In an AD domain you have Server1 and Server2 (both Windows Server). To manage Server2 with the Computer Management console while following least privilege, which two Windows Defender Firewall with Advanced Security rules should be enabled on Server2?
Choose an answer
Tap an option to check your answer.
Correct answer: the COM+ Network Access (DCOM-In) rule, all the rules in the Remote Event Log Management group.
Why this is the answer
To manage a remote server using the Computer Management console, specific firewall rules must be enabled to allow the necessary RPC and DCOM traffic. The "COM+ Network Access (DCOM-In)" rule (TCP Port 135 and dynamic RPC ports) is essential for DCOM communication, which Computer Management relies on for many of its functions, including connecting to remote services and applications. Additionally, "all the rules in the Remote Event Log Management group" are required to view and manage event logs on the remote server through the Computer Management console. This group includes rules for RPC Endpoint Mapper and specific DCOM access for event log services. The "Windows Management Instrumentation (WMI-In)" rule is used for WMI access, which is not the primary mechanism Computer Management uses for its core functions. The "COM+ Remote Administration (DCOM-In)" rule is for remote administration of COM+ applications, not general Computer Management. The "Windows Management Instrumentation (DCOM-In)" rule is also WMI-related and not directly for the overall Computer Management console functionality.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed