← All MCTS 70-640 Flashcard Decks

Technology & Digital Applications Flashcards

7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Technology & Digital Applications flashcards as text
  1. An administrator is deploying an Enterprise CA using AD Certificate Services. What is a prerequisite for installing an Enterprise CA?

    Answer: Active Directory Domain Services must be installed and accessible

    An Enterprise CA requires access to AD DS to publish certificates and CRLs to the directory.

  2. Which AD CS role service allows users to request certificates through a web browser without requiring the CA to be directly accessible?

    Answer: Certification Authority Web Enrollment

    Certification Authority Web Enrollment provides a web interface (certsrv) so clients can request and retrieve certificates via HTTP.

  3. What is the primary purpose of a Certificate Revocation List (CRL) in a PKI deployment?

    Answer: To publish certificates that are no longer trusted before their expiry

    A CRL is a signed list of certificate serial numbers that have been revoked and should no longer be trusted.

  4. A company needs devices like routers to automatically obtain certificates without human interaction. Which AD CS role service supports this via SCEP?

    Answer: Network Device Enrollment Service (NDES)

    NDES implements the Simple Certificate Enrollment Protocol (SCEP), enabling network devices to enroll for certificates automatically.

  5. Which certificate template version (v1, v2, v3) is required to support key archival and recovery in Windows Server 2008 AD CS?

    Answer: Version 2 or higher

    Version 2 (Windows Server 2003) and Version 3 (Windows Server 2008) templates support key archival; Version 1 templates are read-only and do not.

  6. What technology does the Online Responder role service in AD CS implement to provide real-time certificate status without downloading a full CRL?

    Answer: Online Certificate Status Protocol (OCSP)

    The Online Responder implements OCSP, allowing clients to query the revocation status of a single certificate in real time.

  7. An administrator wants users to automatically receive computer certificates without any manual request process. Which Group Policy setting should be configured?

    Answer: Public Key Policies – Autoenrollment Settings

    The Autoenrollment Settings policy under Public Key Policies automates certificate enrollment and renewal for users and computers.