GSLC · Question #245
You are the Administrator of a Windows 2000 based network for Info Tech Inc. You install and configure Certificate Authorities (CAs) on the network. You are currently configuring the public key group
The correct answer is D. An enterprise CA is not online.. Automatic certificate enrollment via Group Policy in Windows 2000 requires an Enterprise CA to be online and reachable. Without an online Enterprise CA, the domain-integrated autoenrollment process cannot function.
Question
You are the Administrator of a Windows 2000 based network for Info Tech Inc. You install and configure Certificate Authorities (CAs) on the network. You are currently configuring the public key group policy for the domain. You configure the group policy to specify automatic enrollment and renewal for certificates. But when you attempt to test this configuration, you find that the enrollment is not working properly. What is the most likely cause?
Options
- AThe group policy is not enabled for the domain.
- BYou failed to add the CA certificate to the trusted root certification authorities container.
- CCertificate enrollment and renewal is not enabled for the group policy.
- DAn enterprise CA is not online.
How the community answered
(31 responses)- A3% (1)
- B10% (3)
- C3% (1)
- D84% (26)
Why each option
Automatic certificate enrollment via Group Policy in Windows 2000 requires an Enterprise CA to be online and reachable. Without an online Enterprise CA, the domain-integrated autoenrollment process cannot function.
If the Group Policy itself were not enabled for the domain, no group policy settings would apply at all, not just certificate enrollment, making this too broad to be the specific cause.
Failing to add the CA certificate to the Trusted Root Certification Authorities container would cause certificate trust validation errors during authentication, not enrollment failures.
The question explicitly states the administrator already configured enrollment and renewal in group policy, so this option directly contradicts the scenario.
Automatic certificate enrollment configured through Group Policy in Windows 2000 requires an Enterprise CA because only Enterprise CAs are integrated with Active Directory and support the autoenrollment feature. If the Enterprise CA is offline or unavailable, enrollment requests cannot be processed, causing the failure observed. Standalone CAs do not support autoenrollment via Group Policy.
Concept tested: Windows 2000 Enterprise CA autoenrollment via Group Policy
Source: https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-2000-server/cc960093(v=technet.10)
Topics
Community Discussion
No community discussion yet for this question.