What should you do?

You are the newly appointed enterprise administrator at Domain.com. The Domain.com network consists of a single Active Directory domain named Domain.com. All servers on the Domain.com network run Windows Server 2008.
You are assigned a Windows Server 2008 server named CERTKILLER-SR05. You are in the
process of planning the installation of the Active Directory Certificate Service (AD CS) role on CERTKILLER-SR05. The Domain.com network contains a group named Data Operators. You receive an instruction from The CIO to ensure that users in Data Operators are given the appropriate permissions to issue smartcard credentials. These users should not be given the permission to revoke certificates.
What should you do? (Choose all that apply.)

You are the newly appointed enterprise administrator at Domain.com. The Domain.com network consists of a single Active Directory domain named Domain.com. All servers on the Domain.com network run Windows Server 2008.

You are assigned a Windows Server 2008 server named CERTKILLER-SR05. You are in the
process of planning the installation of the Active Directory Certificate Service (AD CS) role on CERTKILLER-SR05. The Domain.com network contains a group named Data Operators. You receive an instruction from The CIO to ensure that users in Data Operators are given the appropriate permissions to issue smartcard credentials. These users should not be given the permission to revoke certificates.

What should you do? (Choose all that apply.)

A.
Your best choice would be to have the enrollment agents for the Smartcard logon certificate limited to Data Operators.

B.
Your best choice would be to have an Enrollment Agent certificate created.

C.
Your best choice would be to have the certificate managers for the Smartcard logon certificate limited to Data Operators.

D.
Your best choice would be to have the AD CS role installed.
Thereafter the AD CS role can be configured as an Enterprise Root CA.

E.
Your best choice would be to have the AD CS role installed.
Thereafter the AD CS role can be configured as a Standalone CA.

F.
Your best choice would be to have a Smartcard logon certificate created.

 



Leave a Reply 1

Your email address will not be published. Required fields are marked *


mr_tienvu

mr_tienvu

I have the same idea.