Your network contains an Active Directory domain named adatum.com.
You have a standard primary zone named adatum.com.
You need to provide a user named User1 the ability to modify records in the zone. Other users must
be prevented from modifying records in the zone.
What should you do first?
A.
 Run the Zone Signing Wizard for the zone.
B.
 From the properties of the zone, modify the start of authority (SOA) record.
C.
 From the properties of the zone, change the zone type.
D.
 Run the New Delegation Wizard for the zone.
Explanation:
The Zone would need to be changed to a AD integrated zone When you use directory-integrated
zones, you can use access control list (ACL) editing to secure a dnsZone object container in the
directory tree. This feature provides detailed access to either the zone or a specified resource record
in the zone. For example, an ACL for a zone resource record can be restricted so that dynamic
updates are allowed only for a specified client computer or a secure group, such as a domain
administrators group. This security feature is not available with standard primary zones.
DNS update security is available only for zones that are integrated into Active Directory. After you
integrate a zone, you can use the access control list (ACL) editing features that are available in the
DNS snap-in to add or to remove users or groups from the ACL for a specific zone or for a resource
record.
Standard (not an Active Directory integrated zone) has no Security settings:You need to firstly change the “Standard Primary Zone” to AD Integrated Zone:
Now there’s Security tab:
httpHYPERLINK “http://technet.microsoft.com/en-us/library/cc753014.aspx#_blank”:
//technetHYPERLINK “http://technet.microsoft.com/en-us/library/cc753014.aspx#_blank”.
microsoftHYPERLINK “http://technet.microsoft.com/en-us/library/cc753014.aspx#_blank”. com/enus/library/cc753014HYPERLINK “http://technet.microsoft.com/enus/library/cc753014.aspx#_blank”. aspx
httpHYPERLINK “http://technet.microsoft.com/en-us/library/cc726034.aspx#_blank”:
//technetHYPERLINK “http://technet.microsoft.com/en-us/library/cc726034.aspx#_blank”.
microsoftHYPERLINK “http://technet.microsoft.com/en-us/library/cc726034.aspx#_blank”. com/enus/library/cc726034HYPERLINK “http://technet.microsoft.com/enus/library/cc726034.aspx#_blank”. aspx
httpHYPERLINK “http://support.microsoft.com/kb/816101#_blank”: //supportHYPERLINK
“http://support.microsoft.com/kb/816101#_blank”. microsoftHYPERLINK
“http://support.microsoft.com/kb/816101#_blank”. com/kb/816101



Explanation:
The Zone would need to be changed to a AD integrated zone When you use directoryintegrated zones, you can use access control list (ACL) editing to secure a dnsZone object
Stupid question.
Have to give information integrated/not integrated witch AD.
My first idea was SECURITY tab – but no answer about it.
Stupid question.
Should be an additional information about non-integrated zone adatum.com.
uhhh