To Which Servers Does an AD-Integrated DNS Zone Replicate?
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains the servers shown in the following table. On Server1, you create a DNS zone named Zone1.com as shown in the following exhibit. To which DNS servers is Zone1.com replicated? -
- 
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Assesses knowledge of AD-integrated DNS replication boundaries, trapping candidates who confuse domain-scoped replication with forest-wide or standard zone transfer mechanisms.
This question evaluates the replication behavior of Active Directory-Integrated DNS zones within an AD DS infrastructure. Exam takers consistently confirm that such zones restrict replication to other domain controllers located within the identical domain.
Option B is commonly selected when candidates overlook that child domain controllers or servers outside the target domain do not receive automatic replication from a parent domain's AD-integrated zone.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Active Directory-Integrated DNS zones store their data directly within the Active Directory database, leveraging the native replication mechanisms of AD DS. By default, this configuration restricts zone transfers exclusively to other Domain Controllers that reside in the exact same domain partition as the source server. Since Server1 and Server2 share the same domain identity, the zone automatically synchronizes between them without requiring manual configuration or additional transport protocols. This ensures tight security and immediate consistency across authoritative servers in that specific domain boundary.Why the Other Options Are Wrong
Options involving Server3, Server4, and Server5 incorrectly assume broader replication scopes like forest-wide distribution or standard master/slave zone transfers. Child domain controllers operate under separate domain partitions and will not automatically inherit zones from a parent domain unless explicitly configured for forest-wide replication or secondary zone delegation. Furthermore, any non-Domain Controller nodes would never receive AD-integrated zone data regardless of network connectivity, as the replication engine strictly validates directory service permissions. Selecting multiple servers ignores the fundamental partition-based architecture of Active Directory DNS storage.Community Comment Notes
Multiple high-voted comments correctly emphasize that AD-integrated zones are strictly bound to domain controllers within the same domain ([1], [3], [4]). While one candidate argued for Option B based on a misunderstanding of domain hierarchy, the overwhelming consensus aligns with the strict same-domain replication rule. Test-takers repeatedly validated this behavior through hands-on lab verification and official documentation reviews. These discussions highlight the importance of carefully mapping server roles and domain memberships before answering infrastructure questions.Official Reference
Exam Strategy
Always map out each server's domain membership and role (DC vs member) against the zone's configured replication scope before eliminating options. Remember that AD-integrated zones prioritize directory partition boundaries over network topology, so forest-wide assumptions should only apply when explicitly stated in the scenario. Practicing AD partition visualization will quickly eliminate distractors related to child domains or external DNS servers.