What should you recommend?

Your network contains an Active Directory domain named contoso.com. You deploy Active Directory
Certificate Services (AD CS). You plan to deploy 100 external Web servers that will be publicly accessible
and will require Secure Sockets Layer (SSL) certificates.
You also plan to deploy 50,000 certificates for secure email exchanges with Internet-based recipients.
You need to recommend a certificate services solution for the planned deployment.
What should you recommend? More than one answer choice may achieve the goal. Select the BEST
answer.A. Deploy a certification authority (CA) that is subordinate to an external root CA.

Your network contains an Active Directory domain named contoso.com. You deploy Active Directory
Certificate Services (AD CS). You plan to deploy 100 external Web servers that will be publicly accessible
and will require Secure Sockets Layer (SSL) certificates.
You also plan to deploy 50,000 certificates for secure email exchanges with Internet-based recipients.
You need to recommend a certificate services solution for the planned deployment.
What should you recommend? More than one answer choice may achieve the goal. Select the BEST
answer.A. Deploy a certification authority (CA) that is subordinate to an external root CA.

B.
Purchase 50,100 certificates from a trusted third-party root certification authority (CA).

C.
Distribute a copy of the root certification authority (CA) certificate to external relying parties.

D.
Instruct each user to request a Secure Email certificate from a trusted third-party root CA, and then
purchase 100 Web server certificates.

Explanation:

http://technet.microsoft.com/en-us/library/cc772192(v=ws.10).aspx



Leave a Reply 4

Your email address will not be published. Required fields are marked *


mic

mic

what is the answer?

veekay

veekay

could it be A?

Vintro

Vintro

Answer is indeed A

vader66

vader66

they could buy a wild-czrd cert for the webservers and a UCC/SAN cert for the exchange