Your network contains two Active Directory forests named contoso.com and adatum.com. The functional level of both forests is Windows Server 2008 R2. Each forest contains one domain. Active Directory Certificate Services (AD CS) is configured in the contoso.com forest to allow users from both forests to automatically enroll user certificates.
You need to ensure that all users in the adatum.com forest have a user certificate from the contoso.com certification authority (CA).
What should you configure in the adatum.com domain?
A.
From the Default Domain Controllers Policy, modify the Enterprise Trust settings.
B.
From the Default Domain Controllers Policy, modify the Trusted Publishers settings.
C.
From the Default Domain Policy, modify the Certificate Enrollment policy.
D.
From the Default Domain Policy, modify the Trusted Root Certification Authority settings.