QuestionQ66
Managing Encryption and PrivacyYou are a Network Administrator for NetTech Inc. The company operates a Windows Server 2008 Active Directory-based, single-domain, single-forest network. Its network connects to the Internet through a T1 line, and a firewall is configured to protect the internal network from Internet intruders.
You are designing a public key infrastructure (PKI) for the network. The network will use a root enterprise certificate authority (CA) and two subordinate CAs. The root CA will issue certificates to the subordinate CAs, and the subordinate CAs will issue certificates to clients.
The company security policy requires that high-level CAs not be compromised. Which step should you take to implement the company security policy?
- A Take the root enterprise CA offline after it issues certificates to its subordinate CAs.
- B Place all CA servers in a locked room.
- C Take subordinate CAs offline after they get their certificates from the root CA.
- D Configure a firewall on the network.
Community Discussion