HOTSPOT
Your network contains an Active Directory domain named contoso.com.
The domain has a certification authority (CA). You create four certificate templates. The
templates are configured as shown in the following table:
You install the Remote Access server role in the domain.
You need to configure DirectAccess to use one-time password (OTP) authentication.
What should you do? To answer, select the appropriate options in the answer area,
Correct
“The intended purpose of the certificate must be Smart Card Logon”
https://technet.microsoft.com/en-us/library/jj134161.aspx