New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft AZ-801 Exam - Topic 3 Question 58 Discussion

Actual exam question for Microsoft's AZ-801 exam
Question #: 58
Topic #: 3
[All AZ-801 Questions]

Your network contains an Active Directory Domain Services (AD DS) forest. The forest functional level is Windows Server 2012 R2. The forest contains the domains shown in the following table.

You create a user named Admin1.

You need to ensure that Admin1 can add a new domain controller that runs Windows Server 2022 to the east.contoso.com domain. The solution must follow the principle of least privilege.

To which groups should you add Admin1?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Marjory
3 months ago
Schema Admins are not needed for just adding a DC, right?
upvoted 0 times
...
Flo
3 months ago
Wait, can Admin1 really add a DC with just that group? Sounds risky!
upvoted 0 times
...
Leila
3 months ago
Definitely EAST\Domain Admins only, keeps it simple.
upvoted 0 times
...
Kimberlie
4 months ago
I think CONTOSO\Enterprise Admins is overkill here.
upvoted 0 times
...
Lucy
4 months ago
Admin1 needs to be in EAST\Domain Admins for that.
upvoted 0 times
...
Cherelle
4 months ago
I recall that Enterprise Admins have broad permissions, so it might not be the best choice for least privilege. I’m leaning towards just Domain Admins.
upvoted 0 times
...
Ty
4 months ago
I’m not entirely sure, but I feel like Schema Admins might be needed for certain tasks. Should we consider both Schema and Domain Admins?
upvoted 0 times
...
Melodie
4 months ago
I think I practiced a similar question where we had to assign roles based on functional levels. Could it be the Enterprise Admins instead?
upvoted 0 times
...
Rasheeda
5 months ago
I remember that for adding a domain controller, the least privilege approach usually means not giving too many permissions. Maybe just the Domain Admins group?
upvoted 0 times
...
Catalina
5 months ago
I think the key here is to look at the different domains and their relationships. The east.contoso.com domain is part of the CONTOSO forest, so the CONTOSO\Enterprise Admins and CONTOSO\Schema Admins groups might be needed in addition to the EAST\Domain Admins group. I'll double-check the options to make sure I understand the requirements.
upvoted 0 times
...
Lili
5 months ago
I'm not sure about that. The question also mentions the CONTOSO\Enterprise Admins and CONTOSO\Schema Admins groups. Those might be relevant too, since it's an AD DS forest. I'll need to review the information carefully to determine the best approach.
upvoted 0 times
...
Carin
5 months ago
Hmm, I'm a bit confused. The question mentions the forest functional level and different domains, but I'm not sure how that affects the permissions needed. I'll need to think this through carefully.
upvoted 0 times
...
Alaine
5 months ago
This question is asking about the least privileged way to add a new domain controller to the east.contoso.com domain. I think the key is to identify the minimum permissions required for this task.
upvoted 0 times
...
Carey
5 months ago
Okay, let's see. The user Admin1 needs to be able to add a new domain controller to the east.contoso.com domain. Based on the principle of least privilege, I would guess that they need to be in the EAST\Domain Admins group, since that's the domain they're adding the DC to.
upvoted 0 times
...
Pansy
5 months ago
This seems like a straightforward question about confidentiality regulations. I'll review the key points about the Federal Regulations on Confidentiality of Alcohol and Drug Abuse Patient Records to determine which option best fits.
upvoted 0 times
...
Leota
2 years ago
LOL, I bet the test-makers are trying to trip us up with all these domain names. But Option C looks like the way to go.
upvoted 0 times
Barrett
1 year ago
Let's go with Option C then, covering all our bases.
upvoted 0 times
...
Mignon
2 years ago
Yeah, giving Admin1 both Schema Admins and Domain Admins rights makes sense.
upvoted 0 times
...
Tish
2 years ago
I agree, Option C seems like the best choice.
upvoted 0 times
...
Lilli
2 years ago
I'm going with Option C as well. It follows the principle of least privilege.
upvoted 0 times
...
Annamaria
2 years ago
Yeah, I think adding Admin1 to both Schema Admins and Domain Admins groups makes sense.
upvoted 0 times
...
Christa
2 years ago
I agree, Option C seems like the best choice.
upvoted 0 times
...
...
Kanisha
2 years ago
I'm not sure, but I think the answer might be D) CONTOSO\Enterprise Admins and CONTOSO/Schema Admins.
upvoted 0 times
...
Mireya
2 years ago
I agree with Arlen. The principle of least privilege is important, and granting Admin1 just the specific permissions required makes sense.
upvoted 0 times
...
Arlen
2 years ago
Option C seems to be the most logical choice. Adding Admin1 to both CONTOSO\Schema Admins and EAST\Domain Admins would give him the necessary permissions to add a new domain controller to the east.contoso.com domain.
upvoted 0 times
Felicidad
2 years ago
Exactly, it follows the principle of least privilege.
upvoted 0 times
...
Elli
2 years ago
That way Admin1 will have the necessary permissions to add the new domain controller.
upvoted 0 times
...
Dorathy
2 years ago
I agree, adding Admin1 to both Schema Admins and Domain Admins makes sense.
upvoted 0 times
...
Dusti
2 years ago
I think option C is the best choice.
upvoted 0 times
...
...
Leigha
2 years ago
I disagree, I believe the answer is C) CONTOSO/Schema Admins and EAST\Domain Admins.
upvoted 0 times
...
Tamar
2 years ago
I think the answer is A) EAST\Domain Admins only.
upvoted 0 times
...

Save Cancel