Your network contains an Active Directory domain named adatum.com. The network has an Active Directory Certificate Services (AD CS) infrastructure.
You need to issue a certificate to users to meet the following requirements:
Ensure that the users can encrypt files by using Encrypting File System (EFS).
Ensure that the default key length is 4096 bits for all users.
Ensure that a domain administrator can recover EFS encrypted files
What should you do first?
A. From the properties of the EFS Recovery Agent certificate template assign the Allow -Enroll permission to the Domain Group
B. From the properties of the Basic EFS template, assign the Full Control permission to the Domain Admin group.
C. Create a copy of the Key Recovery Agent certificate template and then modify the permissions of the copy.
D. Create a copy of the Basic EFS certificate template, and then modify key length of the copy.
need answer???

Working