单项选择题

You have an enterprise subordinate certification authority (CA).  
You have a group named Group1.  
You need to allow members of Group1 to publish new certificate revocation lists. Members of Group1  must not be allowed to revoke certificates.  
What should you do()

A.Add Group1 to the local Administrators group.
B.Add Group1 to the Certificate Publishers group.
C.Assign the Manage CA permission to Group1.
D.Assign the Issue and Manage Certificates permission to Group1.


您可能感兴趣的试卷

你可能感兴趣的试题

1.单项选择题

Your network contains an Active Directory forest. The forest contains two domains.  You have a standalone root certification authority (CA).  
On a server in the child domain, you run the Add Roles Wizard and discover that the option to select an  enterprise CA is disabled.  
You need to install an enterprise subordinate CA on the server.  
What should you use to log on to the new server()

A.an account that is a member of the Certificate Publishers group in the child domain
B.an account that is a member of the Certificate Publishers group in the forest root domain
C.an account that is a member of the Schema Admins group in the forest root domain
D.an account that is a member of the Enterprise Admins group in the forest root domain

4.单项选择题

Your network contains an Active Directory domain named contoso.com.  You have a management computer named Computer1 that runs Windows 7.  
You need to forward the logon events of all the domain controllers in contoso.com to Computer1. All new  domain controllers must be dynamically added to the subscription.  
What should you do()

A.From Computer1, configure source-initiated event subscriptions. From a Group Policy object (GPO)  linked to the Domain Controllers organizational unit (OU), configure the Event Forwarding node.
B.From Computer1, configure collector-initiated event subscriptions. From a Group Policy object (GPO)  linked to the Domain Controllers organizational unit (OU), configure the Event Forwarding node.
C.From Computer1, configure source-initiated event subscriptions. Install a serverauthentication  certificate on Computer1. Implement autoenrollment for the Domain Controllers organizational unit (OU).
D.From Computer1, configure collector-initiated event subscriptions. Install a server authentication  certificate on Computer1. Implement autoenrollment for the Domain Controllers organizational unit (OU).

5.单项选择题

You need to receive an e-mail message whenever a domain user account is locked out.  
Which tool should you use()

A.Active Directory Administrative Center
B.Event Viewer
C.Resource Monitor
D.Security Configuration Wizard

6.单项选择题

You have a domain controller named Server1 that runs Windows Server 2008 R2.  You need to determine the size of the Active Directory database on Server1.  
What should you do()

A.Run the Active Directory Sizer tool.
B.Run the Active Directory Diagnostics data collector set.
C.From Windows Explorer, view the properties of the %systemroot%\ntds\ntds.dit file.
D.From Windows Explorer, view the properties of the %systemroot%\sysvol\domain folder.

10.多项选择题

Your network contains an Active Directory domain named contoso.com. The domain contains 
five  domain controllers.  
You add a logoff script to an existing Group Policy object (GPO).  
You need to verify that each domain controller successfully replicates the updated group policy.  
Which two objects should you verify on each domain controller()

A.\\servername\SYSVOL\contoso.com\Policies\{GUID}\gpt.ini
B.\\servername\SYSVOL\contoso.com\Policies\{GUID}\machine\registry.pol
C.the uSNChanged value for the CN={GUID},CN=Policies,CN=System,DC=contoso,DC=com container  
D.the versionNumber value for the  CN={GUID},CN=Policies,CN=System,DC=contoso,DC=com  container

最新试题

You install a standalone root certification authority (CA) on a server named Server1.  You need to ensure that every computer in the forest has a copy of the root CA certificate  installed in the local computer’s Trusted Root Certification Authorities store.    Which command should you run on Server1()

题型:单项选择题

Your network contains an Active Directory forest. The forest contains an Acitve Directory site for a  remote office. The remote site contains a read-only domain controller (RODC).    You need to configure the RODC to store only the password of users in the remote site.    What should you do()

题型:单项选择题

Your network contain 10 domain controller that run Windows Server    R2.  The network contain a member server that is configured to collect all of events that occur on the  domain controllers.  Your need to ensure that administrators are notified when a specific event occurs on any of the  domain controllers. You want to achive the goal by using the minimum amount effort.  What should you do()

题型:单项选择题

You have an enterprise subordinate certification authority (CA). You have a group named  Group1.    You need to allow members of Group1 to publish new certificate revocation lists. Members of  Group1 must not be allowed to revoke certificates.    What should you do()

题型:单项选择题

Your network contains two Active Directory forests named contoso.com and    nwtraders.com. A  two-way forest trust exists between contoso.com and nwtraders.com. The forest trust is  configured to use selective authentication.  Contoso.com contains a server named Server1. Server1 contains a shared folder named  Marketing. Nwtraders.com contains a global group named G_Marketing. The Change share  permission and the Modify NTFS permissions for the Marketing folder are assignes to the  G_Marketing group.  Members of G_Marketing report that they cannot accesss the Marketing folder.  You need to ensure that the G_Marketing members can accesss the folder from the network.    What should you do()

题型:单项选择题

Your company has four offices.  The network contains a single Active Directory domain.  Each office has domain controller. Each office has an organitational unit (OU) that contains the  user accounts for the users in that office.  In each office, support technicians perform basic troubleshooting for the users in their respective  office.  You need to ensure that the support technicians can reset the password for the user accounts in  their respective office only. The solution must prevent the thechnicians from creating user  accounts.  What shoul you do()

题型:单项选择题

Your network contains an Active Directory domain. All domain controller run Windows Server  2003.    You replace all domain controllers with domain controllers that run Windows Server 2008 R2.    You raise the functional level of the domain to Windows Server 2008 R2.    You need to minimize the amount of SYSVOL replication traffic on the network.    What should you do()

题型:单项选择题

You have Active Directory Certificate Services (AD CS) deployed. You create a custom certificate  template.  You need to ensure that all of the users in the domain automatically enroll for a certificate based  on the custom certificate template.    Which two actions should you perform()

题型:多项选择题

Your network contains an Active Directory domain that has two sites.    You need to identify whether logon scripts are replicated to all domain controllers.    Which folder should you verify()

题型:单项选择题

You have an enterprise subordinate certification authority (CA). The CA is configured to use a  hardware security module.  You need to back up Active Directory Certificate Services on the CA.    Which command should you run()

题型:单项选择题