70-685 · Question #85
A user's computer fails. The help desk provides the user with a new computer. The user's Documents folder is restored from the backup. The user reports that he can no longer access his encrypted…
The correct answer is A. credential roaming be enabled. Credential roaming allows organizations to store certificates and private keys in Active Directory Domain Services (AD DS) separately from application state or configuration information. Credential roaming uses existing logon and autoenrollment mechanisms to securely download…
Question
A user's computer fails. The help desk provides the user with a new computer. The user's Documents folder is restored from the backup. The user reports that he can no longer access his encrypted files. The help desk recovers the files by using a data recovery agent (DRA). You need to ensure that when users receive new computers, they can access their encrypted files without administrative intervention. What should you request?
Options
- Acredential roaming be enabled
- BBitLocker be enabled on all computers
- Cuser accounts be trusted for delegation
- Dthe CA be configured for key archival and recovery
How the community answered
(28 responses)- A86% (24)
- B7% (2)
- C4% (1)
- D4% (1)
Explanation
Credential roaming allows organizations to store certificates and private keys in Active Directory Domain Services (AD DS) separately from application state or configuration information. Credential roaming uses existing logon and autoenrollment mechanisms to securely download certificates and keys to a local computer whenever a user logs on and, if desired, remove them when the user logs off. In addition, the integrity of these credentials is maintained under any conditions, such as when certificates are updated and when users log on to more than one computer at a time. This security setting determines which users can set the Trusted for Delegation setting on a user or computer object. The user or object that is granted this privilege must have write access to the account control flags on the user or computer object. A server process running on a computer (or under a user context) that is trusted for delegation can access resources on another computer using delegated credentials of a client, as long as the client account does not have the Account cannot be delegated account control flag set.
Topics
Community Discussion
No community discussion yet for this question.