Your network contains an Active Directory forest. The forest contains two domains. You have a standalone root certification authority (CA). On a server in the child domain, you run the Add Roles Wizard and discover that the option to select an enterprise CA is disabled.
You need to install an enterprise subordinate CA on the server.
What should you use to log on to the new server?
A.
an account that is a member of the Certificate Publishers group in the child domain
B.
an account that is a member of the Certificate Publishers group in the forest root domain
C.
an account that is a member of the Schema Admins group in the forest root domain
D.
an account that is a member of the Enterprise Admins group in the forest root domain