In an AD DS forest (forest functional level Windows Server 2012 R2) that contains multiple domains, you create a user account named Admin1. You need to grant Admin1 only the privileges required to install a Windows Server 2022 domain controller in the east.contoso.com domain. To which group(s) should you add Admin1?
Choose an answer
Tap an option to check your answer.
Correct answer: EAST\Domain Admins only.
Why this is the answer
To install a new domain controller in an existing domain, the user account requires membership in the Domain Admins group of that specific domain. In this scenario, Admin1 needs to install a domain controller in the east.contoso.com domain, so adding Admin1 to EAST\Domain Admins provides the necessary permissions. CONTOSO\Enterprise Admins is incorrect because while it grants forest-wide administrative control, it's excessive for a single domain controller installation and violates the principle of least privilege. CONTOSO\Schema Admins is incorrect because this group is used for modifying the Active Directory schema, which is not required for installing a new domain controller. Combining Schema Admins with Domain Admins or Enterprise Admins is also incorrect as Schema Admins is unnecessary.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed