You have already completed the Test before. Hence you can not start it again.
Test is loading...
You must sign in or sign up to start the Test.
You have to finish following quiz, to start this Test:
Your results are here!! for" AZ-802 Practice Test 11 "
0 of 51 questions answered correctly
Your time:
Time has elapsed
Your Final Score is : 0
You have attempted : 0
Number of Correct Questions : 0 and scored 0
Number of Incorrect Questions : 0 and Negative marks 0
Average score
Your score
AZ-802
You have attempted: 0
Number of Correct Questions: 0 and scored 0
Number of Incorrect Questions: 0 and Negative marks 0
You can review your answers by clicking on “View Answers” option. Important Note : Open Reference Documentation Links in New Tab (Right Click and Open in New Tab).
Answer Review
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
Answer
Review
Unattempted
Correct
Incorrect
Unattempted
Every question in this attempt was answered correctly.
Question 1 of 51
1. Question
You have an Azure VM. You want to use ‘Managed Identities’ to allow the VM to access an Azure SQL Database without storing credentials in a config file. Which type of identity is deleted automatically if the VM is deleted?
Correct
System-assigned managed identities are tied directly to the lifecycle of the Azure resource; deleting the resource deletes the identity.
Incorrect
System-assigned managed identities are tied directly to the lifecycle of the Azure resource; deleting the resource deletes the identity.
Unattempted
System-assigned managed identities are tied directly to the lifecycle of the Azure resource; deleting the resource deletes the identity.
Question 2 of 51
2. Question
Your on-premises Active Directory is syncing to Azure AD. You want to ensure that users who are flagged as ‘High Risk’ by Azure AD Identity Protection are automatically blocked from signing in. What should you configure?
Correct
Conditional Access policies in Azure AD allow you to enforce controls based on sign-in risk levels calculated by Identity Protection.
Incorrect
Conditional Access policies in Azure AD allow you to enforce controls based on sign-in risk levels calculated by Identity Protection.
Unattempted
Conditional Access policies in Azure AD allow you to enforce controls based on sign-in risk levels calculated by Identity Protection.
Question 3 of 51
3. Question
You need to implement a hybrid identity solution. You want to use Azure AD Seamless Single Sign-On (Seamless SSO). Which authentication method(s) can be used in conjunction with Seamless SSO?
Correct
Seamless SSO can be combined with either Password Hash Synchronization or Pass-through Authentication to provide a better sign-in experience.
Incorrect
Seamless SSO can be combined with either Password Hash Synchronization or Pass-through Authentication to provide a better sign-in experience.
Unattempted
Seamless SSO can be combined with either Password Hash Synchronization or Pass-through Authentication to provide a better sign-in experience.
Question 4 of 51
4. Question
You need to migrate a legacy application from an old physical server to an Azure VM. The application is highly sensitive to changes in hardware IDs. Which migration method is most likely to preserve the environment exactly as is?
Correct
Azure Migrate performs block-level replication of the server’s disks ensuring that the VM in Azure is a near-identical copy of the physical source.
Incorrect
Azure Migrate performs block-level replication of the server’s disks ensuring that the VM in Azure is a near-identical copy of the physical source.
Unattempted
Azure Migrate performs block-level replication of the server’s disks ensuring that the VM in Azure is a near-identical copy of the physical source.
Question 5 of 51
5. Question
You need to implement a solution for highly available DHCP in a Windows Server 2022 environment. You want to ensure that both servers can lease IP addresses simultaneously from the same pool. Which mode should you configure?
Correct
In DHCP Failover ‘Load Balance’ mode both servers actively serve IP addresses to clients in the same subnet providing both redundancy and performance.
Incorrect
In DHCP Failover ‘Load Balance’ mode both servers actively serve IP addresses to clients in the same subnet providing both redundancy and performance.
Unattempted
In DHCP Failover ‘Load Balance’ mode both servers actively serve IP addresses to clients in the same subnet providing both redundancy and performance.
Question 6 of 51
6. Question
You need to monitor the health of your Azure AD Connect synchronization. You want to receive alerts if synchronization has stopped for more than two hours. What should you use?
Correct
Azure AD Connect Health provides monitoring and insights into your on-premises identity infrastructure including sync status.
Incorrect
Azure AD Connect Health provides monitoring and insights into your on-premises identity infrastructure including sync status.
Unattempted
Azure AD Connect Health provides monitoring and insights into your on-premises identity infrastructure including sync status.
Question 7 of 51
7. Question
You have an Azure VM. You want to identify if it is underutilized to save costs. Which Azure service provides recommendations to ‘shutdown or resize’ VMs?
Correct
Azure Advisor analyzes your resource configuration and usage telemetry to provide recommendations for cost-savings and performance.
Incorrect
Azure Advisor analyzes your resource configuration and usage telemetry to provide recommendations for cost-savings and performance.
Unattempted
Azure Advisor analyzes your resource configuration and usage telemetry to provide recommendations for cost-savings and performance.
Question 8 of 51
8. Question
You have an Azure File Sync server. You want to move the local Server Endpoint to a different drive on the same server. What is the supported method?
Correct
To change the path of a Server Endpoint you must delete the endpoint in the cloud (which stops sync) move the data and then create a new Server Endpoint pointing to the new path.
Incorrect
To change the path of a Server Endpoint you must delete the endpoint in the cloud (which stops sync) move the data and then create a new Server Endpoint pointing to the new path.
Unattempted
To change the path of a Server Endpoint you must delete the endpoint in the cloud (which stops sync) move the data and then create a new Server Endpoint pointing to the new path.
Question 9 of 51
9. Question
You need to expand the storage of an existing Azure File Sync Server Endpoint. You have already expanded the local disk volume. What is the next step to ensure the sync agent uses the new space?
Correct
The Azure File Sync agent monitors the local volume and will automatically utilize the newly available space once the underlying volume is extended.
Incorrect
The Azure File Sync agent monitors the local volume and will automatically utilize the newly available space once the underlying volume is extended.
Unattempted
The Azure File Sync agent monitors the local volume and will automatically utilize the newly available space once the underlying volume is extended.
Question 10 of 51
10. Question
You have an Azure VM. You want to use ‘Azure Backup’. You want to ensure that even if the entire Azure Region is destroyed your backups are safe. Which storage setting for the vault is needed?
Correct
GRS replicates backup data to a secondary paired region (e.g. from East US to West US) providing protection against regional disasters.
Incorrect
GRS replicates backup data to a secondary paired region (e.g. from East US to West US) providing protection against regional disasters.
Unattempted
GRS replicates backup data to a secondary paired region (e.g. from East US to West US) providing protection against regional disasters.
Question 11 of 51
11. Question
You have an on-premises Hyper-V host. You want to use Azure Site Recovery (ASR) to replicate VMs to Azure. You do not have a System Center Virtual Machine Manager (SCVMM) server. What should you install on the Hyper-V host?
Correct
When replicating Hyper-V VMs without VMM, you install the ASR Provider and the MARS agent directly on the Hyper-V host to manage replication.
Incorrect
When replicating Hyper-V VMs without VMM, you install the ASR Provider and the MARS agent directly on the Hyper-V host to manage replication.
Unattempted
When replicating Hyper-V VMs without VMM, you install the ASR Provider and the MARS agent directly on the Hyper-V host to manage replication.
Question 12 of 51
12. Question
You have an on-premises Windows Server 2022. You want to use ‘Azure Arc’ to manage it. What is the name of the agent service that runs on the server?
Correct
The Azure Connected Machine agent (specifically the ‘himds’ service) is responsible for the connection between the physical server and Azure Arc.
Incorrect
The Azure Connected Machine agent (specifically the ‘himds’ service) is responsible for the connection between the physical server and Azure Arc.
Unattempted
The Azure Connected Machine agent (specifically the ‘himds’ service) is responsible for the connection between the physical server and Azure Arc.
Question 13 of 51
13. Question
You have an Azure VM. You want to ensure it is always patched with the latest ‘Critical’ and ‘Security’ updates automatically. Which feature should you enable in the VM settings?
Correct
Automatic Guest Patching (part of Azure Update Manager) allows Azure to orchestrate the installation of security patches with minimal manual effort.
Incorrect
Automatic Guest Patching (part of Azure Update Manager) allows Azure to orchestrate the installation of security patches with minimal manual effort.
Unattempted
Automatic Guest Patching (part of Azure Update Manager) allows Azure to orchestrate the installation of security patches with minimal manual effort.
Question 14 of 51
14. Question
You have an Azure VM running Windows Server 2022. You want to use ‘Azure Disk Encryption’. What is the prerequisite for storing the encryption keys?
Correct
Azure Disk Encryption (ADE) requires an Azure Key Vault to store and manage the disk encryption keys and secrets.
Incorrect
Azure Disk Encryption (ADE) requires an Azure Key Vault to store and manage the disk encryption keys and secrets.
Unattempted
Azure Disk Encryption (ADE) requires an Azure Key Vault to store and manage the disk encryption keys and secrets.
Question 15 of 51
15. Question
You need to view the effective permissions for a user on a specific folder on a Windows Server 2022 file server. Which tab in the Advanced Security Settings should you use?
Correct
The Effective Access tab allows you to select a user or group and see exactly what permissions they have on that object after all inheritance and groups are calculated.
Incorrect
The Effective Access tab allows you to select a user or group and see exactly what permissions they have on that object after all inheritance and groups are calculated.
Unattempted
The Effective Access tab allows you to select a user or group and see exactly what permissions they have on that object after all inheritance and groups are calculated.
Question 16 of 51
16. Question
You have an on-premises Windows Server 2022. You want to use it as a ‘Print Server’ for your Azure-joined laptops. Which hybrid solution enables this?
Correct
Universal Print is a cloud-based print solution that removes the need for on-premises print servers and works seamlessly with Windows 10/11.
Incorrect
Universal Print is a cloud-based print solution that removes the need for on-premises print servers and works seamlessly with Windows 10/11.
Unattempted
Universal Print is a cloud-based print solution that removes the need for on-premises print servers and works seamlessly with Windows 10/11.
Question 17 of 51
17. Question
You have an Azure File Sync environment. You want to manually trigger a sync of files that were recently uploaded directly to the Azure File Share (bypassing the local server). Which PowerShell cmdlet should you use?
Correct
By default, Azure File Sync only detects changes on the cloud share once every 24 hours. To speed this up, you use Invoke-AzStorageSyncChangeDetection.
Incorrect
By default, Azure File Sync only detects changes on the cloud share once every 24 hours. To speed this up, you use Invoke-AzStorageSyncChangeDetection.
Unattempted
By default, Azure File Sync only detects changes on the cloud share once every 24 hours. To speed this up, you use Invoke-AzStorageSyncChangeDetection.
Question 18 of 51
18. Question
You have an Azure File Share. You want to use ‘Identity-based authentication’. Which identity providers are supported?
Correct
Azure Files supports authentication via on-premises Active Directory or Azure AD Domain Services for SMB access.
Incorrect
Azure Files supports authentication via on-premises Active Directory or Azure AD Domain Services for SMB access.
Unattempted
Azure Files supports authentication via on-premises Active Directory or Azure AD Domain Services for SMB access.
Question 19 of 51
19. Question
You have an Azure File Share. You want to ensure that if a file is modified incorrectly you can go back to a version from 2 hours ago. Which feature provides this?
Correct
Share Snapshots provide a point-in-time read-only version of your Azure File Share which can be used for restoring individual files.
Incorrect
Share Snapshots provide a point-in-time read-only version of your Azure File Share which can be used for restoring individual files.
Unattempted
Share Snapshots provide a point-in-time read-only version of your Azure File Share which can be used for restoring individual files.
Question 20 of 51
20. Question
You have an Azure VM. You want to use ‘Azure Disk Encryption’ (ADE) to encrypt the OS disk. Which underlying Windows technology does ADE use?
Correct
Azure Disk Encryption uses the industry-standard BitLocker feature of Windows to provide volume encryption for the OS and data disks.
Incorrect
Azure Disk Encryption uses the industry-standard BitLocker feature of Windows to provide volume encryption for the OS and data disks.
Unattempted
Azure Disk Encryption uses the industry-standard BitLocker feature of Windows to provide volume encryption for the OS and data disks.
Question 21 of 51
21. Question
You have an on-premises Windows Server 2022. You want to use the ‘Azure Network Adapter’ in Windows Admin Center. What is the maximum number of Azure Network Adapters you can create on a single server?
Correct
Windows Admin Center currently supports creating one Azure Network Adapter per server to establish a P2S VPN.
Incorrect
Windows Admin Center currently supports creating one Azure Network Adapter per server to establish a P2S VPN.
Unattempted
Windows Admin Center currently supports creating one Azure Network Adapter per server to establish a P2S VPN.
Question 22 of 51
22. Question
You want to implement ‘Least Privilege’ for your administrators. You need a solution that allows them to request ‘Global Admin’ rights for only 2 hours when needed. Which Azure AD feature provides this?
Correct
PIM allows for ‘just-in-time’ administrative access reducing the risk of permanently assigned privileged accounts.
Incorrect
PIM allows for ‘just-in-time’ administrative access reducing the risk of permanently assigned privileged accounts.
Unattempted
PIM allows for ‘just-in-time’ administrative access reducing the risk of permanently assigned privileged accounts.
Question 23 of 51
23. Question
You have an Azure VM running an application that requires high availability. You want to protect the VM against a single data center failure within an Azure region. What should you use?
Correct
Availability Zones protect your applications and data from data center failures by placing instances in physically separate locations within a region.
Incorrect
Availability Zones protect your applications and data from data center failures by placing instances in physically separate locations within a region.
Unattempted
Availability Zones protect your applications and data from data center failures by placing instances in physically separate locations within a region.
Question 24 of 51
24. Question
You manage a hybrid environment. You need to deploy a tool that provides a centralized view of security alerts and automated responses across both on-premises Windows Servers and Azure VMs. Which service should you use?
Correct
Microsoft Sentinel (formerly Azure Sentinel) is a cloud-native SIEM that provides security analytics and threat intelligence across the entire hybrid enterprise.
Incorrect
Microsoft Sentinel (formerly Azure Sentinel) is a cloud-native SIEM that provides security analytics and threat intelligence across the entire hybrid enterprise.
Unattempted
Microsoft Sentinel (formerly Azure Sentinel) is a cloud-native SIEM that provides security analytics and threat intelligence across the entire hybrid enterprise.
Question 25 of 51
25. Question
You have an on-premises Windows Server 2022. You want to use ‘Azure Extended Networking’ to migrate a VM to Azure while keeping its original on-premises IP address. What is required?
Correct
Azure Extended Networking allows you to ‘stretch’ your on-premises subnets into Azure, which requires an L2 bridge/tunnel.
Incorrect
Azure Extended Networking allows you to ‘stretch’ your on-premises subnets into Azure, which requires an L2 bridge/tunnel.
Unattempted
Azure Extended Networking allows you to ‘stretch’ your on-premises subnets into Azure, which requires an L2 bridge/tunnel.
Question 26 of 51
26. Question
You have an Azure VM running Windows Server 2022. You want to use Azure Automanage to automatically apply best practices. Which of the following is NOT a service typically managed by Azure Automanage for Windows Server?
Correct
Azure Automanage focuses on VM-level operations like backup patching and security; it does not manage PaaS services like Azure SQL Database.
Incorrect
Azure Automanage focuses on VM-level operations like backup patching and security; it does not manage PaaS services like Azure SQL Database.
Unattempted
Azure Automanage focuses on VM-level operations like backup patching and security; it does not manage PaaS services like Azure SQL Database.
Question 27 of 51
27. Question
You have an on-premises Hyper-V cluster. You want to use Azure as a cold disaster recovery site. You need to replicate the VMs to Azure with a high frequency. Which service should you use?
Correct
Azure Site Recovery (ASR) is designed specifically for near-continuous replication and orchestration of failover for VMs.
Incorrect
Azure Site Recovery (ASR) is designed specifically for near-continuous replication and orchestration of failover for VMs.
Unattempted
Azure Site Recovery (ASR) is designed specifically for near-continuous replication and orchestration of failover for VMs.
Question 28 of 51
28. Question
You have an Azure VM. You want to use the ‘Azure Serial Console’ to troubleshoot a boot issue. Which feature must be enabled on the VM for the console to work?
Correct
Serial Console requires Boot Diagnostics to be enabled so that it can capture the text output from the VM’s serial port.
Incorrect
Serial Console requires Boot Diagnostics to be enabled so that it can capture the text output from the VM’s serial port.
Unattempted
Serial Console requires Boot Diagnostics to be enabled so that it can capture the text output from the VM’s serial port.
Question 29 of 51
29. Question
You have an on-premises Active Directory. You want to use Azure AD Multi-Factor Authentication (MFA) for on-premises VPN users who authenticate via RADIUS. What should you install on your NPS server?
Correct
The NPS extension for Azure MFA allows you to add cloud-based MFA to your existing RADIUS infrastructure.
Incorrect
The NPS extension for Azure MFA allows you to add cloud-based MFA to your existing RADIUS infrastructure.
Unattempted
The NPS extension for Azure MFA allows you to add cloud-based MFA to your existing RADIUS infrastructure.
Question 30 of 51
30. Question
You need to automate the deployment of 50 Azure VMs with Windows Server 2022. You want to ensure they all have the same initial configuration. Which should you use?
Correct
ARM templates (or Bicep) allow you to define the infrastructure and configuration of Azure resources as code for repeatable deployments.
Incorrect
ARM templates (or Bicep) allow you to define the infrastructure and configuration of Azure resources as code for repeatable deployments.
Unattempted
ARM templates (or Bicep) allow you to define the infrastructure and configuration of Azure resources as code for repeatable deployments.
Question 31 of 51
31. Question
You have an on-premises server. You want to use the ‘Azure Network Adapter’ feature in Windows Admin Center. What does this feature do?
Correct
The Azure Network Adapter creates a simplified VPN tunnel from a single server directly into an Azure VNet.
Incorrect
The Azure Network Adapter creates a simplified VPN tunnel from a single server directly into an Azure VNet.
Unattempted
The Azure Network Adapter creates a simplified VPN tunnel from a single server directly into an Azure VNet.
Question 32 of 51
32. Question
You need to provide high availability for a print server in a hybrid environment. You decide to use a Failover Cluster. Which type of storage is recommended for the print spooler folder in a Windows Server 2022 cluster?
Correct
For the Print Server role in a cluster, a traditional shared disk resource is typically used for the spooler rather than a CSV, which is optimized for Hyper-V/SQL.
Incorrect
For the Print Server role in a cluster, a traditional shared disk resource is typically used for the spooler rather than a CSV, which is optimized for Hyper-V/SQL.
Unattempted
For the Print Server role in a cluster, a traditional shared disk resource is typically used for the spooler rather than a CSV, which is optimized for Hyper-V/SQL.
Question 33 of 51
33. Question
You have an on-premises server with the ‘Remote Access’ role. You want to implement ‘DirectAccess’. What is a primary requirement for the client computers?
Correct
DirectAccess is a domain-based technology that provides seamless connectivity for domain-joined Windows clients.
Incorrect
DirectAccess is a domain-based technology that provides seamless connectivity for domain-joined Windows clients.
Unattempted
DirectAccess is a domain-based technology that provides seamless connectivity for domain-joined Windows clients.
Question 34 of 51
34. Question
You need to manage an on-premises server that is behind a strict firewall. You have installed the Azure Arc agent. Which protocol is used for the outbound communication from the server to Azure?
Correct
Azure Arc-enabled servers only require outbound communication over port 443, making it very firewall-friendly.
Incorrect
Azure Arc-enabled servers only require outbound communication over port 443, making it very firewall-friendly.
Unattempted
Azure Arc-enabled servers only require outbound communication over port 443, making it very firewall-friendly.
Question 35 of 51
35. Question
You need to delegate the ability to join computers to the domain to a specific user, without making them a Domain Admin. Which tool should you use?
Correct
The Delegate Control Wizard in ADUC allows you to grant specific permissions (like ‘Join a computer to the domain’) to users or groups for a specific OU.
Incorrect
The Delegate Control Wizard in ADUC allows you to grant specific permissions (like ‘Join a computer to the domain’) to users or groups for a specific OU.
Unattempted
The Delegate Control Wizard in ADUC allows you to grant specific permissions (like ‘Join a computer to the domain’) to users or groups for a specific OU.
Question 36 of 51
36. Question
You have an Azure VM. You want to prevent any changes to the VM configuration (like changing the size or deleting it) even by administrators. What should you use?
Correct
Resource Locks provide a way to prevent accidental or intentional changes/deletions of critical Azure resources.
Incorrect
Resource Locks provide a way to prevent accidental or intentional changes/deletions of critical Azure resources.
Unattempted
Resource Locks provide a way to prevent accidental or intentional changes/deletions of critical Azure resources.
Question 37 of 51
37. Question
You need to view the history of all administrative actions performed on an Azure Arc-enabled server via the Azure portal. Which Azure service provides this log?
Correct
The Azure Activity Log records all ‘write’ operations (PUT POST DELETE) performed on resources in your subscription including Arc server modifications.
Incorrect
The Azure Activity Log records all ‘write’ operations (PUT POST DELETE) performed on resources in your subscription including Arc server modifications.
Unattempted
The Azure Activity Log records all ‘write’ operations (PUT POST DELETE) performed on resources in your subscription including Arc server modifications.
Question 38 of 51
38. Question
You have an on-premises server named Server1. You want to enable ‘Azure Update Manager’. What is the primary prerequisite for an on-premises server to be visible in Azure Update Manager?
Correct
Azure Update Manager uses the Azure Arc agent to communicate with and manage updates for servers located outside of Azure.
Incorrect
Azure Update Manager uses the Azure Arc agent to communicate with and manage updates for servers located outside of Azure.
Unattempted
Azure Update Manager uses the Azure Arc agent to communicate with and manage updates for servers located outside of Azure.
Question 39 of 51
39. Question
You need to restrict which PowerShell commands can be executed by a specific group of help desk users on a hybrid server. What should you implement?
Correct
JEA is a security technology that enables delegate administration for anything managed by PowerShell by creating a restricted endpoint.
Incorrect
JEA is a security technology that enables delegate administration for anything managed by PowerShell by creating a restricted endpoint.
Unattempted
JEA is a security technology that enables delegate administration for anything managed by PowerShell by creating a restricted endpoint.
Question 40 of 51
40. Question
You have an Azure VM running Windows Server 2022 Datacenter: Azure Edition. You want to apply security patches without restarting the VM. Which feature allows this?
Correct
Hotpatching on Windows Server Azure Edition allows security updates to be applied in memory without requiring a reboot.
Incorrect
Hotpatching on Windows Server Azure Edition allows security updates to be applied in memory without requiring a reboot.
Unattempted
Hotpatching on Windows Server Azure Edition allows security updates to be applied in memory without requiring a reboot.
Question 41 of 51
41. Question
You have an on-premises server named Server1. You need to back up files from Server1 to Azure using the Microsoft Azure Recovery Services (MARS) agent. What is the maximum number of times per day you can schedule a backup with the MARS agent?
Correct
The MARS agent allows you to schedule backups up to three times a day (e.g. morning evening and night).
Incorrect
The MARS agent allows you to schedule backups up to three times a day (e.g. morning evening and night).
Unattempted
The MARS agent allows you to schedule backups up to three times a day (e.g. morning evening and night).
Question 42 of 51
42. Question
You need to deploy a new Windows Server VM in Azure. You want to ensure that even if an entire Azure region goes offline your VM can be recovered in a different region. What should you enable?
Correct
Azure Site Recovery provides replication and orchestration for disaster recovery between Azure regions.
Incorrect
Azure Site Recovery provides replication and orchestration for disaster recovery between Azure regions.
Unattempted
Azure Site Recovery provides replication and orchestration for disaster recovery between Azure regions.
Question 43 of 51
43. Question
You have an on-premises Windows Server 2022 named Server1 that is onboarded to Azure Arc. You want to use the Azure Key Vault extension to manage certificates on Server1. What is a prerequisite for the server to access the Key Vault?
Correct
Azure Arc-enabled servers are assigned a system-assigned managed identity by default, which can be granted permissions to Azure resources like Key Vault.
Incorrect
Azure Arc-enabled servers are assigned a system-assigned managed identity by default, which can be granted permissions to Azure resources like Key Vault.
Unattempted
Azure Arc-enabled servers are assigned a system-assigned managed identity by default, which can be granted permissions to Azure resources like Key Vault.
Question 44 of 51
44. Question
You want to use ‘Just-In-Time’ (JIT) VM access for an Azure VM. Which Microsoft Defender for Cloud plan is required to enable this feature?
Correct
JIT VM Access is a premium security feature included in the Microsoft Defender for Servers Plan 2 (formerly the Standard tier).
Incorrect
JIT VM Access is a premium security feature included in the Microsoft Defender for Servers Plan 2 (formerly the Standard tier).
Unattempted
JIT VM Access is a premium security feature included in the Microsoft Defender for Servers Plan 2 (formerly the Standard tier).
Question 45 of 51
45. Question
You want to provide secure, browser-based RDP access to your Azure VMs without exposing public IP addresses. What service should you deploy?
Correct
Azure Bastion provides secure RDP and SSH access to VMs directly through the Azure portal over SSL.
Incorrect
Azure Bastion provides secure RDP and SSH access to VMs directly through the Azure portal over SSL.
Unattempted
Azure Bastion provides secure RDP and SSH access to VMs directly through the Azure portal over SSL.
Question 46 of 51
46. Question
You have an application that requires a static IP address. You are moving it to an Azure VM. Where do you configure the static IP address for the VM?
Correct
In Azure, static IPs must be assigned at the Azure Fabric level via the NIC settings in the portal. Configuring it inside the guest OS can lead to connectivity loss.
Incorrect
In Azure, static IPs must be assigned at the Azure Fabric level via the NIC settings in the portal. Configuring it inside the guest OS can lead to connectivity loss.
Unattempted
In Azure, static IPs must be assigned at the Azure Fabric level via the NIC settings in the portal. Configuring it inside the guest OS can lead to connectivity loss.
Question 47 of 51
47. Question
You have an Azure VM that you want to manage using Windows Admin Center (WAC) in the Azure portal. The VM is running Windows Server 2019. Which port must be open in the VM’s Network Security Group (NSG) for WAC to function?
Correct
Windows Admin Center in the Azure portal requires port 6516 to be open for inbound traffic to the VM for the gateway communication.
Incorrect
Windows Admin Center in the Azure portal requires port 6516 to be open for inbound traffic to the VM for the gateway communication.
Unattempted
Windows Admin Center in the Azure portal requires port 6516 to be open for inbound traffic to the VM for the gateway communication.
Question 48 of 51
48. Question
You need to implement a solution that allows you to manage Windows Server updates using the Azure portal for both Azure VMs and on-premises servers. You decide to use Azure Update Manager. What is a key advantage of this over the older ‘Update Management’?
Correct
Azure Update Manager is the successor that is integrated directly into Azure VM management and doesn’t rely on the legacy Log Analytics agent or Automation accounts.
Incorrect
Azure Update Manager is the successor that is integrated directly into Azure VM management and doesn’t rely on the legacy Log Analytics agent or Automation accounts.
Unattempted
Azure Update Manager is the successor that is integrated directly into Azure VM management and doesn’t rely on the legacy Log Analytics agent or Automation accounts.
Question 49 of 51
49. Question
You need to provide remote access to an internal web application that uses Windows Integrated Authentication. You want to use Azure AD for the sign-in experience. What should you use?
Correct
Azure AD Application Proxy allows remote users to access internal web apps and supports SSO using Kerberos Constrained Delegation.
Incorrect
Azure AD Application Proxy allows remote users to access internal web apps and supports SSO using Kerberos Constrained Delegation.
Unattempted
Azure AD Application Proxy allows remote users to access internal web apps and supports SSO using Kerberos Constrained Delegation.
Question 50 of 51
50. Question
You need to migrate a Windows Server 2012 R2 DHCP server to Windows Server 2022. You want to use a tool that automates the export of settings and leases. Which tool is best suited for this?
Correct
The Windows Server Migration Tools (a feature you install) provides PowerShell cmdlets like Export-DhcpServer to migrate roles between different OS versions.
Incorrect
The Windows Server Migration Tools (a feature you install) provides PowerShell cmdlets like Export-DhcpServer to migrate roles between different OS versions.
Unattempted
The Windows Server Migration Tools (a feature you install) provides PowerShell cmdlets like Export-DhcpServer to migrate roles between different OS versions.
Question 51 of 51
51. Question
You have an on-premises Active Directory. You want to move your ‘File Servers’ to Azure but keep the same drive mappings for users (e.g. H: drive). What is the best hybrid solution?
Correct
Azure File Sync allows you to maintain the local file server interface and share names while the data is actually backed by Azure Files.
Incorrect
Azure File Sync allows you to maintain the local file server interface and share names while the data is actually backed by Azure Files.
Unattempted
Azure File Sync allows you to maintain the local file server interface and share names while the data is actually backed by Azure Files.
X
Use Page numbers below to navigate to other practice tests