网友您好, 请在下方输入框内输入要搜索的题目:

题目内容 (请给出正确答案)
多选题
You have Active Directory Certificate Services (AD CS) deployed.  You create a custom certificate template.   You need to ensure that all of the users in the domain automatically enroll for a certificate based on the  custom certificate template.   Which two actions should you perform()
A

In a Group Policy object (GPO), configure the autoenrollment settings

B

In a Group Policy object (GPO), configure the Automatic Certificate Request Settings.

C

On the certificate template, assign the Read and Autoenroll permission to the Authenticated Users  group.

D

On the certificate template, assign the Read, Enroll, and Autoenroll permission to the Domain Users  group.


参考答案

参考解析
解析: 暂无解析
更多 “多选题You have Active Directory Certificate Services (AD CS) deployed.  You create a custom certificate template.   You need to ensure that all of the users in the domain automatically enroll for a certificate based on the  custom certificate template.   Which two actions should you perform()AIn a Group Policy object (GPO), configure the autoenrollment settingsBIn a Group Policy object (GPO), configure the Automatic Certificate Request Settings.COn the certificate template, assign the Read and Autoenroll permission to the Authenticated Users  group.DOn the certificate template, assign the Read, Enroll, and Autoenroll permission to the Domain Users  group.” 相关考题
考题 Your network contains a server named Server1. The Active Directory Rights Management Services (AD RMS) server role is installed on Server1.   An administrator changes the password of the user account that is used by AD RMS.  You need to update AD RMS to use the new password.   Which console should you use()A、Active Directory Rights Management ServicesB、Active Directory Users and ComputersC、Component ServicesD、Services

考题 You are designing a plan to migrate an existing application to Windows Azure.  The application must use the existing Active Directory Domain Services (AD DS) domain. You need to recommend an approach for joining Windows Azure virtual machines to the domain.  What should you recommend?()A、 Install the Active Directory Certificate Services (AD CS) root certificate into the Enterprise Trustcertificate store on each virtual machine.B、 Configure Windows Azure Connect.C、 Configure Windows Azure AppFabric Access Control.D、 Install Active Directory Federation Services (AD FS) in the existing domain.

考题 You have an Active Directory domain that runs Windows Server 2008 R2. You need to implement  a certification authority (CA) server that meets the following requirements:     - Allows the certification authority to automatically issue certificates  - Integrates with Active Directory Domain Services     What should you do()A、Install and configure the Active Directory Certificate Services server role as a Standalone Root CA .B、Install and configure the Active Directory Certificate Services server role as an Enterprise Root CA .C、Purchase a certificate from a third-party certification authority. Install and configure the Active Directory Certificate SD、Purchase a certificate from a third-party certification authority. Import the certificate into the computer store of the sc

考题 Your company has an Active Directory domain. You plan to install the Active Directory Certificate Services (AD CS) server role on a member  server that runs Windows Server 2008 R2.     You need to ensure that members of the Account Operators group are able to issue smartcard  credentials. They should not be able to revoke certificates.     Which three actions should you perform()A、Install the AD CS server role and configure it as an Enterprise Root CA .B、Install the AD CS server role and configure it as a Standalone CA .C、Restrict enrollment agents for the Smartcard logon certificate to the Account Operator group.D、Restrict certificate managers for the Smartcard logon certificate to the Account Operator group.E、Create a Smartcard logon certificate.F、Create an Enrollment Agent certificate.

考题 Your company has an Active Directory forest. You plan to install an Enterprise certification  authority (CA) on a dedicated stand-alone server. When you attempt to add the Active Directory Certificate Services (AD CS) server role, you find  that the Enterprise CA option is not available. You need to install the AD CS server role as an Enterprise CA.     What should you do first()A、Add the DNS Server server role.B、Join the server to the domain.C、Add the Web Server (IIS) server role and the AD CS server role.D、Add the Active Directory Lightweight Directory Services (AD LDS) server role.

考题 Your company has an Active Directory forest. You plan to install an Enterprise certification authority  (CA) on a dedicated stand-alone server.    When you attempt to add the Active Directory Certificate Services (AD CS) server role, you find that the  Enterprise CA option is not available.    You need to install the AD CS server role as an Enterprise CA.    What should you do first()A、Add the DNS Server server role.B、Join the server to the domain.C、Add the Web Server (IIS) server role and the AD CS server roleD、Add the Active Directory Lightweight Directory Services (AD LDS) server role. .

考题 You have Active Directory Certificate Services (AD CS) deployed.  You create a custom certificate template.   You need to ensure that all of the users in the domain automatically enroll for a certificate based on the  custom certificate template.   Which two actions should you perform()A、In a Group Policy object (GPO), configure the autoenrollment settingsB、In a Group Policy object (GPO), configure the Automatic Certificate Request Settings.C、On the certificate template, assign the Read and Autoenroll permission to the Authenticated Users  group.D、On the certificate template, assign the Read, Enroll, and Autoenroll permission to the Domain Users  group.

考题 Your network contains two standalone servers named Server1 and Server2 that have Active  Directory Lightweight Directory Services (AD LDS) installed.Server1 has an AD LDS instance.  You need to ensure that you can replicate the instance from Server1 to Server2.  What should you do on both servers()A、Obtain a server certificate.B、Import the MS-User.ldf file.C、Create a service user account for AD LDS.D、Register the service location (SRV) resource records.

考题 You are designing a plan to migrate an existing application to Windows Azure.  The application must use the existing Active Directory Domain Services (AD DS) domain. You need to recommend an approach for joining Windows Azure virtual machines to the domain.  What should you recommend?()A、 Install the Active Directory Certificate Services (AD CS) root certificate into the Enterprise Trust certificate store on each virtual machine.B、 Configure Windows Azure Connect.C、 Configure Windows Azure AppFabric Access Control.D、 Install Active Directory Federation Services (AD FS) in the existing domain.

考题 You deploy a new Active Directory Federation Services (AD FS) federation server.   You request new certificates for the AD FS federation server.   You need to ensure that the AD FS federation server can use the new certificates.   To which certificate store should you import the certificates()A、ComputerB、IIS Admin Service service accountC、Local AdministratorD、World Wide Web Publishing Service service account

考题 As an administrator at Certkiller.com, you have installed an Active Directory forest that has a single domain. You have installed an Active Directory Federation services (AD FS) on the domain member server.  What should you do to configure AD FS to make sure that AD FS token contains information from the active directory domain()A、Add a new account store and configure it.B、Add a new resource partner and configure itC、Add a new resource store and configure itD、Add a new administrator account on AD FS and configure itE、None of the above

考题 Your company has an Active Directory Rights Management Services (AD RMS) server. Users have   Windows Vista computers. An Active Directory domain is configured at the Windows Server 2003  functional level.   You need to configure AD?RMS so that users are able to protect their documents.  What should you do()A、Install the AD?RMS client 2.0 on each client computer.B、Add the RMS service account to the local administrators group on the AD RMS server.C、Establish an e-mail account in Active Directory Domain Services (AD DS) for each RMS user.D、Upgrade the Active Directory domain to the functional level of Windows Server 2008.

考题 单选题You are designing a plan to migrate an existing application to Windows Azure.  The application must use the existing Active Directory Domain Services (AD DS) domain. You need to recommend an approach for joining Windows Azure virtual machines to the domain.  What should you recommend?()A  Install the Active Directory Certificate Services (AD CS) root certificate into the Enterprise Trustcertificate store on each virtual machine.B  Configure Windows Azure Connect.C  Configure Windows Azure AppFabric Access Control.D  Install Active Directory Federation Services (AD FS) in the existing domain.

考题 多选题Your company has a server that runs Windows Server 2008 R2. Active Directory Certificate Services  (AD CS) is configured as a standalone Certification Authority (CA) on the server. You need to audit changes to the CA configuration settings and the CA security settings. Which two tasks should you perform()AConfigure auditing in the Certification Authority snap-in.BEnable  auditing  of  successful  and  failed  attempts  to  change  permissions  on  files  in  the %SYSTEM32%/CertSrv directory.CEnable auditing of successful and failed attempts to write to files in the %SYSTEM32%/CertLog directory.DEnable the Audit object access setting in the Local Security Policy for the Active Directory Certificate  Services (AD CS) server.

考题 多选题Your company has a server that runs Windows Server 2008 R2. Active Directory Certificate  Services (AD CS) is configured as a standalone Certification Authority (CA) on the server. You  need to audit changes to the CA configuration settings and the CA security settings.     Which two tasks should you perform()AConfigure auditing in the Certification Authority snap-in.BEnable auditing of successful and failed attempts to change permissions on files in the %SYSTEM32%/CertSrv direCEnable auditing of successful and failed attempts to write to files in the %SYSTEM32%/CertLog directory.DEnable the Audit object access setting in the Local Security Policy for the Active Directory Certificate Services

考题 单选题Your company has an Active Directory forest. You plan to install an Enterprise certification authority (CA) on a dedicated stand-alone server. When you attempt to add the Active Directory Certificate Services (AD CS) role, you find that the Enterprise CA option is not available. You need to install the AD CS role as an Enterprise CA. What should you do first()A Add the DNS Server role.B Join the server to the domain.C Add the Web server (IIS) role and the AD CS role.D Add the Active Directory Lightweight Directory Service (AD LDS) role.

考题 单选题Certkiller.com has a server with Active Directory Rights Management Services (AD RMS) server installed. Users have computers with Windows Vista installed on them with an Active Directory domain installed at Windows Server 2003 functional level. As an administrator at Certkiller.com, you discover that the users are unable to benefit from AD RMS to protect their documents. You need to configure AD RMS to enable users to use it and protect their documents. What should you do to achieve this functionality()A Configure an email account in Active Directory Domain Services (AD DS) for each user.B Add and configure ADRMSADMIN account in local administrators group on the user computersC Add and configure the ADRMSSRVC account in AD RMS server’s local administrator groupD Reinstall the Active Directory domain on user computersE All of the above

考题 单选题You have a server named Server1 that has the following Active Directory Certificate Services (AD CS)   role services installed:   ( Enterprise root certification authority (CA)  .Certificate Enrollment Web Service   .Certificate Enrollment Policy Web Service   You create a new certificate template.   External users report that the new template is unavailable when they request a new certificate.  You verify that all other templates are available to the external users.   You need to ensure that the external users can request certificates by using the new template.  What should you do on Server1()A Run iisreset.exe /restart.  B Run gpupdate.exe /force.  C Run certutil.exe dspublish.D Restart the Active Directory Certificate Services service.

考题 单选题You have a Windows Server 2008 R2 Enterprise Root CA . Security policy prevents port 443 and  port 80 from being opened on domain controllers and on the issuing CA .   You need to allow users to request certificates from a Web interface. You install the Active  Directory Certificate Services (AD CS) server role.     What should you do next()A Configure the Online Responder Role Service on a member server.B Configure the Online Responder Role Service on a domain controller.C Configure the Certificate Enrollment Web Service role service on a member server.D Configure the Certificate Enrollment Web Service role service on a domain controller.

考题 单选题Certkiller .com has a network that is comprise of a single Active Directory Domain.  As an administrator at Certkiller .com, you install Active Directory Lightweight Directory Services (AD LDS) on a server that runs Windows Server 2008. To enable Secure Sockets Layer (SSL) based connections to the AD LDS server, you install certificates from a trusted Certification Authority (CA) on the AD LDS server and client computers.  Which tool should you use to test the certificate with AD LDS()A Ldp.exeB Active Directory Domain servicesC ntdsutil.exeD Lds.exeE wsamain.exeF None of the above

考题 单选题You are designing a plan to migrate an existing application to Windows Azure.  The application must use the existing Active Directory Domain Services (AD DS) domain. You need to recommend an approach for joining Windows Azure virtual machines to the domain.  What should you recommend?()A  Install the Active Directory Certificate Services (AD CS) root certificate into the Enterprise Trust certificate store on each virtual machine.B  Configure Windows Azure Connect.C  Configure Windows Azure AppFabric Access Control.D  Install Active Directory Federation Services (AD FS) in the existing domain.