exam questions

Exam 70-744 All Questions

View all questions & answers for the 70-744 exam

Exam 70-744 topic 1 question 71 discussion

Actual exam question from Microsoft's 70-744
Question #: 71
Topic #: 1
[All 70-744 Questions]

DRAG DROP -
Your network contains an Active Directory domain named contoso.com. The domain contains a user named User1 and a computer named Computer1. Remote
Server Administration Tools (RSAT) is installed on Computer1.
You need to add User1 as a data recovery agent in the domain.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:

Show Suggested Answer Hide Answer
Suggested Answer:
References:
https://msdn.microsoft.com/library/cc875821.aspx#EJAA
https://www.serverbrain.org/managing-security-2003/using-the-cipher-command-to-add-data-recovery-agent.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
KidCastaldo
Highly Voted 4 years, 6 months ago
Just labbed this out. The process is... Log in as User Run Cipher /r Log in as Administrator Add Agent by using CER file Explanation... Cipher creates the files based on the logged in user. We need the user cert, not the administrator cert, thus log in as user first and run cipher. Then since the task is to make the user a domain recovery agent, log in as administrator and use the CER file (group policy asks for the CER file to add the agent, not the pfx file) so use the CER file to add the agent in group policy. Further explanation... Certutil and .PFX may be used if a user wants to give his recovery key to another user, but this is not used for domain agents. (I didn't lab this out, this is jut my educated guess)
upvoted 7 times
...
songogo
Highly Voted 4 years, 5 months ago
Correct Order of Actions:- 1. Instruct User1 to sign in to Computer1. 2. Run cipher.exe and specify the /R parameter. 3. Sign in to Computer1 as Contoso\Administrator. 4. Add the data recovery agent by using a .cer file. First, you have to instruct User1 to sign into computer1 and generate the EFS recovery agent key (private key .pfx file) and certificate (public key only .cer file) cipher.exe /R Generates an EFS recovery agent key and certificate, then writes them to a .pfx file (containing certificate and private key) and a .cer file (containing only the certificate). If /smartcard is specified, it writes the recovery key and certificate to a smart card, and no .pfx file is generated. Next, you have to user Administrative rights to use RSAT - GPMC to modify the default domain policy, add the User1's public key .cer file as DRA of the domain.
upvoted 7 times
...
Luffy
Most Recent 4 years, 6 months ago
.pfx file not .cer file. .pfx file contains the private key that the data recovery agent need to recover encrypted files.
upvoted 3 times
...
buiminhnhat
5 years ago
.pfx.file
upvoted 2 times
...
Provided answer is correct.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago