exam questions

Exam 70-742 All Questions

View all questions & answers for the 70-742 exam

Exam 70-742 topic 1 question 105 discussion

Actual exam question from Microsoft's 70-742
Question #: 105
Topic #: 1
[All 70-742 Questions]

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory domain named contoso.com. The domain contains two domain controllers named DC1 and DC2.
DC1 holds the RID master operations role. DC1 fails and cannot be repaired. You need to move the RID role to DC2.
Solution: On DC2, you open the command prompt, run ntdsutil.exe, connect to DC2, and use the Transfer RID master option.
Does this meet the goal?

  • A. Yes
  • B. No
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
There are 2 ways of transferring FSMO roles. You can do that using graphical consoles available on a DC or any server/workstation with Administrative Tools /
Remote Server Administration Tools installed or using command-line tool called ntdsutil.
First of all you need to connect to Domain Controller to which you want to transfer FSMO roles. To do that you have to type: ntdsutil: roles (enter) fsmo maintenance: connections (enter) server connections: connect to server <DC-Name> (enter) server connections: quit (enter) fsmo maintenance:
Now you will be able to transfer FSMO roles to selected Domain Controller.
✑ RID master
fsmo maintenance: transfer RID master (enter)
Click ג€Yesג€ button to move role.
References:
https://www.faqforge.com/windows-server-2012-r2/transfer-fsmo-roles-another-active-directory-domain-controller-windows-server-2012-r2-using-ntdsutil-utility/

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Charchar
Highly Voted 5 years, 6 months ago
The DC has failed, you can't transfer the role but you can seize it. The given answer is therefore wrong
upvoted 14 times
lbs
4 years, 10 months ago
Agree. Correct answer is No. Transfer RID Master Option is incorrect. It should be Seize RID Master Option. https://blog.stealthbits.com/what-are-fsmo-roles-active-directory/
upvoted 3 times
GenjamBhai
4 years, 8 months ago
B is ok If you have to seize the RID master role, consider using the Move-ADDirectoryServerOperationMasterRole cmdlet instead of the Ntdsutil.exe utility. https://support.microsoft.com/en-us/help/255504/using-ntdsutil-exe-to-transfer-or-seize-fsmo-roles-to-a-domain-control To avoid the risk of duplicate SIDs in the domain, Ntdsutil increments the next available RID in the pool by 10,000 when you seize the RID master role. This behavior can cause your forest to completely consume its available ranges for RID values (also known as "RID burn"). In contrast, if you use the PowerShell cmdlet to seize the RID master role, the next available RID is not affected.
upvoted 3 times
...
...
...
MrRiver
Highly Voted 5 years, 5 months ago
agree with post above ... you need to seize role if original ownwer ist offline
upvoted 5 times
...
lofzee
Most Recent 4 years, 3 months ago
if you try a transfer, it will fail purely because the other DC is offline. You need to either use the -force parameter in powershell or 'seize' the role from ntdsutil. answer = b
upvoted 1 times
...
Yebubbleman
4 years, 3 months ago
The stated specifics of the solution are also messy.
upvoted 1 times
...
mikl
4 years, 3 months ago
Answer is B - for sure. You cannot transfer FSMO roles from a DC that is failed, it has to be seize. Anything I am missing here?
upvoted 1 times
...
Alma30
4 years, 3 months ago
Answer is NO, it should be seized. https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/transfer-or-seize-fsmo-roles-in-ad-ds
upvoted 1 times
...
xosol
4 years, 6 months ago
The answer is wrong - you need to run ntdsutil with the seize option, not transfer. the DC has failed. from: https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/transfer-or-seize-fsmo-roles-in-ad-ds To seize the RID master role, type seize rid master.
upvoted 1 times
...
Diffie
4 years, 7 months ago
Answer is B We recommend that you transfer FSMO roles in the following scenarios: The current role holder is operational and can be accessed on the network by the new FSMO owner. You are gracefully demoting a DC that currently owns FSMO roles that you want to assign to a specific DC in your Active Directory forest. The DC that currently owns FSMO roles is being taken offline for scheduled maintenance, and you have to assign specific FSMO roles to live DCs. You may have to transfer roles to perform operations that affect the FSMO owner. This is especially true for the PDC Emulator role. This is a less important issue for the RID master role, the Domain naming master role, and the Schema master roles. We recommend that you seize FSMO roles in the following scenarios: The current role holder is experiencing an operational error that prevents an FSMO-dependent operation from completing successfully, and you cannot transfer the role. https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/transfer-or-seize-fsmo-roles-in-ad-ds
upvoted 2 times
...
Kamikazekiller
4 years, 9 months ago
The answer is correct. On DC2, you open the command prompt, run ntdsutil.exe, connect to DC2, and use the Transfer RID master option.
upvoted 1 times
3emek
4 years, 9 months ago
Hi Kamikaze, are you sure? All comments above say that the answer is B
upvoted 5 times
...
...
Protomike
4 years, 9 months ago
The Answer should be NO. The reference is in the next question: "This would work if DC1 was still online. In that case we would be "transferring" the role. However, as DC1 is offline, we need to "seize" the role which can only be done by using the ntdsutil command or the Move-AddirectoryServerOperationMasterRole PowerShell cmdlet with the -Force parameter."
upvoted 1 times
...
khalid86
4 years, 11 months ago
Answer is B
upvoted 1 times
...
iemsabi
4 years, 12 months ago
Should be B The suggestion is to: use the Transfer RID-master option. You need to seize the Ridmaster so the answer should be use the Seize RID-master option.
upvoted 3 times
...
Sparrow033
5 years, 1 month ago
As DC1 is offline, we need to “seize” the role which can only be done by using the ntdsutil command or the Move-AddirectoryServerOperationMasterRole PowerShell cmdlet with the -Force parameter.
upvoted 1 times
...
adasko
5 years, 1 month ago
You can seize with ntdsutil https://www.dtonias.com/seize-fsmo-roles-domain-controller/
upvoted 1 times
gysh
5 years, 1 month ago
Yes but the question says Transfer command on a Failed DC so the answer is no
upvoted 5 times
...
...
Nhan
5 years, 2 months ago
The answer is correct, you can also transfer the RID Mayer using PowerShell Move-ADDirectoryServerOperationMasterRole -Identity USER04-DC1 -OperationMasterRole RIDMaster,InfrastructureMaster,DomainNamingMaster -Force Even the machine currently hold the RIDmater is down. You won’t enable to transfer the schema forest master if the machine is down.
upvoted 3 times
gysh
5 years, 1 month ago
But the command is Transfer not move or Seize so should be no
upvoted 4 times
...
...
ITGEEK
5 years, 2 months ago
I believe answer is Yes. Yes its right that first you need to seize the role, but u can seize the role with NTDSUTIL https://www.petri.com/seizing_fsmo_roles
upvoted 1 times
...
beefy
5 years, 2 months ago
You can do this with ntdsutil, but "seize" and "transfer" are different options. In this case you would need to seize the role, so transfer is incorrect
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago