|
What is a X.509 digital certificate?
An entity that list the policies that are used for security on the network
An electronic document that contains information about the owner of the certificate and the public key of the owner and the signature of the certificate authority
A means of updating Active Directory with user information
A way to provide information to the server about the security mechanism needed to establish the connection
| ||
|
Which of the following applications would require that a PKI architecture be in place? (Choose all the apply.)
Smart card logon
Encrypting File System
File sharing
IP security
Secure e-mail
| ||
|
What are the four possible ways of designing a CA hierarchy?
Organization
Groups
Geography
Function
Department
Users
| ||
|
Which of the following ways can you use to enroll for a certificate with a stand-alone CA?
Web enrollment page
Autoenrollment
certreq.exe
Certificate Request Wizard
| ||
|
Which operating systems can be used to perform autoenrollment with an enterprise CA? (Choose all that apply.)
Windows XP
Windows ME
Windows Server 2003
Windows 2000
| ||
|
What are the three possible roles for a CA in the organization?
Root CA
Intermediate CA
Enrollment CA
Issuing CA
Renewal CA
| ||
|
What auditing setting must be enabled to allow CA-specific auditing through the Certification Authority console?
Audit Account Login Events
Audit Object Access
Audit System Events
Audit Process Tracking
| ||
|
Which of the following reasons would you use in choosing to revoke a certificate? (Choose all that apply.)
The CA has been compromised.
The certificate has been renewed.
The CA certificate has been renewed.
The private key was stolen.
The certificate was used for signing.
The certificate authority has been retired.
| ||
|
What are the four roles that perform administrative tasks on a Windows Server 2003 CA server?
PKI Manager
Certificate Manager
PKI Administrator
Auditor
Administrator
Backup Operator
CA Administrator
| ||
|
Why should you perform role separation on a CA server?
To separate the types of CA servers so that renewal and enrollment take place on different servers
To minimize damage done to the certificate hierarchy should an attacker infiltrate the administrator account
To split the roles of the server for renewal and enrollment of certificates
To provide a mechanism to increase the availability of the PKI structure
|
Answers