exam questions

Exam 70-742 All Questions

View all questions & answers for the 70-742 exam

Exam 70-742 topic 1 question 205 discussion

Actual exam question from Microsoft's 70-742
Question #: 205
Topic #: 1
[All 70-742 Questions]

DRAG DROP -
You network contains an Active Directory domain named contoso.com. The domain contains an enterprise certification authority (CA).
A user named Admin1 is a member of the Domain Admins group.
You need to ensure that you can archive keys on the CA. The solution must use Admin1 as a key recovery agent.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
coleman
Highly Voted 5 years, 6 months ago
Correct Order of Actions is : 1) - From the Certificate Templates console, modify the security of a certificate template. 2) - From the Certification Authority console, add a certificate template to issue. 3) - From the Certificates console, request a certificate. 4) - From the Certification Authority console, add a Key Recovery Agent certificate.
upvoted 7 times
MentalG
5 years, 3 months ago
I agree with this one. Get the template, add the security account to match Admin1, ready your new template in the CA to be issued, Admin1 logs on and requests the certificate, then the certificate, once issued, is assigned as a KRA.
upvoted 1 times
...
...
daluadanilo
Highly Voted 4 years, 11 months ago
the given answer is right. Because admin1 is in Domain Admins group, and the Domain Admins group is enabled in "security settings" of the "Certificate template"
upvoted 6 times
...
lofzee
Most Recent 4 years, 5 months ago
Correct answer : 1) From the Certification Authority console, add a certificate template to issue. 2) From the Certification Authority console, add a Key Recovery Agent certificate. 3) From the Certificates Console, request a certificate. 4) From the Certification Authority console, issue a pending request. You do not need the modify the security because Admin1 is in 'Domain Admins'. Domain Admins already have the correct permissions.
upvoted 1 times
...
elopez2207
4 years, 5 months ago
I tested this lab. The right answer is: 1) From the Certification Authority console, add a certificate template to issue. 2) From the Certification Authority console, add a Key Recovery Agent certificate. 3) From the Certificates Console, request a certificate. 4) From the Certification Authority console, issue a pending request. My video of the case: https://drive.google.com/drive/folders/1NcYivqP_KBsltPpOcIY_kiN--8t38--r?usp=sharing Explanation: Here: https://drive.google.com/file/d/1w9-xnuix5bRmofaUL9il4Co_yD6glsLR/view?usp=sharing
upvoted 2 times
user789
4 years, 5 months ago
thanks for the explanation & your efforts
upvoted 1 times
...
...
VeiN
4 years, 8 months ago
The given answer is correct "A user named Admin1 is a member of the Domain Admins group. The solution must use Admin1 as a key recovery agent." When you enter security of a templete Domain Admins already have r/w and enroll rights so you dont need to change anything at security. You don`t need to add Admin1 directly, he`ll inherit this setting from Domain Admins group.
upvoted 6 times
...
eyeteegrunt
4 years, 8 months ago
whats the correct answer for this one?
upvoted 2 times
...
lorenc77
5 years, 2 months ago
I am for another approach: The security of certificate doesn't need to change since Admin1 is member of Domain Admins. so in my opinion the correct order is : 1)From the Certification Authority console, add a certificate template to issue. (add recovery agent to issue) 2)From the Certificates console, request a certificate (request cert from Admin1) 3)From the Certifactes console, issue a pending request. ( issue the admin cert) 4) From the Certification Authority console, add a Key Recovery Agent certificate.
upvoted 5 times
...
adasko
5 years, 3 months ago
As per pluralsight course, the correct order should be 1) From the Certification Authority console, add a Key Recovery Agent certificate. This certificate is not available in certificate templates so you'll have to add it there. (best practice is to duplicate but the option is missing) 2) From the Certificate Templates console, modify the security of a certificate template 3) From the Certification Authority console, add a certificate template to issue 4) From the Certificates console, request a certificate
upvoted 4 times
...
MrRiver
5 years, 7 months ago
The given Answer seems correct "You need to ensure that you can archive keys on the CA" Keyword is "can" ... you don't need to do it now. so you need a Key-Recovery agent certificate ... before you cann issue it you need to enable the template ... step 1 asumes that you don't do any changes ... than you need to request ist ... issue the certificate on the ca ... finaly enable the Key recovery agent on CA Level
upvoted 3 times
...
Charchar
5 years, 8 months ago
It even has the option "From the certificate templates console, modify the security of a certificate template" listed there
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...