niusouti.com

You have a Windows Server 2008 R2 that has the Active Directory Certificate Services server  role installed.   You need to minimize the amount of time it takes for client computers to download a certificate  revocation list (CRL).     What should you do(

题目

You have a Windows Server 2008 R2 that has the Active Directory Certificate Services server  role installed.   You need to minimize the amount of time it takes for client computers to download a certificate  revocation list (CRL).     What should you do()

  • A、Install and configure an Online Responder.
  • B、Install and configure an additional domain controller.
  • C、Import the Root CA certificate into the Trusted Root Certification Authorities store on all client workstations.
  • D、Import the Issuing CA certificate into the Trusted Root Certification Authorities store on all client workstations.

相似考题
更多“You have a Windows Server 2008 R2 that has the Active Directory Certificate Services server  role installed.   You need to minimize the amount of time it takes for client computers to download a certificate  revocation list (CRL).     What should you do()”相关问题
  • 第1题:

    Your company has an Active Directory forest. You plan to install an Enterprise certification authority (CA) on a dedicated stand-alone server. When you attempt to add the Active Directory Certificate Services (AD CS) role, you find that the Enterprise CA option is not available. You need to install the AD CS role as an Enterprise CA. What should you do first()

    • A、Add the DNS Server role.
    • B、Join the server to the domain.
    • C、Add the Web server (IIS) role and the AD CS role.
    • D、Add the Active Directory Lightweight Directory Service (AD LDS) role.

    正确答案:B

  • 第2题:

    Your company has an Active Directory forest. You plan to install an Enterprise certification  authority (CA) on a dedicated stand-alone server. When you attempt to add the Active Directory Certificate Services (AD CS) server role, you find  that the Enterprise CA option is not available. You need to install the AD CS server role as an Enterprise CA.     What should you do first()

    • A、Add the DNS Server server role.
    • B、Join the server to the domain.
    • C、Add the Web Server (IIS) server role and the AD CS server role.
    • D、Add the Active Directory Lightweight Directory Services (AD LDS) server role.

    正确答案:B

  • 第3题:

    Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack 2 (SP2). You have a server named Server1. Server1 is configured as an enterprise root certification authority (CA). You perform a complete backup of Server1 that includes the system state. Server1 fails. You install a new server named Server1. You need to recover the enterprise root CA. What should you do? ()

    • A、Restore the system state backup.
    • B、Restore the %systemroot%/system32/certsrv folder.
    • C、From the Certificates snap-in, import the enterprise root CA certificate.
    • D、From the Certificates snap-in, import the enterprise root CA certificate revocation list (CRL).

    正确答案:A

  • 第4题:

    You have a Windows Server 2008 R2 Enterprise Root CA . Security policy prevents port 443 and  port 80 from being opened on domain controllers and on the issuing CA .   You need to allow users to request certificates from a Web interface. You install the Active  Directory Certificate Services (AD CS) server role.     What should you do next()

    • A、Configure the Online Responder Role Service on a member server.
    • B、Configure the Online Responder Role Service on a domain controller.
    • C、Configure the Certificate Enrollment Web Service role service on a member server.
    • D、Configure the Certificate Enrollment Web Service role service on a domain controller.

    正确答案:C

  • 第5题:

    You have two servers named Server1 and Server2. Both servers run Windows Server 2008 R2.   Server1 is configured as an enterprise root certification authority (CA).    You install the Online Responder role service on Server2.    You need to configure Server1 to support the Online Responder. What should you do()

    • A、Import the enterprise root CA certificate.
    • B、Configure the Certificate Revocation List Distribution Point extension.
    • C、Configure the Authority Information Access (AIA) extension.
    • D、Add the Server2 computer account to the CertPublishers group.

    正确答案:C

  • 第6题:

    Your network contains an Active Directory forest. All domain controllers run Windows Server  2008 Standard. The functional level of the domain is Windows Server 2003. You have a  certification authority (CA).   The relevant servers in the domain are configured as shown in the following table:     Server name  Operating system  Server role   Server1  Windows Server 2003  Enterprise root CA  Server2  Windows Server 2008  Enterprise subordinate CA  Server3  Windows Server 2008 R2  Web Server   You need to ensure that you can install the Active Directory Certificate Services (AD CS)  Certificate Enrollment Web Service on the network.     What should you do()

    • A、Upgrade Server1 to Windows Server 2008 R2.
    • B、Upgrade Server2 to Windows Server 2008 R2.
    • C、Raise the functional level of the domain to Windows Server 2008.
    • D、Install the Windows Server 2008 R2 Active Directory Schema updates.

    正确答案:D

  • 第7题:

    Your network contains an Active Directory domain. You have a server that runs Windows Server 2008 R2 and has the Remote Desktop Services server role enabled. All client computers run Windows 7. You need to plan the deployment of a new line-of-business application to all client computers. The  deployment must meet the following requirements:   èUsers must access the application from an icon on their desktops.   èUsers must have access to the application when they are not connected to the network. What should you do?()

    • A、Publish the application as a RemoteApp.
    • B、Publish the application by using Remote Desktop Web Access (RD Web Access).
    • C、Assign the application to the Remote Desktop Services server by using a Group Policy object (GPO).
    • D、Assign the application to all client computers by using a Group Policy object (GPO).

    正确答案:D

  • 第8题:

    Your network contains an Active Directory forest. All domain controllers run Windows Server 2008   Standard. The functional level of the domain is Windows Server 2003.  You have a certification authority (CA).   The relevant servers in the domain are configured as shown in the following table.  Server name  Operating system  Server role   Server1  Windows Server 2003  Enterprise root CA  Server2  Windows Server 2008  Enterprise subordinate CA    Server3  Windows Server 2008 R2    Web Server   You need to ensure that you can install the Active Directory Certificate Services (AD CS) Certificate   Enrollment Web Service on the network.   What should you do()

    • A、Upgrade Server1 to Windows Server 2008 R2.
    • B、Upgrade Server2 to Windows Server 2008 R2.
    • C、Raise the functional level of the domain to Windows Server 2008.
    • D、Install the Windows Server 2008 R2 Active Directory Schema updates.

    正确答案:D

  • 第9题:

    单选题
    Your company has an Active Directory Domain Services (AD DS) domain that includes an AD security group named Development. You have a member server that runs Windows Server 2008 R2 with the Hyper-V role installed. You need to ensure that Development group members can only manage virtual machines (VMs). Development group members must not have administrative privileges on the host server. What should you use?()
    A

    Authorization Manager

    B

    Local Users and Groups

    C

    the net localgroup command

    D

    Active Directory Administrative Center


    正确答案: C
    解析: 暂无解析

  • 第10题:

    Your company has an Active Directory domain. You plan to install the Active Directory Certificate Services (AD CS) server role on a member  server that runs Windows Server 2008 R2.     You need to ensure that members of the Account Operators group are able to issue smartcard  credentials. They should not be able to revoke certificates.     Which three actions should you perform()

    • A、Install the AD CS server role and configure it as an Enterprise Root CA .
    • B、Install the AD CS server role and configure it as a Standalone CA .
    • C、Restrict enrollment agents for the Smartcard logon certificate to the Account Operator group.
    • D、Restrict certificate managers for the Smartcard logon certificate to the Account Operator group.
    • E、Create a Smartcard logon certificate.
    • F、Create an Enrollment Agent certificate.

    正确答案:A,C,E

  • 第11题:

    You have a Windows Server 2008 R2 that has the Active Directory Certificate Services server  role installed.   You need to minimize the amount of time it takes for client computers to download a certificate  revocation list (CRL).     What should you do()

    • A、Install and configure an Online Responder.
    • B、Install and configure an additional domain controller.
    • C、Import the Root CA certificate into the Trusted Root Certification Authorities store on all client workstations.
    • D、Import the Issuing CA certificate into the Trusted Root Certification Authorities store on all client workstations.

    正确答案:A

  • 第12题:

    Your company has an Active Directory Rights Management Services (AD RMS) server. Users  have Windows Vista computers. An Active Directory domain is configured at the Windows Server  2003 functional level.     You need to configure AD RMS so that users are able to protect their documents.     What should you do()

    • A、Install the AD RMS client 2.0 on each client computer.
    • B、Add the RMS service account to the local administrators group on the AD RMS server.
    • C、Establish an e-mail account in Active Directory Domain Services (AD DS) for each RMS user.
    • D、Upgrade the Active Directory domain to the functional level of Windows Server 2008.

    正确答案:C

  • 第13题:

    Your company has an Active Directory forest. You plan to install an Enterprise certification authority  (CA) on a dedicated stand-alone server.    When you attempt to add the Active Directory Certificate Services (AD CS) server role, you find that the  Enterprise CA option is not available.    You need to install the AD CS server role as an Enterprise CA.    What should you do first()

    • A、Add the DNS Server server role.
    • B、Join the server to the domain.
    • C、Add the Web Server (IIS) server role and the AD CS server role
    • D、Add the Active Directory Lightweight Directory Services (AD LDS) server role. .

    正确答案:B

  • 第14题:

    Your company has an Active Directory Domain Services (AD DS) domain that includes an AD security group named Development. You have a member server that runs Windows Server 2008 R2 with the Hyper-V role installed. You need to ensure that Development group members can only manage virtual machines (VMs). Development group members must not have administrative privileges on the host server. What should you use?()

    • A、Authorization Manager
    • B、Local Users and Groups
    • C、the net localgroup command
    • D、Active Directory Administrative Center

    正确答案:A

  • 第15题:

    You have a server named Server1 that has the following Active Directory Certificate Services (AD CS)   role services installed:   ( Enterprise root certification authority (CA)  .Certificate Enrollment Web Service   .Certificate Enrollment Policy Web Service   You create a new certificate template.   External users report that the new template is unavailable when they request a new certificate.  You verify that all other templates are available to the external users.   You need to ensure that the external users can request certificates by using the new template.  What should you do on Server1()

    • A、Run iisreset.exe /restart.  
    • B、Run gpupdate.exe /force.  
    • C、Run certutil.exe dspublish.
    • D、Restart the Active Directory Certificate Services service.

    正确答案:A

  • 第16题:

    You have a Windows Server 2008 that has the Active Directory Certificate Services server role installed. You need to minimize the amount of time it takes to download a certificate revocation list (CRL). What should you do()

    • A、Install and configure an Online Responder.
    • B、Install and configure an addtional domain controller.
    • C、Import the Root CA certificate into the Trusted Root Certification Authorities on all client workstations.
    • D、Import the Issuing CA certificate into the Trusted Root Certification Authorities on all client workstations.

    正确答案:A

  • 第17题:

    You have an Active Directory domain that runs Windows Server 2008 R2. You need to implement  a certification authority (CA) server that meets the following requirements:     - Allows the certification authority to automatically issue certificates  - Integrates with Active Directory Domain Services     What should you do()

    • A、Install and configure the Active Directory Certificate Services server role as a Standalone Root CA .
    • B、Install and configure the Active Directory Certificate Services server role as an Enterprise Root CA .
    • C、Purchase a certificate from a third-party certification authority. Install and configure the Active Directory Certificate S
    • D、Purchase a certificate from a third-party certification authority. Import the certificate into the computer store of the sc

    正确答案:B