AZ-802 Deploy and Manage AD DS Practice Question
Your company is merging with another firm. You need to allow users in the 'contoso.com' forest to access resources in the 'fabrikam.com' forest. The solution must ensure that users from Fabrikam cannot access any resources in Contoso unless specifically granted permission on each individual resource. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A one-way outgoing forest trust with selective authentication.
A one-way forest trust with selective authentication is the most secure way to connect two forests. The 'one-way' aspect limits the direction of trust, while 'selective authentication' prevents trusted users from automatically being part of the 'Authenticated Users' group on resources in the trusting domain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A two-way forest trust with forest-wide authentication.
Why it's wrong here
A two-way trust would allow users from both forests to potentially access each other's resources, which exceeds the requirement. Furthermore, forest-wide authentication automatically adds trusted users to the 'Authenticated Users' group, granting them broad access that the scenario specifically aims to restrict for security reasons.
- ✓
A one-way outgoing forest trust with selective authentication.
Why this is correct
A one-way outgoing trust (from Contoso's perspective) allows Contoso to trust Fabrikam. By enabling selective authentication, administrators must manually grant Fabrikam users the 'Allowed to Authenticate' permission on specific computer objects in Contoso, ensuring the highest level of granular control over resource access.
- ✗
An external trust with SID filtering disabled.
Why it's wrong here
External trusts are intended for specific domains rather than entire forests and are less efficient for forest-wide resource sharing. Disabling SID filtering is a significant security risk that could allow for privilege escalation attacks, which is contrary to the requirement of maintaining a highly secure environment.
- ✗
A realm trust with a non-Windows Kerberos environment.
Why it's wrong here
Realm trusts are specifically used to establish a relationship between an Active Directory domain and a non-Windows Kerberos v5 realm, such as Linux. Since both organizations in this scenario are using Active Directory forests, a standard forest trust is the appropriate and required solution.
About these practice questions
This AZ-802 question is part of Courseiva's 116-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.