70-640 Microsoft Real Questions Pass4Sure Free Tests 91-95

Ensurepass

d1. Ensurepass has a server that runs Windows Server 2008 R2. Active Directory Certificate Services (AD CS) is configured as a standalone Certification Authority (CA) on the server.
You need to audit changes to the CA configuration settings and the CA security settings.
Which two tasks should you perform? (Each correct answer presents part of the solution. Choose two.)
A. Configure auditing in the Certification Authority snap-in.
B. Enable auditing of successful and failed attempts to change permissions on files in the %SYSTEM32%CertSrv directory.
C. Enable auditing of successful and failed attempts to write to files in the %SYSTEM32%CertLog directory.
D. Enable the Audit object access setting in the Local Security Policy for the Active Directory Certificate Services (AD CS) server.
Answer: AD

82. Ensurepass has an Active Directory domain.
You install an Enterprise Root certification authority (CA) on a member server named Server1.
You need to ensure that only the Security Manager is authorized to revoke certificates that are supplied by Server1.
What should you do?
A. Remove the Request Certificates permission from the Domain Users group.
B. Remove the Request Certificates permission from the Authenticated Users group.
C. Assign the Allow – Manage CA permission to only the Security Manager user account.
D. Assign the Allow – Issue and Manage Certificates permission to only the Security Manager user account.
Answer: D

83. You have a Windows Server 2008 R2 Enterprise Root certification authority (CA).
You need to grant members of the Account Operators group the ability to only manage Basic EFS certificates.
You grant the Account Operators group the Issue and Manage Certificates permission on the CA.
Which three tasks should you perform next? (Each correct answer presents part of the solution. Choose three.)
A. Enable the Restrict Enrollment Agents option on the CA.
B. Enable the Restrict Certificate Managers option on the CA.
C. Add the Basic EFS certificate template for the Account Operators group.
D. Grant the Account Operators group the Manage CA permission on the CA.
E. Remove all unnecessary certificate templates that are assigned to the Account Operators group.
Answer: BCE

84. You have two servers named Server1 and Server2. Both servers run Windows Server 2008 R2. Server1 is configured as an enterprise root certification authority (CA).
You install the Online Responder role service on Server2.
You need to configure Server1 to support the Online Responder.
What should you do?
A. Import the enterprise root CA certificate.
B. Configure the Certificate Revocation List Distribution Point extension.
C. Configure the Authority Information Access (AIA) extension.
D. Add the Server2 computer account to the CertPublishers group.
Answer: C

85. Ensurepass has an Active Directory domain. All servers run Windows Server 2008 R2. Ensurepass runs an Enterprise Root certification authority (CA).
You need to ensure that only administrators can sign code.
Which two tasks should you perform? (Each correct answer presents part of the solution. Choose two.)
A. Publish the code signing template.
B. Edit the local computer policy of the Enterprise Root CA to allow users to trust peer certificates and allow only administrators to apply the policy.
C. Edit the local computer policy of the Enterprise Root CA to allow only administrators to manage Trusted Publishers.
D. Modify the security settings on the template to allow only administrators to request code signing certificates.
Answer: AD

Ensurepass offers the Latest 2013 70-640 Exam PDF to pass the exams.