Your network contains an Active Directory forest named contoso.com. The forest contains a single domain.
All domain controllers run Windows Server 2012 R2.
The domain contains two domain controllers. The domain controllers are configured as shown in the
Active Directory Recycle Bin is enabled.
You discover that a support technician accidentally removed 100 users from an Active Directory group
named Group1 an hour ago.
You need to restore the membership of Group1.
What should you do?
A. Recover the items by using Active Directory Recycle Bin.
B. Modify the Recycled attribute of Group1.
C. Perform tombstone reanimation.
D. Perform an authoritative restore.
E. Perform a non-authoritative restore.
F. Modify the isDeleted attribute of Group1.
G. Apply a virtual machine snapshot to DC2.
Because removing user accounts from an Active Directory group will not send them to the Active Directory
Recycle Bin, performing an authoritative restore is the best option.