Your network consists of a single Active Directory forest that contains two domains named contoso.com and EU.contoso.com. All network servers run Windows Server 2003 Service Pack 2 (SP2).
The contoso.com domain contains a domain local group named Contoso-HR. The EU.contoso.com domain contains a domain local group name EU-HR.
On a server named Server1 in the contoso.com domain, you create a shared folder named Share1. You assign the Contoso-HR group the Read permission for Share1.
You discover that you cannot assign permissions on Share1 to the EU-HR group.
You need to ensure that the members of the EU-HR group have the Read permission on Share1.
Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)
A.
Add the EU-HR group to Contoso-HR.
B.
Change the scope of the EU-HR group to global.
C.
Change the scope of the Contoso-HR group to universal.
D.
Configure a shortcut trust between the EU and the Contoso domains.