I don't know about legalities, but that's not how I would do it. Set up a new VM running Windows 2000 and promote to a DC on the current domain. Allow everything to replicate. Then remove the VM DC from the network, seize the FSMO roles and metadata cleanup the other (phsyical DC). You now have an exact copy of your domain.
The key in both scenarios is to NEVER EVER rejoin the VM DC to the production network. Also, if you are thinking about using images to backup DCs, forget it. It is completely unsupported and a wonderful way to completely fubar your domain.