exam questions

Exam 70-742 All Questions

View all questions & answers for the 70-742 exam

Exam 70-742 topic 1 question 213 discussion

Actual exam question from Microsoft's 70-742
Question #: 213
Topic #: 1
[All 70-742 Questions]

You have a standalone root certification authority (CA).
You have a new security policy requirements specifying that any changes to the CA configuration must be logged.
You need to ensure that the CA meets the new security requirement.
Which two actions should you perform? Each correct answer presents part of the solution.

  • A. From the Certification Authority console, modify the Auditing settings for the CA.
  • B. From the Certification Authority console, modify the Security settings for the CA.
  • C. From Local Group Policy Editor, configure auditing for policy change.
  • D. From the Certification Authority console, modify the Certificate Managers settings for the CA.
  • E. From Local Group Policy Editor, configure auditing for object access.
Show Suggested Answer Hide Answer
Suggested Answer: CE 🗳️
Audit policy change defines whether every incident of a change to user rights assignment policies, audit policies, or trust policies is audited.
Audit object access defines whether the event of a user accessing an object--for example, a file, folder, registry key, printer, and so forth--that has its own system access control list (SACL) specified is audited.
References:
https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-policy-change https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-object-access

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
coleman
Highly Voted 5 years, 5 months ago
the answer should be A&E A. From the Certification Authority console, modify the Auditing settings for the CA. E. From Local Group Policy Editor, configure auditing for object access.
upvoted 17 times
...
[Removed]
Highly Voted 5 years, 4 months ago
One more vote for A and E. https://www.itprotoday.com/security/q-addition-certification-authority-ca-level-auditing-settings-are-there-any-other
upvoted 10 times
lbs
4 years, 11 months ago
Agree. A and E
upvoted 2 times
...
...
Kamikazekiller
Most Recent 4 years, 10 months ago
A. From the Certification Authority console, modify the Auditing settings for the CA. E. From Local Group Policy Editor, configure auditing for object access.
upvoted 1 times
...
Lelek
4 years, 12 months ago
In Policy, the answer correct is "Object Access", then Answer E "Policy Change" is wrong, this policy will only audit policy changes. In CA, the answer correct is "auditing settings", then answer A "Security Settings" is wrong, this tab is responsible for applying permissions of which user or group can issue, manage or request a certificate Final answer A and E
upvoted 3 times
...
khalid86
5 years ago
Correct answer is A and E
upvoted 2 times
...
AZ764
5 years, 1 month ago
According to Pluralsight (Course is Implemented Active Directory Certificate Services in Windows Server 2016), the correct answers are: A E You enable on the Local Security Policy for OBJECT ACCESS Auditing After that, you change the AUDITING SETTINGS from the CA Properties
upvoted 1 times
...
Adeban
5 years, 5 months ago
The right is CD ,
upvoted 2 times
...
panda
5 years, 5 months ago
To meet goal both CA side settings and Group policy side settings is needed. In CA side A is correct which agree with MrRiver and Charchar. In Group policy side E is correct which agree with Charchar only. Because in Group policy side what modify is not configure auditing for policy change but configure auditing for object access.
upvoted 3 times
...
MrRiver
5 years, 7 months ago
i gues the answer is not correct if you follow the link i provide, you see thers a "audith" tab on the CA Properties So A should be include and i think C to So i would go with A and C https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn786432(v%3Dws.11)
upvoted 1 times
Charchar
5 years, 7 months ago
I think the answer should be A and E. From the link you posted "Object access auditing must be configured for Certification Services ". So first you enable Object Access Auditing through group policy, and then you select which things to audit from the Auditing tab as you said.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...