Your network contains an Active Directory domain named contoso.com.
The network has an Active Directory Certificate Services (AD CS) infrastructure
You need to issue a certificate to users to meet the following requirements:
– Ensure that the users can encrypt files by using Encrypting File System (EFS).
– Ensure that all of the users reenroll for their certificate every six months.
Solution: You create a copy of the Basic EFS certificate template, and then you modify the validity period of the copy.
Does this meet the goal?
A.
Yes
B.
No
This is the correct answer for the series of questions.
If you need to implement EFS, it might be recommended to use duplicated template, because it supports autoenrollment and allows you to modify some settings (if necessary). If you don’t need EFS — remove all EFS templates from the CA.
Source: https://social.technet.microsoft.com/Forums/windows/en-US/15e17e90-eba8-4ee0-8d22-03e9f9f3d884/certificate-authority-template-basic-efs-and-cep-encryption?forum=winserversecurity