单选题You have an enterprise subordinate certification authority (CA). You have a custom Version 3 certificate template.  Users can enroll for certificates based on the custom certificate template by using the Certificates console. The certificate template is unavailable for Web enrollment. You need to ensure that the certificate template is available on the Web enrollment pages. What should you do()ARun certutil.exe pulse.BRun certutil.exe installcert.CChange the certificate template to a Version 2 certificate template.DOn the certificate template, assign the Autoenroll permission to the users.

单选题
You have an enterprise subordinate certification authority (CA). You have a custom Version 3 certificate template.  Users can enroll for certificates based on the custom certificate template by using the Certificates console. The certificate template is unavailable for Web enrollment. You need to ensure that the certificate template is available on the Web enrollment pages. What should you do()
A

Run certutil.exe pulse.

B

Run certutil.exe installcert.

C

Change the certificate template to a Version 2 certificate template.

D

On the certificate template, assign the Autoenroll permission to the users.


参考解析

解析: 暂无解析

相关考题:

Your company has an Active Directory domain. You have a two-tier PKI infrastructure that  contains an offline root CA and an online issuing CA. The Enterprise certification authority is  running Windows Server 2008 R2.   You need to ensure users are able to enroll new certificates.     What should you do()A、Renew the Certificate Revocation List (CRL) on the root CA . Copy the CRL to the CertEnroll folder on the issuing CB、Renew the Certificate Revocation List (CRL) on the issuing CA . Copy the CRL to the SystemCertificates folder in thC、Import the root CA certificate into the Trusted Root Certification Authorities store on all client workstations.D、Import the issuing CA certificate into the Intermediate Certification Authorities store on all client workstations.

Your company uses a Windows 2008 Enterprise certificate authority (CA) to issue certificates. You need to implement key archival. What should you do()A、Archive the private key on the server.B、Apply the Hisecdc security template to the domain controllers.C、Configure the certificate for automatic enrollment for the computers that store encrypted files.D、Install an Enterprise Subordinate CA and issue a user certificate to users of the encrypted files.

You have an enterprise subordinate certification authority (CA). You have a group named  Group1.     You need to allow members of Group1 to publish new certificate revocation lists. Members of  Group1 must not be allowed to revoke certificates.     What should you do()A、Add Group1 to the local Administrators group.B、Add Group1 to the Certificate Publishers group.C、Assign the Manage CA permission to Group1.D、Assign the Issue and Manage Certificates permission to Group1.

You have an enterprise subordinate certification authority (CA).   You have a custom certificate template that has a key length of 1,024 bits. The template is enabled for  autoenrollment.   You increase the template key length to 2,048 bits.   You need to ensure that all current certificate holders automatically enroll for a certificate that uses the  new template.   Which console should you use()A、Active Directory Administrative CenterB、Certification AuthorityC、Certificate TemplatesD、Group Policy Management

You have a Windows Server 2008 R2 Enterprise Root certification authority (CA). You need to  grant members of the Account Operators group the ability to only manage Basic EFS certificates.     You grant the Account Operators group the Issue and Manage Certificates permission on the CA .   Which three tasks should you perform next()A、Enable the Restrict Enrollment Agents option on the CA .B、Enable the Restrict Certificate Managers option on the CA .C、Add the Basic EFS certificate template for the Account Operators group.D、Grant the Account Operators group the Manage CA permission on the CA .E、Remove all unnecessary certificate templates that are assigned to the Account Operators group.

You have an enterprise subordinate certification authority (CA). You have a custom Version 3  certificate template.     Users can enroll for certificates based on the custom certificate template by using the Certificates  console.     The certificate template is unavailable for Web enrollment. You need to ensure that the certificate  template is available on the Web enrollment pages.     What should you do()A、Run certutil.exe -pulse.B、Run certutil.exe -installcert.C、Change the certificate template to a Version 2 certificate template.D、On the certificate template, assign the Autoenroll permission to the users.

You have Active Directory Certificate Services (AD CS) deployed.  You create a custom certificate template.   You need to ensure that all of the users in the domain automatically enroll for a certificate based on the  custom certificate template.   Which two actions should you perform()A、In a Group Policy object (GPO), configure the autoenrollment settingsB、In a Group Policy object (GPO), configure the Automatic Certificate Request Settings.C、On the certificate template, assign the Read and Autoenroll permission to the Authenticated Users  group.D、On the certificate template, assign the Read, Enroll, and Autoenroll permission to the Domain Users  group.

You have a server that runs Windows Server 2003 Service Pack 2 (SP2). The server contains one volume. You install Certificate Services. You need to back up the Certificates Services database by using the minimum amount of storage space. Which tool should you use? ()A、Certification Authority snap-inB、Certificates snap-inC、Certificate Templates snap-inD、Windows Backup

You are a network administrator for your company. The network consists of two Active Directory domains. You are responsible for administering one domain, which contains users who work in the sales department. User objects for the users in the sales department are stored in an organizational unit (OU) named Sales in your domain.   Users in the sales department use a public key infrastructure (PKI) enabled application that requires users to present client authentication certificates before they are granted access. You install Certificate Services on two member servers  running Windows Server 2003. You configure one server as an enterprise subordinate certification authority (CA) and the other server as a stand-alone root CA.   You need to issue certificates that support client authentication to sales users only. You need to achieve this goal by using the minimum amount of administrative effort.   What should you do?  ()A、 Create a duplicate of the User certificate template and configure it to support autoenrollment. Configure the enterprise subordinate CA to issue certificates based on the template. Configure the Default Domain Policy Group Policy object (GPO) to autoenroll users for certificates.B、 Create a duplicate of the Computer certificate template and configure it to support autoenrollment. Configure the enterprise subordinate CA to issue certificates based on the template. Configure the Default Domain Policy Group Policy object (GPO) to autoenroll computers for certificates.C、 Create a duplicate of the User certificate template and configure it to support autoenrollment. Configure the enterprise subordinate CA to issue certificates based on the template. Create a new Group Policy object (GPO) and link it to the Sales OU. Configure the GPO to autoenroll sales users for certificates.D、 Create a duplicate of the Computer certificate template and configure it to support autoenrollment. Configure the enterprise subordinate CA to issue certificates based on the template. Create a new Group Policy object (GPO) and link it to the Sales OU. Configure the GPO to autoenroll sales client computers for certificates.

You have an enterprise subordinate certification authority (CA). The CA issues smart card logon  certificates.   Users are required to log on to the domain by using a smart card.   Your companys corporate security policy states that when an employee resigns, his ability to log on to the network must be immediately revoked.   An employee resigns.   You need to immediately prevent the employee from logging on to the domain.  What should you do()A、Revoke the employees smart card certificate.B、Disable the employees Active Directory account.C、Publish a new delta certificate revocation list (CRL).D、Reset the password for the employees Active Directory account.

You have a server named Server1 that has the following Active Directory Certificate Services (AD CS)   role services installed:   ( Enterprise root certification authority (CA)  .Certificate Enrollment Web Service   .Certificate Enrollment Policy Web Service   You create a new certificate template.   External users report that the new template is unavailable when they request a new certificate.  You verify that all other templates are available to the external users.   You need to ensure that the external users can request certificates by using the new template.  What should you do on Server1()A、Run iisreset.exe /restart.  B、Run gpupdate.exe /force.  C、Run certutil.exe dspublish.D、Restart the Active Directory Certificate Services service.

You have an Active Directory domain that runs Windows Server 2008 R2. You need to implement  a certification authority (CA) server that meets the following requirements:     - Allows the certification authority to automatically issue certificates  - Integrates with Active Directory Domain Services     What should you do()A、Install and configure the Active Directory Certificate Services server role as a Standalone Root CA .B、Install and configure the Active Directory Certificate Services server role as an Enterprise Root CA .C、Purchase a certificate from a third-party certification authority. Install and configure the Active Directory Certificate SD、Purchase a certificate from a third-party certification authority. Import the certificate into the computer store of the sc

You are the network administrator for your company. The network contains a single Active Directory domain. All computers on the network are members of the domain. All domain controllers run Windows Server 2003.   You are planning a public key infrastructure (PKI). The PKI design documents for your company specify that certificates that users request to encrypt files must have a validity period of two years.   The validity period of a Basic EFS certificate is one year. In the Certificates Templates console, you attempt to change the validity period for the Basic EFS certificate template. However, the console does not allow you to change the value.  You need to ensure that you can change the value of the validity period of the certificate that users request to encrypt files. What should you do?  ()A、 Install an enterprise certification authority (CA) in each domain.B、 Assign the Domain Admins group the Allow - Full Control permission for the Basic EFS certificate template.C、 Create a duplicate of the Basic EFS certificate template. Enable the new template for issuing certificate authorities.D、 Instruct users to connect to the certification authority (CA) Web enrollment pages to request a Basic EFS certificate.

You have an enterprise subordinate certification authority (CA). You have a custom Version 3 certificate template.  Users can enroll for certificates based on the custom certificate template by using the Certificates console. The certificate template is unavailable for Web enrollment. You need to ensure that the certificate template is available on the Web enrollment pages. What should you do()A、Run certutil.exe pulse.B、Run certutil.exe installcert.C、Change the certificate template to a Version 2 certificate template.D、On the certificate template, assign the Autoenroll permission to the users.

单选题You have an enterprise subordinate certification authority (CA). You have a custom Version 3  certificate template.     Users can enroll for certificates based on the custom certificate template by using the Certificates  console.     The certificate template is unavailable for Web enrollment. You need to ensure that the certificate  template is available on the Web enrollment pages.     What should you do()ARun certutil.exe -pulse.BRun certutil.exe -installcert.CChange the certificate template to a Version 2 certificate template.DOn the certificate template, assign the Autoenroll permission to the users.

单选题You are the network administrator for Contoso Pharmaceuticals. The network consists of a single Active Directory forest. The forest contains Windows Server 2003 servers and Windows XP Professional computers.   The forest consists of a forest root domain named contoso.com and two child domains named child1.contoso.com and child2.contoso.com. The child1.contoso.com domain contains a member server named Server1. You configure Server1 to be an enterprise certification authority (CA), and you configure a user certificate template. You enable the Publish certificate in Active Directory setting in the certificate template. You instruct users in both the child1.contoso.com and the child2.contoso.com domains to enroll for user certificates.   You discover that the certificates for user accounts in the child1.contoso.com domain are being published to Active Directory, but the certificates for user accounts in the child2.contoso.com domain are not.   You want certificates issued by Server1 to child2.contoso.com domain user accounts to be published in Active Directory.   What should you do? ()A Configure user certificate autoenrollment for all domain user accounts in the contoso.com domain.B Configure user certificate autoenrollment for all domain user accounts in the child2.contoso.com domain.C Add Server1 to the Cert Publishers group in the contoso.com domain.D Add Server1 to the Cert Publishers group in the child2.contoso.com domain.

多选题You have Active Directory Certificate Services (AD CS) deployed.  You create a custom certificate template.   You need to ensure that all of the users in the domain automatically enroll for a certificate based on the  custom certificate template.   Which two actions should you perform()AIn a Group Policy object (GPO), configure the autoenrollment settingsBIn a Group Policy object (GPO), configure the Automatic Certificate Request Settings.COn the certificate template, assign the Read and Autoenroll permission to the Authenticated Users  group.DOn the certificate template, assign the Read, Enroll, and Autoenroll permission to the Domain Users  group.

单选题You have a server named Server1 that has the following Active Directory Certificate Services (AD CS)   role services installed:   ( Enterprise root certification authority (CA)  .Certificate Enrollment Web Service   .Certificate Enrollment Policy Web Service   You create a new certificate template.   External users report that the new template is unavailable when they request a new certificate.  You verify that all other templates are available to the external users.   You need to ensure that the external users can request certificates by using the new template.  What should you do on Server1()ARun iisreset.exe /restart.  BRun gpupdate.exe /force.  CRun certutil.exe dspublish.DRestart the Active Directory Certificate Services service.

单选题You have an enterprise subordinate certification authority (CA).   You have a custom certificate template that has a key length of 1,024 bits. The template is enabled for  autoenrollment.   You increase the template key length to 2,048 bits.   You need to ensure that all current certificate holders automatically enroll for a certificate that uses the  new template.   Which console should you use()AActive Directory Administrative CenterBCertification AuthorityCCertificate TemplatesDGroup Policy Management

单选题Your company uses a Windows 2008 Enterprise certificate authority (CA) to issue certificates. You need to implement key archival. What should you do()AArchive the private key on the server.BApply the Hisecdc security template to the domain controllers.CConfigure the certificate for automatic enrollment for the computers that store encrypted files.DInstall an Enterprise Subordinate CA and issue a user certificate to users of the encrypted files.

单选题You have an enterprise subordinate certification authority (CA). The CA issues smart card logon  certificates.     Users are required to log on to the domain by using a smart card. Your company’s corporate  security policy states that when an employee resigns, his ability to log on to the network must be  immediately revoked.     An employee resigns. You need to immediately prevent the employee from logging on to the  domain.     What should you do()ARevoke the employee’s smart card certificate.BDisable the employee’s Active Directory account.CPublish a new delta certificate revocation list (CRL).DReset the password for the employee’s Active Directory account.

单选题You are the network administrator for your company. The network contains a single Active Directory domain. All computers on the network are members of the domain. All domain controllers run Windows Server 2003.   You are planning a public key infrastructure (PKI). The PKI design documents for your company specify that certificates that users request to encrypt files must have a validity period of two years.   The validity period of a Basic EFS certificate is one year. In the Certificates Templates console, you attempt to change the validity period for the Basic EFS certificate template. However, the console does not allow you to change the value.  You need to ensure that you can change the value of the validity period of the certificate that users request to encrypt files. What should you do?  ()A Install an enterprise certification authority (CA) in each domain.B Assign the Domain Admins group the Allow - Full Control permission for the Basic EFS certificate template.C Create a duplicate of the Basic EFS certificate template. Enable the new template for issuing certificate authorities.D Instruct users to connect to the certification authority (CA) Web enrollment pages to request a Basic EFS certificate.

单选题You have an enterprise subordinate certification authority (CA). The CA issues smart card logon  certificates.   Users are required to log on to the domain by using a smart card.   Your companys corporate security policy states that when an employee resigns, his ability to log on to the network must be immediately revoked.   An employee resigns.   You need to immediately prevent the employee from logging on to the domain.  What should you do()ARevoke the employees smart card certificate.BDisable the employees Active Directory account.CPublish a new delta certificate revocation list (CRL).DReset the password for the employees Active Directory account.

单选题You have an enterprise subordinate certification authority (CA).   You have a group named Group1.   You need to allow members of Group1 to publish new certificate revocation lists. Members of Group1  must not be allowed to revoke certificates.   What should you do()AAdd Group1 to the local Administrators group.BAdd Group1 to the Certificate Publishers group.CAssign the Manage CA permission to Group1.DAssign the Issue and Manage Certificates permission to Group1.

单选题You have an Active Directory domain that runs Windows Server 2008 R2. You need to implement  a certification authority (CA) server that meets the following requirements:     - Allows the certification authority to automatically issue certificates  - Integrates with Active Directory Domain Services     What should you do()AInstall and configure the Active Directory Certificate Services server role as a Standalone Root CA .BInstall and configure the Active Directory Certificate Services server role as an Enterprise Root CA .CPurchase a certificate from a third-party certification authority. Install and configure the Active Directory Certificate SDPurchase a certificate from a third-party certification authority. Import the certificate into the computer store of the sc

单选题Your company has an Active Directory domain. You have a two-tier PKI infrastructure that  contains an offline root CA and an online issuing CA. The Enterprise certification authority is  running Windows Server 2008 R2.   You need to ensure users are able to enroll new certificates.     What should you do()ARenew the Certificate Revocation List (CRL) on the root CA . Copy the CRL to the CertEnroll folder on the issuing CBRenew the Certificate Revocation List (CRL) on the issuing CA . Copy the CRL to the SystemCertificates folder in thCImport the root CA certificate into the Trusted Root Certification Authorities store on all client workstations.DImport the issuing CA certificate into the Intermediate Certification Authorities store on all client workstations.

单选题You are a network administrator for your company. The network consists of two Active Directory domains. You are responsible for administering one domain, which contains users who work in the sales department. User objects for the users in the sales department are stored in an organizational unit (OU) named Sales in your domain.   Users in the sales department use a public key infrastructure (PKI) enabled application that requires users to present client authentication certificates before they are granted access. You install Certificate Services on two member servers  running Windows Server 2003. You configure one server as an enterprise subordinate certification authority (CA) and the other server as a stand-alone root CA.   You need to issue certificates that support client authentication to sales users only. You need to achieve this goal by using the minimum amount of administrative effort.   What should you do?  ()A Create a duplicate of the User certificate template and configure it to support autoenrollment. Configure the enterprise subordinate CA to issue certificates based on the template. Configure the Default Domain Policy Group Policy object (GPO) to autoenroll users for certificates.B Create a duplicate of the Computer certificate template and configure it to support autoenrollment. Configure the enterprise subordinate CA to issue certificates based on the template. Configure the Default Domain Policy Group Policy object (GPO) to autoenroll computers for certificates.C Create a duplicate of the User certificate template and configure it to support autoenrollment. Configure the enterprise subordinate CA to issue certificates based on the template. Create a new Group Policy object (GPO) and link it to the Sales OU. Configure the GPO to autoenroll sales users for certificates.D Create a duplicate of the Computer certificate template and configure it to support autoenrollment. Configure the enterprise subordinate CA to issue certificates based on the template. Create a new Group Policy object (GPO) and link it to the Sales OU. Configure the GPO to autoenroll sales client computers for certificates.