单项选择题

You have an enterprise subordinate certification authority (CA). The CA issues smart card logon  certificates.    
Users are required to log on to the domain by using a smart card. Your company’s corporate  security policy states that when an employee resigns, his ability to log on to the network must be  immediately revoked.    
An employee resigns. You need to immediately prevent the employee from logging on to the  domain.    
What should you do()

A.Revoke the employee’s smart card certificate.
B.Disable the employee’s Active Directory account.
C.Publish a new delta certificate revocation list (CRL).
D.Reset the password for the employee’s Active Directory account.


您可能感兴趣的试卷

你可能感兴趣的试题

1.单项选择题

Your network contains an enterprise root certification authority (CA). You need to ensure that a  certificate issued by the CA is valid.    
What should you do()

A.Run syskey.exe and use the Update option.
B.Run sigverif.exe and use the Advanced option.
C.Run certutil.exe and specify the -verify parameter.
D.Run certreq.exe and specify the -retrieve parameter.

9.多项选择题

You have Active Directory Certificate Services (AD CS) deployed.  You create a custom certificate template.  
You need to ensure that all of the users in the domain automatically enroll for a certificate based on the  custom certificate template.  
Which two actions should you perform()

A.In a Group Policy object (GPO), configure the autoenrollment settings
B.In a Group Policy object (GPO), configure the Automatic Certificate Request Settings.
C.On the certificate template, assign the Read and Autoenroll permission to the Authenticated Users  group.
D.On the certificate template, assign the Read, Enroll, and Autoenroll permission to the Domain Users  group.

最新试题

You have a domain controller named Server1 that runs Windows Server 2008 R2.    You need to determine the size of the Active Directory database on Server1.    What should you do()

题型:单项选择题

Your network contains an Active Directory forest. All domain controllers run Windows Server  2008 Standard. The functional level of the domain is Windows Server 2003. You have a  certification authority (CA).  The relevant servers in the domain are configured as shown in the following table:    Server name  Operating system  Server role  Server1  Windows Server 2003  Enterprise root CA  Server2  Windows Server 2008  Enterprise subordinate CA  Server3  Windows Server 2008 R2  Web Server  You need to ensure that you can install the Active Directory Certificate Services (AD CS)  Certificate Enrollment Web Service on the network.    What should you do()

题型:单项选择题

Your network contains an Active Directory domain that contains five domain controllers. You have  a management computer that runs Windows 7.  From the Windows 7 computer, you need to view all account logon failures that occur in the  domain.    The information must be consolidated on one list.  Which command should you run on each domain controller()

题型:单项选择题

You have an enterprise subordinate certification authority (CA) configured for key archival. Three  key recovery agent certificates are issued.  The CA is configured to use two recovery agents.    You need to ensure that all of the recovery agent certificates can be used to recover all new  private keys.    What should you do()

题型:单项选择题

Your network contains two Active Directory forests named contoso.com and    nwtraders.com. A  two-way forest trust exists between contoso.com and nwtraders.com. The forest trust is  configured to use selective authentication.  Contoso.com contains a server named Server1. Server1 contains a shared folder named  Marketing. Nwtraders.com contains a global group named G_Marketing. The Change share  permission and the Modify NTFS permissions for the Marketing folder are assignes to the  G_Marketing group.  Members of G_Marketing report that they cannot accesss the Marketing folder.  You need to ensure that the G_Marketing members can accesss the folder from the network.    What should you do()

题型:单项选择题

Your network contains an Active Directory domain. The domain contains a group named Group1.  The minimum password lenght for the domain is set to six characters.  you need to ensure that the passwords for all users in Group1 are at least 10 characters long. All  other users must be able to use passwords that are six characters long.    What should you do first()

题型:单项选择题

You have an enterprise subordinate certification authority (CA). You have a custom Version 3  certificate template.    Users can enroll for certificates based on the custom certificate template by using the Certificates  console.    The certificate template is unavailable for Web enrollment. You need to ensure that the certificate  template is available on the Web enrollment pages.    What should you do()

题型:单项选择题

You have an enterprise subordinate certification authority (CA). You have a group named  Group1.    You need to allow members of Group1 to publish new certificate revocation lists. Members of  Group1 must not be allowed to revoke certificates.    What should you do()

题型:单项选择题

Your network contains an Active Directory forest. The forest contains an Acitve Directory site for a  remote office. The remote site contains a read-only domain controller (RODC).    You need to configure the RODC to store only the password of users in the remote site.    What should you do()

题型:单项选择题

Your network contains an Active Directory forest. The forest contains two domain controllers. The  domain controllers are configured as shown in the following table. All client computers run Windows 7.    You need to ensure that all client computers in the domain keep the same time as an external  time server.    What should you do()

题型:单项选择题