AZ-802 Deploy and Manage AD DS Practice Question
You are deploying a Read-Only Domain Controller (RODC) in a branch office with low physical security. You need to ensure that the branch manager, who is not a member of Domain Admins, can log on to the RODC even if the WAN link to the main office is down. What must you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Password Replication Policy (PRP) of the RODC.
By default, RODCs do not store user passwords. To allow a user to log on when the WAN link is unavailable, their credentials must be cached locally. This is achieved by adding the user or their group to the 'Allowed RODC Password Replication Group' or modifying the RODC's Password Replication Policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Managed By tab in the RODC computer account properties.
Why it's wrong here
Setting the 'Managed By' property allows a specific user to perform administrative tasks on the RODC, such as installing updates or joining the server to the domain. However, it does not automatically grant that user the right to have their password replicated and cached for offline authentication.
- ✓
The Password Replication Policy (PRP) of the RODC.
Why this is correct
The Password Replication Policy determines which user and computer credentials can be cached on an RODC. By adding the branch manager to the 'Allowed' list in the PRP, the RODC will store a copy of their password, enabling authentication even when the central domain controllers are unreachable.
- ✗
The Default Domain Controllers Policy for the site.
Why it's wrong here
The Default Domain Controllers Policy applies Group Policy settings to all DCs in the OU, such as security rights and auditing. While it can control who can log on locally, it cannot override the fundamental RODC behavior regarding password caching, which is managed strictly via the PRP.
- ✗
The Global Catalog role on the branch office RODC.
Why it's wrong here
Enabling the Global Catalog on an RODC allows it to resolve multi-domain group memberships and universal groups locally. However, without the user's password being explicitly allowed for replication via the PRP, the user still cannot authenticate against the RODC if the link to a writeable DC is down.
About these practice questions
This AZ-802 question is part of Courseiva's 116-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.