You need to ensure that clients will only attempt to establish connections to the new AD RMS deployment
You need to delegate permissions to modify the records in the adatum.com zone to a group named Group1
All domain computers have certificates that are issued by a certification authority (CA) named Contoso C