You must design an internal PKI that supports autoenrollment for domain users and computers and maximizes protection of the trust anchor. The design must include an offline root and permit normal enrollment operations from a domain-joined CA. Which deployment approach should you implement?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy a standalone offline root CA (workgroup, kept offline) that issues an enterprise subordinate CA certificate to a domain-joined enterprise CA; publish the root CA CRL/AIA over HTTP and use the subordinate for enrollment..
Why this is the answer
The correct approach uses a standalone offline root CA to maximize trust anchor protection. This root CA, kept offline and not domain-joined, issues a certificate to an online, domain-joined enterprise subordinate CA. This subordinate CA then handles autoenrollment for users and computers. The root's Certificate Revocation List (CRL) and Authority Information Access (AIA) are published over HTTP, allowing clients to validate certificates without the root being online. Incorrect options: A single online enterprise root CA is vulnerable and doesn't maximize trust anchor protection. Using a public CA as the forest root doesn't provide internal control or autoenrollment capabilities for a private PKI. Azure Key Vault is for key management, not a full-fledged root CA for an on-premises PKI. Two online enterprise root CAs increase redundancy but also increase the attack surface for the most critical component.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed