Which tool provides granular control to allow or disallow inheritance of a policy from one group or container to another?

Study for the CompTIA SecurityX Test. Equip yourself with comprehensive flashcards and multiple choice questions that include hints and explanations. Gear up for your certification exam!

Multiple Choice

Which tool provides granular control to allow or disallow inheritance of a policy from one group or container to another?

Explanation:
Managing how policies flow between containers in Active Directory is about Group Policy inheritance, and the Group Policy Management Console is the tool that controls this flow. GPMC lets you view, link, and manage Group Policy Objects across domains, sites, and organizational units, giving you precise control over where a policy is applied. You can enable or block inheritance on a specific container, and you can enforce a GPO so its settings take precedence over others higher up in the hierarchy. This combination—linking policies to containers and adjusting how they inherit—provides the granular control described in the question. The other options don’t fit this function. An Air Gap describes complete network isolation, which has nothing to do with how policies cascade. Region-Based Segmentation is about dividing a network into segments, not about policy inheritance. Data Zone isn’t a standard tool for managing policy inheritance.

Managing how policies flow between containers in Active Directory is about Group Policy inheritance, and the Group Policy Management Console is the tool that controls this flow. GPMC lets you view, link, and manage Group Policy Objects across domains, sites, and organizational units, giving you precise control over where a policy is applied. You can enable or block inheritance on a specific container, and you can enforce a GPO so its settings take precedence over others higher up in the hierarchy. This combination—linking policies to containers and adjusting how they inherit—provides the granular control described in the question.

The other options don’t fit this function. An Air Gap describes complete network isolation, which has nothing to do with how policies cascade. Region-Based Segmentation is about dividing a network into segments, not about policy inheritance. Data Zone isn’t a standard tool for managing policy inheritance.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy