directory of your choice and Comment.
You can continue backing up several GPOs to the same directory.
Import:
Copy the directory to the destination domain. Then you can either import the GPOs one-by-one or all of them with the same name as they had in the source:
Import one-by-one:
Create a new GPO.
Right-click the GPO and choose Import Settings…
Choose the backup folder you copied.
Choose which GPO you want to import.
Done.
It’s A, because it’s the first step on …DC2, the second Forest!
Back up is on DC1
You want to copy GPO from dev.contoso.com to contoso.com. DC2 is on dev.contoso.com and is where the GPO is to copy. To copy a GPO from one forest to another, you have to do a backup.
Answer is D.
70-411 MS egzam book part 6.3
1 step – find GPO you want to migrate
2 step – COPY GPO from domain 1
3 step – paste GPO to domain 2
4 step – go through Cross Domain Copying Wizard
any words about backup GPO
I vote A definitelly !!
In the GPMC console tree, right-click the GPO that you want to copy, and then click Copy .
To create a copy of the GPO in a different domain, double-click the destination domain, right-click Group Policy objects , and then click Paste . Answer all the questions in the cross-domain copying wizard that appears, and then click Finish .
https://technet.microsoft.com/en-za/enus/library/cc733107.aspx?f=255&MSPPError=-2147217396
A is the correct answer.
The Backup-Gpo cmdlet allows you to create a backup of the GPO, in case you need to quickly restore it (i.e. – protection against accidental deletion). While this is certainly a good idea and a best practice, it does not accomplish the goal of copying the GPO.
The question does not specify that there is a forest trust in place, so we have have to assume that no trust exists. Therefore exporting/importing the GPO is not an option. The only way to copy GPO1 from DC2 to DC1 is to copy and paste.
A is a wrong answer !
D is a correct answer -> What should you do first on DC2 ?
You don’t need use GPO backup cmdlet not at all 🙂
Independently of DC1 or DC2.
Why D can be right answer ?
I think it’s A. The question mentions two diferent forests to confuse us. The GPO is copied from dev.contoso.com to contoso.com. In this case, it’s not diferent forests and there’s a trust relationship between domains.
Paulo, you got correct point sir, you are right. Thank you
Question states: “Your network contains two Active Directory forests named contoso.com and dev.contoso.com”
Paulo states: “In this case, it’s not diferent forests and there’s a trust relationship between domains.”
You always see what you’d like to see, aren’t you? 🙂
I sincerely thing there’s a typo in this question. As “evil” as we think these questions can be, I seriously doubt they would say two separate forests with relative domain name. So I’m thinking this should be saying something along the lines of “two separate domains in the same forest”.
Anyone else think the same?