Answered step by step
Verified Expert Solution
Question
1 Approved Answer
Which of the following is considered a best practice in the handling of EFS certificates? Users should export their public keys and store them in
- Which of the following is considered a best practice in the handling of EFS certificates?
- Users should export their public keys and store them in a safe place.
- Recovery agents should export their private keys and store them in a safe place.
- Users should export their symmetric keys and store them in a safe place.
- EFS key pairs should always be encrypted.
- You are a network administrator of a Windows Server 2016 domain tasked with implementing the auto-enrollment of user certificates, which will be used to digitally sign emails. You perform the following procedures:
- Install an enterprise root CA.
- Choose a certificate template that allows users to digitally sign emails.
- Duplicate the certificate template.
- Assign permissions of Read, Enroll, and Autoenroll to the global security group that contains the users who need to be able to digitally sign emails.
- Edit the Default Domain Policy and enable the Certificate Services Client Auto-Enrollment policy in User Configuration/Policies/Windows Settings/Security Settings/Public Key Policies.
- Run gpupdate /force on the domain controller.
- Log on to a domain workstation with a test domain account that is a member of the global security group to which you assigned Read, Enroll, and Autoenroll permissions to the certificate template.
- Create an mmc that contains the Certificates snap-in.
- Right-click the CertificatesCurrent User node under the Console Root, click All Tasks, and click Automatically Enroll and Retrieve Certificates.
The certificate does not appear in the users Certificates console. The most likely reason for this is that ___________________.
-
- you did not issue the certificate template
- you did not assign the global security group the View permission to the certificate template
- only administrators can manually trigger the enrollment and installation of certificates
- you did not run gpupdate /force on the workstation
- In Lab 4.4, Anthony Newman received a certificate based on the User template. Which of the following statements regarding these certificates is correct? (Choose all that apply.)
- Both certificates allow Anthony Newman to use the Encrypting File System.
- Once a User certificate is issued to a user, the best practice is to revoke the users EFS certificate.
- The User certificate contains three different private keys, one for each of the three purposes of the certificate.
- Both certificates were issued by ServerName.
- In this lab, the auto-enrollment policy was configured so that all domain users could receive the certificate based on the User certificate template. (True or False)?
- Anthony used the certificate he received in Lab 4.4 to place his digital signature on an email to a customer named Helene Grimaud. For Helene to be sure that the email came from Anthony, she must __________________.
- trust ServerName
- install Anthonys certificate
- compare the thumbprint on Anthonys certificate with the result of her own hashing of his certificate
- send Anthony her certificate
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started