Your network contains an Active Directory forest named contoso.com. The forest contains two domains named
contoso.com and childl.contoso.com. The domains contain three domain controllers. The domain controllers
are configured as shown in the following table.
You need to ensure that the KDC support for claims, compound authentication, and kerberos armoring setting
is enforced in both domains.
Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)
A.
Raise the domain functional level of contoso.com.
B.
Raise the domain functional level of child1.contoso.com.
C.
Raise the forest functional level of contoso.com.
D.
Upgrade DC11 to Windows Server 2012 R2.
E.
Upgrade DC1 to Windows Server 2012 R2.
Explanation:
The root domain in the forest must be at Windows Server 2012 level. First upgrade DC1 to this level, then raisethe contoso.com domain functional level to Windows Server 2012.
Not sure this question is worded correctly, to have KDC support for claims, compound authentication, and Kerberos armoring it Requires Windows Server 2012 domain functional level.
The question asks what must be done to enforce it in both domains.
That would require upgrading both DC 1 and DC 11 to 2012 R2 and raising the functional level of both domains.
Which is not covered in the answers.
I believe this to be a missed worded version of question number 93, which asked to do this in only one domain.
Just my thoughts
Justbecause, I quite agree with you!
justbecause is correct.