Your company has an Active Directory domain. All servers run Windows Server 2008. Your company runs an Enterprise Root certification authority (CA). You need to ensure that only administrators can sign code. Which two tasks should you perform()
第1题:
Your company has 10 servers that run Windows Server 2008. The servers have Remote Desktop Protocol (RDP) enabled for server administration. RDP is configured to use default security settings. All administrators’ computers run Windows Vista. You need to ensure the RDP connections are as secure as possible.Which two actions should you perform? ()
第2题:
Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your company uses an Enterprise Root certification authority (CA) and an Enterprise Intermediate CA. The Enterprise Intermediate CA certificate expires. You need to deploy a new Enterprise Intermediate CA certificate to all computers in the domain. What should you do()
第3题:
Your company has an Active Directory forest that contains only Windows Server 2008 domain controllers. You need to prepare the Active Directory domain to install Windows Server 2008 R2 domain controllers. Which two tasks should you perform()
第4题:
Your company has a single Active Directory forest that has six domains.All DNS servers in the forest run Windows Server 2008 R2.You need to ensure that all public DNS queries are channeled through a single-caching-only DNS server.Which two actions should you perform?()
第5题:
Your company has an Active Directory forest that contains only Windows Server 2003 domain controllers. You need to prepare the Active Directory domain to install Windows Server 2008 domain controllers. Which two tasks should you perform()
第6题:
Your company has a server that runs Windows Server 2008. Certification Services is configured as a stand-alone Certification Authority (CA) on the server. You need to audit changes to the CA configuration settings and the CA security settings. Which two tasks should you perform()
第7题:
Your company has a single Active Directory forest that has six domains. All DNS servers in the forest run Windows Server 2008.You need to ensure that all public DNS queries are channeled through a single-caching-only DNS server. Which two actions should you perform? (Each correct answer presents part of the solution.()
第8题:
Your company has a server that runs Windows Server 2008 R2. Active Directory Certificate Services (AD CS) is configured as a standalone Certification Authority (CA) on the server. You need to audit changes to the CA configuration settings and the CA security settings. Which two tasks should you perform()
第9题:
Publish the code signing template.
Edit the local computer policy of the Enterprise Root CA to allow users to trust peer certificates and allow only administrators to apply the policy.
Edit the local computer policy of the Enterprise Root CA to allow only administrators to manage Trusted Publishers.
Modify the security settings on the template to allow only administrators to request code signing certificates.
第10题:
Publish the code signing template.
Edit the local computer policy of the Enterprise Root CA to allow users to trust peer certificates and allow only admi
Edit the local computer policy of the Enterprise Root CA to allow only administrators to manage Trusted Publishers.
Modify the security settings on the template to allow only administrators to request code signing certificates.
第11题:
Assign the Certificate Manager role to the CertIssuers group.
Place CertIssuers group in the Certificate Publisher group
Run the certsrv -add CertIssuers command promt of the certificate server
Run the add -member-membertype memberset CertIssuers command by using Microsoft WindowsPowershell
第12题:
Assign the user account to the CA Admin role.
Add the user account to the local Administrators group.
Grant the user the Back up files and directories user right.
Grant the user the Manage auditing and security log user right.
第13题:
Your company has an Active Directory domain. AlI servers run Windows Server 2008. Your company uses an Enterprise Root certificate authority (CA). You need to ensure that revoked certificate information is highly available. What should you do()
第14题:
Your company has an Active Directory domain. All servers run Windows Server 2008. Your company uses an ENterprise Root certification authority (CA) and an Enterprise Intermediate CA. The Enterprise intermediate CA certificate expires. You need to deploy a new Enterprise Intermediate CA certificate to all computers in the domain. What should you do()
第15题:
Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your company runs an Enterprise Root certification authority (CA). You need to ensure that only administrators can sign code. Which two task should you perform()
第16题:
Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. You have a stand-alone server that serves as a Stand-alone root certification authority (CA). You need to ensure that a specific user can back up the CA and configure the audit parameters on the CA. What should you do?()
第17题:
Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your company uses an Enterprise Root certification authority (CA) and an Enterprise Intermediate CA. The Enterprise Intermediate CA certificate expires. You need to deploy a new Enterprise Intermediate CA certificate to all computers in the domain. What should you do()
第18题:
Your company has a single Active Directory forest that has six domains. All DNS servers in the forest run Windows Server 2008. You need to ensure that all public DNS quieries are channeled through a singlecahing- only DNS server. Which two actions should you perform?()
第19题:
Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your company uses an Enterprise Root certificate authority (CA). You need to ensure that revoked certificate information is highly available. What should you do()
第20题:
Publish the code signing template.
Edit the local computer policy of the Enterprise Root CA to allow users to trust peer certificates and allow only administrators to apply the policy.
Edit the local computer policy of the Enterprise Root CA to allow only administrators to manage Trusted Publishers.
Modify the security settings on the template to allow only administrators to request code signing certificates.
第21题:
Run the adprep /forestprep command.
Run the adprep /domainprep command.
Raise the forest functional level to Windows Server 2008.
Raise the domain functional level to Windows Server 2008.
第22题:
Implement an Online Certificate Status Protocol (OCSP) responder by using Network Load Balancing.
Implement an Online Certificate Status Protocol (OCSP) responder by using an Internet Security and Acceleration Server array.
Publish the trusted certificate authorities list to the domain by using a Group Policy Object (GPO).
Create a new Group Policy Object (GPO) that allows users to trust peer certificates. Link the GPO to the domain.
第23题:
Configure auditing in the Certification Authority snap-in.
Enable auditing of successful and failed attempts to change permissions on files in the %SYSTEM32%/CertSrv dire
Enable auditing of successful and failed attempts to write to files in the %SYSTEM32%/CertLog directory.
Enable the Audit object access setting in the Local Security Policy for the Active Directory Certificate Services