Your network contains an Active Directory forest named contoso.com. The forest functional level is
Windows Server 2012.
The forest contains an Active Directory domain. The domain contains a global security group named
GPO_Admins that is responsible for managing Group Policies in the forest.
A second forest named fabrikam.com contains three domains. The forest functional level is Windows
Server 2003.
You need to design a trust infrastructure to ensure that the GPO_Admins group can create, edit, and link
Group Policies in every domain of the fabrikam.com forest.
What should you include in the design?
More than one answer choice may achieve the goal. Select the BEST answer.
A.
A two-way forest trust
B.
A one-way forest trust
C.
Three external trusts
D.
Three shortcut trusts
Explanation:
A one-way trust is a unidirectional authentication path created between two domains. In a one-way trust
between Domain A and Domain B, users in Domain A can access resources in Domain B. However, users
in Domain B cannot access resources in Domain A. In this question Domain A would be contoso.com,
which has the GPO_Admins group, and Domain B would the fabrikam.com domain, to which the
GPO_Admins should have access.
How Domain and Forest Trusts Work
https://technet.microsoft.com/en-us/library/cc773178(v=ws.10).aspx