During Active Directory setup, which combination of group scope and group type should you select when creating a group to manage access control lists?

Prepare for the TestOut Labs Test. Interactive quizzes and flashcards with insights and tips for a comprehensive review. Ace your exam!

Multiple Choice

During Active Directory setup, which combination of group scope and group type should you select when creating a group to manage access control lists?

Explanation:
Security groups are the principals Windows uses to enforce permissions in ACLs. A distribution group is meant for email distribution, not for granting access, so it isn’t usable for ACLs. The Global scope is ideal for organizing users from the same domain who need access to resources in that domain, and you can nest that group later into domain local or universal groups if cross-domain access becomes necessary. So, a security group with Global scope is the best fit for managing access control lists. Local/domain-local scope groups are more about cross-domain or resource-local scenarios and add complexity, which isn’t needed for straightforward ACL management.

Security groups are the principals Windows uses to enforce permissions in ACLs. A distribution group is meant for email distribution, not for granting access, so it isn’t usable for ACLs. The Global scope is ideal for organizing users from the same domain who need access to resources in that domain, and you can nest that group later into domain local or universal groups if cross-domain access becomes necessary. So, a security group with Global scope is the best fit for managing access control lists. Local/domain-local scope groups are more about cross-domain or resource-local scenarios and add complexity, which isn’t needed for straightforward ACL management.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy