Server 4-12 Chapter 19 – Flashcards
Unlock all answers in this set
Unlock answersquestion
What is another name for Asymmetric encryption?
answer
Public key cryptography
question
How is an Online Responder different than a certificate revocation list (CRL)?
answer
The Online Responder provides a validation response for a single certificate, whereas the CRL provides revocation information about all revoked certificates
question
What is the name of the role in the PKI that is responsible for the distribution of keys and the validation of identities?
answer
Registration authority
question
Which Windows client operating systems are capable of using the Online Responder to check certificate revocation status? (Choose all that apply)
answer
Windows 7 and Windows 8
question
By default, if you install a CA server on January 1, 2014, when will the CA certificate expire?
answer
January 1, 2019
question
What file can you deploy to CAs so they have predefined values or parameters during installation?
answer
CAPolicy.inf
question
What should be done as soon as possible once you have been notified that a user has lost control of the private keys for their certificates?
answer
Revoke the user's issued certificates
question
Your network has a mix of Windows, Macintosh, Linux and AIX computers. All of your internal web applications use Web Server certificates issued by your PKI. How will you need to configure your AIA and CDP?
answer
As URLs (HTTP paths)
question
Which of the following is not a choice when installing a new CA?
answer
Bridged CA
question
You have built a two-tier PKI with an offline Root CA and an online Enterprise Subordinate CA. What must you do so that Active Directory clients will trust certificates issued from the Subordinate CA?
answer
Manually import the Root CA certificate into Active Directory one time
question
The benefits of PKI include all of the following except one item. What item listed is not a benefit of PKI?
answer
Availability
question
What is the function of the AIA?
answer
it specifies where to find up-to-date certificates for the CA