exam questions

Exam MS-203 All Questions

View all questions & answers for the MS-203 exam

Exam MS-203 topic 3 question 23 discussion

Actual exam question from Microsoft's MS-203
Question #: 23
Topic #: 3
[All MS-203 Questions]

Your company has an Exchange Server 2019 organization that has servers deployed in two Active Directory forests named adatum.com and contoso.com.
The organization contains five Mailbox servers and two Edge Transport servers.
You deploy Microsoft 365 and configure Exchange Online.
You plan to configure hybrid mail transport.
You need to identify the number of third-party CA certificates that must be used in the deployment.
What is the minimum number of certificates?

  • A. 1
  • B. 2
  • C. 4
  • D. 5
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Crixus
Highly Voted 2 years, 11 months ago
If you're configuring a hybrid deployment in an organization that has Exchange servers deployed in multiple Active Directory forests, you must use a separate third-party CA certificate for each Active Directory forest.
upvoted 20 times
...
Stev_M
Highly Voted 2 years, 11 months ago
Answer should be B. A separate certificate is required for each Active Directory forest. The linked documentation also mentions this.
upvoted 6 times
...
Cooljoy7777
Most Recent 8 months, 3 weeks ago
Selected Answer: B
If you're configuring a hybrid deployment in an organization that has Exchange servers deployed in multiple Active Directory forests, you must use a separate third-party CA certificate for each Active Directory forest. https://learn.microsoft.com/en-us/exchange/certificate-requirements
upvoted 1 times
...
jonasrcampos
1 year ago
Selected Answer: B
2 Certificates!
upvoted 1 times
...
99redeyeflight
1 year, 9 months ago
Selected Answer: B
"For a multi-forest hybrid deployment, a single digital certificate can't be used for multiple Active Directory forests. Each forest must use a dedicated CA-issued certificate for secure mail transport to function correctly in a hybrid deployment. The certificate used for hybrid deployment features for each forest in a multi-forest organization must differ in at least one of the following properties..." https://docs.microsoft.com/en-us/exchange/hybrid-deployment/hybrid-with-multiple-forests
upvoted 3 times
...
rujuare
2 years ago
Selected Answer: B
A separate certificate is required for each Active Directory forest.
upvoted 1 times
...
Kodeblack
2 years, 1 month ago
ON exam - 4/18/2022 All 3 case studies were also on exam
upvoted 2 times
...
kazaki
2 years, 3 months ago
Selected Answer: B
If you're configuring a hybrid deployment in an organization that has Exchange servers deployed in multiple Active Directory forests, you must use a separate third-party CA certificate for each Active Directory forest.
upvoted 1 times
...
kazaki
2 years, 3 months ago
The question is saying 3rd party certificate u can use self signed certificate for one of the domains not recommended but it works so answer is correct
upvoted 1 times
kazaki
2 years, 3 months ago
Sorry I take back all I said the answer is 2 cert If you're configuring a hybrid deployment in an organization that has Exchange servers deployed in multiple Active Directory forests, you must use a separate third-party CA certificate for each Active Directory forest.
upvoted 1 times
...
...
iuli4854
2 years, 6 months ago
Selected Answer: B
If you're configuring a hybrid deployment in an organization that has Exchange servers deployed in multiple Active Directory forests, you must use a separate third-party CA certificate for each Active Directory forest.
upvoted 2 times
...
SCT
2 years, 6 months ago
If you're configuring a hybrid deployment in an organization that has Exchange servers deployed in multiple Active Directory forests, you must use a separate third-party CA certificate for each Active Directory forest.
upvoted 1 times
...
AwesomeSlide
2 years, 7 months ago
I thought 2 certificates too. Then You can have a single SSL certificate with multiple SANs (both domains specified). So Answer is you only need 1 SSL certificate.
upvoted 5 times
HawkesLager
1 year, 7 months ago
https://www.digicert.com/tls-ssl/multi-domain-ssl-certificates?
upvoted 1 times
...
...
kazaki
2 years, 7 months ago
Third-party certificate for each server: Using a dedicated certificate for each server that hosts services allows you to configure the certificate specifically for the services on that server. If you need to replace the certificate or renew it, you only need to replace it on the server where the services are installed. Other servers aren't impacted. https://docs.microsoft.com/en-us/exchange/certificate-requirements
upvoted 1 times
...
LoremanReturns
2 years, 9 months ago
"If you're configuring a hybrid deployment in an organization that has Exchange servers deployed in multiple Active Directory forests, you must use a separate third-party CA certificate for each Active Directory forest. When Exchange Edge Transport servers are deployed in an on-premises organization, this certificate must also be installed on all Edge Transport servers. Each Edge transport server must use a certificate that shares the same issuing CA and the same subject for hybrid secure mail to function correctly." Correct answer is B.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...