You need to delegate administrative control of a specific DNS zone to a junior administrator without giving them rights to other zones or the DNS server configuration. What is the correct approach?
-
A
Add the user to the DnsAdmins group for that zone's security descriptor only via the zone's ACL
-
B
Make the user a local administrator on the DNS server
-
C
Add the user to the Domain Admins group with restricted logon hours
-
D
Create a custom MMC console with the DNS snap-in for that zone only