You have already completed the Test before. Hence you can not start it again.
Test is loading...
You must sign in or sign up to start the Test.
You have to finish following quiz, to start this Test:
Your results are here!! for" AZ-802 Practice Test 10 "
0 of 60 questions answered correctly
Your time:
Time has elapsed
Your Final Score is : 0
You have attempted : 0
Number of Correct Questions : 0 and scored 0
Number of Incorrect Questions : 0 and Negative marks 0
Average score
Your score
AZ-802
You have attempted: 0
Number of Correct Questions: 0 and scored 0
Number of Incorrect Questions: 0 and Negative marks 0
You can review your answers by clicking on “View Answers” option. Important Note : Open Reference Documentation Links in New Tab (Right Click and Open in New Tab).
Answer Review
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Answer
Review
Unattempted
Correct
Incorrect
Unattempted
Every question in this attempt was answered correctly.
Question 1 of 60
1. Question
You need to provide remote access to a legacy on-premises application that uses Kerberos authentication. You want to use Azure AD Application Proxy. What component is required on-premises?
Correct
The Application Proxy Connector is a lightweight agent installed on an on-premises server that facilitates the connection between Azure AD and the internal app.
Incorrect
The Application Proxy Connector is a lightweight agent installed on an on-premises server that facilitates the connection between Azure AD and the internal app.
Unattempted
The Application Proxy Connector is a lightweight agent installed on an on-premises server that facilitates the connection between Azure AD and the internal app.
Question 2 of 60
2. Question
You have an Azure File Sync environment. You want to move a ‘Cloud Endpoint’ to a different ‘Sync Group’. What should you do?
Correct
Cloud Endpoints cannot be moved between Sync Groups. You must delete the endpoint (which does not delete the data in the Azure File share) and then create a new Cloud Endpoint in the target Sync Group pointing to that same share.
Incorrect
Cloud Endpoints cannot be moved between Sync Groups. You must delete the endpoint (which does not delete the data in the Azure File share) and then create a new Cloud Endpoint in the target Sync Group pointing to that same share.
Unattempted
Cloud Endpoints cannot be moved between Sync Groups. You must delete the endpoint (which does not delete the data in the Azure File share) and then create a new Cloud Endpoint in the target Sync Group pointing to that same share.
Question 3 of 60
3. Question
You want to use ‘Azure Policy’ to manage the security settings of several hybrid servers. You need to ensure that the ‘Guest Configuration’ extension is working. Which two requirements must be met on the local server?
Correct
Azure Policy Guest Configuration requires the server to be an Arc-enabled resource. It uses the server’s Managed Identity to securely communicate with the Azure Policy service and retrieve the required configurations.
Incorrect
Azure Policy Guest Configuration requires the server to be an Arc-enabled resource. It uses the server’s Managed Identity to securely communicate with the Azure Policy service and retrieve the required configurations.
Unattempted
Azure Policy Guest Configuration requires the server to be an Arc-enabled resource. It uses the server’s Managed Identity to securely communicate with the Azure Policy service and retrieve the required configurations.
Question 4 of 60
4. Question
You have an Azure File Sync deployment. You need to ensure that the server ‘Server1’ uses a specific network interface for sync traffic to avoid congesting the management network. Which PowerShell cmdlet should you use?
Correct
The ‘New-StorageSyncNetworkLimit’ cmdlet allows you to define specific bandwidth limits or restrict sync traffic to specific IP ranges or network interfaces based on a schedule.
Incorrect
The ‘New-StorageSyncNetworkLimit’ cmdlet allows you to define specific bandwidth limits or restrict sync traffic to specific IP ranges or network interfaces based on a schedule.
Unattempted
The ‘New-StorageSyncNetworkLimit’ cmdlet allows you to define specific bandwidth limits or restrict sync traffic to specific IP ranges or network interfaces based on a schedule.
Question 5 of 60
5. Question
You are configuring ‘Azure AD Connect’ for a ‘Staged Rollout’. Which two features can be tested using Staged Rollout?
Correct
Staged Rollout is specifically designed to transition users from Federation to cloud authentication methods like PHS or PTA. It also supports testing ‘Seamless SSO’ in conjunction with these methods for the rollout group.
Incorrect
Staged Rollout is specifically designed to transition users from Federation to cloud authentication methods like PHS or PTA. It also supports testing ‘Seamless SSO’ in conjunction with these methods for the rollout group.
Unattempted
Staged Rollout is specifically designed to transition users from Federation to cloud authentication methods like PHS or PTA. It also supports testing ‘Seamless SSO’ in conjunction with these methods for the rollout group.
Question 6 of 60
6. Question
You have an Azure File Share that is synced to an on-premises server using Azure File Sync. You accidentally deleted a file on the on-premises server. Where should you go to restore the file if Cloud Tiering is enabled?
Correct
If a file is deleted and synced, it’s deleted everywhere. You should use Azure Backup (if configured for the share) or the snapshots feature in the Azure portal to restore.
Incorrect
If a file is deleted and synced, it’s deleted everywhere. You should use Azure Backup (if configured for the share) or the snapshots feature in the Azure portal to restore.
Unattempted
If a file is deleted and synced, it’s deleted everywhere. You should use Azure Backup (if configured for the share) or the snapshots feature in the Azure portal to restore.
Question 7 of 60
7. Question
You need to verify the replication health of your on-premises Active Directory. Which command-line tool provides a summary of replication status for all DCs?
Correct
The ‘repadmin /replsummary’ command provides a quick table showing the replication status and any errors for all domain controllers in the forest.
Incorrect
The ‘repadmin /replsummary’ command provides a quick table showing the replication status and any errors for all domain controllers in the forest.
Unattempted
The ‘repadmin /replsummary’ command provides a quick table showing the replication status and any errors for all domain controllers in the forest.
Question 8 of 60
8. Question
Your company has an Azure environment with several virtual machines. You need to configure Azure Backup for these VMs. You want to ensure that if an administrator accidentally deletes a backup item the data is retained for 14 days. Which feature should you ensure is enabled?
Correct
Soft Delete in Azure Backup protects backup data from accidental deletions by retaining the data for 14 additional days at no cost.
Incorrect
Soft Delete in Azure Backup protects backup data from accidental deletions by retaining the data for 14 additional days at no cost.
Unattempted
Soft Delete in Azure Backup protects backup data from accidental deletions by retaining the data for 14 additional days at no cost.
Question 9 of 60
9. Question
You have an Azure VM. You want to use ‘Azure Policy’ to ensure that all VMs in your resource group have a specific ‘Tag’ (e.g. Environment=Prod). Which policy effect should you use?
Correct
The ‘Modify’ or ‘Append’ effects can automatically add or update tags on resources to ensure they meet your organizational standards.
Incorrect
The ‘Modify’ or ‘Append’ effects can automatically add or update tags on resources to ensure they meet your organizational standards.
Unattempted
The ‘Modify’ or ‘Append’ effects can automatically add or update tags on resources to ensure they meet your organizational standards.
Question 10 of 60
10. Question
You need to provide high availability for a Windows Server web application. You want to ensure that if one server fails, traffic is automatically routed to another. Which feature should you use?
Correct
NLB is used to distribute traffic across a group of web or application servers to ensure availability and scalability.
Incorrect
NLB is used to distribute traffic across a group of web or application servers to ensure availability and scalability.
Unattempted
NLB is used to distribute traffic across a group of web or application servers to ensure availability and scalability.
Question 11 of 60
11. Question
You have an on-premises Windows Server 2022 cluster. You need to implement a storage solution that replicates volumes between servers for disaster recovery using Storage Replica. The solution must support synchronous replication. What is a requirement for this configuration?
Correct
Storage Replica requires the destination volume to be equal to or larger than the source volume; while 10GbE is recommended for performance it is not a hard requirement.
Incorrect
Storage Replica requires the destination volume to be equal to or larger than the source volume; while 10GbE is recommended for performance it is not a hard requirement.
Unattempted
Storage Replica requires the destination volume to be equal to or larger than the source volume; while 10GbE is recommended for performance it is not a hard requirement.
Question 12 of 60
12. Question
You have an on-premises Active Directory. You want to implement ‘Azure AD Password Protection’. Which component must be installed on EVERY domain controller in the forest?
Correct
While the Proxy only needs to be on one or two servers the DC Agent must be on every DC to intercept and validate password changes.
Incorrect
While the Proxy only needs to be on one or two servers the DC Agent must be on every DC to intercept and validate password changes.
Unattempted
While the Proxy only needs to be on one or two servers the DC Agent must be on every DC to intercept and validate password changes.
Question 13 of 60
13. Question
You need to provide a developer with access to an Azure VM for 4 hours to perform a specific update. You want to minimize the attack surface by not leaving RDP ports open permanently. What should you use?
Correct
JIT VM Access (part of Microsoft Defender for Cloud) allows you to request access to VM ports only when needed and for a limited time.
Incorrect
JIT VM Access (part of Microsoft Defender for Cloud) allows you to request access to VM ports only when needed and for a limited time.
Unattempted
JIT VM Access (part of Microsoft Defender for Cloud) allows you to request access to VM ports only when needed and for a limited time.
Question 14 of 60
14. Question
You have an on-premises server named Server1. You want to use Azure File Sync. The server is currently running Windows Server 2012. What is the first thing you must do to support the Azure File Sync agent?
Correct
The Azure File Sync agent requires at least Windows Server 2012 R2; the original 2012 version is not supported.
Incorrect
The Azure File Sync agent requires at least Windows Server 2012 R2; the original 2012 version is not supported.
Unattempted
The Azure File Sync agent requires at least Windows Server 2012 R2; the original 2012 version is not supported.
Question 15 of 60
15. Question
You have an on-premises Active Directory domain. You want to prevent users from using weak or common passwords like ‘Password123’ for both on-premises and cloud accounts. What should you implement?
Correct
Azure AD Password Protection uses a global and custom banned password list to block weak passwords in both Azure and on-premises AD.
Incorrect
Azure AD Password Protection uses a global and custom banned password list to block weak passwords in both Azure and on-premises AD.
Unattempted
Azure AD Password Protection uses a global and custom banned password list to block weak passwords in both Azure and on-premises AD.
Question 16 of 60
16. Question
You are troubleshooting Azure AD Connect ‘Cloud Sync’. You want to see why a specific user account was ‘Skipped’ during the sync process. Where should you look?
Correct
Cloud Sync is ‘cloud-driven’. Detailed information about why objects were skipped, filtered, or updated is found in the ‘Provisioning logs’ under the ‘Monitoring’ section of the Cloud Sync configuration in the portal.
Incorrect
Cloud Sync is ‘cloud-driven’. Detailed information about why objects were skipped, filtered, or updated is found in the ‘Provisioning logs’ under the ‘Monitoring’ section of the Cloud Sync configuration in the portal.
Unattempted
Cloud Sync is ‘cloud-driven’. Detailed information about why objects were skipped, filtered, or updated is found in the ‘Provisioning logs’ under the ‘Monitoring’ section of the Cloud Sync configuration in the portal.
Question 17 of 60
17. Question
You have an on-premises Windows Server 2022 that you want to manage using the Azure portal. You have already installed the Azure Arc agent. You want to view and manage the server’s certificates. Which tool should you use within the Azure portal?
Correct
Windows Admin Center integrated into the Azure portal for Arc-enabled servers provides a web-based UI for managing local certificates.
Incorrect
Windows Admin Center integrated into the Azure portal for Arc-enabled servers provides a web-based UI for managing local certificates.
Unattempted
Windows Admin Center integrated into the Azure portal for Arc-enabled servers provides a web-based UI for managing local certificates.
Question 18 of 60
18. Question
You need to implement a hybrid identity solution that allows users to use their on-premises credentials for Azure resources. You want to minimize the on-premises infrastructure required. Which method is most suitable?
Correct
PHS is the simplest identity method to implement and requires the least amount of on-premises infrastructure compared to PTA or AD FS.
Incorrect
PHS is the simplest identity method to implement and requires the least amount of on-premises infrastructure compared to PTA or AD FS.
Unattempted
PHS is the simplest identity method to implement and requires the least amount of on-premises infrastructure compared to PTA or AD FS.
Question 19 of 60
19. Question
You have an Azure File Share. You want to map this share as a drive letter on an on-premises Windows Server 2022. Which port must be open outbound on your corporate firewall?
Correct
SMB communication for mapping Azure File Shares occurs over port 445.
Incorrect
SMB communication for mapping Azure File Shares occurs over port 445.
Unattempted
SMB communication for mapping Azure File Shares occurs over port 445.
Question 20 of 60
20. Question
You have an on-premises Active Directory forest. You need to provide users with Single Sign-On (SSO) to cloud applications while keeping the authentication process on your on-premises domain controllers for compliance. Which Azure AD Connect option should you choose?
Correct
Pass-through Authentication allows users to sign in to both on-premises and cloud-based applications using the same passwords while validating the credentials against the on-premises DC.
Incorrect
Pass-through Authentication allows users to sign in to both on-premises and cloud-based applications using the same passwords while validating the credentials against the on-premises DC.
Unattempted
Pass-through Authentication allows users to sign in to both on-premises and cloud-based applications using the same passwords while validating the credentials against the on-premises DC.
Question 21 of 60
21. Question
You have an Azure VM running Windows Server 2022. You want to move it to a different Azure region to improve latency for users. Which tool simplifies this process?
Correct
Azure Site Recovery can be used to replicate VMs between Azure regions and perform a planned failover to move them permanently.
Incorrect
Azure Site Recovery can be used to replicate VMs between Azure regions and perform a planned failover to move them permanently.
Unattempted
Azure Site Recovery can be used to replicate VMs between Azure regions and perform a planned failover to move them permanently.
Question 22 of 60
22. Question
Your company uses Azure File Sync. You notice that some files are not syncing. You need to check the sync status and errors on the on-premises server. Which event log should you examine?
Correct
Azure File Sync has its own specific telemetry and operational logs located under Applications and Services Logs in Event Viewer.
Incorrect
Azure File Sync has its own specific telemetry and operational logs located under Applications and Services Logs in Event Viewer.
Unattempted
Azure File Sync has its own specific telemetry and operational logs located under Applications and Services Logs in Event Viewer.
Question 23 of 60
23. Question
You need to update 50 on-premises Windows Servers and 50 Azure VMs. You want a single interface to schedule and track the installation of these updates. Which Azure service should you use?
Correct
Azure Automation Update Management (now moving to Azure Update Manager) allows for cross-platform and hybrid update scheduling for both Azure and on-premises machines.
Incorrect
Azure Automation Update Management (now moving to Azure Update Manager) allows for cross-platform and hybrid update scheduling for both Azure and on-premises machines.
Unattempted
Azure Automation Update Management (now moving to Azure Update Manager) allows for cross-platform and hybrid update scheduling for both Azure and on-premises machines.
Question 24 of 60
24. Question
You need to implement a solution that allows users to access internal web applications from outside the corporate network without using a VPN. The solution must integrate with Azure AD for pre-authentication. What should you use?
Correct
Azure AD Application Proxy provides secure remote access to on-premises web applications using Azure AD identities.
Incorrect
Azure AD Application Proxy provides secure remote access to on-premises web applications using Azure AD identities.
Unattempted
Azure AD Application Proxy provides secure remote access to on-premises web applications using Azure AD identities.
Question 25 of 60
25. Question
You have an on-premises Active Directory. You want to sync a specific Organizational Unit (OU) to Azure AD, but exclude all others. Where do you configure this?
Correct
Filtering by OU is configured during the Azure AD Connect installation or by re-running the wizard to change sync options.
Incorrect
Filtering by OU is configured during the Azure AD Connect installation or by re-running the wizard to change sync options.
Unattempted
Filtering by OU is configured during the Azure AD Connect installation or by re-running the wizard to change sync options.
Question 26 of 60
26. Question
You have an Azure File Sync deployment. You notice that the local server disk is filling up despite Cloud Tiering being enabled. What should you check first?
Correct
The Volume Free Space policy dictates how much space the agent must keep free. If this is set too low the local disk will fill up before tiering triggers.
Incorrect
The Volume Free Space policy dictates how much space the agent must keep free. If this is set too low the local disk will fill up before tiering triggers.
Unattempted
The Volume Free Space policy dictates how much space the agent must keep free. If this is set too low the local disk will fill up before tiering triggers.
Question 27 of 60
27. Question
You need to manage several Windows Server 2022 instances located in a remote branch office that has no VPN connection to your main office. You want to use a web-based management tool via the Azure portal. What should you implement?
Correct
By onboarding servers to Azure Arc you can use Windows Admin Center directly in the Azure portal to manage servers over the internet without a VPN.
Incorrect
By onboarding servers to Azure Arc you can use Windows Admin Center directly in the Azure portal to manage servers over the internet without a VPN.
Unattempted
By onboarding servers to Azure Arc you can use Windows Admin Center directly in the Azure portal to manage servers over the internet without a VPN.
Question 28 of 60
28. Question
You have an Azure VM. You want to implement ‘Automatic VM Guest Patching’. Which service orchestrates the actual installation and rebooting of the VM?
Correct
Azure Update Manager (the successor to Automation Update Management) is the platform-orchestrator for patching both Azure and Arc servers.
Incorrect
Azure Update Manager (the successor to Automation Update Management) is the platform-orchestrator for patching both Azure and Arc servers.
Unattempted
Azure Update Manager (the successor to Automation Update Management) is the platform-orchestrator for patching both Azure and Arc servers.
Question 29 of 60
29. Question
You have an Azure VM. You want to ensure that it can only be accessed via RDP during a specific window of time requested by an admin. Which security feature should you use?
Correct
JIT VM Access allows you to block inbound traffic by default and open ports only when a request is approved for a limited duration.
Incorrect
JIT VM Access allows you to block inbound traffic by default and open ports only when a request is approved for a limited duration.
Unattempted
JIT VM Access allows you to block inbound traffic by default and open ports only when a request is approved for a limited duration.
Question 30 of 60
30. Question
You have an on-premises Windows Server 2022. You want to use ‘Azure Key Vault’ to store the BitLocker recovery keys. Which hybrid service enables this integration?
Correct
Azure Arc-enabled servers can be integrated with Azure Key Vault to manage and store secrets and keys for on-premises systems.
Incorrect
Azure Arc-enabled servers can be integrated with Azure Key Vault to manage and store secrets and keys for on-premises systems.
Unattempted
Azure Arc-enabled servers can be integrated with Azure Key Vault to manage and store secrets and keys for on-premises systems.
Question 31 of 60
31. Question
You are managing a hybrid environment. You need to provide a developer with access to an Azure Arc-enabled server’s command line directly from the Azure portal. Which feature provides this without requiring a VPN?
Correct
Azure Arc-enabled servers support SSH access via the Azure CLI or portal. This uses the Arc agent as a proxy, allowing secure, authenticated command-line access without needing a public IP or a VPN connection.
Incorrect
Azure Arc-enabled servers support SSH access via the Azure CLI or portal. This uses the Arc agent as a proxy, allowing secure, authenticated command-line access without needing a public IP or a VPN connection.
Unattempted
Azure Arc-enabled servers support SSH access via the Azure CLI or portal. This uses the Arc agent as a proxy, allowing secure, authenticated command-line access without needing a public IP or a VPN connection.
Question 32 of 60
32. Question
You need to connect an on-premises Windows Server 2022 to an Azure VNet. You want to use ‘Azure Extended Networking’ to migrate a VM while keeping its original on-premises IP address. Which two components are required?
Correct
Azure Extended Networking (using VXLAN) allows for Layer 2 connectivity. It requires a specialized appliance in Azure and a corresponding gateway setup via Windows Admin Center to bridge the on-premises and Azure subnets.
Incorrect
Azure Extended Networking (using VXLAN) allows for Layer 2 connectivity. It requires a specialized appliance in Azure and a corresponding gateway setup via Windows Admin Center to bridge the on-premises and Azure subnets.
Unattempted
Azure Extended Networking (using VXLAN) allows for Layer 2 connectivity. It requires a specialized appliance in Azure and a corresponding gateway setup via Windows Admin Center to bridge the on-premises and Azure subnets.
Question 33 of 60
33. Question
You need to implement ‘Azure AD Password Protection’ in a forest with three child domains. Where must you install the ‘Proxy’ service?
Correct
A single Azure AD Password Protection Proxy can serve an entire forest. The DC agents in any child domain can be configured to point to the centralized proxy servers.
Incorrect
A single Azure AD Password Protection Proxy can serve an entire forest. The DC agents in any child domain can be configured to point to the centralized proxy servers.
Unattempted
A single Azure AD Password Protection Proxy can serve an entire forest. The DC agents in any child domain can be configured to point to the centralized proxy servers.
Question 34 of 60
34. Question
You need to implement a hybrid backup solution for a SQL Server instance running on a physical on-premises server. Which two Azure-integrated components can back up the database directly to the cloud?
Correct
MABS is an on-premises server that can handle app-aware backups like SQL. Alternatively, modern versions of SQL Server can natively back up directly to Azure Blob Storage (Backup to URL) without needing a backup agent.
Incorrect
MABS is an on-premises server that can handle app-aware backups like SQL. Alternatively, modern versions of SQL Server can natively back up directly to Azure Blob Storage (Backup to URL) without needing a backup agent.
Unattempted
MABS is an on-premises server that can handle app-aware backups like SQL. Alternatively, modern versions of SQL Server can natively back up directly to Azure Blob Storage (Backup to URL) without needing a backup agent.
Question 35 of 60
35. Question
You need to implement ‘Azure AD Password Protection’ for your on-premises Active Directory. You want to test the impact of the banned password list before enforcing it. Which two actions should you take?
Correct
The ‘Audit’ mode allows the DC agent to evaluate password changes against the banned lists without actually blocking them. Results are logged to the Event Viewer, allowing administrators to see what would have been blocked.
Incorrect
The ‘Audit’ mode allows the DC agent to evaluate password changes against the banned lists without actually blocking them. Results are logged to the Event Viewer, allowing administrators to see what would have been blocked.
Unattempted
The ‘Audit’ mode allows the DC agent to evaluate password changes against the banned lists without actually blocking them. Results are logged to the Event Viewer, allowing administrators to see what would have been blocked.
Question 36 of 60
36. Question
You are using ‘Azure Site Recovery’ (ASR). You need to enable ‘Encryption-at-rest’ for the data replicated to Azure. Which two options are available?
Correct
All data replicated to Azure is automatically encrypted by SSE. For higher security, you can also enable ADE on the Azure VMs after they fail over, using keys stored in an Azure Key Vault.
Incorrect
All data replicated to Azure is automatically encrypted by SSE. For higher security, you can also enable ADE on the Azure VMs after they fail over, using keys stored in an Azure Key Vault.
Unattempted
All data replicated to Azure is automatically encrypted by SSE. For higher security, you can also enable ADE on the Azure VMs after they fail over, using keys stored in an Azure Key Vault.
Question 37 of 60
37. Question
You need to migrate a Windows Server 2012 R2 workload to Azure. You decide to use the ‘Azure Migrate: Server Migration’ tool. You want to minimize downtime during the final cutover. Which two actions help achieve this?
Correct
Testing the migration ensures the VM boots and the app works. During the actual cutover, shutting down the on-premises server ensures that the ‘Final Sync’ captures 100% of the data without any changes occurring during the transfer.
Incorrect
Testing the migration ensures the VM boots and the app works. During the actual cutover, shutting down the on-premises server ensures that the ‘Final Sync’ captures 100% of the data without any changes occurring during the transfer.
Unattempted
Testing the migration ensures the VM boots and the app works. During the actual cutover, shutting down the on-premises server ensures that the ‘Final Sync’ captures 100% of the data without any changes occurring during the transfer.
Question 38 of 60
38. Question
You are using Azure Site Recovery (ASR). You need to replicate an on-premises VM that has a 40 TB data disk. What is the maximum disk size supported by ASR for a single managed disk in Azure?
Correct
Azure Managed Disks (and consequently ASR) support a maximum disk size of 32,767 GB (approximately 32 TB). Disks exceeding this size cannot be replicated directly and must be refactored or split.
Incorrect
Azure Managed Disks (and consequently ASR) support a maximum disk size of 32,767 GB (approximately 32 TB). Disks exceeding this size cannot be replicated directly and must be refactored or split.
Unattempted
Azure Managed Disks (and consequently ASR) support a maximum disk size of 32,767 GB (approximately 32 TB). Disks exceeding this size cannot be replicated directly and must be refactored or split.
Question 39 of 60
39. Question
You are troubleshooting a ‘Pass-through Authentication’ (PTA) deployment. The PTA agents are showing a status of ‘Inactive’. What is the most common cause?
Correct
PTA agents require a persistent outbound connection to Azure. If the server is behind a firewall or proxy that blocks port 443 to the specific Microsoft Entra service URLs, the agent will appear as ‘Inactive’.
Incorrect
PTA agents require a persistent outbound connection to Azure. If the server is behind a firewall or proxy that blocks port 443 to the specific Microsoft Entra service URLs, the agent will appear as ‘Inactive’.
Unattempted
PTA agents require a persistent outbound connection to Azure. If the server is behind a firewall or proxy that blocks port 443 to the specific Microsoft Entra service URLs, the agent will appear as ‘Inactive’.
Question 40 of 60
40. Question
You are using ‘Azure Migrate’ to migrate a physical server. During the ‘Replication’ phase, you notice the performance of the source server is significantly degraded. Which component of the Migrate appliance should you throttle?
Correct
The Gateway component on the Azure Migrate appliance handles the data upload. You can configure bandwidth throttling in the appliance configuration manager to reduce the impact on the source server’s network and disk I/O.
Incorrect
The Gateway component on the Azure Migrate appliance handles the data upload. You can configure bandwidth throttling in the appliance configuration manager to reduce the impact on the source server’s network and disk I/O.
Unattempted
The Gateway component on the Azure Migrate appliance handles the data upload. You can configure bandwidth throttling in the appliance configuration manager to reduce the impact on the source server’s network and disk I/O.
Question 41 of 60
41. Question
You need to audit who accessed sensitive files on an on-premises server that is synced via Azure File Sync. You want to use Azure-native tools for this. Which two steps are required?
Correct
To track file access in a hybrid setup, you must first enable standard Windows File System auditing on the local server. Then, use the AMA to forward those Security Event logs to a Log Analytics workspace for centralized querying.
Incorrect
To track file access in a hybrid setup, you must first enable standard Windows File System auditing on the local server. Then, use the AMA to forward those Security Event logs to a Log Analytics workspace for centralized querying.
Unattempted
To track file access in a hybrid setup, you must first enable standard Windows File System auditing on the local server. Then, use the AMA to forward those Security Event logs to a Log Analytics workspace for centralized querying.
Question 42 of 60
42. Question
You have an Azure File Sync server. You want to exclude all ‘.tmp’ files from being synchronized to the cloud. Which file should you modify on the local server?
Correct
Azure File Sync uses a specific text file named ‘GhostingExclusionList.txt’ located in the ‘System Volume Information’ folder of the synced volume to define which file extensions or patterns should be ignored by the sync engine.
Incorrect
Azure File Sync uses a specific text file named ‘GhostingExclusionList.txt’ located in the ‘System Volume Information’ folder of the synced volume to define which file extensions or patterns should be ignored by the sync engine.
Unattempted
Azure File Sync uses a specific text file named ‘GhostingExclusionList.txt’ located in the ‘System Volume Information’ folder of the synced volume to define which file extensions or patterns should be ignored by the sync engine.
Question 43 of 60
43. Question
You are managing an Azure Stack HCI cluster. You need to enable ‘ReFS Integrity Streams’ on a specific volume. Which tool should you use to ensure this is done correctly for an HCI environment?
Correct
While Windows Admin Center can create volumes, fine-grained ReFS settings like Integrity Streams are typically managed via the ‘Set-FileIntegrity’ PowerShell cmdlet to ensure they are enabled for the specific files or folders on the HCI volume.
Incorrect
While Windows Admin Center can create volumes, fine-grained ReFS settings like Integrity Streams are typically managed via the ‘Set-FileIntegrity’ PowerShell cmdlet to ensure they are enabled for the specific files or folders on the HCI volume.
Unattempted
While Windows Admin Center can create volumes, fine-grained ReFS settings like Integrity Streams are typically managed via the ‘Set-FileIntegrity’ PowerShell cmdlet to ensure they are enabled for the specific files or folders on the HCI volume.
Question 44 of 60
44. Question
You have an Azure Arc-enabled server. You need to view the ‘Inventory’ of all installed software on the machine. Which feature within the Azure portal provides this without needing to log in to the machine?
Correct
Change Tracking and Inventory (part of Azure Automation but integrated with Arc) periodically collects the list of installed software, services, and registry keys from the server and makes them searchable in the Azure portal.
Incorrect
Change Tracking and Inventory (part of Azure Automation but integrated with Arc) periodically collects the list of installed software, services, and registry keys from the server and makes them searchable in the Azure portal.
Unattempted
Change Tracking and Inventory (part of Azure Automation but integrated with Arc) periodically collects the list of installed software, services, and registry keys from the server and makes them searchable in the Azure portal.
Question 45 of 60
45. Question
You are troubleshooting a hybrid VPN connection. You see ‘Phase 1’ is successful, but ‘Phase 2’ (IPsec) is failing. Which setting is likely mismatched between the on-premises device and the Azure VPN Gateway?
Correct
Phase 1 handles the secure tunnel establishment (where IKE versions and keys matter). Phase 2 (IPsec) handles the actual data encryption; mismatches in PFS groups, encryption algorithms, or SAs (Security Associations) usually cause failures at this stage.
Incorrect
Phase 1 handles the secure tunnel establishment (where IKE versions and keys matter). Phase 2 (IPsec) handles the actual data encryption; mismatches in PFS groups, encryption algorithms, or SAs (Security Associations) usually cause failures at this stage.
Unattempted
Phase 1 handles the secure tunnel establishment (where IKE versions and keys matter). Phase 2 (IPsec) handles the actual data encryption; mismatches in PFS groups, encryption algorithms, or SAs (Security Associations) usually cause failures at this stage.
Question 46 of 60
46. Question
You need to manage a fleet of hybrid servers. You want to use ‘Azure Policy’ to ensure that all servers have a specific security baseline. Which two steps are required for on-premises servers?
Correct
Azure Arc provides the management plane, and the Guest Configuration extension (now part of Azure Automanage machine configuration) is required to audit and enforce settings inside the local Windows OS.
Incorrect
Azure Arc provides the management plane, and the Guest Configuration extension (now part of Azure Automanage machine configuration) is required to audit and enforce settings inside the local Windows OS.
Unattempted
Azure Arc provides the management plane, and the Guest Configuration extension (now part of Azure Automanage machine configuration) is required to audit and enforce settings inside the local Windows OS.
Question 47 of 60
47. Question
You need to implement a ‘Just-In-Time’ (JIT) administration model for your hybrid Windows Servers. You want to ensure that users can only perform specific administrative tasks on specific servers for a limited time. Which two features should you use?
Correct
JEA is a PowerShell technology that limits *what* a user can do (cmdlet-level restriction), while PIM limits *when* and *on which resources* a user has high-level Azure/Arc permissions.
Incorrect
JEA is a PowerShell technology that limits *what* a user can do (cmdlet-level restriction), while PIM limits *when* and *on which resources* a user has high-level Azure/Arc permissions.
Unattempted
JEA is a PowerShell technology that limits *what* a user can do (cmdlet-level restriction), while PIM limits *when* and *on which resources* a user has high-level Azure/Arc permissions.
Question 48 of 60
48. Question
You have an Azure Stack HCI cluster. You want to use ‘Azure Monitor’ to see a visual map of how your VMs are connected to other services. Which feature should you enable?
Correct
VM Insights ‘Map’ view uses data from the Dependency Agent (via AMA) to visualize the network connections, open ports, and dependencies of both your Azure and Arc-enabled HCI virtual machines.
Incorrect
VM Insights ‘Map’ view uses data from the Dependency Agent (via AMA) to visualize the network connections, open ports, and dependencies of both your Azure and Arc-enabled HCI virtual machines.
Unattempted
VM Insights ‘Map’ view uses data from the Dependency Agent (via AMA) to visualize the network connections, open ports, and dependencies of both your Azure and Arc-enabled HCI virtual machines.
Question 49 of 60
49. Question
You need to implement Azure File Sync for a branch office. The branch office has limited internet bandwidth. Which two features or tools can help you manage the bandwidth used by the synchronization process?
Correct
The StorageSyncNetworkLimit cmdlet allows you to set specific bandwidth limits for sync based on a schedule. Additionally, standard Windows Server QoS policies can be used to throttle traffic from the File Sync service.
Incorrect
The StorageSyncNetworkLimit cmdlet allows you to set specific bandwidth limits for sync based on a schedule. Additionally, standard Windows Server QoS policies can be used to throttle traffic from the File Sync service.
Unattempted
The StorageSyncNetworkLimit cmdlet allows you to set specific bandwidth limits for sync based on a schedule. Additionally, standard Windows Server QoS policies can be used to throttle traffic from the File Sync service.
Question 50 of 60
50. Question
You have an Azure Arc-enabled server. You want to use the ‘Azure Policy’ to ensure that a specific Windows Feature (e.g., Telnet-Client) is UNINSTALLED. Which ‘Guest Configuration’ policy effect should you use?
Correct
To take an action—such as uninstalling a feature—the policy must use the ‘DeployIfNotExists’ (DINE) effect. This triggers a remediation task that uses the Guest Configuration agent to remove the specified feature.
Incorrect
To take an action—such as uninstalling a feature—the policy must use the ‘DeployIfNotExists’ (DINE) effect. This triggers a remediation task that uses the Guest Configuration agent to remove the specified feature.
Unattempted
To take an action—such as uninstalling a feature—the policy must use the ‘DeployIfNotExists’ (DINE) effect. This triggers a remediation task that uses the Guest Configuration agent to remove the specified feature.
Question 51 of 60
51. Question
You manage a Windows Server 2022 machine named Server1. You need to use the Azure portal to manage the local firewall and view real-time performance metrics without establishing a VPN. Which two steps are required?
Correct
By onboarding the server to Azure Arc and then enabling the Windows Admin Center (WAC) extension, you can manage the local OS (including firewalls and metrics) directly through the Azure portal interface over an outbound HTTPS connection.
Incorrect
By onboarding the server to Azure Arc and then enabling the Windows Admin Center (WAC) extension, you can manage the local OS (including firewalls and metrics) directly through the Azure portal interface over an outbound HTTPS connection.
Unattempted
By onboarding the server to Azure Arc and then enabling the Windows Admin Center (WAC) extension, you can manage the local OS (including firewalls and metrics) directly through the Azure portal interface over an outbound HTTPS connection.
Question 52 of 60
52. Question
You are managing a hybrid identity. You want to enable ‘Password Hash Sync’ (PHS) as a backup for ‘Pass-through Authentication’ (PTA). What is the primary benefit of this configuration?
Correct
If PTA is the primary method and the agents or local servers fail, having PHS as a ‘backup’ allows the Entra ID service to handle the authentication directly in the cloud, ensuring business continuity.
Incorrect
If PTA is the primary method and the agents or local servers fail, having PHS as a ‘backup’ allows the Entra ID service to handle the authentication directly in the cloud, ensuring business continuity.
Unattempted
If PTA is the primary method and the agents or local servers fail, having PHS as a ‘backup’ allows the Entra ID service to handle the authentication directly in the cloud, ensuring business continuity.
Question 53 of 60
53. Question
You are troubleshooting Azure AD Connect ‘Health’. You want to monitor the ‘latency’ of the password hash synchronization. Which metric in the Health portal provides this?
Correct
The ‘Heartbeat’ metric for Password Hash Sync indicates when the last successful sync occurred. If the latency between heartbeats increases, it suggests a performance bottleneck or communication issue between the sync server and Azure.
Incorrect
The ‘Heartbeat’ metric for Password Hash Sync indicates when the last successful sync occurred. If the latency between heartbeats increases, it suggests a performance bottleneck or communication issue between the sync server and Azure.
Unattempted
The ‘Heartbeat’ metric for Password Hash Sync indicates when the last successful sync occurred. If the latency between heartbeats increases, it suggests a performance bottleneck or communication issue between the sync server and Azure.
Question 54 of 60
54. Question
You are implementing Azure AD Application Proxy for an internal IIS-based website. The website uses ‘Header-based’ authentication. Which two components are needed to support this?
Correct
While App Proxy handles the connection, Entra ID (Azure AD) now supports native header-based authentication through specific application configurations, allowing you to map Entra attributes to HTTP headers.
Incorrect
While App Proxy handles the connection, Entra ID (Azure AD) now supports native header-based authentication through specific application configurations, allowing you to map Entra attributes to HTTP headers.
Unattempted
While App Proxy handles the connection, Entra ID (Azure AD) now supports native header-based authentication through specific application configurations, allowing you to map Entra attributes to HTTP headers.
Question 55 of 60
55. Question
You manage several Azure Arc-enabled servers. You need to automate the deployment of a specific software package across all these servers. Which two Azure features can you use?
Correct
Custom Script Extensions allow you to run scripts directly on Arc-managed servers, while Azure Automation DSC provides a way to enforce a specific configuration state (including installed software) across a hybrid fleet.
Incorrect
Custom Script Extensions allow you to run scripts directly on Arc-managed servers, while Azure Automation DSC provides a way to enforce a specific configuration state (including installed software) across a hybrid fleet.
Unattempted
Custom Script Extensions allow you to run scripts directly on Arc-managed servers, while Azure Automation DSC provides a way to enforce a specific configuration state (including installed software) across a hybrid fleet.
Question 56 of 60
56. Question
You have an on-premises SQL Server. You want to use ‘Azure SQL Managed Instance’ but need to keep the data on-premises for compliance. Which feature allows you to extend the cloud SQL engine to your local hardware?
Correct
Azure Arc-enabled data services allow you to run Azure SQL Managed Instance on-premises using your own Kubernetes infrastructure, providing cloud-like management while keeping data local.
Incorrect
Azure Arc-enabled data services allow you to run Azure SQL Managed Instance on-premises using your own Kubernetes infrastructure, providing cloud-like management while keeping data local.
Unattempted
Azure Arc-enabled data services allow you to run Azure SQL Managed Instance on-premises using your own Kubernetes infrastructure, providing cloud-like management while keeping data local.
Question 57 of 60
57. Question
You are managing an Azure Stack HCI cluster. You want to use ‘GPU Partitioning’ (GPU-P) to share a physical GPU across multiple virtual machines. Which OS is required for the guest VMs to support GPU-P?
Correct
GPU Partitioning (GPU-P) in Azure Stack HCI requires modern guest operating systems that support the necessary WDDM drivers, specifically Windows 10/11 or Windows Server 2019 and newer.
Incorrect
GPU Partitioning (GPU-P) in Azure Stack HCI requires modern guest operating systems that support the necessary WDDM drivers, specifically Windows 10/11 or Windows Server 2019 and newer.
Unattempted
GPU Partitioning (GPU-P) in Azure Stack HCI requires modern guest operating systems that support the necessary WDDM drivers, specifically Windows 10/11 or Windows Server 2019 and newer.
Question 58 of 60
58. Question
You are using ‘Azure Site Recovery’ (ASR). You need to change the ‘Recovery Point Retention’ from 24 hours to 72 hours. Where do you modify this setting?
Correct
Retention settings are defined at the ‘Replication Policy’ level. Note that increasing retention might increase the amount of storage consumed in Azure for recovery points.
Incorrect
Retention settings are defined at the ‘Replication Policy’ level. Note that increasing retention might increase the amount of storage consumed in Azure for recovery points.
Unattempted
Retention settings are defined at the ‘Replication Policy’ level. Note that increasing retention might increase the amount of storage consumed in Azure for recovery points.
Question 59 of 60
59. Question
You are managing a hybrid identity. You want to use ‘Azure AD Identity Protection’ to detect risky sign-ins for your on-premises users. Which authentication method provides the best telemetry for this?
Correct
PHS provides the best telemetry because the authentication happens entirely within Azure. This allows Identity Protection to analyze the sign-in patterns, leaked credentials, and behavioral risks much more effectively than redirected methods.
Incorrect
PHS provides the best telemetry because the authentication happens entirely within Azure. This allows Identity Protection to analyze the sign-in patterns, leaked credentials, and behavioral risks much more effectively than redirected methods.
Unattempted
PHS provides the best telemetry because the authentication happens entirely within Azure. This allows Identity Protection to analyze the sign-in patterns, leaked credentials, and behavioral risks much more effectively than redirected methods.
Question 60 of 60
60. Question
You have an Azure File Sync server. You want to see which files were *successfully* tiered to the cloud in the last hour. Which Event Log should you check?
Correct
The ‘Diagnostic’ log under the FileSync agent category contains detailed entries for every file sync and tiering operation, including successes and specific error codes for failures.
Incorrect
The ‘Diagnostic’ log under the FileSync agent category contains detailed entries for every file sync and tiering operation, including successes and specific error codes for failures.
Unattempted
The ‘Diagnostic’ log under the FileSync agent category contains detailed entries for every file sync and tiering operation, including successes and specific error codes for failures.
X
Use Page numbers below to navigate to other practice tests