Difficulty: Medium
Correct Answer: Create a global group in BASS (Gbl-Admins) containing Lisa, and add BASS\Gbl-Admins to the local Administrators group in TUNA
Explanation:
Introduction / Context:Classic Windows NT domain administration employs well-known group scoping rules and trust relationships. With a one-way trust where TUNA trusts BASS, TUNA may assign permissions to security principals from BASS. Using the correct combination of global and local groups is crucial for least privilege and manageability.
Given Data / Assumptions:
Concept / Approach:Global groups contain user accounts from their own domain; local groups (on a member server or domain local in later models) grant rights on resources. Best practice: put users into a global group in their account domain, then add that global group to a local Administrators group in the resource domain. Because TUNA trusts BASS, TUNA can place a BASS global group into its local Administrators.
Step-by-Step Solution:
Create BASS\Gbl-Admins and add BASS\Lisa to it.On a TUNA server or in domain local context, add BASS\Gbl-Admins to TUNA's local Administrators.Trust allows TUNA to validate BASS identities and grant rights accordingly.Lisa now has administrative rights in TUNA while the trust is in place.Verification / Alternative check:Log in as BASS\Lisa and open Computer Management on a TUNA server; verify administrative tasks are permitted. Audit group membership to confirm effective rights.
Why Other Options Are Wrong:
Common Pitfalls:Confusing global vs local scope nesting rules and granting Domain Admins unnecessarily, which over-privileges the user beyond the specific administrative need.
Final Answer:Create a global group in BASS (Gbl-Admins) containing Lisa, and add BASS\Gbl-Admins to the local Administrators group in TUNA
Discussion & Comments