Identity with Windows Server 2016 — Question 113
Your network contains an Active Directory domain named contoso.com.
You have an organizational unit (OU) named OU1. A Group Policy object (GPO) named GPO1 is linked to OU1.
You create a user named User1, and you assign User1 the Full control permission to OU1.
Which administrative action for GPOs can User1 perform?
Answer options
- A. Link an existing GPO from the domain to OU1
- B. Create a new GPO and link the GPO to OU1
- C. Add an administrative template to GPO1
- D. Edit the User Rights Assignment in GPO1
Correct answer: A
Explanation
User1, having Full control permission on OU1, can link an existing GPO from the domain to OU1, which is why option A is correct. However, User1 does not have permission to create a new GPO (option B), add templates (option C), or edit User Rights Assignments (option D), as those actions typically require higher-level permissions than Full control of an OU.