PrepAway - Latest Free Exam Questions & Answers

What should you use to log on to the new server?

Your network contains an Active Directory forest. The forest contains two domains. You
have a standalone root certification authority (CA).
On a server in the child domain, you run the Add Roles Wizard and discover that the option
to select an enterprise CA is disabled.
You need to install an enterprise subordinate CA on the server.
What should you use to log on to the new server?

PrepAway - Latest Free Exam Questions & Answers

A.
an account that is a member of the Certificate Publishers group in the child domain

B.
an account that is a member of the Certificate Publishers group in the forest root domain

C.
an account that is a member of the Schema Admins group in the forest root domain

D.
an account that is a member of the Enterprise Admins group in the forest root domain

Explanation:
http://social.technet.microsoft.com/Forums/uk/winserversecurity/thread/887f4cec-12f6-4c15-
a506-568ddb21d46b
In order to install Enterprise CA you MUST have Enterprise Admins permissions, because
Configuration naming context is replicated between domain controllers in the forest (not only
current domain) and are writable for Enterprise Admins (domain admins permissions are
insufficient).


Leave a Reply