A county places a read-only domain controller at a lightly secured branch with a weak password-caching policy. What AD design risk is most relevant?
Select an answer to reveal the explanation.
Short Explanation
An RODC is a locked display case — useful, but only if you do not stash the master keys inside a glass storefront. Bad placement or over-caching puts secrets where physical and network controls are weaker. Design the branch case carefully.
Full Explanation
Read-only domain controllers reduce some attack surfaces at remote sites, but placement and password replication policies still matter. Caching sensitive accounts at poorly controlled locations increases exposure if the RODC is stolen or compromised. RODCs do not become schema masters, nor do they require caching all privileged secrets. Reviewers should treat RODC policy and siting as AD architecture risk awareness items.