Publish the code signing template.
Edit the local computer policy of the Enterprise Root CA to allow users to trust peer certificates and allow only admi
Edit the local computer policy of the Enterprise Root CA to allow only administrators to manage Trusted Publishers.
Modify the security settings on the template to allow only administrators to request code signing certificates.
第1题:
Your company has an Active Directory domain. All servers run Windows Server 2008. You deploy a Certification Authority (CA) server. You create a new global security group named CertIssuers. You need to ensure that members of the CertIssuers group can issue, approve, and revoke certificates. What should you do()
第2题:
Your company has an Active Directory domain. All servers run Windows Server 2008. Your company uses an ENterprise Root certification authority (CA) and an Enterprise Intermediate CA. The Enterprise intermediate CA certificate expires. You need to deploy a new Enterprise Intermediate CA certificate to all computers in the domain. What should you do()
第3题:
Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. You have a stand-alone server that serves as a Stand-alone root certification authority (CA). You need to ensure that a specific user can back up the CA and configure the audit parameters on the CA. What should you do?()
第4题:
Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your company uses an Enterprise Root certification authority (CA) and an Enterprise Intermediate CA. The Enterprise Intermediate CA certificate expires. You need to deploy a new Enterprise Intermediate CA certificate to all computers in the domain. What should you do()
第5题:
Your company has an Active Directory Domain Services (AD DS) domain. All servers run Windows Server 2008 R2. All client computers run Windows 7. You manage client computers by using Microsoft System Center Configuration Manager 2007 R2. You are deploying Microsoft Enterprise Desktop Virtualization (MED-V) to support client virtualization requirements. You need to ensure that administrators can centrally store MED-V logging information and generate reports. Which two actions should you perform?()
第6题:
Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your company uses an Enterprise Root certificate authority (CA). You need to ensure that revoked certificate information is highly available. What should you do()
第7题:
Your network contains an Active Directory domain. You have a server named Server1 that runs Windows Server 2008 R2. Server1 is an enterprise root certification authority (CA). You have a client computer named Computer1 that runs Windows 7. You enable automatic certificate enrollment for all client computers that run Windows 7. You need to verify that the Windows 7 client computers can automatically enroll for certificates. Which command should you run on Computer1()
第8题:
Configure auditing in the Certification Authority snap-in.
Enable auditing of successful and failed attempts to change permissions on files in the %SYSTEM32%/CertSrv directory.
Enable auditing of successful and failed attempts to write to files in the %SYSTEM32%/CertLog directory.
Enable the Audit object access setting in the Local Security Policy for the Active Directory Certificate Services (AD CS) server.
第9题:
Configure the Workspace as revertible.
Set an expiration date for the Workspace.
Specify the number of image versions to keep.
Configure automatic deletion of the Workspace.
第10题:
Disable the root hints
Enable BIND secondaries
Configure a forwarder to the caching DNS server
Configure a GlobalNames host (A) record for the hostname of the caching DNS server
第11题:
Assign the user account to the CA Admin role.
Add the user account to the local Administrators group.
Grant the user the Back up files and directories user right.
Grant the user the Manage auditing and security log user right.
第12题:
Install and configure IIS on a member server.
Configure a shared folder on a member server.
Install and configure Microsoft SQL Server 2008 on a member server.
Configure permissions for the shared folder on a member server.
第13题:
Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your company uses an Enterprise Root certification authority (CA) and an Enterprise Intermediate CA. The Enterprise Intermediate CA certificate expires. You need to deploy a new Enterprise Intermediate CA certificate to all computers in the domain. What should you do()
第14题:
Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your company runs an Enterprise Root certification authority (CA). You need to ensure that only administrators can sign code. Which two task should you perform()
第15题:
Your company has an Active Directory forest that contains only Windows Server 2003 domain controllers. You need to prepare the Active Directory domain to install Windows Server 2008 domain controllers. Which two tasks should you perform()
第16题:
Your company has a single Active Directory forest that has six domains. All DNS servers in the forest run Windows Server 2008. You need to ensure that all public DNS quieries are channeled through a singlecahing- only DNS server. Which two actions should you perform?()
第17题:
Your company has an Active Directory domain. All servers run Windows Server 2008. Your company runs an Enterprise Root certification authority (CA). You need to ensure that only administrators can sign code. Which two tasks should you perform()
第18题:
Your company has a server that runs Windows Server 2008 R2. Active Directory Certificate Services (AD CS) is configured as a standalone Certification Authority (CA) on the server. You need to audit changes to the CA configuration settings and the CA security settings. Which two tasks should you perform()
第19题:
Publish the code signing template.
Edit the local computer policy of the Enterprise Root CA to allow users to trust peer certificates and allow only administrators to apply the policy.
Edit the local computer policy of the Enterprise Root CA to allow only administrators to manage Trusted Publishers.
Modify the security settings on the template to allow only administrators to request code signing certificates.
第20题:
Publish the code signing template.
Edit the local computer policy of the Enterprise Root CA to allow users to trust peer certificates and allow only administrators to apply the policy.
Edit the local computer policy of the Enterprise Root CA to allow only administrators to manage Trusted Publishers.
Modify the security settings on the template to allow only administrators to request code signing certificates.
第21题:
Publish the code signing template.
Edit the local computer policy of the Enterprise Root CA to allow users to trust peer certificates and allow only admi
Edit the local computer policy of the Enterprise Root CA to allow only administrators to manage Trusted Publishers.
Modify the security settings on the template to allow only administrators to request code signing certificates.
第22题:
Configure auditing in the Certification Authority snap-in.
Enable auditing of successful and failed attempts to change permissions on files in the %SYSTEM32%/CertSrv dire
Enable auditing of successful and failed attempts to write to files in the %SYSTEM32%/CertLog directory.
Enable the Audit object access setting in the Local Security Policy for the Active Directory Certificate Services
第23题:
Disable the root hints.
Enable BIND secondaries.
Configure a forwarder to the caching DNS server.
Configure a GlobalNames host (A) record for the hostname of the caching DNS server.
第24题:
Install and configure IIS on a member server.
Configure a shared folder on a member server.
Install and configure Microsoft SQL Server 2008 on a member server.
Configure permissions for the shared folder on a member server.