You need to implement a certification authority (CA) serverthat meets the following requirements…
You have an Active Directory domainthat runs Windows Server 2008 R2.
You need to implement a certification authority (CA) serverthat meets the following requirements:
Allows the certification authority to automatically issue certificates
Integrates with Active Directory Domain Services
What should you do?
You need to grant members of the Account Operators group the ability to only manage Basic EFS certificates
You have a Windows Server 2008 R2 Enterprise Root certification authority (CA).
You need to grant members of the Account Operators group the ability to only manage Basic EFS
certificates.
You grant the Account Operators group the Issue and Manage Certificates permission on the CA.
Which three tasks should you perform next?
(Each correct answer presents part of the solution. Choose three.)
What should you do?
Your company has an Active Directory domain.
You have a two-tier PKI infrastructurethat contains an offline root CAand an online issuing CA.
The Enterprise certification authority is running Windows Server 2008 R2.
Youneed to ensure users are able to enroll new certificates.
What should you do?
Your company uses an Enterprise Root certification authority (CA)and an Enterprise Intermediate C
Your company has an Active Directory domain.
All serversrun Windows Server 2008 R2.
Your company uses an Enterprise Root certification authority (CA)and an Enterprise Intermediate CA.
The Enterprise Intermediate CA certificate expires.
Youneed to deploy a new Enterprise Intermediate CA certificate to all computers in the domain.
What should you do?
You need to ensure that the French-language version of the templates is available
Your company has recently acquired a new subsidiary company in Quebec.
The Active Directory administrators of the subsidiarycompany must use the French-language version
of the administrative templates.
You create a folder on the PDC emulator for the subsidiary domain in the path %systemroot%\SYSVOL
\domain\Policies\PolicyDefinitions\FR.
You need to ensure that the French-language version of the templates is available.
What should you do?
You need to enable the user to join a single computer to the domain
A user in a branch officeof your company attempts to join a computer to the domain, but the attempt
fails.
You need to enable the user to join a single computer to the domain.
You must ensure that the user is denied any additional rights beyond those required to complete the
task.
What should you do?
Which two actionsshould you perform?
The default domain GPOin your company is configuredby using the following account policy settings:
– Minimum password length: 8 characters
– Maximum password age: 30 days
– Enforce password history: 12 passwords remembered
– Account lockout threshold: 3 invalid logon attempts
– Account lockout duration: 30 minutes
Youinstall Microsoft SQL Serveron a computer named Server1that runs Windows Server 2008 R2.
The SQL Server applicationuses a service accountnamed SQLSrv.
The SQLSrv account has domain user rights.
The SQL Server computer fails after running successfully for several weeks.
The SQLSrv user account is not locked out.
You need to resolve the server failure and prevent recurrence of the failure.
Which two actionsshould you perform?
(Each correct answer presents part of the solution. Choose two.)
You need to set up a transitive forest trust between Forest1 and Forest2, What should you do first?
Your company has two Active Directory forestsnamed Forest1and Forest2.
The forest functional leveland the domain functional levelof Forest1are set to Windows Server 2008.
The forest functional levelof Forest2is set to Windows 2000, and the domain functional levelsin Forest2
are set to Windows Server 2003.
You need to set up a transitive forest trust between Forest1 and Forest2,
What should you do first?
You need to decrease the amount of time it takes for the branch office users to logon
Your company has an Active Directory forestthat contains two domains.
The forest hasuniversal groupsthat contain members from each domain.
A branch officehas a domain controllernamed DC1.
Users at the branch office report that the logon process takes too long.
You need to decrease the amount of time it takes for the branch office users to logon.
What should you do?
You need to ensure that the user is able to connect to the new server
Your company has an Active Directory domain.
The main officehas a DNS servernamed DNS1that is configured with Active Directory-integrated DNS.
The branch officehas a DNS servernamed DNS2that contains a secondary copy of the zone from DNS1.
The two officesare connectedwith an unreliable WAN link.
You add a new server to the main office.
Five minutes after adding the server, a user from the branch office reports that he is unable to connect
to the new server.
You need to ensure that the user is able to connect to the new server.
What should you do?