exam questions

Exam MS-203 All Questions

View all questions & answers for the MS-203 exam

Exam MS-203 topic 3 question 31 discussion

Actual exam question from Microsoft's MS-203
Question #: 31
Topic #: 3
[All MS-203 Questions]

You have a Microsoft Exchange Server 2019 organization named contoso.com and an Exchange Online tenant.
You plan to implement a hybrid deployment.
You have the certificates shown in the following table.

You need to identify which certificates can be assigned in the Microsoft Office 365 Exchange Hybrid Configuration wizard.
Which certificates should you identify?

  • A. Cert2 and Cert4 only
  • B. Cert3 and Cert5 only
  • C. Cert4 and Cert5 only
  • D. Cert2, Cert3, Cert4, and Cert5 only
  • E. Cert2 and Cert3 only
  • F. Cert1 only
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
Reference:
https://docs.microsoft.com/en-us/exchange/certificate-requirements

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Amir1909
6 months, 2 weeks ago
C is correct
upvoted 1 times
...
Paulie69
1 year, 6 months ago
on exam 12/9/22
upvoted 1 times
...
DD2021
2 years, 2 months ago
04/16/2022 - on the exam
upvoted 1 times
...
Thor123
2 years, 3 months ago
Selected Answer: C
I will go with C as the correct answer. The question specifically states "assigned in the Microsoft Office 365 Exchange Hybrid Configuration wizard" In the Hybrid Deployment Prerequisites here: https://docs.microsoft.com/en-us/exchange/hybrid-deployment-prerequisites The certificate requirements state: Certificates: Assign Exchange services to a valid digital certificate that you purchased from a trusted public certificate authority (CA). Although you should use self-signed certificates for the on-premises federation trust with the Microsoft Federation Gateway, you can't use self-signed certificates for Exchange services in a hybrid deployment. The EWS external URL and the Autodiscover endpoint that you specified in your public DNS must be listed in the Subject Alternative Name (SAN) field of the certificate. The certificates that you install on the Exchange servers for mail flow in the hybrid deployment must all be issued by the same certificate authority and have the same subject. Only Cert 4 and 5 meet these requirements.
upvoted 2 times
...
Harshul
2 years, 4 months ago
Correct Answer should be Cert1 and Cert5 Cert1: Exchange federation: A self-signed certificate is used to create a secure connection between the on-premises Exchange servers and the Azure Active Directory authentication system Cert5" When configuring a hybrid deployment, you must use and configure certificates that you have purchased from a trusted third-party CA. The certificate used for hybrid secure mail transport must be installed on all on-premises Mailbox (Exchange 2016 and newer), and Mailbox and Client Access (Exchange 2013 and older) servers. Nowhere mentioned that you can use Internal CA, please share link if anyone has it to support the internal CA as answer https://docs.microsoft.com/en-us/exchange/certificate-requirements#:~:text=When%20configuring%20a%20hybrid%20deployment%2C%20you%20must%20use,Client%20Access%20%28Exchange%202013%20and%20older%29%20servers.%20Important
upvoted 2 times
...
SCT
2 years, 7 months ago
Correct answer: B. Cert3 and Cert5 only, Modern Hybrid Topology with Hybrid Agent can use Internal CA.
upvoted 2 times
...
Bobalo
2 years, 10 months ago
Assuming * means *.contose.com, it's C. * certificates don't exist, but only 5 is not an option. 3rd party cert is required.
upvoted 2 times
...
MomoLomo
2 years, 11 months ago
cert 2 and 5
upvoted 1 times
...
josemariamr
3 years, 1 month ago
I think it refers to wilcards certificates for the domain you own: *.yourdomain.com. Obviously you can not buy a * certificates for thw whole Internet. A requisite when buying certificates related to a domain is verify that you own it.
upvoted 1 times
...
brad1
3 years, 2 months ago
Anyone know where I can buy a publicly signed cert for "*"? Lol. Silly answer.
upvoted 4 times
...
Briareus
3 years, 3 months ago
Hybrid deployment require Public certificate (SAN), there for Cert4 and Cert5.
upvoted 4 times
terences
2 years, 11 months ago
modern hybrid can use internal cert
upvoted 1 times
Cbruce
2 years, 11 months ago
No internal certs. "When configuring a hybrid deployment, you must use and configure certificates that you have purchased from a trusted third-party CA. The certificate used for hybrid secure mail transport must be installed on all on-premises Mailbox (Exchange 2016 and newer), and Mailbox and Client Access (Exchange 2013 and older) servers."
upvoted 3 times
...
...
...
Sisko
3 years, 3 months ago
You can't generate a public cert for the name *, so this answer doesn't make sense.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...