ADCS Part 1
ADCS Part 2
ADCS Part 3
ADCS Part 4
ADCS Part 5
100

This AD CS role is responsible for issuing and managing certificates in a Windows domain.

What is a Certification Authority (CA)?

100

This protocol is used by AD CS to publish certificate revocation lists (CRLs).

What is HTTP?

100

This type of CA sits at the top of a PKI hierarchy and is typically kept offline for security.

What is a Root CA?

100

This built-in Windows group grants full control over a CA, including configuration and certificate issuance.

What is the CA Administrators group?

100

This setting determines how long a CA-issued certificate remains active.

What is the Validity Period?

200

This type of CA is typically used in enterprise environments and is integrated with Active Directory.

What is an Enterprise CA?

200

This type of CA is not domain-joined and is often used as a root CA in a PKI hierarchy.

What is a Standalone CA?

200

This configuration file is used during CA installation to define certificate policies, extensions, and authority information access.

What is CAPolicy.inf??

200

This role can approve certificate requests but cannot change CA configuration

What is the Certificate Manager?

200

This CA configuration file can be used to define custom policy module behavior.

What is CAPolicy.inf??

300

This AD CS component allows users to request certificates via a web browser.

What is the Certificate Enrollment Web Service?

300

This AD CS role service enables certificate requests from non-domain joined devices.

What is the Network Device Enrollment Service (NDES)?

300

This CAPolicy.inf  section defines the URLs where clients can retrieve the CA’s certificate and CRL.

What is [AuthorityInformationAccess]?

300

This CA security setting determines who can request, issue, and manage certificates.

What is the CA ACL (Access Control List)?

300

This CA management action should be performed before making major changes to templates or issuance rules.

What is backing up the CA?

400

This certificate template setting determines who can enroll for a certificate.

What is Security Permissions?

400

This file contains a list of certificates that have been revoked before their expiration date.

What is a Certificate Revocation List (CRL)?

400

When deploying a root CA, this physical security measure is often recommended to prevent unauthorized access.

What is keeping the root CA offline?

400

This tool is used to back up and restore a CA’s private key and database.

What is certutil?

400

This CA role is responsible for managing certificate templates and enrollment permissions.

What is the Template Administrator?

500

This AD CS feature automatically assigns and renews certificates for domain-joined clients.

What is Autoenrollment?

500

This PowerShell cmdlet can be used to install the AD CS role on a Windows Server.

What is Install-AdcsCertificationAuthority?

500

Before deploying a root CA, administrators should carefully plan these three elements: certificate validity period, key length, and this critical trust anchor.

What is the root CA certificate?

500

This module evaluates incoming certificate requests and enforces issuance policies.

What is the Policy Module?

500

This CA security Zero Trust best practice involves limiting access to the CA server and using role separation.

What is implementing least privilege?

M
e
n
u