AZ-802 Administering Windows Server Questions and Answers
Your network contains two Active Directory Domain Services (AD DS) forests named contoso.com and adatum.com. A two-way external trust exists between contoso.com and adatum.com. The forests contain the servers shown in the following table: DC1 (contoso.com, hosts all FSMO roles), DC2 (adatum.com, hosts all FSMO roles), SRV1 (adatum.com, file server), SRV2 (adatum.com, file server). You need to ensure that users from contoso.com can access only shared resources hosted on SRV1. The solution must meet the following requirements: • Ensure that users from adatum.com can access the resources hosted in contoso.com (unrestricted, as today). • Prevent the contoso.com users from accessing any other resources in adatum.com. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.


You have four servers that run Windows Server. Each server has the direct-attached storage (DAS) devices shown in the following table.
You need to deploy Storage Spaces Direct.
Which types of devices will be used for the cache, and what will be the default cache behavior? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit
Exhibit
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains the groups shown in the following table: Group11 (Domain local, contoso.com), Group12 (Global, contoso.com), Group13 (Global, contoso.com), Group14 (Universal, contoso.com), Group21 (Universal, east.contoso.com). You need to implement a group nesting strategy. Which groups can be added as members of Group12, and which groups can be added as members of Group21? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Group scope/domain table

You have an on-premises server named Server1 that runs Windows Server.
You have an Azure subscription that uses Microsoft Defender for Cloud.
You need to onboard Server1 to Defender for Cloud.
Which actions should you perform in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Exhibit
Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contos.com. The domain contains the accounts shown in the following table.
The domain is configured to store BitLocker recovery keys in Active Directory.
* Admin1 turns on BitLocker Drive Encryption (BitLocker) for volume C on Server1.
* Admin1 moves Server1 to OU1.
* Admin2 turns on BitLocker for removable volume E on Server2.
* Admin2 moves removable volume E from Server2 to Server1 and unlocks the volume.
On which Active Directory object can you each BitLocker recovery key? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth on point.


You plan to deploy an Azure confidential virtual machine named VM1. You need to ensure that you can implement confidential disk encryption for VM1. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You have an Azure virtual machine named VM1 that runs Windows Server. VM1 fails to start properly. You need to review the serial log to identify the issue. What should you use from the VM1 blade in the Azure portal?
You have a Hyper-V host named HV1 tha1 contains a virtual machine named VM1.
VM1 has Dynamic Memory enabled. HV1 contains a PCIe NVMe storage device named Device1 that supports Discrete Device Assignment (DDA) and is disabled on HV1.
You need to ensure that Device1 can be assigned directly to VM1 by using DDA. The solution must perform only the configurations required for the assignment
What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You have two servers named Server1 and Server2 that run Windows Server. You perform the following actions: on Server1, you create an Application Control policy named Policy1 that contains a rule to allow all the executables in a folder named D:\Folder1; you add a rule to Policy1 to trust a folder named \\Server2\Folder2; you deploy Policy1. You need to verify that Policy1 is applied to Server1. Which Event Viewer log should you review?
Your network contains an Active Directory Domain Services (AD DS) forest that has a Windows Server 2008 R2 forest functional level. The forest contains the domains shown in the following table. You need to perform an in-place upgrade of the domain controllers in east.contoso.com to Windows Server 2025. The solution must minimize administrative effort. What should you do first? (Exhibit: domain functional levels table.)

Domain functional levels
Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com. The domain contains a file server named Server1 and three users named User1, User2, and User3. Server1 contains a shared folder named Share1 (path E:\Share1) that has Access-Based Enumeration enabled. The share permissions for Share1 grant the Domain Users group Allow: Change and Read (Full Control is not granted). Share1 contains a file named File1.txt. The NTFS permissions on File1.txt (no inherited entries) grant: Domain Admins - Full control; User1 - Full control; User2 - Read; User3 - Write. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Share permissions for Share1

Advanced security settings for File1.txt

Share1 configuration (Get-SmbShare)

You have an Azure subscription named sub1 and 500 on-premises virtual machines that run Windows Server. You plan to onboard the on-premises virtual machines to Azure Arc by running the Azure Arc deployment script. You need to create an identity that will be used by the script to authenticate access to sub1. The solution must use the principle of least privilege. How should you complete the command? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. ___ -DisplayName ' arc-for-servers ' -Role ___

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the servers shown in the following table.
You need to migrate Site1 from Server 1 to Server2. The solution must meet the following requirements:
• Minimize how long it takes to perform the migration.
• Minimize administrative effort.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of cations to the answer area and arrange them in the correct order.

Exhibit

You have two servers named Server1 and Server2 that run Windows Server. Both servers have the Hyper-V server role installed. Server1 hosts three virtual machines named VM1, VM2, and VM3. The virtual machines replicate to Server2. Server1 experiences a hardware failure. You need to bring VM1, VM2, and VM3 back online as soon as possible. From the Hyper-V Manager console on Server2, what should you run for each virtual machine?
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a group named Group1 and the member servers shown in the following table.
Server1 contains the printers shown in the following table.
You use Print Management to migrate the printers from Server1 to Server2.
Which migrated printers can print to file, and to which migrated printers can the members of Group1 print? To answer, select the appropriate options in the answer area.

Exhibit

Exhibit

You have an Active Directory Domain Services (AD DS) domain that contains a group named Group1. You need to create a group managed service account (gMSA) named Account1. The solution must ensure that Group1 can use Account1. How should you complete the script? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Your network contains the Active Directory Domain Services (AD DS) forests shown in the following table.

You need to configure trust relationships as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No NOTE: Each correct selection is worth one point.

You have an Active Directory Domain Services (AD DS) domain that contains the member servers shown in the following table. Server1: Windows Server 2019, Data Deduplication role service Installed Server2: Windows Server 2022, Data Deduplication role service Not installed Server3: Windows Server 2022, Data Deduplication role service Installed Server3 contains a data disk named Disk1 that has Data Deduplication installed. Disk1 contains the files shown in the following table. File1.txt: 5 KB File2.docx: 800 KB File3.sys: 2 MB File4.bmp: 5 GB Server3 fails. You need to recover the files on Disk1. Which files can you recover if you attach Disk1 to Server1, and which files can you recover if you attach Disk1 to Server2? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Server Dedup role table

File size table

You have the on-premises servers shown in the following table. You have an Azure subscription. You plan to migrate the servers to Azure generation 2 virtual machines. Which servers can be migrated to Azure by using Azure Migrate?

On-premises servers, OS disk size, and BitLocker table
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant. You deploy an app that adds custom attributes to the domain. From Azure Cloud Shell, you discover that you cannot query the custom attributes of users. You need to ensure that the custom attributes are available in Microsoft Entra ID. Which task should you perform from Microsoft Entra Connect first?
You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server.
You need to back up VM1 by using Azure Backup. The solution must minimize potential data loss.
What is the minimum backup interval you can configure for a standard backup policy and an enhanced backup policy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
The servers run Windows Server and have the network configurations shown in the following table.
Server3 is configured as a NAT gateway. All the servers allow ICMP requests.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a root domain named contoso.com and a child domain named branch.contoso.com. The forest contains the domain controllers shown in the following table: DC1 (contoso.com; a global catalog server that holds the schema master, domain naming master, PDC emulator, RID master, and infrastructure master roles); DC2 (contoso.com; NOT a global catalog server and does NOT hold any FSMO roles); DC3 (branch.contoso.com; a global catalog server that holds the PDC emulator and RID master roles); DC4 (branch.contoso.com; NOT a global catalog server and holds the infrastructure master role). You discover that cross-domain object references in contoso.com fail to update for objects in branch.contoso.com. You need to modify the FSMO role placement. The solution must minimize administrative changes. What should you do?
You need to configure BitLocker on Server4.
On which volumes can you turn on BitLocker, and on which volumes can you turn on auto-unlock? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to back up Server4 to meet the technical requirements. What should you do first?
What is the effective minimum password length for User1 and Admin1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for Share1. What should you use?
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to identify the minimum number of Azure Site Recovery Provider installations required to protect Cluster2. What is the minimum number of installations required?
You need to meet the technical requirements for Cluster2.
Which four actions should you perform in sequence before you can enable replication? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

With which servers can Server1 and Server3 communicate? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for User1. To which group in contoso.com should you add User1?
You need to implement alerts for the domain controllers. The solution must meet the technical requirements.
What should you do on the domain controllers, and what should you create on Azure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to promote DC4 to meet the technical requirements. Which domain controller should be online to meet the technical requirements for DC4?
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for Cluster3. What should you include in the solution?
Which two languages can you use for Task1? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
You need to implement the planned change for Microsoft Entra users to sign in to Server1. Which PowerShell cmdlet should you run?
You need to implement the planned change for Data1. Which actions should you perform in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. NOTE: Each correct selection is worth one point.

You need to meet the technical requirement for HyperV1. Which command should you run? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to ensure that access to storage1 for the Marketing OU users meets the technical requirements. What should you implement?
You need to implement the planned change for the Azure DNS Private Resolver. Which private DNS zones can you use for name resolution?
You need to ensure that Automanage meets the technical requirements. On which Azure virtual machines should you enable Automanage?
You need to ensure that VM3 meets the technical requirement. What should you install first?
DC1 fails.
You need to meet the technical requirements for the schema master.
Yourunntdsutil.exe.
Which five commands should you run in sequence? To answer, move the appropriate commands from the list of commands to the answer area and arrange them in the correct order?

You need to ensure that data availability on SSPace1 meets the technical requirements. What is the maximum number of physical disks that can fail on each disk without losing data? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to meet the technical requirements for the site links. Which users can perform the required task?
Which groups can you add to Group3, and which groups can you add to Group5? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

You need to meet the technical requirements for Server1. Which users can currently perform the required task?
You need to configure remote administration to meet the security requirements. What should you use?
You are planning the implementation of Azure Arc to support the planned changes. You need to configure the environment to support configuration management policies. What should you do?
You need to implement a name resolution solution that meets the requirements for DC3. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
You need to configure Azure File Sync to meet the file sharing requirements. What is the minimum number of sync groups you should create, and what is the minimum number of Storage Sync Services you should create? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to configure the Group Policy settings to ensure that the Azure Virtual Desktop session hosts meet the security requirements. What should you configure?
You need to configure network communication between the Seattle and New York offices. The solution must meet the requirements. What should you configure? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to implement an availability solution for DHCP that meets the requirements. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Which three actions should you perform in sequence to meet the security requirements for Webapp1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You are planning the implementation of Cluster2 to support the on-premises migration plan. You need to ensure that the disks on Cluster2 meet the security requirements. In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.

You are remediating the firewall security risks to meet the security requirements. What should you configure to reduce the risks?
You are planning the migration of APP3 and APP4 to support the Azure migration plan. What should you do on Cluster1 and in Azure before you perform the migration? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to implement a security policy solution to authorize the applications. The solution must meet the security requirements. Which service should you use to enforce the security policy, and what should you use to manage the policy settings? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You are planning the DHCP1 migration to support the DHCP migration plan. Which two PowerShell cmdlets should you run on DHCP1, and which two PowerShell cmdlets should you run on DHCP2? To answer, drag the appropriate cmdlets to the correct servers. Each cmdlet may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

You are planning the migration of Archive1 to support the on-premises migration plan. What is the minimum number of IP addresses required for the node and cluster roles on Cluster3?
You are planning the data share migration to support the on-premises migration plan. What should you use to perform the migration?
You are planning the deployment of Microsoft Sentinel. Which type of Microsoft Sentinel data connector should you use to meet the security requirements?
You are planning the www.fabrikam.com website migration to support the Azure migration plan. How should you configure WebApp1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.






































