Khozi from New Zealand – 04 26 2011, 9:14 AM Report Spam To Vernon:Actually you can use Dsmod with the -remmbr option can remove members from a group Spider from United States – 04 05 2011, 8:23 AM Report Spam Think answer's explanation is wrong. Question is just tricky: a normal user does not have default right to modify SOA records in any case, therefore you just need to give permission for the contoso.com zone. gipson from Bulgaria – 04 04 2011, 9:37 AM Report Spam In Exam B one of the questions is wrong or the answer and the explanation is wrong.Question: Your network consists of an Active Directory forest that contains one domain named contoso.com. All domain controllers run Windows Server 2008 R2 and are configured as DNS servers. You have two Active Directory-integrated zones: contoso.com and nwtraders.com. You need to ensure a user is able to modify records in the contoso.com zone. You must prevent the user from modifying the SOA record in the nwtraders.com zone. What should you do? Answer:C.