Courseiva
Deploy and Manage AD DShardMultiple ChoiceObjective-mapped

AZ-802 Deploy and Manage AD DS Practice Question

You are deploying a Read-Only Domain Controller (RODC) in a branch office with low physical security. You need to ensure that the branch manager, who is not a member of Domain Admins, can log on to the RODC even if the WAN link to the main office is down. What must you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The Password Replication Policy (PRP) of the RODC.

By default, RODCs do not store user passwords. To allow a user to log on when the WAN link is unavailable, their credentials must be cached locally. This is achieved by adding the user or their group to the 'Allowed RODC Password Replication Group' or modifying the RODC's Password Replication Policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The Managed By tab in the RODC computer account properties.

    Why it's wrong here

    Setting the 'Managed By' property allows a specific user to perform administrative tasks on the RODC, such as installing updates or joining the server to the domain. However, it does not automatically grant that user the right to have their password replicated and cached for offline authentication.

  • The Password Replication Policy (PRP) of the RODC.

    Why this is correct

    The Password Replication Policy determines which user and computer credentials can be cached on an RODC. By adding the branch manager to the 'Allowed' list in the PRP, the RODC will store a copy of their password, enabling authentication even when the central domain controllers are unreachable.

  • The Default Domain Controllers Policy for the site.

    Why it's wrong here

    The Default Domain Controllers Policy applies Group Policy settings to all DCs in the OU, such as security rights and auditing. While it can control who can log on locally, it cannot override the fundamental RODC behavior regarding password caching, which is managed strictly via the PRP.

  • The Global Catalog role on the branch office RODC.

    Why it's wrong here

    Enabling the Global Catalog on an RODC allows it to resolve multi-domain group memberships and universal groups locally. However, without the user's password being explicitly allowed for replication via the PRP, the user still cannot authenticate against the RODC if the link to a writeable DC is down.

About these practice questions

This AZ-802 question is part of Courseiva's 116-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.