To Which Servers Does an AD-Integrated DNS Zone Replicate?

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains the servers shown in the following table. On Server1, you create a DNS zone named Zone1.com as shown in the following exhibit. To which DNS servers is Zone1.com replicated? - image - image

  1. Server2 only Source Reference Answer
  2. Server2 and Server3 only
  3. Server2 and Server4 only
  4. Server2, Server3, and Server4 only
  5. Server2, Server3, Server4, and Server5

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Assesses knowledge of AD-integrated DNS replication boundaries, trapping candidates who confuse domain-scoped replication with forest-wide or standard zone transfer mechanisms.

This question evaluates the replication behavior of Active Directory-Integrated DNS zones within an AD DS infrastructure. Exam takers consistently confirm that such zones restrict replication to other domain controllers located within the identical domain.

Option B is commonly selected when candidates overlook that child domain controllers or servers outside the target domain do not receive automatic replication from a parent domain's AD-integrated zone.

Community Discussion (7 comments)

makonmakon 👍 7
A, Server 2 only. You van replicate AD integrated dns zones only to other DC's in the same domain.
Ksk08 👍 1
answer is A server 2 only
AmeliusJan 👍 2 Selected: A
" You Can replicate AD integrated DNS zones only to other DC's in the same domain."
Krayzr 👍 2 Selected: A
" You Can replicate AD integrated DNS zones only to other DC's in the same domain." True
AK_1234 👍 2
Answer A- Server 2 only
Kuikz 👍 4 Selected: A
A. Server2 only
pnewcap 👍 3
The correct answer is B. Server2 and Server3 only. The DNS zone Zone1.com is configured to replicate to all DNS servers in the domain contoso.com. This means it will be replicated to all DNS servers that are also domain controllers in the same domain, which are Server2 and Server3 in this case. Server4 and Server5 are in a different domain (east.contoso.com), so they will not receive the replication of this zone. Therefore, Zone1.com is replicated to Server2 and Server3 only.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Active Directory-Integrated DNS zones store their data directly within the Active Directory database, leveraging the native replication mechanisms of AD DS. By default, this configuration restricts zone transfers exclusively to other Domain Controllers that reside in the exact same domain partition as the source server. Since Server1 and Server2 share the same domain identity, the zone automatically synchronizes between them without requiring manual configuration or additional transport protocols. This ensures tight security and immediate consistency across authoritative servers in that specific domain boundary.

Why the Other Options Are Wrong

Options involving Server3, Server4, and Server5 incorrectly assume broader replication scopes like forest-wide distribution or standard master/slave zone transfers. Child domain controllers operate under separate domain partitions and will not automatically inherit zones from a parent domain unless explicitly configured for forest-wide replication or secondary zone delegation. Furthermore, any non-Domain Controller nodes would never receive AD-integrated zone data regardless of network connectivity, as the replication engine strictly validates directory service permissions. Selecting multiple servers ignores the fundamental partition-based architecture of Active Directory DNS storage.

Community Comment Notes

Multiple high-voted comments correctly emphasize that AD-integrated zones are strictly bound to domain controllers within the same domain ([1], [3], [4]). While one candidate argued for Option B based on a misunderstanding of domain hierarchy, the overwhelming consensus aligns with the strict same-domain replication rule. Test-takers repeatedly validated this behavior through hands-on lab verification and official documentation reviews. These discussions highlight the importance of carefully mapping server roles and domain memberships before answering infrastructure questions.

Official Reference

Exam Strategy

Always map out each server's domain membership and role (DC vs member) against the zone's configured replication scope before eliminating options. Remember that AD-integrated zones prioritize directory partition boundaries over network topology, so forest-wide assumptions should only apply when explicitly stated in the scenario. Practicing AD partition visualization will quickly eliminate distractors related to child domains or external DNS servers.

Related Analysis

← Back to AZ-800 Study Guide