1.What are the two independent properties every Active Directory group has?
2.A distribution group is nested inside a security group that has write access to a file share. Can the distribution group's members reach that share through this nesting?
3.Which scope can contain members from any domain in the forest but can only be granted permissions within its own domain?
4.Why can a global group not contain a member from a different domain?
5.Why does only universal group membership replicate to the global catalog, while domain local and global group membership does not?
6.You query the global catalog for a resource's full group membership and get a result. What is the risk in trusting that result as complete?
7.A user in Domain A appears to have access to a resource in Domain B, and the access does not come from a global group directly. What must be true about how that access is structured?