nerdexam
Microsoft

70-647 · Question #61

You network contains one Active Directory domain. All domain controllers run Windows Server 2008. The network has 100 servers and 5,000 client computers. Client computers run either Windows XP…

The correct answer is C. Deploy an enterprise certification authority (CA). Create V2 templates. To deploy Certificate Services on the network and ensure that there is automatic certificate enrollment on the network and there are supported certificates for all client computers, you need to Deploy an enterprise certification authority (CA) and create V2 templates. You…

Planning and Implementing Security

Question

You network contains one Active Directory domain. All domain controllers run Windows Server 2008. The network has 100 servers and 5,000 client computers. Client computers run either Windows XP Service Pack 2 (SP2) or Windows Vista Service Pack 1 (SP1). You need to plan the deployment of Certificate Services on the network to support the following requirements:

  • Automatic certificate enrollment
  • Supported certificates for all client computers

What should you include in your plan?

Options

  • ADeploy a stand-alone certification authority (CA). Create V2 templates.
  • BDeploy a stand-alone certification authority (CA). Create V3 templates.
  • CDeploy an enterprise certification authority (CA). Create V2 templates.
  • DDeploy an enterprise certification authority (CA). Create V3 templates.

How the community answered

(30 responses)
  • A
    10% (3)
  • B
    3% (1)
  • C
    83% (25)
  • D
    3% (1)

Explanation

To deploy Certificate Services on the network and ensure that there is automatic certificate enrollment on the network and there are supported certificates for all client computers, you need to Deploy an enterprise certification authority (CA) and create V2 templates. You should use enterprise certification authority (CA) because it is integrated with Active Directory, and only provides certificates to members within that Active Directory. You should not use Standalone CA because it doesn't tap into a local or domain user account. You should used V2 templates instead of V1 templates because V2 templates are customizable. With V2 templates, a CA administrator is able to configure a wide range of settings that apply during certificate enrollment, such as minimum key length, subject name definition, enrollment requirements like enrollment agent signature, and so on 2fea1b7eceba1033.mspx?mfr=true

Topics

#enterprise CA#certificate auto-enrollment#certificate templates#PKI

Community Discussion

No community discussion yet for this question.

Full 70-647 Practice