单项选择题

Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your  company uses an Enterprise Root certification authority (CA) and an Enterprise Intermediate CA.    
The Enterprise Intermediate CA certificate expires.    
You need to deploy a new Enterprise Intermediate CA certificate to all computers in the domain.    
What should you do()

A.Import the new certificate into the Intermediate Certification Store on the Enterprise Root CA server.
B.Import the new certificate into the Intermediate Certification Store on the Enterprise Intermediate CA server.
C.Import the new certificate into the Intermediate Certification Store in the Default Domain Controllers group policy ob
D.Import the new certificate into the Intermediate Certification Store in the Default Domain group policy object.


您可能感兴趣的试卷

你可能感兴趣的试题

1.多项选择题

Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your  company runs an Enterprise Root certification authority (CA).    
You need to ensure that only administrators can sign code.    
Which two tasks should you perform()

A.Publish the code signing template.
B.Edit the local computer policy of the Enterprise Root CA to allow users to trust peer certificates and allow only admi
C.Edit the local computer policy of the Enterprise Root CA to allow only administrators to manage Trusted Publishers.
D.Modify the security settings on the template to allow only administrators to request code signing certificates.

2.单项选择题

You have two servers named Server1 and Server2. Both servers run Windows Server 2008 R2.  Server1 is configured as an enterprise root certification authority (CA).    
You install the Online Responder role service on Server2. You need to configure Server1 to  support the Online Responder.    
What should you do()

A.Import the enterprise root CA certificate.
B.Configure the Certificate Revocation List Distribution Point extension.
C.Configure the Authority Information Access (AIA) extension.
D.Add the Server2 computer account to the CertPublishers group.

3.多项选择题

You have a Windows Server 2008 R2 Enterprise Root certification authority (CA). You need to  grant members of the Account Operators group the ability to only manage Basic EFS certificates.    
You grant the Account Operators group the Issue and Manage Certificates permission on the CA .  
Which three tasks should you perform next()

A.Enable the Restrict Enrollment Agents option on the CA .
B.Enable the Restrict Certificate Managers option on the CA .
C.Add the Basic EFS certificate template for the Account Operators group.
D.Grant the Account Operators group the Manage CA permission on the CA .
E.Remove all unnecessary certificate templates that are assigned to the Account Operators group.

4.单项选择题

Your company has an Active Directory domain. 
You install an Enterprise Root certification authority (CA) on a member server named Server1.  You need to ensure that only the Security Manager is authorized to revoke certificates that are  supplied by Server1.    
What should you do()

A.Remove the Request Certificates permission from the Domain Users group.
B.Remove the Request Certificates permission from the Authenticated Users group.
C.Assign the Allow - Manage CA permission to only the Security Manager user account.
D.Assign the Allow - Issue and Manage Certificates permission to only the Security Manager user account.

5.多项选择题

Your company has a server that runs Windows Server 2008 R2. Active Directory Certificate  Services (AD CS) is configured as a standalone Certification Authority (CA) on the server. You  need to audit changes to the CA configuration settings and the CA security settings.    
Which two tasks should you perform()

A.Configure auditing in the Certification Authority snap-in.
B.Enable auditing of successful and failed attempts to change permissions on files in the %SYSTEM32%\CertSrv dire
C.Enable auditing of successful and failed attempts to write to files in the %SYSTEM32%\CertLog directory.
D.Enable the Audit object access setting in the Local Security Policy for the Active Directory Certificate Services

6.单项选择题

You have a Windows Server 2008 R2 Enterprise Root CA . Security policy prevents port 443 and  port 80 from being opened on domain controllers and on the issuing CA .  
You need to allow users to request certificates from a Web interface. You install the Active  Directory Certificate Services (AD CS) server role.    
What should you do next()

A.Configure the Online Responder Role Service on a member server.
B.Configure the Online Responder Role Service on a domain controller.
C.Configure the Certificate Enrollment Web Service role service on a member server.
D.Configure the Certificate Enrollment Web Service role service on a domain controller.

7.单项选择题

You have a Windows Server 2008 R2 that has the Active Directory Certificate Services server  role installed.  
You need to minimize the amount of time it takes for client computers to download a certificate  revocation list (CRL).    
What should you do()

A.Install and configure an Online Responder.
B.Install and configure an additional domain controller.
C.Import the Root CA certificate into the Trusted Root Certification Authorities store on all client workstations.
D.Import the Issuing CA certificate into the Trusted Root Certification Authorities store on all client workstations.

9.单项选择题

You have an Active Directory domain that runs Windows Server 2008 R2. You need to implement  a certification authority (CA) server that meets the following requirements:    
- Allows the certification authority to automatically issue certificates  - Integrates with Active Directory Domain Services    
What should you do()

A.Install and configure the Active Directory Certificate Services server role as a Standalone Root CA .
B.Install and configure the Active Directory Certificate Services server role as an Enterprise Root CA .
C.Purchase a certificate from a third-party certification authority. Install and configure the Active Directory Certificate S
D.Purchase a certificate from a third-party certification authority. Import the certificate into the computer store of the sc

10.单项选择题

Your network consists of a single Active Directory domain. All domain controllers run Windows  Server 2008 R2.    
You need to capture all replication errors from all domain controllers to a central location.    
What should you do()

A.Configure event log subscriptions.
B.Start the System Performance data collector set.
C.Start the Active Directory Diagnostics data collector set.
D.Install Network Monitor and create a new capture.

最新试题

Your network contains an Active Directory forest. All domain controllers run Windows Server  2008 Standard. The functional level of the domain is Windows Server 2003. You have a  certification authority (CA).  The relevant servers in the domain are configured as shown in the following table:    Server name  Operating system  Server role  Server1  Windows Server 2003  Enterprise root CA  Server2  Windows Server 2008  Enterprise subordinate CA  Server3  Windows Server 2008 R2  Web Server  You need to ensure that you can install the Active Directory Certificate Services (AD CS)  Certificate Enrollment Web Service on the network.    What should you do()

题型:单项选择题

Your network contains an Active Directory domain named contoso.com. Contoso.com contains  three servers.The servers are configure as shown in the following table.    Server name   Server roel Service  Server1                          Certification authority (CA)  Server2                         Certificate Enrollment Web Service  Server3                          Certificate Enrollment Policy Web Service  You need to ensure that users can manually enroll and renew their certificates by using the  Certificate Enrollment Web Service.    Which two actions should you perform()

题型:多项选择题

Your network contains three Active Directory forest named Forest1, Forest2, and Forest3. Each  forest contains three domains.  A two-way forest trust exists between Forest1 and Forest2. A two-way forest trust exists between  Forest2 and Forest3.     You need to configure the forest to meet the following requirements    Users in Forest3 must be able to access resources in Forest1.  Users in Forest1 must be able to access resources in Forest3.  The number of trusts must be minimized.    What should you do()

题型:单项选择题

Your network contains an Active Directory forest. The forest contains two domain controllers. The  domain controllers are configured as shown in the following table. All client computers run Windows 7.    You need to ensure that all client computers in the domain keep the same time as an external  time server.    What should you do()

题型:单项选择题

You have an enterprise subordinate certification authority (CA). The CA is configured to use a  hardware security module.  You need to back up Active Directory Certificate Services on the CA.    Which command should you run()

题型:单项选择题

You have an enterprise subordinate certification authority (CA). You have a group named  Group1.    You need to allow members of Group1 to publish new certificate revocation lists. Members of  Group1 must not be allowed to revoke certificates.    What should you do()

题型:单项选择题

Your network contains an Active Directory domain. The domain contains a group named Group1.  The minimum password lenght for the domain is set to six characters.  you need to ensure that the passwords for all users in Group1 are at least 10 characters long. All  other users must be able to use passwords that are six characters long.    What should you do first()

题型:单项选择题

You create a new Active Directory domain. The functional level of the domain is Windows Server  2008 R2.  The domain contains five domain controllers. You need to monitor the replication of the group  policy template files. Which tool should you use()

题型:单项选择题

Your network contains an Active Directory domain named contoso.com. Contoso.com contains a  member server that runs Windows Serever 2008 Standart.  You need to install an enterprise subordinate certification authority (CA) that support private key  archival. You must achieve this goal by using the minimum amount of administrative effort.What do you do first()

题型:单项选择题

You remotely monitor several domain controllers.  You run winrm.exe quickconfig on each domain controller. You need to create a WMI script query  to retrieve information from the bios of each domain controller.    Which format should you use to write the query()

题型:单项选择题