Prev Question
Next Question

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2.
Server1 is an enterprise root certification authority (CA) for contoso.com.
You need to ensure that the members of a group named Group1 can request code signing certificates. The certificates must be issued automatically to the
members.
Which two actions should you perform? (Each correct answer presents part of the solution.

Choose two.)

A. From Certificate Templates, modify the certificate template.

B. From Certification Authority, add a certificate template to be issued.

C. From Certificate Authority, modify the CA properties.

D. From Certificate Templates, duplicate a certificate template.

E. From Certificate Authority, stop and start the Active Directory Certificate Services (AD CS) service.

Explanation:

Explanation/Reference:
Best Practices include: Duplicate new templates from existing templates closest in function to the intended template.
New certificate templates are duplicated from existing templates. Many settings are copied from the original template. Because of this, duplicating one template to
another of a totally different type may carry over some unintended settings. When duplicating a template, examine the subject type of the original template and
ensure that you duplicate one that has a similar function to that of the intended template. Although most settings for certificate templates can be edited once the
template is duplicated, the subject type cannot be changed.
Reference: Deploying Certificate Templates
https://technet.microsoft.com/en-us/library/cc770794%28v=ws.10%29.aspx

Prev Question
Next Question

Leave a Reply

Your email address will not be published. Required fields are marked *