In an AD DS forest you deployed a read-only domain controller (RODC1). You need to make User1 a local administrator on RODC1 while following the principle of least privilege. Which tool should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: ntdsutil.exe.
Why this is the answer
You should use ntdsutil.exe to manage the local administrator password replication policy (LAPS) for an RODC. This tool allows you to specify which users or groups can be delegated local administrator rights on an RODC, adhering to the principle of least privilege by controlling who can manage the local administrator account. dsamain.exe is used to expose Active Directory data stored in an NTDS.DIT file as an LDAP server, primarily for offline maintenance or recovery, not for managing RODC local administrators. 'net user' is a command-line tool for managing local user accounts on a standard server or workstation, but it cannot be used to manage the specific local administrator policy on an RODC. The Local Users and Groups snap-in is also for managing local accounts on standard servers and workstations and does not apply to the special case of RODCs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed