单选题You have an enterprise subordinate certification authority (CA). You have a custom Version 3 certificate template.  Users can enroll for certificates based on the custom certificate template by using the Certificates console. The certificate template i

题目
单选题
You have an enterprise subordinate certification authority (CA). You have a custom Version 3 certificate template.  Users can enroll for certificates based on the custom certificate template by using the Certificates console. The certificate template is unavailable for Web enrollment. You need to ensure that the certificate template is available on the Web enrollment pages. What should you do()
A

Run certutil.exe pulse.

B

Run certutil.exe installcert.

C

Change the certificate template to a Version 2 certificate template.

D

On the certificate template, assign the Autoenroll permission to the users.

参考答案和解析
正确答案: A
解析: 暂无解析
如果没有搜索结果或未解决您的问题,请直接 联系老师 获取答案。
相似问题和答案

第1题:

You have an enterprise subordinate certification authority (CA). You have a group named  Group1.     You need to allow members of Group1 to publish new certificate revocation lists. Members of  Group1 must not be allowed to revoke certificates.     What should you do()

  • A、Add Group1 to the local Administrators group.
  • B、Add Group1 to the Certificate Publishers group.
  • C、Assign the Manage CA permission to Group1.
  • D、Assign the Issue and Manage Certificates permission to Group1.

正确答案:C

第2题:

You have a Windows Server 2008 R2 Enterprise Root certification authority (CA). You need to  grant members of the Account Operators group the ability to only manage Basic EFS certificates.     You grant the Account Operators group the Issue and Manage Certificates permission on the CA .   Which three tasks should you perform next()

  • A、Enable the Restrict Enrollment Agents option on the CA .
  • B、Enable the Restrict Certificate Managers option on the CA .
  • C、Add the Basic EFS certificate template for the Account Operators group.
  • D、Grant the Account Operators group the Manage CA permission on the CA .
  • E、Remove all unnecessary certificate templates that are assigned to the Account Operators group.

正确答案:B,C,E

第3题:

Your company has an Active Directory domain. You have a two-tier PKI infrastructure that  contains an offline root CA and an online issuing CA. The Enterprise certification authority is  running Windows Server 2008 R2.   You need to ensure users are able to enroll new certificates.     What should you do()

  • A、Renew the Certificate Revocation List (CRL) on the root CA . Copy the CRL to the CertEnroll folder on the issuing C
  • B、Renew the Certificate Revocation List (CRL) on the issuing CA . Copy the CRL to the SystemCertificates folder in th
  • C、Import the root CA certificate into the Trusted Root Certification Authorities store on all client workstations.
  • D、Import the issuing CA certificate into the Intermediate Certification Authorities store on all client workstations.

正确答案:A

第4题:

You are a network administrator for your company. The network consists of two Active Directory domains. You are responsible for administering one domain, which contains users who work in the sales department. User objects for the users in the sales department are stored in an organizational unit (OU) named Sales in your domain.   Users in the sales department use a public key infrastructure (PKI) enabled application that requires users to present client authentication certificates before they are granted access. You install Certificate Services on two member servers  running Windows Server 2003. You configure one server as an enterprise subordinate certification authority (CA) and the other server as a stand-alone root CA.   You need to issue certificates that support client authentication to sales users only. You need to achieve this goal by using the minimum amount of administrative effort.   What should you do?  ()

  • A、 Create a duplicate of the User certificate template and configure it to support autoenrollment. Configure the enterprise subordinate CA to issue certificates based on the template. Configure the Default Domain Policy Group Policy object (GPO) to autoenroll users for certificates.
  • B、 Create a duplicate of the Computer certificate template and configure it to support autoenrollment. Configure the enterprise subordinate CA to issue certificates based on the template. Configure the Default Domain Policy Group Policy object (GPO) to autoenroll computers for certificates.
  • C、 Create a duplicate of the User certificate template and configure it to support autoenrollment. Configure the enterprise subordinate CA to issue certificates based on the template. Create a new Group Policy object (GPO) and link it to the Sales OU. Configure the GPO to autoenroll sales users for certificates.
  • D、 Create a duplicate of the Computer certificate template and configure it to support autoenrollment. Configure the enterprise subordinate CA to issue certificates based on the template. Create a new Group Policy object (GPO) and link it to the Sales OU. Configure the GPO to autoenroll sales client computers for certificates.

正确答案:C

第5题:

You have Active Directory Certificate Services (AD CS) deployed.  You create a custom certificate template.   You need to ensure that all of the users in the domain automatically enroll for a certificate based on the  custom certificate template.   Which two actions should you perform()

  • A、In a Group Policy object (GPO), configure the autoenrollment settings
  • B、In a Group Policy object (GPO), configure the Automatic Certificate Request Settings.
  • C、On the certificate template, assign the Read and Autoenroll permission to the Authenticated Users  group.
  • D、On the certificate template, assign the Read, Enroll, and Autoenroll permission to the Domain Users  group.

正确答案:A,D

第6题:

You have an enterprise subordinate certification authority (CA).   You have a custom certificate template that has a key length of 1,024 bits. The template is enabled for  autoenrollment.   You increase the template key length to 2,048 bits.   You need to ensure that all current certificate holders automatically enroll for a certificate that uses the  new template.   Which console should you use()

  • A、Active Directory Administrative Center
  • B、Certification Authority
  • C、Certificate Templates
  • D、Group Policy Management

正确答案:C

第7题:

You have an enterprise subordinate certification authority (CA). You have a custom Version 3  certificate template.     Users can enroll for certificates based on the custom certificate template by using the Certificates  console.     The certificate template is unavailable for Web enrollment. You need to ensure that the certificate  template is available on the Web enrollment pages.     What should you do()

  • A、Run certutil.exe -pulse.
  • B、Run certutil.exe -installcert.
  • C、Change the certificate template to a Version 2 certificate template.
  • D、On the certificate template, assign the Autoenroll permission to the users.

正确答案:C

第8题:

Your company uses a Windows 2008 Enterprise certificate authority (CA) to issue certificates. You need to implement key archival. What should you do()

  • A、Archive the private key on the server.
  • B、Apply the Hisecdc security template to the domain controllers.
  • C、Configure the certificate for automatic enrollment for the computers that store encrypted files.
  • D、Install an Enterprise Subordinate CA and issue a user certificate to users of the encrypted files.

正确答案:A

第9题:

You have a server that runs Windows Server 2003 Service Pack 2 (SP2). The server contains one volume. You install Certificate Services. You need to back up the Certificates Services database by using the minimum amount of storage space. Which tool should you use? ()

  • A、Certification Authority snap-in
  • B、Certificates snap-in
  • C、Certificate Templates snap-in
  • D、Windows Backup

正确答案:A

第10题:

You have an enterprise subordinate certification authority (CA). The CA issues smart card logon  certificates.   Users are required to log on to the domain by using a smart card.   Your companys corporate security policy states that when an employee resigns, his ability to log on to the network must be immediately revoked.   An employee resigns.   You need to immediately prevent the employee from logging on to the domain.  What should you do()

  • A、Revoke the employees smart card certificate.
  • B、Disable the employees Active Directory account.
  • C、Publish a new delta certificate revocation list (CRL).
  • D、Reset the password for the employees Active Directory account.

正确答案:B

更多相关问题