Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2. Server1 has the Active Directory Cer- tificate Services server role installed and is configured as an enterprise certification authority (CA).
You need to ensure that all of the users in the domain are issued a certificate that can be used for the following purposes:
. Email security
. Client authentication
. Encrypting File System (EFS)
Which two actions should you perform? (Each correct answer presents part of the solution.Choose two.)
A. From a Group Policy, configure the Certificate Services Client Auto-Enrollment settings.
B. From a Group Policy, configure the Certificate Services Client Certificate Enrollment Pol- icy settings.
C. Modify the properties of the User certificate template, and then publish the template.
D. Duplicate the User certificate template, and then publish the template.
E. From a Group Policy, configure the Automatic Certificate Request Settings settings.
Correct Answer: A,D
Explanation/Reference:
The default user template supports all of the requirements EXCEPT auto enroll as shown below:



Reference: Manage Certificate Enrollment Policy by Using Group Policy http://technet.microsoft.com/en- us/library/dd851772.aspx
No comments:
Post a Comment