Your company has an Active Directory domain.
You plan to install the Active Directory Certificate Services (AD CS) server role on a member server that runs Windows Server 2008 R2.
You need to ensure that members of the Account Operators group are able to issue smartcard credentials. They should not be able to revoke certificates. Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)
A.
Install the AD CS server role and configure it as an Enterprise Root CA .
B.
Install the AD CS server role and configure it as a Standalone CA .
C.
Restrict enrollment agents for the Smartcard logon certificate to the Account Operator group.
D.
Restrict certificate managers for the Smartcard logon certificate to the Account Operator group.
E.
Create a Smartcard logon certificate.
F.
Create an Enrollment Agent certificate.