You have Active Directory Certificate Services (AD CS) deplo

题目
多选题
You have Active Directory Certificate Services (AD CS) deployed.  You create a custom certificate template.   You need to ensure that all of the users in the domain automatically enroll for a certificate based on the  custom certificate template.   Which two actions should you perform()
A

In a Group Policy object (GPO), configure the autoenrollment settings

B

In a Group Policy object (GPO), configure the Automatic Certificate Request Settings.

C

On the certificate template, assign the Read and Autoenroll permission to the Authenticated Users  group.

D

On the certificate template, assign the Read, Enroll, and Autoenroll permission to the Domain Users  group.

如果没有搜索结果或未解决您的问题,请直接 联系老师 获取答案。
相似问题和答案

第1题:

You have an Active Directory domain that runs Windows Server 2008 R2. You need to implement  a certification authority (CA) server that meets the following requirements:     - Allows the certification authority to automatically issue certificates  - Integrates with Active Directory Domain Services     What should you do()

  • A、Install and configure the Active Directory Certificate Services server role as a Standalone Root CA .
  • B、Install and configure the Active Directory Certificate Services server role as an Enterprise Root CA .
  • C、Purchase a certificate from a third-party certification authority. Install and configure the Active Directory Certificate S
  • D、Purchase a certificate from a third-party certification authority. Import the certificate into the computer store of the sc

正确答案:B

第2题:

Your company has an Active Directory forest. You plan to install an Enterprise certification  authority (CA) on a dedicated stand-alone server. When you attempt to add the Active Directory Certificate Services (AD CS) server role, you find  that the Enterprise CA option is not available. You need to install the AD CS server role as an Enterprise CA.     What should you do first()

  • A、Add the DNS Server server role.
  • B、Join the server to the domain.
  • C、Add the Web Server (IIS) server role and the AD CS server role.
  • D、Add the Active Directory Lightweight Directory Services (AD LDS) server role.

正确答案:B

第3题:

Your network contains a server named Server1. The Active Directory Rights Management Services (AD RMS) server role is installed on Server1.   An administrator changes the password of the user account that is used by AD RMS.  You need to update AD RMS to use the new password.   Which console should you use()

  • A、Active Directory Rights Management Services
  • B、Active Directory Users and Computers
  • C、Component Services
  • D、Services

正确答案:A

第4题:

You are designing a plan to migrate an existing application to Windows Azure.  The application must use the existing Active Directory Domain Services (AD DS) domain. You need to recommend an approach for joining Windows Azure virtual machines to the domain.  What should you recommend?()

  • A、 Install the Active Directory Certificate Services (AD CS) root certificate into the Enterprise Trust certificate store on each virtual machine.
  • B、 Configure Windows Azure Connect.
  • C、 Configure Windows Azure AppFabric Access Control.
  • D、 Install Active Directory Federation Services (AD FS) in the existing domain.

正确答案:B

第5题:

You have Active Directory Certificate Services (AD CS) deployed.  You create a custom certificate template.   You need to ensure that all of the users in the domain automatically enroll for a certificate based on the  custom certificate template.   Which two actions should you perform()

  • A、In a Group Policy object (GPO), configure the autoenrollment settings
  • B、In a Group Policy object (GPO), configure the Automatic Certificate Request Settings.
  • C、On the certificate template, assign the Read and Autoenroll permission to the Authenticated Users  group.
  • D、On the certificate template, assign the Read, Enroll, and Autoenroll permission to the Domain Users  group.

正确答案:A,D

第6题:

Your company has an Active Directory domain. You plan to install the Active Directory Certificate Services (AD CS) server role on a member  server that runs Windows Server 2008 R2.     You need to ensure that members of the Account Operators group are able to issue smartcard  credentials. They should not be able to revoke certificates.     Which three actions should you perform()

  • A、Install the AD CS server role and configure it as an Enterprise Root CA .
  • B、Install the AD CS server role and configure it as a Standalone CA .
  • C、Restrict enrollment agents for the Smartcard logon certificate to the Account Operator group.
  • D、Restrict certificate managers for the Smartcard logon certificate to the Account Operator group.
  • E、Create a Smartcard logon certificate.
  • F、Create an Enrollment Agent certificate.

正确答案:A,C,E

第7题:

Your company has an Active Directory forest. You plan to install an Enterprise certification authority  (CA) on a dedicated stand-alone server.    When you attempt to add the Active Directory Certificate Services (AD CS) server role, you find that the  Enterprise CA option is not available.    You need to install the AD CS server role as an Enterprise CA.    What should you do first()

  • A、Add the DNS Server server role.
  • B、Join the server to the domain.
  • C、Add the Web Server (IIS) server role and the AD CS server role
  • D、Add the Active Directory Lightweight Directory Services (AD LDS) server role. .

正确答案:B

第8题:

You are designing a plan to migrate an existing application to Windows Azure.  The application must use the existing Active Directory Domain Services (AD DS) domain. You need to recommend an approach for joining Windows Azure virtual machines to the domain.  What should you recommend?()

  • A、 Install the Active Directory Certificate Services (AD CS) root certificate into the Enterprise Trustcertificate store on each virtual machine.
  • B、 Configure Windows Azure Connect.
  • C、 Configure Windows Azure AppFabric Access Control.
  • D、 Install Active Directory Federation Services (AD FS) in the existing domain.

正确答案:B

第9题:

Your network contains two standalone servers named Server1 and Server2 that have Active  Directory Lightweight Directory Services (AD LDS) installed.Server1 has an AD LDS instance.  You need to ensure that you can replicate the instance from Server1 to Server2.  What should you do on both servers()

  • A、Obtain a server certificate.
  • B、Import the MS-User.ldf file.
  • C、Create a service user account for AD LDS.
  • D、Register the service location (SRV) resource records.

正确答案:C

第10题:

You deploy a new Active Directory Federation Services (AD FS) federation server.   You request new certificates for the AD FS federation server.   You need to ensure that the AD FS federation server can use the new certificates.   To which certificate store should you import the certificates()

  • A、Computer
  • B、IIS Admin Service service account
  • C、Local Administrator
  • D、World Wide Web Publishing Service service account

正确答案:A

更多相关问题