Certkiller .com has a domain controller that runs Windows Server 2008. The Certkiller .com network boosts 40 Windows Vista client machines. As an administrator at Certkiller .com, you want to deploy Active Directory Certificate service (AD CS) to authorize the network users by issuing digital certificates.  What should you do to manage certificate settings on all machines in a domain from one main location()A、Configure Enterprise CA certificate settingsB、Configure Enterprise trust certificate settingsC、Configure Advance CA certificate settingsD、Configure Group Policy certificate settingsE、All of the above

Certkiller .com has a domain controller that runs Windows Server 2008. The Certkiller .com network boosts 40 Windows Vista client machines. As an administrator at Certkiller .com, you want to deploy Active Directory Certificate service (AD CS) to authorize the network users by issuing digital certificates.  What should you do to manage certificate settings on all machines in a domain from one main location()

  • A、Configure Enterprise CA certificate settings
  • B、Configure Enterprise trust certificate settings
  • C、Configure Advance CA certificate settings
  • D、Configure Group Policy certificate settings
  • E、All of the above

相关考题:

Certkiller .com has asked you to develop an application that displays the properties for all Certkiller.com‘s network drives.The information generated by this application will be utilized by Certkiller .com‘s network administrators to verify client setups.You need to ensure that these requirements are fully satisfied.What should you do?()A.B.C.D.

Certkiller.com has servers on the main network that run Windows Server 2008. It also has two domain controllers. Active Directory services are running on a domain controller named CKDC1. You have to perform critical updates of Windows Server 2008 on CKDC1 without rebooting the server. What should you do to perform offline critical updates on CKDC1 without rebooting the server()A、Start the Active Directory Domain Services on CKDC1B、Disconnect from the network and start the Windows update featureC、Stop the Active Directory domain services and install the updates. Start the Active Directorydomain services after installing the updates.D、Stop Active Directory domain services and install updates. Disconnect from the network and then connect againE、None of the above

You are the network administrator for Contoso Pharmaceuticals. The network consists of a single Active Directory forest. The forest contains Windows Server 2003 servers and Windows XP Professional computers.   The forest consists of a forest root domain named contoso.com and two child domains named child1.contoso.com and child2.contoso.com. The child1.contoso.com domain contains a member server named Server1. You configure Server1 to be an enterprise certification authority (CA), and you configure a user certificate template. You enable the Publish certificate in Active Directory setting in the certificate template. You instruct users in both the child1.contoso.com and the child2.contoso.com domains to enroll for user certificates.   You discover that the certificates for user accounts in the child1.contoso.com domain are being published to Active Directory, but the certificates for user accounts in the child2.contoso.com domain are not.   You want certificates issued by Server1 to child2.contoso.com domain user accounts to be published in Active Directory.   What should you do? ()A、 Configure user certificate autoenrollment for all domain user accounts in the contoso.com domain.B、 Configure user certificate autoenrollment for all domain user accounts in the child2.contoso.com domain.C、 Add Server1 to the Cert Publishers group in the contoso.com domain.D、 Add Server1 to the Cert Publishers group in the child2.contoso.com domain.

You work as an application developer at Certkiller .com. Certkiller .com has asked you to develop an application that monitors and controls the activities of a Windows service.You need to use the appropriate class to meet Certkiller .com’s requirements. What should you do?()A、 Use the ServiceBase class.B、 Use the ServiceInstaller class.C、 Use the ServiceManager class.D、 Use the ServiceController class.

Certkiller .com has a main office and branch office in another city. You are assigned to deploy and implement a Read-only Domain Controller (RODC) at the branch office. You deploy a RODC that runs Windows Server 2008.  What should you do to ensure that the users at the branch office can log on to the domain using RODC()A、Use Password Replication Policy on the RODCB、Add RODC to the main officeC、Deploy and configure a new bridgehead server in the branch officeD、Deploy and configure a Password Replication Policy on the RODC in the main office

Certkiller .com has a main office and a branch office. Certkiller .com’s network consists of a single Active Directory forest. Some of the servers in the network run Windows Server 2008 and the rest run Windows server 2003.  You are the administrator at Certkiller .com. You have installed Active Directory Domain Services (AD DS) on a computer that runs Windows Server 2008. The branch office is located in a physically insecure place. It has not IT personnel onsite and there are no administrators over there. You need to setup a Read-Only Domain Controller (RODC) on the Server Core installation computer in the branch office. What should you do to setup RODC on the computer in branch office()A、Execute an attended installation of AD DSB、Execute an unattended installation of AD DSC、Execute RODC through AD DSD、Execute AD DS by using deploying the image of AD DSE、none of the above

Your company has a single Active Directory Domain Services (AD DS) domain named PassGuide.com that uses Active Directory-integrated DNS. You deploy the Key Management Service (KMS) on a Windows 7 computer. You need to ensure that Windows 7 client computers can locate the KMS host and perform activation.   Which two actions should you perform?()A、Deploy a Windows Server 2008 KMS host.B、Grant the KMS server the Full Control permission on the _vlmcs._tcp.PassGuide.com DNS record.C、Grant the KMS server the Full Control permission on the _msdcs._tcp.PassGuide.com DNS zone.D、Create and deploy a GPO firewall rule to allow RPC traffic through TCP port 1688 on the client computers.

Certkiller.com runs Window Server 2008 on all of its servers. It has a single Active Directory domain and it uses Enterprise Certificate Authority. The security policy at Certkiller .com makes it necessary to examine revoked certificate information.  You need to make sure that the revoked certificate information is available at all times. What should you do to achieve that()A、Add and configure a new GPO (Group Policy Object) that enables users to accept peer certificates and link the GPO to the domain.B、Configure and use a GPO to publish a list of trusted certificate authorities to the domainC、Configure and publish an OCSP (Online certificate status protocol) responder through ISAS (Internet Security and Acceleration Server) array.D、Use network load balancing and publish an OCSP responder.E、None of the above

Certkiller is having an Active Directory Rights Management Service (AD RMS) server.  Users machines are running Windows Vista and an Active Directory domain is configured at Microsoft Windows Server 2003 functional level.  Users are complaining that they cannot protect their documents. You need to configure AD RMS so that users are able to protect their documents. What should you do()A、Use a group policy to install the AD RMS client computersB、Add the ADRMSADMIN account to the local administrators group on the computersC、Add the ADRMSSRVC account to the local administrators on the AD RMS serverD、Establish an e-mail account in Active Directory Domain Services (AD DS) for each userE、Upgrade the active directory domain to the functional level of Windows 2008 server

Cer-tech .com has an Active Directory domain installed on a server that runs Windows Server 2008.Another server named S3 also runs Windows Server 2008. All client machines have Windows Vista. Cer-tech .com has instructed you to install the Terminal Services role, Terminal Services Gateway role andTerminal Services Web Access role service on S3. To protect the network, you want to ensure that all client machines have firewall, antivirus software and anti-spyware software installed. Which actions shouldyou perform to achieve this task?()A、Configure Windows Authorization Access domain local security group and add Terminal Services clientcomputersB、Configure Terminal Services client computers to access the Terminal Services health policy.C、Set the Request clients to sent a health option statement in the Terminal Services client access policyD、Install and configure Network Access Protection (NAP) on the server in the domain

Certkiller .com has a network that consists of a single Active Directory domain.Windows Server 2008 is installed on all domain controllers in the network.  You are instructed to capture all replication errors from all domain controllers to a central location. What should you do to achieve this task()A、Initiate the Active Directory Diagnostics data collector setB、Set event log subscriptions and configure itC、Initiate the System Performance data collector setD、Create a new capture in the Network Monitor

Certkiller .com has a domain controller that runs Windows Server 2008. The Certkiller .com network boosts 40 Windows Vista client machines. As an administrator at Certkiller .com, you want to deploy Active Directory Certificate service (AD CS) to authorize the network users by issuing digital certificates.  What should you do to manage certificate settings on all machines in a domain from one main location()A、Configure Enterprise CA certificate settingsB、Configure Enterprise trust certificate settingsC、Configure Advance CA certificate settingsD、Configure Group Policy certificate settingsE、All of the above

Certkiller .com has organizational units in the Active Directory domain. There are 10 servers in the organizational unit called Security. As an administrator at Certkiller .com, you generate a Group Policy Object (GPO) and link it to the Security organizational unit. What should you do to monitor the network connections to the servers in Security organizational unit()A、Start the Audit Object Access optionB、Start the Audit System Events optionC、Start the Audit Logon Events optionD、Start the Audit process tracking optionE、All of the above

Your network contains a single Active Directory domain named contoso.com. The functional level of the domain is Windows 2000 mixed.You have a domain controller named DC1 that runs Windows Server 2003 Service Pack 2 (SP2). DC1 hosts a standard primary zone for contoso.com.You need to ensure that only computers in the contoso.com domain can register host records in the contoso.com zone. What should you do? ()A、Convert contoso.com to a secondary zone. B、Convert contoso.com to an Active Directory-integrated zone. Set dynamic updates for the zone to Secure only. C、Convert contoso.com to an Active Directory-integrated zone. Set dynamic updates for the zone to Nonsecure and secure. D、Change the domain functional level to Windows Server 2003. Set dynamic updates for the zone to Nonsecure and secure.

Certkiller.COM有一个单一的Active Directory域命名的广告。 Certkiller.COM。 Windows Server 2008的所有域控制器上安装。域功能级别和林功能级别设置为Windows 2000本机模式。您必须确保为Certkiller UPN后缀.COM用户帐户。首先你应该怎么做来实现这一任务呢()A、更改默认域控制器组策略对象(GPO)Certkiller.COM的主DNS后缀选项。B、添加新的UPN后缀到林。C、提高Certkiller.com域的功能级别到Windows Server 2003或Windows Server 2008。D、提高Certkiller.COM森林功能级别到Windows Server 2003或Windows Server 2008。

Certkiller .com has a server that runs on Windows Server 2008. The server also has an instance of Active Directory Lightweight Directory Services (AD LDS) running.  In order to test AD LDS, you need to replicate the AD LDS instance on a test computer located on the network.  What should you do to achieve this objective()A、Execute AD LDS Setup wizard on the test computer to create and install a replica of AD LDS.B、Execute repadmin/bs  command on the test computerC、Install and configure a new AD LDS instance on the test computer by copy and pasting the entire partition on the test computerD、Execute the Dsmgmt command on the test computer and create a naming context

Certkiller .com has a network that consists of a single Active Directory domain. A technician has accidently deleted an Organizational unit (OU) on the domain controller. As an administrator of Certkiller .com, you are in process of restoring the OU. You need to execute a non-authoritative restore before an authoritative restore of the OU. Which backup should you use to perform non-authoritative restore of Active Directory Domain Services (AD DS) without disturbing other data stored on domain controller()A、Critical volume backupB、Backup of all the volumesC、Backup of the volume that hosts Operating systemD、Backup of AD DS foldersE、all of the above

As an administrator at Certkiller.com, you have installed an Active Directory forest that has a single domain. You have installed an Active Directory Federation services (AD FS) on the domain member server.  What should you do to configure AD FS to make sure that AD FS token contains information from the active directory domain()A、Add a new account store and configure it.B、Add a new resource partner and configure itC、Add a new resource store and configure itD、Add a new administrator account on AD FS and configure itE、None of the above

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2008 R2. The functional level of the domain is Windows Server 2008 R2. The functional  level of the forest is Windows Server 2008.   You have a member server named Server1 that runs Windows Server 2008.   You need to ensure that you can add Server1 to contoso.com as a domain controller.   What should you run before you promote Server1()A、dcpromo.exe /CreateDCAccountB、dcpromo.exe /ReplicaOrNewDomain:replicaC、Set-ADDomainMode -Identity contoso.com -DomainMode Windows2008DomainD、Set-ADForestMode -Identity contoso.com -ForestMode Windows2008R2Forest

Certkiller.com has a server with Active Directory Rights Management Services (AD RMS) server installed. Users have computers with Windows Vista installed on them with an Active Directory domain installed at Windows Server 2003 functional level. As an administrator at Certkiller.com, you discover that the users are unable to benefit from AD RMS to protect their documents. You need to configure AD RMS to enable users to use it and protect their documents. What should you do to achieve this functionality()A、Configure an email account in Active Directory Domain Services (AD DS) for each user.B、Add and configure ADRMSADMIN account in local administrators group on the user computersC、Add and configure the ADRMSSRVC account in AD RMS server’s local administrator groupD、Reinstall the Active Directory domain on user computersE、All of the above

单选题Certkiller .com has a network that is comprise of a single Active Directory Domain.  As an administrator at Certkiller .com, you install Active Directory Lightweight Directory Services (AD LDS) on a server that runs Windows Server 2008. To enable Secure Sockets Layer (SSL) based connections to the AD LDS server, you install certificates from a trusted Certification Authority (CA) on the AD LDS server and client computers.  Which tool should you use to test the certificate with AD LDS()ALdp.exeBActive Directory Domain servicesCntdsutil.exeDLds.exeEwsamain.exeFNone of the above

单选题Certkiller .com has a network that consists of a single Active Directory domain. A technician has accidently deleted an Organizational unit (OU) on the domain controller. As an administrator of Certkiller .com, you are in process of restoring the OU. You need to execute a non-authoritative restore before an authoritative restore of the OU. Which backup should you use to perform non-authoritative restore of Active Directory Domain Services (AD DS) without disturbing other data stored on domain controller()ACritical volume backupBBackup of all the volumesCBackup of the volume that hosts Operating systemDBackup of AD DS foldersEall of the above

多选题Your company has a single Active Directory Domain Services (AD DS) domain named PassGuide.com that uses Active Directory-integrated DNS. You deploy the Key Management Service (KMS) on a Windows 7 computer. You need to ensure that Windows 7 client computers can locate the KMS host and perform activation.   Which two actions should you perform?()ADeploy a Windows Server 2008 KMS host.BGrant the KMS server the Full Control permission on the _vlmcs._tcp.PassGuide.com DNS record.CGrant the KMS server the Full Control permission on the _msdcs._tcp.PassGuide.com DNS zone.DCreate and deploy a GPO firewall rule to allow RPC traffic through TCP port 1688 on the client computers.

单选题You work as an application developer at Certkiller .com. You have created a Windows service application for the purpose of monitoring the number of active service requests running on Certkiller .com’s server.  You want to configure this Windows service application to produce a report every ten minutes. You start by placing the reporting logic in the GenerateReport method of this Windows service.You want to create a Timer object that invokes this method every ten minutes.What should you do? ()A AB BC CD D

单选题Certkiller .com has a main office and branch office in another city. You are assigned to deploy and implement a Read-only Domain Controller (RODC) at the branch office. You deploy a RODC that runs Windows Server 2008.  What should you do to ensure that the users at the branch office can log on to the domain using RODC()AUse Password Replication Policy on the RODCBAdd RODC to the main officeCDeploy and configure a new bridgehead server in the branch officeDDeploy and configure a Password Replication Policy on the RODC in the main office