Windows Server Administration Fundamentals — Question 168
Your network is configured as single Active Directory Domain Services (AD DS) domain. Network member servers run Windows Server 2016 or Windows Server
2012 R2. Network clients run Windows 10.
You need to ensure that domain users cannot use Device Manager to update installed device drivers.
You want to minimize the effort needed to accomplish this goal.
Which should you use?
Answer options
- A. domain-linked Group Policy Object
- B. local system policy
- C. Windows Update
- D. remote administration
Correct answer: A
Explanation
Using a domain-linked Group Policy Object (GPO) allows for centralized management and enforcement of policies across all domain users, effectively preventing them from updating device drivers through Device Manager. Local system policy only applies to individual machines, which would not be efficient for a domain environment. Windows Update is not directly related to restricting device driver updates, and remote administration does not address user permissions regarding Device Manager.