129k views
4 votes
Which of the following methods are acceptable when it comes to implementing a group nesting strategy in a corporate network spanning more than one Active Directory domain? [Choose two that apply].

A. A-G-L-P
B. A-G-P
C. A-G-DL-P
D. A-G-U-DL-P

User Nate Symer
by
8.2k points

1 Answer

4 votes

Final answer:

The acceptable methods of group nesting in a corporate network with multiple Active Directory domains are A-G-L-P and A-G-DL-P. These methods help organize users and resources effectively across domains.

Step-by-step explanation:

When it comes to implementing a group nesting strategy in a corporate network spanning more than one Active Directory domain, the acceptable methods are A-G-L-P (Accounts-Global-Local-Permissions) and A-G-DL-P (Accounts-Global-Domain Local-Permissions).

The A-G-L-P strategy is used when you have trusts between domains and each domain is responsible for maintaining its own groups. Within this strategy, user accounts (A) are put into global groups (G) based on their roles, those global groups are then nested into domain local groups (L) that relate to the resource being accessed, and permissions (P) are assigned to those domain local groups.

On the other hand, A-G-DL-P is similar but it involves domain local groups (DL) and is used within a single domain where the domain local group has access to resources within the same domain, where permissions are assigned to that domain local group.

Both A-G-L-P and A-G-DL-P are effective for organizing users and resources in large and complex networks.

User Panos Boc
by
8.4k points