You have already completed the Test before. Hence you can not start it again.
Test is loading...
You must sign in or sign up to start the Test.
You have to finish following quiz, to start this Test:
Your results are here!! for" AZ-802 Practice Test 4 "
0 of 60 questions answered correctly
Your time:
Time has elapsed
Your Final Score is : 0
You have attempted : 0
Number of Correct Questions : 0 and scored 0
Number of Incorrect Questions : 0 and Negative marks 0
Average score
Your score
AZ-802
You have attempted: 0
Number of Correct Questions: 0 and scored 0
Number of Incorrect Questions: 0 and Negative marks 0
You can review your answers by clicking on “View Answers” option. Important Note : Open Reference Documentation Links in New Tab (Right Click and Open in New Tab).
Answer Review
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Answer
Review
Unattempted
Correct
Incorrect
Unattempted
Every question in this attempt was answered correctly.
Question 1 of 60
1. Question
You are configuring a hybrid network. You want to use ‘Azure Private Link’ to access a Storage Account from an on-premises server over a VPN. Which two components are necessary to ensure the name ‘storage1.blob.core.windows.net’ resolves to the private IP?
Correct
The Private Endpoint provides the internal IP. To ensure on-premises servers use that IP instead of the public one, you must forward DNS queries from your local DNS server to an Azure DNS Private Resolver (or similar proxy) that can see the Private DNS Zone.
Incorrect
The Private Endpoint provides the internal IP. To ensure on-premises servers use that IP instead of the public one, you must forward DNS queries from your local DNS server to an Azure DNS Private Resolver (or similar proxy) that can see the Private DNS Zone.
Unattempted
The Private Endpoint provides the internal IP. To ensure on-premises servers use that IP instead of the public one, you must forward DNS queries from your local DNS server to an Azure DNS Private Resolver (or similar proxy) that can see the Private DNS Zone.
Question 2 of 60
2. Question
You are configuring ‘Azure Site Recovery’ for on-premises VMware VMs. You need to ensure that the replication traffic does not consume all available internet bandwidth during business hours. Which two methods can you use?
Correct
Replication throttling for VMware/Physical migrations is managed either within the Configuration Server (for agentless/appliance-based) or through the MARS agent properties if used for direct-to-cloud replication.
Incorrect
Replication throttling for VMware/Physical migrations is managed either within the Configuration Server (for agentless/appliance-based) or through the MARS agent properties if used for direct-to-cloud replication.
Unattempted
Replication throttling for VMware/Physical migrations is managed either within the Configuration Server (for agentless/appliance-based) or through the MARS agent properties if used for direct-to-cloud replication.
Question 3 of 60
3. Question
You are implementing Azure AD Connect. You need to ensure that users’ passwords are not only synced to the cloud but also that any changes made in Azure AD are reflected in the on-premises Active Directory. Which two configurations are required?
Correct
Password Writeback is the specific feature in Azure AD Connect that sends password changes from the cloud to on-premises. This requires SSPR to be enabled in the tenant to provide the user interface for those changes.
Incorrect
Password Writeback is the specific feature in Azure AD Connect that sends password changes from the cloud to on-premises. This requires SSPR to be enabled in the tenant to provide the user interface for those changes.
Unattempted
Password Writeback is the specific feature in Azure AD Connect that sends password changes from the cloud to on-premises. This requires SSPR to be enabled in the tenant to provide the user interface for those changes.
Question 4 of 60
4. Question
You are implementing Azure AD Connect Cloud Sync instead of the standard Azure AD Connect. Which two scenarios are best suited for Cloud Sync?
Correct
Cloud Sync is designed for lightweight deployment and is ideal for disconnected forests or organizations that do not require complex features like Device Writeback or large-scale object handling (over 100k).
Incorrect
Cloud Sync is designed for lightweight deployment and is ideal for disconnected forests or organizations that do not require complex features like Device Writeback or large-scale object handling (over 100k).
Unattempted
Cloud Sync is designed for lightweight deployment and is ideal for disconnected forests or organizations that do not require complex features like Device Writeback or large-scale object handling (over 100k).
Question 5 of 60
5. Question
You are configuring Azure Site Recovery (ASR) for on-premises Hyper-V VMs. You need to ensure that the VMs can fail over to Azure with minimal data loss. Which two replication settings should you configure?
Correct
Replication frequency determines how often data is sent to Azure (RPO), while App-consistent snapshots ensure that the application data (like SQL or AD) is in a usable state upon recovery.
Incorrect
Replication frequency determines how often data is sent to Azure (RPO), while App-consistent snapshots ensure that the application data (like SQL or AD) is in a usable state upon recovery.
Unattempted
Replication frequency determines how often data is sent to Azure (RPO), while App-consistent snapshots ensure that the application data (like SQL or AD) is in a usable state upon recovery.
Question 6 of 60
6. Question
You are implementing Azure AD Connect. You need to ensure that specific sensitive attributes in your on-premises AD are never synchronized to Azure AD. Which two methods can you use?
Correct
Attribute filtering can be done during the initial installation wizard by deselecting specific attributes, or more granularly by creating a ‘Join’ or ‘Projection’ rule in the Synchronization Rules Editor to block the flow.
Incorrect
Attribute filtering can be done during the initial installation wizard by deselecting specific attributes, or more granularly by creating a ‘Join’ or ‘Projection’ rule in the Synchronization Rules Editor to block the flow.
Unattempted
Attribute filtering can be done during the initial installation wizard by deselecting specific attributes, or more granularly by creating a ‘Join’ or ‘Projection’ rule in the Synchronization Rules Editor to block the flow.
Question 7 of 60
7. Question
You are implementing ‘Azure File Sync’. You need to ensure that the sync service uses a specific proxy server for all outbound traffic. Where should you configure this proxy setting?
Correct
Azure File Sync has its own proxy configuration separate from the OS settings. You must use the sync-specific PowerShell cmdlets on the local server to define the proxy server and credentials for the sync traffic.
Incorrect
Azure File Sync has its own proxy configuration separate from the OS settings. You must use the sync-specific PowerShell cmdlets on the local server to define the proxy server and credentials for the sync traffic.
Unattempted
Azure File Sync has its own proxy configuration separate from the OS settings. You must use the sync-specific PowerShell cmdlets on the local server to define the proxy server and credentials for the sync traffic.
Question 8 of 60
8. Question
You are managing hybrid servers via Azure Arc. You want to apply a specific Registry setting to all Windows Servers automatically. Which two tools can achieve this ‘Desired State’?
Correct
Azure Automanage (Machine Configuration) uses DSC under the hood to enforce settings inside the OS. Azure Automation DSC is the classic way to maintain a pull-server model for configuration management across hybrid nodes.
Incorrect
Azure Automanage (Machine Configuration) uses DSC under the hood to enforce settings inside the OS. Azure Automation DSC is the classic way to maintain a pull-server model for configuration management across hybrid nodes.
Unattempted
Azure Automanage (Machine Configuration) uses DSC under the hood to enforce settings inside the OS. Azure Automation DSC is the classic way to maintain a pull-server model for configuration management across hybrid nodes.
Question 9 of 60
9. Question
You are configuring a hybrid network. You want to use Azure Relay to allow an on-premises WCF service to be reachable by an Azure Web App. Which two entities must you create in Azure to support this?
Correct
While ‘Hybrid Connections’ are common for general TCP traffic, WCF services specifically utilize the ‘WCF Relay’ type within an Azure Relay namespace to expose their endpoints to the cloud.
Incorrect
While ‘Hybrid Connections’ are common for general TCP traffic, WCF services specifically utilize the ‘WCF Relay’ type within an Azure Relay namespace to expose their endpoints to the cloud.
Unattempted
While ‘Hybrid Connections’ are common for general TCP traffic, WCF services specifically utilize the ‘WCF Relay’ type within an Azure Relay namespace to expose their endpoints to the cloud.
Question 10 of 60
10. Question
You are managing an Azure Stack HCI cluster and need to implement ‘Microsegmentation’. Which two elements define the security rules for the ‘Data Center Firewall’?
Correct
In the SDN context for Azure Stack HCI, you define ACLs that are applied to Virtual Networks or specific subnets. This allows you to restrict traffic between VMs (East-West traffic) regardless of their physical node location.
Incorrect
In the SDN context for Azure Stack HCI, you define ACLs that are applied to Virtual Networks or specific subnets. This allows you to restrict traffic between VMs (East-West traffic) regardless of their physical node location.
Unattempted
In the SDN context for Azure Stack HCI, you define ACLs that are applied to Virtual Networks or specific subnets. This allows you to restrict traffic between VMs (East-West traffic) regardless of their physical node location.
Question 11 of 60
11. Question
You are preparing to migrate an on-premises Windows Server 2016 physical server to Azure. You need to perform a ‘test migration’ without impacting the production environment. Which two steps are part of this process?
Correct
A test migration replicates data to Azure and spins up a VM in a designated test VNet, allowing you to verify the migration without disrupting the source server or the production network.
Incorrect
A test migration replicates data to Azure and spins up a VM in a designated test VNet, allowing you to verify the migration without disrupting the source server or the production network.
Unattempted
A test migration replicates data to Azure and spins up a VM in a designated test VNet, allowing you to verify the migration without disrupting the source server or the production network.
Question 12 of 60
12. Question
You are preparing to migrate a Windows Server 2012 R2 physical server to an Azure VM using Azure Migrate. Which two agents or components must be running on the local server or within the environment to perform a ‘discovery’?
Correct
For physical server migration, the Azure Migrate appliance is used for discovery, and the Mobility service (InMage) must be installed on the physical server itself to handle data replication.
Incorrect
For physical server migration, the Azure Migrate appliance is used for discovery, and the Mobility service (InMage) must be installed on the physical server itself to handle data replication.
Unattempted
For physical server migration, the Azure Migrate appliance is used for discovery, and the Mobility service (InMage) must be installed on the physical server itself to handle data replication.
Question 13 of 60
13. Question
You are implementing Azure AD Password Protection for an on-premises Active Directory domain. You need to ensure that the ‘Global Banned Password List’ is applied to all on-premises users. Which two components are mandatory for this deployment?
Correct
The DC agent captures the password change requests on the domain controllers, while the Proxy service acts as the communication bridge to fetch the banned password lists from Azure.
Incorrect
The DC agent captures the password change requests on the domain controllers, while the Proxy service acts as the communication bridge to fetch the banned password lists from Azure.
Unattempted
The DC agent captures the password change requests on the domain controllers, while the Proxy service acts as the communication bridge to fetch the banned password lists from Azure.
Question 14 of 60
14. Question
You are configuring Azure Stack HCI networking. You want to use ‘Switch Embedded Teaming’ (SET) for high availability. Which two requirements must be met for the physical network adapters?
Correct
SET requires that all member NICs have identical speeds and identical firmware/driver versions to ensure consistent performance and stability in the virtual switch team.
Incorrect
SET requires that all member NICs have identical speeds and identical firmware/driver versions to ensure consistent performance and stability in the virtual switch team.
Unattempted
SET requires that all member NICs have identical speeds and identical firmware/driver versions to ensure consistent performance and stability in the virtual switch team.
Question 15 of 60
15. Question
An organization uses a Windows Server 2022 failover cluster. You need to configure a cloud witness to provide a quorum vote. Which two items are required to complete this configuration?
Correct
A Cloud Witness requires a standard Azure Storage account and the associated access key for the cluster to authenticate and maintain the witness file.
Incorrect
A Cloud Witness requires a standard Azure Storage account and the associated access key for the cluster to authenticate and maintain the witness file.
Unattempted
A Cloud Witness requires a standard Azure Storage account and the associated access key for the cluster to authenticate and maintain the witness file.
Question 16 of 60
16. Question
You are planning to migrate a 5 TB volume from a physical Windows Server 2016 to Azure using Azure File Sync. You want to ensure the metadata and ACLs are preserved. Which two tools should you use for the initial data copy?
Correct
Robocopy (with backup mode and copyall flags) and Azure Data Box are the primary tools that support the preservation of NTFS ACLs and metadata during a large-scale migration to Azure Files.
Incorrect
Robocopy (with backup mode and copyall flags) and Azure Data Box are the primary tools that support the preservation of NTFS ACLs and metadata during a large-scale migration to Azure Files.
Unattempted
Robocopy (with backup mode and copyall flags) and Azure Data Box are the primary tools that support the preservation of NTFS ACLs and metadata during a large-scale migration to Azure Files.
Question 17 of 60
17. Question
You are configuring a hybrid network. You want to use ‘Azure Private Link’ to access a Storage Account from an on-premises server over a VPN. Which two components are necessary to ensure the name ‘storage1.blob.core.windows.net’ resolves to the private IP?
Correct
The Private Endpoint provides the internal IP. To ensure on-premises servers use that IP instead of the public one, you must forward DNS queries from your local DNS server to an Azure DNS Private Resolver (or similar proxy) that can see the Private DNS Zone.
Incorrect
The Private Endpoint provides the internal IP. To ensure on-premises servers use that IP instead of the public one, you must forward DNS queries from your local DNS server to an Azure DNS Private Resolver (or similar proxy) that can see the Private DNS Zone.
Unattempted
The Private Endpoint provides the internal IP. To ensure on-premises servers use that IP instead of the public one, you must forward DNS queries from your local DNS server to an Azure DNS Private Resolver (or similar proxy) that can see the Private DNS Zone.
Question 18 of 60
18. Question
You are configuring a Windows Server hybrid environment. You need to monitor the performance of on-premises servers using Azure Monitor. Which two steps are necessary?
Correct
To monitor performance via Azure Monitor, you must install the Azure Monitor Agent and define a Data Collection Rule (DCR) to specify which performance counters and logs are collected.
Incorrect
To monitor performance via Azure Monitor, you must install the Azure Monitor Agent and define a Data Collection Rule (DCR) to specify which performance counters and logs are collected.
Unattempted
To monitor performance via Azure Monitor, you must install the Azure Monitor Agent and define a Data Collection Rule (DCR) to specify which performance counters and logs are collected.
Question 19 of 60
19. Question
You are preparing for a migration using Azure Migrate. You need to estimate the costs of running your on-premises servers in Azure. Which two factors are primarily used by the ‘Azure Migrate: Assessment’ tool to calculate this?
Correct
Azure Migrate assessments look at actual performance data (Rightsizing) to suggest VM sizes and calculate costs based on the prices in the selected Azure Region and the chosen licensing (like Azure Hybrid Benefit).
Incorrect
Azure Migrate assessments look at actual performance data (Rightsizing) to suggest VM sizes and calculate costs based on the prices in the selected Azure Region and the chosen licensing (like Azure Hybrid Benefit).
Unattempted
Azure Migrate assessments look at actual performance data (Rightsizing) to suggest VM sizes and calculate costs based on the prices in the selected Azure Region and the chosen licensing (like Azure Hybrid Benefit).
Question 20 of 60
20. Question
You are managing a hybrid environment with ‘Azure AD Connect’. You need to ensure that ‘Self-Service Password Reset’ (SSPR) allows users to change their passwords in the cloud and have them updated in the local AD. Which two configurations are required?
Correct
Password Writeback is the bridge that sends cloud-initiated password changes back to the on-premises AD. SSPR must also be enabled in the Entra portal to allow users to access the reset interface.
Incorrect
Password Writeback is the bridge that sends cloud-initiated password changes back to the on-premises AD. SSPR must also be enabled in the Entra portal to allow users to access the reset interface.
Unattempted
Password Writeback is the bridge that sends cloud-initiated password changes back to the on-premises AD. SSPR must also be enabled in the Entra portal to allow users to access the reset interface.
Question 21 of 60
21. Question
You are troubleshooting a migration from Hyper-V to Azure using Azure Migrate. Several VMs are showing a status of ‘Not Ready’ for Azure. Which two factors could cause this status?
Correct
Azure has specific limits for OS support and disk size (the maximum for a managed disk is 32,767 GB). While Gen 2 VMs are supported, unsupported OS versions or oversized disks will trigger a ‘Not Ready’ or ‘Ready with conditions’ warning.
Incorrect
Azure has specific limits for OS support and disk size (the maximum for a managed disk is 32,767 GB). While Gen 2 VMs are supported, unsupported OS versions or oversized disks will trigger a ‘Not Ready’ or ‘Ready with conditions’ warning.
Unattempted
Azure has specific limits for OS support and disk size (the maximum for a managed disk is 32,767 GB). While Gen 2 VMs are supported, unsupported OS versions or oversized disks will trigger a ‘Not Ready’ or ‘Ready with conditions’ warning.
Question 22 of 60
22. Question
You are configuring ‘Azure AD Password Protection’ for your local AD. You want to ensure that passwords like ‘Company123!’ are blocked even though they aren’t on the global banned list. Which two steps are required?
Correct
The Custom Banned Password List allows you to block organization-specific terms. You must then set the mode to ‘Enforced’ to ensure the DC agents actually block the password changes rather than just auditing them.
Incorrect
The Custom Banned Password List allows you to block organization-specific terms. You must then set the mode to ‘Enforced’ to ensure the DC agents actually block the password changes rather than just auditing them.
Unattempted
The Custom Banned Password List allows you to block organization-specific terms. You must then set the mode to ‘Enforced’ to ensure the DC agents actually block the password changes rather than just auditing them.
Question 23 of 60
23. Question
You are configuring a hybrid network. You want to use ‘Azure Private Link’ to access a Storage Account from an on-premises server over a VPN. Which two components are necessary to ensure the name ‘storage1.blob.core.windows.net’ resolves to the private IP?
Correct
The Private Endpoint provides the internal IP. To ensure on-premises servers use that IP instead of the public one, you must forward DNS queries from your local DNS server to an Azure DNS Private Resolver.
Incorrect
The Private Endpoint provides the internal IP. To ensure on-premises servers use that IP instead of the public one, you must forward DNS queries from your local DNS server to an Azure DNS Private Resolver.
Unattempted
The Private Endpoint provides the internal IP. To ensure on-premises servers use that IP instead of the public one, you must forward DNS queries from your local DNS server to an Azure DNS Private Resolver.
Question 24 of 60
24. Question
You are configuring a hybrid Windows Server 2022 environment. You want to use ‘Azure Automanage’ to automate server management. Which two ‘Best Practices’ profiles are available by default?
Correct
Azure Automanage provides two primary pre-defined profiles: ‘Production’ (which includes more intensive monitoring and backup) and ‘Dev/Test’ (which is a lighter, cost-effective version of the management services).
Incorrect
Azure Automanage provides two primary pre-defined profiles: ‘Production’ (which includes more intensive monitoring and backup) and ‘Dev/Test’ (which is a lighter, cost-effective version of the management services).
Unattempted
Azure Automanage provides two primary pre-defined profiles: ‘Production’ (which includes more intensive monitoring and backup) and ‘Dev/Test’ (which is a lighter, cost-effective version of the management services).
Question 25 of 60
25. Question
You are monitoring a hybrid environment using Azure Monitor. You want to collect security-related events from several Windows Server 2022 domain controllers and store them in a Log Analytics workspace. Which two components are required?
Correct
Modern monitoring for Windows Server requires the AMA installed on the servers and a DCR to specify that Security Event logs should be collected and sent to the targeted Log Analytics workspace.
Incorrect
Modern monitoring for Windows Server requires the AMA installed on the servers and a DCR to specify that Security Event logs should be collected and sent to the targeted Log Analytics workspace.
Unattempted
Modern monitoring for Windows Server requires the AMA installed on the servers and a DCR to specify that Security Event logs should be collected and sent to the targeted Log Analytics workspace.
Question 26 of 60
26. Question
You are configuring ‘Azure AD Connect’ for a hybrid identity solution. You want to ensure that if the primary sync server fails, you can quickly promote a secondary server. Which mode should you use for the secondary server?
Correct
Staging Mode allows a server to run its synchronization engine and import data, but it does not export data to AD or Microsoft Entra ID. This keeps the metadata current so it can be promoted to Active Mode instantly.
Incorrect
Staging Mode allows a server to run its synchronization engine and import data, but it does not export data to AD or Microsoft Entra ID. This keeps the metadata current so it can be promoted to Active Mode instantly.
Unattempted
Staging Mode allows a server to run its synchronization engine and import data, but it does not export data to AD or Microsoft Entra ID. This keeps the metadata current so it can be promoted to Active Mode instantly.
Question 27 of 60
27. Question
You are deploying the Azure Monitor Agent (AMA) to several hybrid servers. You need to ensure the servers can send data to a Log Analytics workspace even though they do not have direct internet access. Which two solutions can you implement?
Correct
The Log Analytics Gateway acts as a forwarding proxy for the AMA. Alternatively, if servers are Arc-enabled, you can configure the Arc agent to use a proxy, allowing management and monitoring traffic to flow through a central exit point.
Incorrect
The Log Analytics Gateway acts as a forwarding proxy for the AMA. Alternatively, if servers are Arc-enabled, you can configure the Arc agent to use a proxy, allowing management and monitoring traffic to flow through a central exit point.
Unattempted
The Log Analytics Gateway acts as a forwarding proxy for the AMA. Alternatively, if servers are Arc-enabled, you can configure the Arc agent to use a proxy, allowing management and monitoring traffic to flow through a central exit point.
Question 28 of 60
28. Question
You are managing an Azure Stack HCI cluster and need to configure ‘Network ATC’ for a ‘Management’ intent. Which physical adapter property is most critical for this intent?
Correct
Network ATC requires that the physical adapters assigned to an intent are consistent across all nodes in the cluster (e.g., same name or same slot) to ensure that the configuration is applied uniformly.
Incorrect
Network ATC requires that the physical adapters assigned to an intent are consistent across all nodes in the cluster (e.g., same name or same slot) to ensure that the configuration is applied uniformly.
Unattempted
Network ATC requires that the physical adapters assigned to an intent are consistent across all nodes in the cluster (e.g., same name or same slot) to ensure that the configuration is applied uniformly.
Question 29 of 60
29. Question
You are configuring Azure Stack HCI. You need to ensure that the storage traffic is isolated and prioritized. Which two networking technologies are required to support RDMA with RoCE v2?
Correct
RoCE v2 requires a ‘lossless’ network. PFC and DCB work together to manage congestion and ensure that RDMA storage traffic is not dropped during periods of high network utilization.
Incorrect
RoCE v2 requires a ‘lossless’ network. PFC and DCB work together to manage congestion and ensure that RDMA storage traffic is not dropped during periods of high network utilization.
Unattempted
RoCE v2 requires a ‘lossless’ network. PFC and DCB work together to manage congestion and ensure that RDMA storage traffic is not dropped during periods of high network utilization.
Question 30 of 60
30. Question
You are implementing Azure AD Application Proxy for an internal IIS-based website. The website uses ‘Header-based’ authentication. Which two components are needed to support this?
Correct
While App Proxy handles the connection, Entra ID (Azure AD) now supports native header-based authentication through specific application configurations, allowing you to map Entra attributes to HTTP headers.
Incorrect
While App Proxy handles the connection, Entra ID (Azure AD) now supports native header-based authentication through specific application configurations, allowing you to map Entra attributes to HTTP headers.
Unattempted
While App Proxy handles the connection, Entra ID (Azure AD) now supports native header-based authentication through specific application configurations, allowing you to map Entra attributes to HTTP headers.
Question 31 of 60
31. Question
Data Deduplication savings rates vary significantly by workload. Which workload type typically achieves the highest deduplication savings ratio?
Correct
Correct :
C. Software library shares containing multiple versions of similar software packages and installers.
Data Deduplication achieves the highest savings on workloads with high redundancy and low change rates, such as software deployment shares (e.g., multiple builds, patches, or ISO files) where identical or near-identical blocks recur across many files. Microsoft documentation specifically cites general-purpose file servers, software build shares, and VDI repositories as optimal candidates, with software libraries often reaching 50–80%+ savings due to block-level chunking and redundancy across versions.
Incorrect :
A. Transaction log files which are unique sequential write files with low redundancy. Incorrect. Transaction logs are append-only, continuously written, and contain largely unique, non-redundant data. They are explicitly not recommended for deduplication because the overhead outweighs savings, and the high churn degrades performance.
B. Video surveillance footage which consists of high-entropy compressed video frames. Incorrect. Video files (e.g., MP4, H.264) are already compressed and contain high entropy with minimal block-level redundancy. Deduplication yields very low or zero savings on such media, and Microsoft advises against enabling it on media workloads.
D. Database data files for active OLTP databases under continuous write load. Incorrect. Active OLTP database files (e.g., SQL Server .mdf/.ndf) experience frequent random writes and page modifications, reducing block stability. Deduplication is not supported or recommended on volumes hosting live databases due to poor savings, high I/O impact, and potential compatibility issues—Microsoft explicitly excludes this as a suitable workload.
Incorrect
Correct :
C. Software library shares containing multiple versions of similar software packages and installers.
Data Deduplication achieves the highest savings on workloads with high redundancy and low change rates, such as software deployment shares (e.g., multiple builds, patches, or ISO files) where identical or near-identical blocks recur across many files. Microsoft documentation specifically cites general-purpose file servers, software build shares, and VDI repositories as optimal candidates, with software libraries often reaching 50–80%+ savings due to block-level chunking and redundancy across versions.
Incorrect :
A. Transaction log files which are unique sequential write files with low redundancy. Incorrect. Transaction logs are append-only, continuously written, and contain largely unique, non-redundant data. They are explicitly not recommended for deduplication because the overhead outweighs savings, and the high churn degrades performance.
B. Video surveillance footage which consists of high-entropy compressed video frames. Incorrect. Video files (e.g., MP4, H.264) are already compressed and contain high entropy with minimal block-level redundancy. Deduplication yields very low or zero savings on such media, and Microsoft advises against enabling it on media workloads.
D. Database data files for active OLTP databases under continuous write load. Incorrect. Active OLTP database files (e.g., SQL Server .mdf/.ndf) experience frequent random writes and page modifications, reducing block stability. Deduplication is not supported or recommended on volumes hosting live databases due to poor savings, high I/O impact, and potential compatibility issues—Microsoft explicitly excludes this as a suitable workload.
Unattempted
Correct :
C. Software library shares containing multiple versions of similar software packages and installers.
Data Deduplication achieves the highest savings on workloads with high redundancy and low change rates, such as software deployment shares (e.g., multiple builds, patches, or ISO files) where identical or near-identical blocks recur across many files. Microsoft documentation specifically cites general-purpose file servers, software build shares, and VDI repositories as optimal candidates, with software libraries often reaching 50–80%+ savings due to block-level chunking and redundancy across versions.
Incorrect :
A. Transaction log files which are unique sequential write files with low redundancy. Incorrect. Transaction logs are append-only, continuously written, and contain largely unique, non-redundant data. They are explicitly not recommended for deduplication because the overhead outweighs savings, and the high churn degrades performance.
B. Video surveillance footage which consists of high-entropy compressed video frames. Incorrect. Video files (e.g., MP4, H.264) are already compressed and contain high entropy with minimal block-level redundancy. Deduplication yields very low or zero savings on such media, and Microsoft advises against enabling it on media workloads.
D. Database data files for active OLTP databases under continuous write load. Incorrect. Active OLTP database files (e.g., SQL Server .mdf/.ndf) experience frequent random writes and page modifications, reducing block stability. Deduplication is not supported or recommended on volumes hosting live databases due to poor savings, high I/O impact, and potential compatibility issues—Microsoft explicitly excludes this as a suitable workload.
Question 32 of 60
32. Question
Azure Monitor can alert on Windows Server application event log entries. Which alert rule type evaluates Windows application event log entries stored in Log Analytics for error events?
Correct
Correct : C. Log search alert rule which runs a KQL query against the Event or SecurityEvent table in Log Analytics and alerts when matching error events are found.
Reference (AZ-802): Log search alert rules are the designated type for querying Log Analytics data (including Event and SecurityEvent tables) using KQL. They evaluate the query results at set intervals and trigger alerts when the number of results meets the defined threshold (e.g., error-level events). This is the only rule type that directly supports custom queries against Windows event log entries stored in Log Analytics.
Incorrect :
A. Smart detection alert which uses ML to automatically detect application failures without a defined query. Incorrect for this scenario. Smart detection (now part of Application Insights) is designed for anomaly detection in application performance telemetry, not for querying static Windows event log entries in Log Analytics. It does not allow you to define a custom query against the Event table for specific error events; it uses ML on aggregated patterns.
B. Activity log alert which triggers on Azure control plane operations. Incorrect. Activity log alerts monitor Azure resource management operations (e.g., VM start/stop, role assignments), not Windows Server application event log data stored in Log Analytics. They are not capable of evaluating log entry contents or error events from guest OS logs.
D. Metric alert which evaluates platform metrics from the server resource. Incorrect. Metric alerts evaluate numerical performance counters (e.g., CPU %, memory, disk IOPS) from Azure platform metrics or guest OS performance metrics, not textual application event log entries. They cannot query the Event table or detect error-level log entries.
Incorrect
Correct : C. Log search alert rule which runs a KQL query against the Event or SecurityEvent table in Log Analytics and alerts when matching error events are found.
Reference (AZ-802): Log search alert rules are the designated type for querying Log Analytics data (including Event and SecurityEvent tables) using KQL. They evaluate the query results at set intervals and trigger alerts when the number of results meets the defined threshold (e.g., error-level events). This is the only rule type that directly supports custom queries against Windows event log entries stored in Log Analytics.
Incorrect :
A. Smart detection alert which uses ML to automatically detect application failures without a defined query. Incorrect for this scenario. Smart detection (now part of Application Insights) is designed for anomaly detection in application performance telemetry, not for querying static Windows event log entries in Log Analytics. It does not allow you to define a custom query against the Event table for specific error events; it uses ML on aggregated patterns.
B. Activity log alert which triggers on Azure control plane operations. Incorrect. Activity log alerts monitor Azure resource management operations (e.g., VM start/stop, role assignments), not Windows Server application event log data stored in Log Analytics. They are not capable of evaluating log entry contents or error events from guest OS logs.
D. Metric alert which evaluates platform metrics from the server resource. Incorrect. Metric alerts evaluate numerical performance counters (e.g., CPU %, memory, disk IOPS) from Azure platform metrics or guest OS performance metrics, not textual application event log entries. They cannot query the Event table or detect error-level log entries.
Unattempted
Correct : C. Log search alert rule which runs a KQL query against the Event or SecurityEvent table in Log Analytics and alerts when matching error events are found.
Reference (AZ-802): Log search alert rules are the designated type for querying Log Analytics data (including Event and SecurityEvent tables) using KQL. They evaluate the query results at set intervals and trigger alerts when the number of results meets the defined threshold (e.g., error-level events). This is the only rule type that directly supports custom queries against Windows event log entries stored in Log Analytics.
Incorrect :
A. Smart detection alert which uses ML to automatically detect application failures without a defined query. Incorrect for this scenario. Smart detection (now part of Application Insights) is designed for anomaly detection in application performance telemetry, not for querying static Windows event log entries in Log Analytics. It does not allow you to define a custom query against the Event table for specific error events; it uses ML on aggregated patterns.
B. Activity log alert which triggers on Azure control plane operations. Incorrect. Activity log alerts monitor Azure resource management operations (e.g., VM start/stop, role assignments), not Windows Server application event log data stored in Log Analytics. They are not capable of evaluating log entry contents or error events from guest OS logs.
D. Metric alert which evaluates platform metrics from the server resource. Incorrect. Metric alerts evaluate numerical performance counters (e.g., CPU %, memory, disk IOPS) from Azure platform metrics or guest OS performance metrics, not textual application event log entries. They cannot query the Event table or detect error-level log entries.
Question 33 of 60
33. Question
BranchCache reduces WAN bandwidth consumption for branch office clients. Which BranchCache mode stores cached content on a dedicated server in the branch office rather than on individual client machines?
Correct
Correct Option D. Hosted Cache mode where a dedicated server in the branch office stores cached content on behalf of all branch clients.
This is the correct answer because Hosted Cache mode specifically uses a designated Hosted Cache Server located in the branch office to store and serve cached content to all BranchCache-enabled clients in that location. Instead of clients retrieving content from each other or from the WAN, they request content from the local Hosted Cache Server, which significantly reduces WAN bandwidth consumption. This mode is ideal for larger branch offices that have a Windows Server available to dedicate to this role.
Incorrect Options A. Centralised Cache mode where a single head office server caches content for all branch offices simultaneously.
This option is incorrect because “Centralised Cache mode” is not a valid BranchCache mode. BranchCache has only two operating modes: Distributed Cache mode and Hosted Cache mode. Additionally, the scenario describes caching at the head office rather than at the branch office, which would not reduce WAN bandwidth for branch clients accessing content—they would still need to traverse the WAN to reach the central cache.
B. Split Cache mode where content is split between clients and a dedicated server.
This option is incorrect because “Split Cache mode” is not a recognized BranchCache mode. This appears to be a fabricated term. BranchCache does not offer a hybrid mode that splits caching between clients and servers in the manner described. You must choose either Distributed Cache mode (peer-to-peer among clients) or Hosted Cache mode (dedicated server).
C. Distributed Cache mode where each client stores a portion of the cached content it has requested.
This option is incorrect because, while the description accurately describes how Distributed Cache mode works, it does not match the question’s requirement of using “a dedicated server in the branch office.” In Distributed Cache mode, there is no designated server—each client stores its own cached content and shares it peer-to-peer with other clients on the same subnet. This mode is suitable for smaller branch offices without a local server, but it does not meet the scenario’s requirement for a dedicated caching server.
Incorrect
Correct Option D. Hosted Cache mode where a dedicated server in the branch office stores cached content on behalf of all branch clients.
This is the correct answer because Hosted Cache mode specifically uses a designated Hosted Cache Server located in the branch office to store and serve cached content to all BranchCache-enabled clients in that location. Instead of clients retrieving content from each other or from the WAN, they request content from the local Hosted Cache Server, which significantly reduces WAN bandwidth consumption. This mode is ideal for larger branch offices that have a Windows Server available to dedicate to this role.
Incorrect Options A. Centralised Cache mode where a single head office server caches content for all branch offices simultaneously.
This option is incorrect because “Centralised Cache mode” is not a valid BranchCache mode. BranchCache has only two operating modes: Distributed Cache mode and Hosted Cache mode. Additionally, the scenario describes caching at the head office rather than at the branch office, which would not reduce WAN bandwidth for branch clients accessing content—they would still need to traverse the WAN to reach the central cache.
B. Split Cache mode where content is split between clients and a dedicated server.
This option is incorrect because “Split Cache mode” is not a recognized BranchCache mode. This appears to be a fabricated term. BranchCache does not offer a hybrid mode that splits caching between clients and servers in the manner described. You must choose either Distributed Cache mode (peer-to-peer among clients) or Hosted Cache mode (dedicated server).
C. Distributed Cache mode where each client stores a portion of the cached content it has requested.
This option is incorrect because, while the description accurately describes how Distributed Cache mode works, it does not match the question’s requirement of using “a dedicated server in the branch office.” In Distributed Cache mode, there is no designated server—each client stores its own cached content and shares it peer-to-peer with other clients on the same subnet. This mode is suitable for smaller branch offices without a local server, but it does not meet the scenario’s requirement for a dedicated caching server.
Unattempted
Correct Option D. Hosted Cache mode where a dedicated server in the branch office stores cached content on behalf of all branch clients.
This is the correct answer because Hosted Cache mode specifically uses a designated Hosted Cache Server located in the branch office to store and serve cached content to all BranchCache-enabled clients in that location. Instead of clients retrieving content from each other or from the WAN, they request content from the local Hosted Cache Server, which significantly reduces WAN bandwidth consumption. This mode is ideal for larger branch offices that have a Windows Server available to dedicate to this role.
Incorrect Options A. Centralised Cache mode where a single head office server caches content for all branch offices simultaneously.
This option is incorrect because “Centralised Cache mode” is not a valid BranchCache mode. BranchCache has only two operating modes: Distributed Cache mode and Hosted Cache mode. Additionally, the scenario describes caching at the head office rather than at the branch office, which would not reduce WAN bandwidth for branch clients accessing content—they would still need to traverse the WAN to reach the central cache.
B. Split Cache mode where content is split between clients and a dedicated server.
This option is incorrect because “Split Cache mode” is not a recognized BranchCache mode. This appears to be a fabricated term. BranchCache does not offer a hybrid mode that splits caching between clients and servers in the manner described. You must choose either Distributed Cache mode (peer-to-peer among clients) or Hosted Cache mode (dedicated server).
C. Distributed Cache mode where each client stores a portion of the cached content it has requested.
This option is incorrect because, while the description accurately describes how Distributed Cache mode works, it does not match the question’s requirement of using “a dedicated server in the branch office.” In Distributed Cache mode, there is no designated server—each client stores its own cached content and shares it peer-to-peer with other clients on the same subnet. This mode is suitable for smaller branch offices without a local server, but it does not meet the scenario’s requirement for a dedicated caching server.
Question 34 of 60
34. Question
OpenSSH server is included as a built-in optional feature in Windows Server 2025. What management benefit does SSH access provide compared to WinRM-based PowerShell Remoting?
Correct
OpenSSH on Windows Server allows administrators to establish secure, cross-platform terminal sessions. While WinRM relies on WS-Management and complex authentication protocols (WS-Man/Kerberos/NTLM) native to Windows environments, SSH is a ubiquitous industry standard supported by virtually all operating systems.
Therefore, Option C is the correct answer.
Details:
Option A is incorrect: WinRM uses HTTPS (port 5986) with SSL/TLS for encrypted sessions or encrypts HTTP (port 5985) traffic at the protocol level using Kerberos/NTLM authentication. WinRM is not unencrypted by default, so SSH does not inherit a inherent cryptographic advantage over properly configured WinRM.
Option B is incorrect: While X11 forwarding is a feature of the SSH protocol in Unix/Linux environments, Windows Server administration via OpenSSH is intended for command-line management (PowerShell or Command Prompt). It is not designed or supported as a replacement for remote GUI server administration (like Remote Desktop Services).
Option C is correct: OpenSSH provides a universal, platform-agnostic management pipeline. System administrators on Linux, macOS, or non-Windows devices can execute remote PowerShell sessions and commands natively via SSH without configuring complex WinRM authentication mechanisms or installing Windows-specific client utilities.
Option D is incorrect: Both protocols require specific inbound firewall ports to be open (TCP port 22 for SSH; TCP ports 5985/5986 for WinRM). Neither protocol requires opening all ports.
Incorrect
OpenSSH on Windows Server allows administrators to establish secure, cross-platform terminal sessions. While WinRM relies on WS-Management and complex authentication protocols (WS-Man/Kerberos/NTLM) native to Windows environments, SSH is a ubiquitous industry standard supported by virtually all operating systems.
Therefore, Option C is the correct answer.
Details:
Option A is incorrect: WinRM uses HTTPS (port 5986) with SSL/TLS for encrypted sessions or encrypts HTTP (port 5985) traffic at the protocol level using Kerberos/NTLM authentication. WinRM is not unencrypted by default, so SSH does not inherit a inherent cryptographic advantage over properly configured WinRM.
Option B is incorrect: While X11 forwarding is a feature of the SSH protocol in Unix/Linux environments, Windows Server administration via OpenSSH is intended for command-line management (PowerShell or Command Prompt). It is not designed or supported as a replacement for remote GUI server administration (like Remote Desktop Services).
Option C is correct: OpenSSH provides a universal, platform-agnostic management pipeline. System administrators on Linux, macOS, or non-Windows devices can execute remote PowerShell sessions and commands natively via SSH without configuring complex WinRM authentication mechanisms or installing Windows-specific client utilities.
Option D is incorrect: Both protocols require specific inbound firewall ports to be open (TCP port 22 for SSH; TCP ports 5985/5986 for WinRM). Neither protocol requires opening all ports.
Unattempted
OpenSSH on Windows Server allows administrators to establish secure, cross-platform terminal sessions. While WinRM relies on WS-Management and complex authentication protocols (WS-Man/Kerberos/NTLM) native to Windows environments, SSH is a ubiquitous industry standard supported by virtually all operating systems.
Therefore, Option C is the correct answer.
Details:
Option A is incorrect: WinRM uses HTTPS (port 5986) with SSL/TLS for encrypted sessions or encrypts HTTP (port 5985) traffic at the protocol level using Kerberos/NTLM authentication. WinRM is not unencrypted by default, so SSH does not inherit a inherent cryptographic advantage over properly configured WinRM.
Option B is incorrect: While X11 forwarding is a feature of the SSH protocol in Unix/Linux environments, Windows Server administration via OpenSSH is intended for command-line management (PowerShell or Command Prompt). It is not designed or supported as a replacement for remote GUI server administration (like Remote Desktop Services).
Option C is correct: OpenSSH provides a universal, platform-agnostic management pipeline. System administrators on Linux, macOS, or non-Windows devices can execute remote PowerShell sessions and commands natively via SSH without configuring complex WinRM authentication mechanisms or installing Windows-specific client utilities.
Option D is incorrect: Both protocols require specific inbound firewall ports to be open (TCP port 22 for SSH; TCP ports 5985/5986 for WinRM). Neither protocol requires opening all ports.
Question 35 of 60
35. Question
The Server service (LanmanServer) on Windows Server handles SMB file sharing. What is the impact of stopping the Server service on a file server with active client connections?
Correct
A. The Server service cannot be stopped while client connections are active and returns an access denied error
Incorrect.
The Server service can be stopped manually or via automation even if client connections are active.
Windows does not block the stop operation with an “access denied” error.
B. Active sessions are transferred to a secondary file server if DFS replication is configured
Incorrect.
DFS Replication synchronizes data between servers but does not provide live session failover.
Active SMB sessions are not automatically redirected to another server when LanmanServer stops.
C. Active SMB sessions are immediately disconnected and open file handles are closed, causing data loss for clients with unsaved work
Correct.
Stopping the Server service (LanmanServer) terminates all active SMB connections.
Open file handles are closed abruptly, which can cause data loss if clients have unsaved work.
Certification guidance emphasizes that administrators must plan carefully before stopping this service on production file servers.
D. Active connections are gracefully drained over 30 minutes before the service stops
Incorrect.
There is no built?in “graceful drain” mechanism for LanmanServer.
Connections are terminated immediately when the service stops.
Incorrect
A. The Server service cannot be stopped while client connections are active and returns an access denied error
Incorrect.
The Server service can be stopped manually or via automation even if client connections are active.
Windows does not block the stop operation with an “access denied” error.
B. Active sessions are transferred to a secondary file server if DFS replication is configured
Incorrect.
DFS Replication synchronizes data between servers but does not provide live session failover.
Active SMB sessions are not automatically redirected to another server when LanmanServer stops.
C. Active SMB sessions are immediately disconnected and open file handles are closed, causing data loss for clients with unsaved work
Correct.
Stopping the Server service (LanmanServer) terminates all active SMB connections.
Open file handles are closed abruptly, which can cause data loss if clients have unsaved work.
Certification guidance emphasizes that administrators must plan carefully before stopping this service on production file servers.
D. Active connections are gracefully drained over 30 minutes before the service stops
Incorrect.
There is no built?in “graceful drain” mechanism for LanmanServer.
Connections are terminated immediately when the service stops.
Unattempted
A. The Server service cannot be stopped while client connections are active and returns an access denied error
Incorrect.
The Server service can be stopped manually or via automation even if client connections are active.
Windows does not block the stop operation with an “access denied” error.
B. Active sessions are transferred to a secondary file server if DFS replication is configured
Incorrect.
DFS Replication synchronizes data between servers but does not provide live session failover.
Active SMB sessions are not automatically redirected to another server when LanmanServer stops.
C. Active SMB sessions are immediately disconnected and open file handles are closed, causing data loss for clients with unsaved work
Correct.
Stopping the Server service (LanmanServer) terminates all active SMB connections.
Open file handles are closed abruptly, which can cause data loss if clients have unsaved work.
Certification guidance emphasizes that administrators must plan carefully before stopping this service on production file servers.
D. Active connections are gracefully drained over 30 minutes before the service stops
Incorrect.
There is no built?in “graceful drain” mechanism for LanmanServer.
Connections are terminated immediately when the service stops.
Question 36 of 60
36. Question
Log Analytics workspace pricing changed from per-node to per-GB. What does the Commitment Tier pricing model offer compared to Pay-As-You-Go?
Correct
Correct Answer: D
D. Commitment Tier provides a discounted per-GB rate compared to Pay-As-You-Go for customers who commit to a minimum monthly data ingestion volume.
Correct. In Azure Monitor Log Analytics, Commitment Tiers (formerly called Dedicated Tiers) allow organizations to commit to a baseline daily data ingestion volume (starting at 100 GB/day). In exchange for committing to a fixed minimum daily intake, Microsoft provides a discounted effective per-gigabyte ingestion rate compared to standard Pay-As-You-Go pricing.
Incorrect :
A. Commitment Tier eliminates export costs when sending data from Log Analytics to Azure Storage.
Incorrect. Commitment Tiers apply directly to the cost of data ingestion into the Log Analytics workspace. They do not alter or remove egress fees or data export charges for streaming or exporting log data out to Azure Storage accounts or Event Hubs.
B. Commitment Tier provides unlimited data ingestion for a fixed monthly fee per workspace.
Incorrect. Commitment Tiers are not uncapped or unlimited plans. You commit to a baseline volume (e.g., 100 GB/day), and any data ingested beyond your selected tier level is billed at a discounted overage rate per GB, not covered under a flat unlimited fee.
C. Commitment Tier requires pre-purchasing dedicated server capacity in Azure.
Incorrect. Commitment Tiers in Log Analytics are purely financial commitment models based on daily data ingestion volumes. They do not require provisioning, reserving, or pre-purchasing dedicated server compute infrastructure within Azure.
Incorrect
Correct Answer: D
D. Commitment Tier provides a discounted per-GB rate compared to Pay-As-You-Go for customers who commit to a minimum monthly data ingestion volume.
Correct. In Azure Monitor Log Analytics, Commitment Tiers (formerly called Dedicated Tiers) allow organizations to commit to a baseline daily data ingestion volume (starting at 100 GB/day). In exchange for committing to a fixed minimum daily intake, Microsoft provides a discounted effective per-gigabyte ingestion rate compared to standard Pay-As-You-Go pricing.
Incorrect :
A. Commitment Tier eliminates export costs when sending data from Log Analytics to Azure Storage.
Incorrect. Commitment Tiers apply directly to the cost of data ingestion into the Log Analytics workspace. They do not alter or remove egress fees or data export charges for streaming or exporting log data out to Azure Storage accounts or Event Hubs.
B. Commitment Tier provides unlimited data ingestion for a fixed monthly fee per workspace.
Incorrect. Commitment Tiers are not uncapped or unlimited plans. You commit to a baseline volume (e.g., 100 GB/day), and any data ingested beyond your selected tier level is billed at a discounted overage rate per GB, not covered under a flat unlimited fee.
C. Commitment Tier requires pre-purchasing dedicated server capacity in Azure.
Incorrect. Commitment Tiers in Log Analytics are purely financial commitment models based on daily data ingestion volumes. They do not require provisioning, reserving, or pre-purchasing dedicated server compute infrastructure within Azure.
Unattempted
Correct Answer: D
D. Commitment Tier provides a discounted per-GB rate compared to Pay-As-You-Go for customers who commit to a minimum monthly data ingestion volume.
Correct. In Azure Monitor Log Analytics, Commitment Tiers (formerly called Dedicated Tiers) allow organizations to commit to a baseline daily data ingestion volume (starting at 100 GB/day). In exchange for committing to a fixed minimum daily intake, Microsoft provides a discounted effective per-gigabyte ingestion rate compared to standard Pay-As-You-Go pricing.
Incorrect :
A. Commitment Tier eliminates export costs when sending data from Log Analytics to Azure Storage.
Incorrect. Commitment Tiers apply directly to the cost of data ingestion into the Log Analytics workspace. They do not alter or remove egress fees or data export charges for streaming or exporting log data out to Azure Storage accounts or Event Hubs.
B. Commitment Tier provides unlimited data ingestion for a fixed monthly fee per workspace.
Incorrect. Commitment Tiers are not uncapped or unlimited plans. You commit to a baseline volume (e.g., 100 GB/day), and any data ingested beyond your selected tier level is billed at a discounted overage rate per GB, not covered under a flat unlimited fee.
C. Commitment Tier requires pre-purchasing dedicated server capacity in Azure.
Incorrect. Commitment Tiers in Log Analytics are purely financial commitment models based on daily data ingestion volumes. They do not require provisioning, reserving, or pre-purchasing dedicated server compute infrastructure within Azure.
Question 37 of 60
37. Question
Windows Server includes Controlled Folder Access as a ransomware protection feature. What does it do?
Correct
Correct Option: C. It prevents untrusted processes from reading or writing files in protected folders, blocking ransomware from encrypting those files.
Reference (AZ-802): Controlled Folder Access is a Windows Defender Exploit Guard feature that allows only trusted applications to access specified protected folders. It blocks unauthorized or untrusted processes (including ransomware) from making changes to files in those folders, effectively preventing encryption attacks.
Incorrect Options & Explanations:
A. It restricts which users can access shared folders based on Active Directory group membership. Incorrect. This describes standard NTFS or Share permissions (access-based enumeration or ACLs), not Controlled Folder Access. Controlled Folder Access is process-based, not user-based, and applies to local folders, not network shares.
Incorrect
Correct Option: C. It prevents untrusted processes from reading or writing files in protected folders, blocking ransomware from encrypting those files.
Reference (AZ-802): Controlled Folder Access is a Windows Defender Exploit Guard feature that allows only trusted applications to access specified protected folders. It blocks unauthorized or untrusted processes (including ransomware) from making changes to files in those folders, effectively preventing encryption attacks.
Incorrect Options & Explanations:
A. It restricts which users can access shared folders based on Active Directory group membership. Incorrect. This describes standard NTFS or Share permissions (access-based enumeration or ACLs), not Controlled Folder Access. Controlled Folder Access is process-based, not user-based, and applies to local folders, not network shares.
Unattempted
Correct Option: C. It prevents untrusted processes from reading or writing files in protected folders, blocking ransomware from encrypting those files.
Reference (AZ-802): Controlled Folder Access is a Windows Defender Exploit Guard feature that allows only trusted applications to access specified protected folders. It blocks unauthorized or untrusted processes (including ransomware) from making changes to files in those folders, effectively preventing encryption attacks.
Incorrect Options & Explanations:
A. It restricts which users can access shared folders based on Active Directory group membership. Incorrect. This describes standard NTFS or Share permissions (access-based enumeration or ACLs), not Controlled Folder Access. Controlled Folder Access is process-based, not user-based, and applies to local folders, not network shares.
Question 38 of 60
38. Question
The Azure Connected Machine agent installed on Arc-enabled servers regularly communicates with Azure. What is the recommended network architecture for servers that must not have direct internet access?
Correct
Deploying an Azure Arc Private Link Scope (AAPLS) allows the Azure Connected Machine agent to communicate with Azure Arc control plane management endpoints via a Private Endpoint inside an Azure Virtual Network (VNet). This ensures all traffic travels over private IP routes (such as an ExpressRoute or Site-to-Site VPN) directly into the VNet, preventing the agent from needing direct internet egress.
Therefore, Option C is the correct answer.
Detailed Breakdown of Options
Option A is incorrect: Restricting Windows Firewall to HTTPS traffic still requires outbound routing to public Azure IP addresses across the public internet, failing the requirement for isolated, zero-direct-internet servers.
Option B is incorrect: Attaching a secondary network interface connected to the internet breaches network isolation policies and exposes the server directly to external threats. Azure Arc provides secure enterprise architecture options specifically to avoid exposing servers to public networks.
Option C is correct: Azure Arc Private Link Scope (AAPLS) links your Arc-enabled servers to a private endpoint within your VNet. All authentication, metadata, and agent telemetry are routed privately through the corporate network (VPN/ExpressRoute) to the Azure Private Endpoint instead of traversing public endpoints.
Option D is incorrect: Using ExpressRoute alone (via Microsoft Peering) routes traffic to public endpoints rather than private IP space. To ensure traffic stays completely on private IPs and avoids public internet routes, ExpressRoute must be combined with an Azure Arc Private Link Scope.
Incorrect
Deploying an Azure Arc Private Link Scope (AAPLS) allows the Azure Connected Machine agent to communicate with Azure Arc control plane management endpoints via a Private Endpoint inside an Azure Virtual Network (VNet). This ensures all traffic travels over private IP routes (such as an ExpressRoute or Site-to-Site VPN) directly into the VNet, preventing the agent from needing direct internet egress.
Therefore, Option C is the correct answer.
Detailed Breakdown of Options
Option A is incorrect: Restricting Windows Firewall to HTTPS traffic still requires outbound routing to public Azure IP addresses across the public internet, failing the requirement for isolated, zero-direct-internet servers.
Option B is incorrect: Attaching a secondary network interface connected to the internet breaches network isolation policies and exposes the server directly to external threats. Azure Arc provides secure enterprise architecture options specifically to avoid exposing servers to public networks.
Option C is correct: Azure Arc Private Link Scope (AAPLS) links your Arc-enabled servers to a private endpoint within your VNet. All authentication, metadata, and agent telemetry are routed privately through the corporate network (VPN/ExpressRoute) to the Azure Private Endpoint instead of traversing public endpoints.
Option D is incorrect: Using ExpressRoute alone (via Microsoft Peering) routes traffic to public endpoints rather than private IP space. To ensure traffic stays completely on private IPs and avoids public internet routes, ExpressRoute must be combined with an Azure Arc Private Link Scope.
Unattempted
Deploying an Azure Arc Private Link Scope (AAPLS) allows the Azure Connected Machine agent to communicate with Azure Arc control plane management endpoints via a Private Endpoint inside an Azure Virtual Network (VNet). This ensures all traffic travels over private IP routes (such as an ExpressRoute or Site-to-Site VPN) directly into the VNet, preventing the agent from needing direct internet egress.
Therefore, Option C is the correct answer.
Detailed Breakdown of Options
Option A is incorrect: Restricting Windows Firewall to HTTPS traffic still requires outbound routing to public Azure IP addresses across the public internet, failing the requirement for isolated, zero-direct-internet servers.
Option B is incorrect: Attaching a secondary network interface connected to the internet breaches network isolation policies and exposes the server directly to external threats. Azure Arc provides secure enterprise architecture options specifically to avoid exposing servers to public networks.
Option C is correct: Azure Arc Private Link Scope (AAPLS) links your Arc-enabled servers to a private endpoint within your VNet. All authentication, metadata, and agent telemetry are routed privately through the corporate network (VPN/ExpressRoute) to the Azure Private Endpoint instead of traversing public endpoints.
Option D is incorrect: Using ExpressRoute alone (via Microsoft Peering) routes traffic to public endpoints rather than private IP space. To ensure traffic stays completely on private IPs and avoids public internet routes, ExpressRoute must be combined with an Azure Arc Private Link Scope.
Question 39 of 60
39. Question
Azure Disaster Recovery test failover allows validating recovery plans without impacting production replication. What happens to the replicated VM during a test failover?
Correct
A. Test failover requires manually stopping the source VM to ensure a consistent recovery point for the test
Incorrect.
Test failover does not require shutting down the source VM.
Replication continues from the source VM to Azure during the test, ensuring production workloads remain unaffected.
B. The replicated VM is permanently failed over to Azure and a new replication baseline is established
Incorrect.
Permanent failover is a different operation.
Test failover is temporary and does not reset replication baselines or permanently move workloads.
C. A separate test VM is created in Azure from the replicated data while the original replication continues uninterrupted, allowing validation of the recovery environment
Correct.
Test failover spins up a temporary test VM in Azure using replicated data.
The original replication continues without interruption, so production workloads are not impacted.
Certification highlights this as the safe way to validate recovery plans.
D. The replicated VM is started in Azure and replication to the vault is paused until the test is cleaned
Incorrect.
Replication is not paused during test failover.
The source VM continues replicating to Azure, ensuring continuity of protection.
Incorrect
A. Test failover requires manually stopping the source VM to ensure a consistent recovery point for the test
Incorrect.
Test failover does not require shutting down the source VM.
Replication continues from the source VM to Azure during the test, ensuring production workloads remain unaffected.
B. The replicated VM is permanently failed over to Azure and a new replication baseline is established
Incorrect.
Permanent failover is a different operation.
Test failover is temporary and does not reset replication baselines or permanently move workloads.
C. A separate test VM is created in Azure from the replicated data while the original replication continues uninterrupted, allowing validation of the recovery environment
Correct.
Test failover spins up a temporary test VM in Azure using replicated data.
The original replication continues without interruption, so production workloads are not impacted.
Certification highlights this as the safe way to validate recovery plans.
D. The replicated VM is started in Azure and replication to the vault is paused until the test is cleaned
Incorrect.
Replication is not paused during test failover.
The source VM continues replicating to Azure, ensuring continuity of protection.
Unattempted
A. Test failover requires manually stopping the source VM to ensure a consistent recovery point for the test
Incorrect.
Test failover does not require shutting down the source VM.
Replication continues from the source VM to Azure during the test, ensuring production workloads remain unaffected.
B. The replicated VM is permanently failed over to Azure and a new replication baseline is established
Incorrect.
Permanent failover is a different operation.
Test failover is temporary and does not reset replication baselines or permanently move workloads.
C. A separate test VM is created in Azure from the replicated data while the original replication continues uninterrupted, allowing validation of the recovery environment
Correct.
Test failover spins up a temporary test VM in Azure using replicated data.
The original replication continues without interruption, so production workloads are not impacted.
Certification highlights this as the safe way to validate recovery plans.
D. The replicated VM is started in Azure and replication to the vault is paused until the test is cleaned
Incorrect.
Replication is not paused during test failover.
The source VM continues replicating to Azure, ensuring continuity of protection.
Question 40 of 60
40. Question
Locating stale Active Directory user accounts that have not logged on in 90 days requires which PowerShell approach?
Correct
Correct Answer: C
C. Get-ADUser -Filter {LastLogonDate -lt (Get-Date).AddDays(-90)} -Properties LastLogonDate which returns users whose last logon was more than 90 days ago.
Correct. LastLogonDate (the human-readable, replicated PowerShell property calculated from lastLogonTimestamp) reflects an account’s last authentication across domain controllers. Filtering for accounts where LastLogonDate is less than (older than) 90 days prior to the current date accurately identifies users who have not logged on in the past 90 days. Note that -Properties LastLogonDate must be passed so the cmdlet retrieves this extended attribute.
Incorrect Options:
A. Get-ADUser -Filter {Enabled -eq $true} | Select-Object -Last 90 which selects the last 90 enabled users.
Incorrect. Select-Object -Last 90 simply selects the final 90 objects returned in the pipeline sequence. It evaluates no date criteria, logon timestamps, or account activity.
B. Get-ADUser -Filter * | Where-Object {$_.Created -lt (Get-Date).AddDays(-90)} which returns users created more than 90 days.
Incorrect. Checking the Created property only determines when the account object was created in Active Directory. An account created 90+ days ago could still be actively logged into every day.
D. Search-ADAccount -AccountInactive -TimeSpan 90.00:00:00 which searches specifically for inactive accounts.
Incorrect. While Search-ADAccount -AccountInactive is a valid Active Directory cmdlet for finding inactive accounts, the syntax specified in this option is invalid for this query. To pass a 90-day duration via -TimeSpan, standard System.TimeSpan formatting or a [TimeSpan] object (such as (New-TimeSpan -Days 90)) is required. Additionally, option C directly demonstrates querying and filtering the specific user logon property.
Incorrect
Correct Answer: C
C. Get-ADUser -Filter {LastLogonDate -lt (Get-Date).AddDays(-90)} -Properties LastLogonDate which returns users whose last logon was more than 90 days ago.
Correct. LastLogonDate (the human-readable, replicated PowerShell property calculated from lastLogonTimestamp) reflects an account’s last authentication across domain controllers. Filtering for accounts where LastLogonDate is less than (older than) 90 days prior to the current date accurately identifies users who have not logged on in the past 90 days. Note that -Properties LastLogonDate must be passed so the cmdlet retrieves this extended attribute.
Incorrect Options:
A. Get-ADUser -Filter {Enabled -eq $true} | Select-Object -Last 90 which selects the last 90 enabled users.
Incorrect. Select-Object -Last 90 simply selects the final 90 objects returned in the pipeline sequence. It evaluates no date criteria, logon timestamps, or account activity.
B. Get-ADUser -Filter * | Where-Object {$_.Created -lt (Get-Date).AddDays(-90)} which returns users created more than 90 days.
Incorrect. Checking the Created property only determines when the account object was created in Active Directory. An account created 90+ days ago could still be actively logged into every day.
D. Search-ADAccount -AccountInactive -TimeSpan 90.00:00:00 which searches specifically for inactive accounts.
Incorrect. While Search-ADAccount -AccountInactive is a valid Active Directory cmdlet for finding inactive accounts, the syntax specified in this option is invalid for this query. To pass a 90-day duration via -TimeSpan, standard System.TimeSpan formatting or a [TimeSpan] object (such as (New-TimeSpan -Days 90)) is required. Additionally, option C directly demonstrates querying and filtering the specific user logon property.
Unattempted
Correct Answer: C
C. Get-ADUser -Filter {LastLogonDate -lt (Get-Date).AddDays(-90)} -Properties LastLogonDate which returns users whose last logon was more than 90 days ago.
Correct. LastLogonDate (the human-readable, replicated PowerShell property calculated from lastLogonTimestamp) reflects an account’s last authentication across domain controllers. Filtering for accounts where LastLogonDate is less than (older than) 90 days prior to the current date accurately identifies users who have not logged on in the past 90 days. Note that -Properties LastLogonDate must be passed so the cmdlet retrieves this extended attribute.
Incorrect Options:
A. Get-ADUser -Filter {Enabled -eq $true} | Select-Object -Last 90 which selects the last 90 enabled users.
Incorrect. Select-Object -Last 90 simply selects the final 90 objects returned in the pipeline sequence. It evaluates no date criteria, logon timestamps, or account activity.
B. Get-ADUser -Filter * | Where-Object {$_.Created -lt (Get-Date).AddDays(-90)} which returns users created more than 90 days.
Incorrect. Checking the Created property only determines when the account object was created in Active Directory. An account created 90+ days ago could still be actively logged into every day.
D. Search-ADAccount -AccountInactive -TimeSpan 90.00:00:00 which searches specifically for inactive accounts.
Incorrect. While Search-ADAccount -AccountInactive is a valid Active Directory cmdlet for finding inactive accounts, the syntax specified in this option is invalid for this query. To pass a 90-day duration via -TimeSpan, standard System.TimeSpan formatting or a [TimeSpan] object (such as (New-TimeSpan -Days 90)) is required. Additionally, option C directly demonstrates querying and filtering the specific user logon property.
Question 41 of 60
41. Question
Azure Arc and Windows Admin Center integration allows managing on-premises servers from the Azure portal. What is the role of the Windows Admin Center in Azure when using this integration?
Correct
Integrating Windows Admin Center (WAC) with Azure Arc allows administrators to access the full suit of Windows Admin Center management tools directly inside the Azure portal. The Azure Arc agent establishes a secure, outbound reverse proxy connection back to Azure. This connection enables full administrative access to local Windows Server OS features (such as Event Viewer, Device Manager, PowerShell, and Performance Monitor) without opening inbound firewall ports or configuring VPNs/public IPs.
Therefore, Option C is the correct answer.
Details:
Option A is incorrect: While Remote Desktop (RDP) functionality can be accessed via Windows Admin Center, WAC itself is not primarily a remote desktop server/session host. Its role in Azure is to provide broad OS-level management tools, performance monitoring, and configuration capabilities via the web-based gateway interface.
Option B is incorrect: Windows Admin Center in the Azure portal does not replace the Azure Portal; rather, it is embedded within the Azure Portal as an extension. Azure Portal handles resource management, identity, and governance, while the embedded WAC extension handles local in-guest Windows Server administration.
Option C is correct: The Windows Admin Center integration acts as an outbound gateway through the Azure Arc Connected Machine agent infrastructure. It provides administrators with standard WAC features directly within the Azure portal, bypassing the need for public IPs, VPN tunnels, or inbound firewall port rules.
Option D is incorrect: Windows Admin Center is a server management and monitoring tool, not a backup service. Dedicated solutions such as Azure Backup or Azure Arc-enabled Backup integration handle cloud backups to Azure Blob Storage.
Incorrect
Integrating Windows Admin Center (WAC) with Azure Arc allows administrators to access the full suit of Windows Admin Center management tools directly inside the Azure portal. The Azure Arc agent establishes a secure, outbound reverse proxy connection back to Azure. This connection enables full administrative access to local Windows Server OS features (such as Event Viewer, Device Manager, PowerShell, and Performance Monitor) without opening inbound firewall ports or configuring VPNs/public IPs.
Therefore, Option C is the correct answer.
Details:
Option A is incorrect: While Remote Desktop (RDP) functionality can be accessed via Windows Admin Center, WAC itself is not primarily a remote desktop server/session host. Its role in Azure is to provide broad OS-level management tools, performance monitoring, and configuration capabilities via the web-based gateway interface.
Option B is incorrect: Windows Admin Center in the Azure portal does not replace the Azure Portal; rather, it is embedded within the Azure Portal as an extension. Azure Portal handles resource management, identity, and governance, while the embedded WAC extension handles local in-guest Windows Server administration.
Option C is correct: The Windows Admin Center integration acts as an outbound gateway through the Azure Arc Connected Machine agent infrastructure. It provides administrators with standard WAC features directly within the Azure portal, bypassing the need for public IPs, VPN tunnels, or inbound firewall port rules.
Option D is incorrect: Windows Admin Center is a server management and monitoring tool, not a backup service. Dedicated solutions such as Azure Backup or Azure Arc-enabled Backup integration handle cloud backups to Azure Blob Storage.
Unattempted
Integrating Windows Admin Center (WAC) with Azure Arc allows administrators to access the full suit of Windows Admin Center management tools directly inside the Azure portal. The Azure Arc agent establishes a secure, outbound reverse proxy connection back to Azure. This connection enables full administrative access to local Windows Server OS features (such as Event Viewer, Device Manager, PowerShell, and Performance Monitor) without opening inbound firewall ports or configuring VPNs/public IPs.
Therefore, Option C is the correct answer.
Details:
Option A is incorrect: While Remote Desktop (RDP) functionality can be accessed via Windows Admin Center, WAC itself is not primarily a remote desktop server/session host. Its role in Azure is to provide broad OS-level management tools, performance monitoring, and configuration capabilities via the web-based gateway interface.
Option B is incorrect: Windows Admin Center in the Azure portal does not replace the Azure Portal; rather, it is embedded within the Azure Portal as an extension. Azure Portal handles resource management, identity, and governance, while the embedded WAC extension handles local in-guest Windows Server administration.
Option C is correct: The Windows Admin Center integration acts as an outbound gateway through the Azure Arc Connected Machine agent infrastructure. It provides administrators with standard WAC features directly within the Azure portal, bypassing the need for public IPs, VPN tunnels, or inbound firewall port rules.
Option D is incorrect: Windows Admin Center is a server management and monitoring tool, not a backup service. Dedicated solutions such as Azure Backup or Azure Arc-enabled Backup integration handle cloud backups to Azure Blob Storage.
Question 42 of 60
42. Question
Active Directory Sites are used to define physical network topology. How do clients use site information when locating domain controllers?
Correct
A. Clients always contact the first domain controller that responds regardless of site assignment
Incorrect.
Clients do not randomly contact the first responding DC.
Active Directory uses site awareness to ensure clients connect to domain controllers in their local site whenever possible.
B. Clients use the DNS SRV records filtered by site to prefer domain controllers in their local site
Correct.
When a client queries DNS for a domain controller, the returned SRV records are site?aware.
Clients prefer domain controllers in their own site, reducing WAN traffic and improving authentication performance.
Certification emphasizes this as the key benefit of defining AD Sites.
C. Clients contact the PDC Emulator for all initial authentication and then use site information for subsequent requests
Incorrect.
The PDC Emulator is used for specific tasks (password changes, time sync, legacy operations), not for all initial authentication.
Clients authenticate against any available domain controller, preferably in their local site.
D. Clients use WINS name resolution to find domain controllers and sites are not involved in DC location
Incorrect.
WINS is a legacy NetBIOS name resolution service and is not used for domain controller location in modern AD environments.
Domain controller discovery relies on DNS SRV records, not WINS.
Incorrect
A. Clients always contact the first domain controller that responds regardless of site assignment
Incorrect.
Clients do not randomly contact the first responding DC.
Active Directory uses site awareness to ensure clients connect to domain controllers in their local site whenever possible.
B. Clients use the DNS SRV records filtered by site to prefer domain controllers in their local site
Correct.
When a client queries DNS for a domain controller, the returned SRV records are site?aware.
Clients prefer domain controllers in their own site, reducing WAN traffic and improving authentication performance.
Certification emphasizes this as the key benefit of defining AD Sites.
C. Clients contact the PDC Emulator for all initial authentication and then use site information for subsequent requests
Incorrect.
The PDC Emulator is used for specific tasks (password changes, time sync, legacy operations), not for all initial authentication.
Clients authenticate against any available domain controller, preferably in their local site.
D. Clients use WINS name resolution to find domain controllers and sites are not involved in DC location
Incorrect.
WINS is a legacy NetBIOS name resolution service and is not used for domain controller location in modern AD environments.
Domain controller discovery relies on DNS SRV records, not WINS.
Unattempted
A. Clients always contact the first domain controller that responds regardless of site assignment
Incorrect.
Clients do not randomly contact the first responding DC.
Active Directory uses site awareness to ensure clients connect to domain controllers in their local site whenever possible.
B. Clients use the DNS SRV records filtered by site to prefer domain controllers in their local site
Correct.
When a client queries DNS for a domain controller, the returned SRV records are site?aware.
Clients prefer domain controllers in their own site, reducing WAN traffic and improving authentication performance.
Certification emphasizes this as the key benefit of defining AD Sites.
C. Clients contact the PDC Emulator for all initial authentication and then use site information for subsequent requests
Incorrect.
The PDC Emulator is used for specific tasks (password changes, time sync, legacy operations), not for all initial authentication.
Clients authenticate against any available domain controller, preferably in their local site.
D. Clients use WINS name resolution to find domain controllers and sites are not involved in DC location
Incorrect.
WINS is a legacy NetBIOS name resolution service and is not used for domain controller location in modern AD environments.
Domain controller discovery relies on DNS SRV records, not WINS.
Question 43 of 60
43. Question
Active Directory Users and Computers displays user accounts with a red X icon. What does this icon indicate?
Correct
Correct Option: B. The user account has been disabled and cannot be used for authentication until re-enabled.
In Active Directory Users and Computers (ADUC), a red X icon over a user account visually indicates that the account is disabled. A disabled account cannot be used for authentication or network access until an administrator re-enables it (right-click ? Enable Account).
Incorrect Options & Explanations:
A. The user account is locked out due to too many failed password attempts. Incorrect. A locked-out account displays a different icon—typically a small circle with an “X” or a padlock symbol, not a red X overlay on the user icon. Lockout status is also not persistently shown in ADUC by default; it must be checked via the “Active Directory Users and Computers” properties or using net user / Get-ADUser.
C. The user account has a weak password that does not meet complexity requirements. Incorrect. ADUC does not display any icon for weak passwords. Password complexity is enforced at the time of password change or reset; non-compliant passwords are rejected during the change process, but no persistent visual indicator exists for an already-set password.
D. The user account’s password has expired and must be changed at next login. Incorrect. Password expiration is indicated by a different visual cue—typically a yellow triangle with an exclamation mark, or the account is flagged in the properties under “Password last set” / “Password expires.” The red X icon specifically denotes a disabled state, not an expired password.
Incorrect
Correct Option: B. The user account has been disabled and cannot be used for authentication until re-enabled.
In Active Directory Users and Computers (ADUC), a red X icon over a user account visually indicates that the account is disabled. A disabled account cannot be used for authentication or network access until an administrator re-enables it (right-click ? Enable Account).
Incorrect Options & Explanations:
A. The user account is locked out due to too many failed password attempts. Incorrect. A locked-out account displays a different icon—typically a small circle with an “X” or a padlock symbol, not a red X overlay on the user icon. Lockout status is also not persistently shown in ADUC by default; it must be checked via the “Active Directory Users and Computers” properties or using net user / Get-ADUser.
C. The user account has a weak password that does not meet complexity requirements. Incorrect. ADUC does not display any icon for weak passwords. Password complexity is enforced at the time of password change or reset; non-compliant passwords are rejected during the change process, but no persistent visual indicator exists for an already-set password.
D. The user account’s password has expired and must be changed at next login. Incorrect. Password expiration is indicated by a different visual cue—typically a yellow triangle with an exclamation mark, or the account is flagged in the properties under “Password last set” / “Password expires.” The red X icon specifically denotes a disabled state, not an expired password.
Unattempted
Correct Option: B. The user account has been disabled and cannot be used for authentication until re-enabled.
In Active Directory Users and Computers (ADUC), a red X icon over a user account visually indicates that the account is disabled. A disabled account cannot be used for authentication or network access until an administrator re-enables it (right-click ? Enable Account).
Incorrect Options & Explanations:
A. The user account is locked out due to too many failed password attempts. Incorrect. A locked-out account displays a different icon—typically a small circle with an “X” or a padlock symbol, not a red X overlay on the user icon. Lockout status is also not persistently shown in ADUC by default; it must be checked via the “Active Directory Users and Computers” properties or using net user / Get-ADUser.
C. The user account has a weak password that does not meet complexity requirements. Incorrect. ADUC does not display any icon for weak passwords. Password complexity is enforced at the time of password change or reset; non-compliant passwords are rejected during the change process, but no persistent visual indicator exists for an already-set password.
D. The user account’s password has expired and must be changed at next login. Incorrect. Password expiration is indicated by a different visual cue—typically a yellow triangle with an exclamation mark, or the account is flagged in the properties under “Password last set” / “Password expires.” The red X icon specifically denotes a disabled state, not an expired password.
Question 44 of 60
44. Question
Azure Backup soft delete protects Recovery Services vault data against accidental or malicious deletion. What happens when an administrator deletes a backup item with soft delete enabled?
Correct
When soft delete is enabled for a Recovery Services vault in Azure Backup, explicitly deleting a backup item puts it into a soft-deleted state rather than purging it immediately. In this soft-deleted state, scheduled backup jobs are disabled (no new recovery points are generated), but all existing recovery points are safely retained for an additional 14 days (configurable up to 180 days) at no extra cost before being permanently deleted.
Therefore, Option D is the correct answer.
Details:
Option A is incorrect: While Azure Backup sends email alerts to notify administrators when a soft delete operation takes place, the vault does not hold the operation in a pending state waiting for subscription owner approval; the item transitions immediately into the soft-deleted state.
Option B is incorrect: Soft delete specifically prevents immediate, permanent deletion to safeguard against accidental actions or ransomware attacks. Data cannot be purged while in the soft-deleted retention period. Harvesting Clouds
Option C is incorrect: Choosing to delete backup data stops protection and moves existing recovery points to the soft-deleted state. It does not follow the natural backup policy retention schedule—instead, the fixed soft-delete retention window (14 additional days by default) governs when permanent deletion occurs.
Option D is correct: Once deleted, backup generation is disabled for the item, but existing recovery points remain recoverable in the soft-deleted state for 14 additional days before permanent deletion occurs. During this period, administrators can use the “Undelete” feature to restore the item if needed.
Incorrect
When soft delete is enabled for a Recovery Services vault in Azure Backup, explicitly deleting a backup item puts it into a soft-deleted state rather than purging it immediately. In this soft-deleted state, scheduled backup jobs are disabled (no new recovery points are generated), but all existing recovery points are safely retained for an additional 14 days (configurable up to 180 days) at no extra cost before being permanently deleted.
Therefore, Option D is the correct answer.
Details:
Option A is incorrect: While Azure Backup sends email alerts to notify administrators when a soft delete operation takes place, the vault does not hold the operation in a pending state waiting for subscription owner approval; the item transitions immediately into the soft-deleted state.
Option B is incorrect: Soft delete specifically prevents immediate, permanent deletion to safeguard against accidental actions or ransomware attacks. Data cannot be purged while in the soft-deleted retention period. Harvesting Clouds
Option C is incorrect: Choosing to delete backup data stops protection and moves existing recovery points to the soft-deleted state. It does not follow the natural backup policy retention schedule—instead, the fixed soft-delete retention window (14 additional days by default) governs when permanent deletion occurs.
Option D is correct: Once deleted, backup generation is disabled for the item, but existing recovery points remain recoverable in the soft-deleted state for 14 additional days before permanent deletion occurs. During this period, administrators can use the “Undelete” feature to restore the item if needed.
Unattempted
When soft delete is enabled for a Recovery Services vault in Azure Backup, explicitly deleting a backup item puts it into a soft-deleted state rather than purging it immediately. In this soft-deleted state, scheduled backup jobs are disabled (no new recovery points are generated), but all existing recovery points are safely retained for an additional 14 days (configurable up to 180 days) at no extra cost before being permanently deleted.
Therefore, Option D is the correct answer.
Details:
Option A is incorrect: While Azure Backup sends email alerts to notify administrators when a soft delete operation takes place, the vault does not hold the operation in a pending state waiting for subscription owner approval; the item transitions immediately into the soft-deleted state.
Option B is incorrect: Soft delete specifically prevents immediate, permanent deletion to safeguard against accidental actions or ransomware attacks. Data cannot be purged while in the soft-deleted retention period. Harvesting Clouds
Option C is incorrect: Choosing to delete backup data stops protection and moves existing recovery points to the soft-deleted state. It does not follow the natural backup policy retention schedule—instead, the fixed soft-delete retention window (14 additional days by default) governs when permanent deletion occurs.
Option D is correct: Once deleted, backup generation is disabled for the item, but existing recovery points remain recoverable in the soft-deleted state for 14 additional days before permanent deletion occurs. During this period, administrators can use the “Undelete” feature to restore the item if needed.
Question 45 of 60
45. Question
Just In Time VM access in Microsoft Defender for Cloud applies to Azure VMs. For on-premises Arc-enabled servers, what is the recommended equivalent control for managing inbound management port access?
Correct
A. Disabling WinRM and RDP permanently and requiring console access for all administration
Incorrect.
Permanently disabling remote management ports is not practical for enterprise administration.
EASE guidance emphasizes controlled, time?bound access rather than eliminating remote management entirely.
B. Purchasing Microsoft Defender for Servers Plan 2 which automatically extends JIT access to Arc?enabled on?premises servers
Incorrect.
JIT VM access is an Azure?native feature and does not automatically extend to Arc?enabled on?premises servers.
Defender for Servers Plan 2 provides vulnerability management and advanced security, but not JIT port control for Arc servers.
C. Using Privileged Access Management with time?limited Active Directory group membership combined with GPO?controlled firewall rules that open management ports only when group membership is active
Correct.
For Arc?enabled on?premises servers, the recommended equivalent to JIT VM access is Privileged Access Management (PAM).
Administrators are granted time?limited AD group membership, and Group Policy Objects (GPOs) enforce firewall rules that open management ports (e.g., RDP, WinRM) only while membership is active.
This ensures secure, temporary access similar to JIT in Azure.
D. Enabling remote desktop without any time restriction but requiring MFA at the application level
Incorrect.
While MFA adds security, leaving RDP permanently open increases attack surface.
Certification guidance stresses time?bound access to reduce exposure, not unrestricted port availability.
Incorrect
A. Disabling WinRM and RDP permanently and requiring console access for all administration
Incorrect.
Permanently disabling remote management ports is not practical for enterprise administration.
EASE guidance emphasizes controlled, time?bound access rather than eliminating remote management entirely.
B. Purchasing Microsoft Defender for Servers Plan 2 which automatically extends JIT access to Arc?enabled on?premises servers
Incorrect.
JIT VM access is an Azure?native feature and does not automatically extend to Arc?enabled on?premises servers.
Defender for Servers Plan 2 provides vulnerability management and advanced security, but not JIT port control for Arc servers.
C. Using Privileged Access Management with time?limited Active Directory group membership combined with GPO?controlled firewall rules that open management ports only when group membership is active
Correct.
For Arc?enabled on?premises servers, the recommended equivalent to JIT VM access is Privileged Access Management (PAM).
Administrators are granted time?limited AD group membership, and Group Policy Objects (GPOs) enforce firewall rules that open management ports (e.g., RDP, WinRM) only while membership is active.
This ensures secure, temporary access similar to JIT in Azure.
D. Enabling remote desktop without any time restriction but requiring MFA at the application level
Incorrect.
While MFA adds security, leaving RDP permanently open increases attack surface.
Certification guidance stresses time?bound access to reduce exposure, not unrestricted port availability.
Unattempted
A. Disabling WinRM and RDP permanently and requiring console access for all administration
Incorrect.
Permanently disabling remote management ports is not practical for enterprise administration.
EASE guidance emphasizes controlled, time?bound access rather than eliminating remote management entirely.
B. Purchasing Microsoft Defender for Servers Plan 2 which automatically extends JIT access to Arc?enabled on?premises servers
Incorrect.
JIT VM access is an Azure?native feature and does not automatically extend to Arc?enabled on?premises servers.
Defender for Servers Plan 2 provides vulnerability management and advanced security, but not JIT port control for Arc servers.
C. Using Privileged Access Management with time?limited Active Directory group membership combined with GPO?controlled firewall rules that open management ports only when group membership is active
Correct.
For Arc?enabled on?premises servers, the recommended equivalent to JIT VM access is Privileged Access Management (PAM).
Administrators are granted time?limited AD group membership, and Group Policy Objects (GPOs) enforce firewall rules that open management ports (e.g., RDP, WinRM) only while membership is active.
This ensures secure, temporary access similar to JIT in Azure.
D. Enabling remote desktop without any time restriction but requiring MFA at the application level
Incorrect.
While MFA adds security, leaving RDP permanently open increases attack surface.
Certification guidance stresses time?bound access to reduce exposure, not unrestricted port availability.
Question 46 of 60
46. Question
Enhanced Administrative Security Environment (EASE) guidance recommends separating Active Directory administration tiers. Which Tier would a helpdesk operator who only resets end-user passwords be assigned to?
Correct
A. Tier 0 which covers the most sensitive assets including domain controllers and AD administration tools
Incorrect.
Tier 0 is reserved for highly privileged accounts managing domain controllers, forest trusts, and AD infrastructure.
Helpdesk operators performing password resets do not require Tier 0 access.
B. Tier 2 which covers end?user workstation and user account administration with limited privileges
Correct.
Tier 2 is designated for end?user support operations, including workstation management and user account tasks such as password resets.
This tier isolates lower?privilege accounts from Tier 0 and Tier 1, reducing risk exposure.
Certification guidance emphasizes that helpdesk operators belong in Tier 2.
C. No tier assignment as helpdesk password resets do not require administrative access to Active Directory
Incorrect.
Password resets do require delegated administrative rights in Active Directory.
Therefore, helpdesk operators must be assigned to a tier (Tier 2), not excluded.
D. Tier 1 which covers server and application administration across the enterprise
Incorrect.
Tier 1 is for administrators managing enterprise servers and applications.
Helpdesk operators resetting user passwords do not fall under Tier 1 responsibilities.
Incorrect
A. Tier 0 which covers the most sensitive assets including domain controllers and AD administration tools
Incorrect.
Tier 0 is reserved for highly privileged accounts managing domain controllers, forest trusts, and AD infrastructure.
Helpdesk operators performing password resets do not require Tier 0 access.
B. Tier 2 which covers end?user workstation and user account administration with limited privileges
Correct.
Tier 2 is designated for end?user support operations, including workstation management and user account tasks such as password resets.
This tier isolates lower?privilege accounts from Tier 0 and Tier 1, reducing risk exposure.
Certification guidance emphasizes that helpdesk operators belong in Tier 2.
C. No tier assignment as helpdesk password resets do not require administrative access to Active Directory
Incorrect.
Password resets do require delegated administrative rights in Active Directory.
Therefore, helpdesk operators must be assigned to a tier (Tier 2), not excluded.
D. Tier 1 which covers server and application administration across the enterprise
Incorrect.
Tier 1 is for administrators managing enterprise servers and applications.
Helpdesk operators resetting user passwords do not fall under Tier 1 responsibilities.
Unattempted
A. Tier 0 which covers the most sensitive assets including domain controllers and AD administration tools
Incorrect.
Tier 0 is reserved for highly privileged accounts managing domain controllers, forest trusts, and AD infrastructure.
Helpdesk operators performing password resets do not require Tier 0 access.
B. Tier 2 which covers end?user workstation and user account administration with limited privileges
Correct.
Tier 2 is designated for end?user support operations, including workstation management and user account tasks such as password resets.
This tier isolates lower?privilege accounts from Tier 0 and Tier 1, reducing risk exposure.
Certification guidance emphasizes that helpdesk operators belong in Tier 2.
C. No tier assignment as helpdesk password resets do not require administrative access to Active Directory
Incorrect.
Password resets do require delegated administrative rights in Active Directory.
Therefore, helpdesk operators must be assigned to a tier (Tier 2), not excluded.
D. Tier 1 which covers server and application administration across the enterprise
Incorrect.
Tier 1 is for administrators managing enterprise servers and applications.
Helpdesk operators resetting user passwords do not fall under Tier 1 responsibilities.
Question 47 of 60
47. Question
Failover Cluster validation tests must pass before a cluster is supported by Microsoft. Which test category specifically validates that all nodes can access the shared storage simultaneously?
Correct
Failover Cluster validation (Test-Cluster) runs targeted tests across broad system categories to verify that hardware, networking, and storage components meet Microsoft support standards for high availability. The Storage category specifically verifies shared disk access, SCSI commands, reservation release capabilities, and multipathing across all nodes.
Therefore, Option A is the correct answer.
Details:
Option A is correct: The Storage validation tests confirm that all potential cluster disks and storage pools are visible to and accessible by all nodes in the cluster. This includes testing persistent reservation (SCSI-3 PR) capabilities to ensure nodes can negotiate shared access and take ownership of shared storage without data corruption.
Option B is incorrect: System Configuration tests evaluate operating system settings, software updates, driver versions, and domain membership consistency across cluster nodes. They do not evaluate physical or logical shared storage access.
Option C is incorrect: Network tests evaluate adapter configurations, IP subnet consistency, latency, and communication paths between cluster nodes. While essential for cluster heartbeat and inter-node communication, network tests do not validate shared disk access or storage array compatibility.
Option D is incorrect: Hyper-V Configuration tests evaluate host role settings, virtual network switch setups, and VM migration compatibility when the Hyper-V role is present. They do not validate the underlying shared storage infrastructure access.
Incorrect
Failover Cluster validation (Test-Cluster) runs targeted tests across broad system categories to verify that hardware, networking, and storage components meet Microsoft support standards for high availability. The Storage category specifically verifies shared disk access, SCSI commands, reservation release capabilities, and multipathing across all nodes.
Therefore, Option A is the correct answer.
Details:
Option A is correct: The Storage validation tests confirm that all potential cluster disks and storage pools are visible to and accessible by all nodes in the cluster. This includes testing persistent reservation (SCSI-3 PR) capabilities to ensure nodes can negotiate shared access and take ownership of shared storage without data corruption.
Option B is incorrect: System Configuration tests evaluate operating system settings, software updates, driver versions, and domain membership consistency across cluster nodes. They do not evaluate physical or logical shared storage access.
Option C is incorrect: Network tests evaluate adapter configurations, IP subnet consistency, latency, and communication paths between cluster nodes. While essential for cluster heartbeat and inter-node communication, network tests do not validate shared disk access or storage array compatibility.
Option D is incorrect: Hyper-V Configuration tests evaluate host role settings, virtual network switch setups, and VM migration compatibility when the Hyper-V role is present. They do not validate the underlying shared storage infrastructure access.
Unattempted
Failover Cluster validation (Test-Cluster) runs targeted tests across broad system categories to verify that hardware, networking, and storage components meet Microsoft support standards for high availability. The Storage category specifically verifies shared disk access, SCSI commands, reservation release capabilities, and multipathing across all nodes.
Therefore, Option A is the correct answer.
Details:
Option A is correct: The Storage validation tests confirm that all potential cluster disks and storage pools are visible to and accessible by all nodes in the cluster. This includes testing persistent reservation (SCSI-3 PR) capabilities to ensure nodes can negotiate shared access and take ownership of shared storage without data corruption.
Option B is incorrect: System Configuration tests evaluate operating system settings, software updates, driver versions, and domain membership consistency across cluster nodes. They do not evaluate physical or logical shared storage access.
Option C is incorrect: Network tests evaluate adapter configurations, IP subnet consistency, latency, and communication paths between cluster nodes. While essential for cluster heartbeat and inter-node communication, network tests do not validate shared disk access or storage array compatibility.
Option D is incorrect: Hyper-V Configuration tests evaluate host role settings, virtual network switch setups, and VM migration compatibility when the Hyper-V role is present. They do not validate the underlying shared storage infrastructure access.
Question 48 of 60
48. Question
Windows Server role removal using Server Manager can sometimes fail if dependencies exist. Which PowerShell cmdlet performs a role or feature removal and specifies to also remove all dependent features?
Correct
A. Uninstall?WindowsFeature -Name ‘Role Name’ -IncludeManagementTools -Remove which removes the role, its tools, and feature files, and -IncludeSubFeature removes all dependent sub?features
Correct.
The Uninstall?WindowsFeature cmdlet is the supported method for removing roles/features.
The -IncludeManagementTools parameter removes associated management consoles/tools.
The -Remove parameter deletes feature binaries from disk.
The -IncludeSubFeature parameter ensures dependent sub?features are also removed, which is critical when Server Manager fails due to dependencies.
Certification emphasizes this cmdlet as the proper way to handle role removal with dependencies.
B. Remove?WindowsFeature -Name Hyper?V -IncludeManagementTools which removes the role and its management tools
Incorrect.
Remove?WindowsFeature is not a valid cmdlet in modern Windows Server versions.
The supported cmdlet is Uninstall?WindowsFeature.
C. Uninstall?WindowsFeature -Name Hyper?V -IncludeManagementTools which also removes GUI tools
Incorrect.
While this cmdlet removes the role and management tools, it does not specify -IncludeSubFeature, meaning dependent features may remain.
This can cause incomplete removal if dependencies exist.
D. Uninstall?WindowsFeature -Name Hyper?V -Remove which marks the feature for permanent removal without removing dependencies
Incorrect.
The -Remove parameter deletes feature binaries from disk but does not handle dependent features.
Dependencies must be explicitly removed using -IncludeSubFeature.
Incorrect
A. Uninstall?WindowsFeature -Name ‘Role Name’ -IncludeManagementTools -Remove which removes the role, its tools, and feature files, and -IncludeSubFeature removes all dependent sub?features
Correct.
The Uninstall?WindowsFeature cmdlet is the supported method for removing roles/features.
The -IncludeManagementTools parameter removes associated management consoles/tools.
The -Remove parameter deletes feature binaries from disk.
The -IncludeSubFeature parameter ensures dependent sub?features are also removed, which is critical when Server Manager fails due to dependencies.
Certification emphasizes this cmdlet as the proper way to handle role removal with dependencies.
B. Remove?WindowsFeature -Name Hyper?V -IncludeManagementTools which removes the role and its management tools
Incorrect.
Remove?WindowsFeature is not a valid cmdlet in modern Windows Server versions.
The supported cmdlet is Uninstall?WindowsFeature.
C. Uninstall?WindowsFeature -Name Hyper?V -IncludeManagementTools which also removes GUI tools
Incorrect.
While this cmdlet removes the role and management tools, it does not specify -IncludeSubFeature, meaning dependent features may remain.
This can cause incomplete removal if dependencies exist.
D. Uninstall?WindowsFeature -Name Hyper?V -Remove which marks the feature for permanent removal without removing dependencies
Incorrect.
The -Remove parameter deletes feature binaries from disk but does not handle dependent features.
Dependencies must be explicitly removed using -IncludeSubFeature.
Unattempted
A. Uninstall?WindowsFeature -Name ‘Role Name’ -IncludeManagementTools -Remove which removes the role, its tools, and feature files, and -IncludeSubFeature removes all dependent sub?features
Correct.
The Uninstall?WindowsFeature cmdlet is the supported method for removing roles/features.
The -IncludeManagementTools parameter removes associated management consoles/tools.
The -Remove parameter deletes feature binaries from disk.
The -IncludeSubFeature parameter ensures dependent sub?features are also removed, which is critical when Server Manager fails due to dependencies.
Certification emphasizes this cmdlet as the proper way to handle role removal with dependencies.
B. Remove?WindowsFeature -Name Hyper?V -IncludeManagementTools which removes the role and its management tools
Incorrect.
Remove?WindowsFeature is not a valid cmdlet in modern Windows Server versions.
The supported cmdlet is Uninstall?WindowsFeature.
C. Uninstall?WindowsFeature -Name Hyper?V -IncludeManagementTools which also removes GUI tools
Incorrect.
While this cmdlet removes the role and management tools, it does not specify -IncludeSubFeature, meaning dependent features may remain.
This can cause incomplete removal if dependencies exist.
D. Uninstall?WindowsFeature -Name Hyper?V -Remove which marks the feature for permanent removal without removing dependencies
Incorrect.
The -Remove parameter deletes feature binaries from disk but does not handle dependent features.
Dependencies must be explicitly removed using -IncludeSubFeature.
Question 49 of 60
49. Question
Split-brain DNS on Windows Server can serve different responses for internal and external clients without two separate zones. Which DNS configuration achieves this?
Correct
Correct :
A. Creating multiple zone scopes within the same DNS zone and using DNS policies with client subnet criteria to direct each subnet to the appropriate scope.
Correct. Windows Server DNS supports Split-Brain (or split-horizon) DNS using DNS Policies and Zone Scopes. Multiple zone scopes are defined inside a single DNS zone (e.g., an internal scope and an external scope for contoso.com). DNS policies then map client subnet criteria (IP range/subnet) to specific zone scopes. When an internal client queries the DNS server, the policy routes the request to the internal scope, returning local IP addresses; when an external/untrusted subnet queries, it receives responses from the default or external scope—all maintained within a single unified zone.
Incorrect :
B. Enabling DNS over HTTPS which serves different records based on the client’s HTTP request headers.
Incorrect. DNS over HTTPS (DoH) encrypts DNS queries via HTTPS (port 443) to enhance privacy and security. DoH does not inspect or use HTTP request headers to alter DNS record resolution or perform split-brain DNS mapping.
C. Configuring secondary zones for internal clients and primary zones for external clients.
Incorrect. Secondary zones contain read-only copies of a zone transferred from a primary DNS server. They replicate the exact same DNS records as the primary server and cannot natively partition or return different IP address answers based on client origin.
D. Configuring conditional forwarders that route internal queries to the internal DNS and external queries to the public DNS.
Incorrect. Conditional forwarders direct queries for specific domain names (e.g., sales.contoso.com) to designated DNS servers based on the requested domain suffix, not based on the requesting client’s IP address. Moreover, they do not resolve split-brain records for a single zone hosted on the same server without underlying DNS policies.
Incorrect
Correct :
A. Creating multiple zone scopes within the same DNS zone and using DNS policies with client subnet criteria to direct each subnet to the appropriate scope.
Correct. Windows Server DNS supports Split-Brain (or split-horizon) DNS using DNS Policies and Zone Scopes. Multiple zone scopes are defined inside a single DNS zone (e.g., an internal scope and an external scope for contoso.com). DNS policies then map client subnet criteria (IP range/subnet) to specific zone scopes. When an internal client queries the DNS server, the policy routes the request to the internal scope, returning local IP addresses; when an external/untrusted subnet queries, it receives responses from the default or external scope—all maintained within a single unified zone.
Incorrect :
B. Enabling DNS over HTTPS which serves different records based on the client’s HTTP request headers.
Incorrect. DNS over HTTPS (DoH) encrypts DNS queries via HTTPS (port 443) to enhance privacy and security. DoH does not inspect or use HTTP request headers to alter DNS record resolution or perform split-brain DNS mapping.
C. Configuring secondary zones for internal clients and primary zones for external clients.
Incorrect. Secondary zones contain read-only copies of a zone transferred from a primary DNS server. They replicate the exact same DNS records as the primary server and cannot natively partition or return different IP address answers based on client origin.
D. Configuring conditional forwarders that route internal queries to the internal DNS and external queries to the public DNS.
Incorrect. Conditional forwarders direct queries for specific domain names (e.g., sales.contoso.com) to designated DNS servers based on the requested domain suffix, not based on the requesting client’s IP address. Moreover, they do not resolve split-brain records for a single zone hosted on the same server without underlying DNS policies.
Unattempted
Correct :
A. Creating multiple zone scopes within the same DNS zone and using DNS policies with client subnet criteria to direct each subnet to the appropriate scope.
Correct. Windows Server DNS supports Split-Brain (or split-horizon) DNS using DNS Policies and Zone Scopes. Multiple zone scopes are defined inside a single DNS zone (e.g., an internal scope and an external scope for contoso.com). DNS policies then map client subnet criteria (IP range/subnet) to specific zone scopes. When an internal client queries the DNS server, the policy routes the request to the internal scope, returning local IP addresses; when an external/untrusted subnet queries, it receives responses from the default or external scope—all maintained within a single unified zone.
Incorrect :
B. Enabling DNS over HTTPS which serves different records based on the client’s HTTP request headers.
Incorrect. DNS over HTTPS (DoH) encrypts DNS queries via HTTPS (port 443) to enhance privacy and security. DoH does not inspect or use HTTP request headers to alter DNS record resolution or perform split-brain DNS mapping.
C. Configuring secondary zones for internal clients and primary zones for external clients.
Incorrect. Secondary zones contain read-only copies of a zone transferred from a primary DNS server. They replicate the exact same DNS records as the primary server and cannot natively partition or return different IP address answers based on client origin.
D. Configuring conditional forwarders that route internal queries to the internal DNS and external queries to the public DNS.
Incorrect. Conditional forwarders direct queries for specific domain names (e.g., sales.contoso.com) to designated DNS servers based on the requested domain suffix, not based on the requesting client’s IP address. Moreover, they do not resolve split-brain records for a single zone hosted on the same server without underlying DNS policies.
Question 50 of 60
50. Question
Windows Server provides iSCSI software initiator support. What is the maximum number of iSCSI targets that a Windows Server can connect to simultaneously using the software initiator?
Correct
The Microsoft iSCSI Software Initiator allows a Windows Server host to act as an iSCSI client connecting to storage arrays (iSCSI Targets). The software initiator supports connecting to multiple simultaneous targets and creating multiple sessions per target. There is no artificial hard-coded limit restricting the initiator to a small static number of target connections; instead, maximum operational concurrency is bound by available system memory, network interface throughput, and underlying storage processing capabilities.
Therefore, Option B is the correct answer.
Details:
Option A is incorrect: The Microsoft iSCSI Initiator is fully multi-session capable. It can establish concurrent TCP/IP sessions to many different targets across single or multiple storage portals simultaneously.
Option B is correct: Windows Server supports multiple simultaneous iSCSI target sessions using the software initiator. Scalability and connection throughput are primarily bounded by host hardware resources (such as CPU utilization, RAM, and network bandwidth) rather than an explicit hard software cap on the initiator side.
Option C is incorrect: While 255 (or 256) is a common limit for certain target-side capabilities or specific SAN device implementations (e.g., maximum LUN IDs per target or iSCSI Target Server limits), it is not a fixed software restriction governing how many total external targets the Windows iSCSI software initiator can connect to.
Option D is incorrect: Windows Server iSCSI Initiator supports far more than eight simultaneous targets. Eight is an arbitrary small number and does not represent an architectural limitation of the Microsoft iSCSI Initiator component.
Incorrect
The Microsoft iSCSI Software Initiator allows a Windows Server host to act as an iSCSI client connecting to storage arrays (iSCSI Targets). The software initiator supports connecting to multiple simultaneous targets and creating multiple sessions per target. There is no artificial hard-coded limit restricting the initiator to a small static number of target connections; instead, maximum operational concurrency is bound by available system memory, network interface throughput, and underlying storage processing capabilities.
Therefore, Option B is the correct answer.
Details:
Option A is incorrect: The Microsoft iSCSI Initiator is fully multi-session capable. It can establish concurrent TCP/IP sessions to many different targets across single or multiple storage portals simultaneously.
Option B is correct: Windows Server supports multiple simultaneous iSCSI target sessions using the software initiator. Scalability and connection throughput are primarily bounded by host hardware resources (such as CPU utilization, RAM, and network bandwidth) rather than an explicit hard software cap on the initiator side.
Option C is incorrect: While 255 (or 256) is a common limit for certain target-side capabilities or specific SAN device implementations (e.g., maximum LUN IDs per target or iSCSI Target Server limits), it is not a fixed software restriction governing how many total external targets the Windows iSCSI software initiator can connect to.
Option D is incorrect: Windows Server iSCSI Initiator supports far more than eight simultaneous targets. Eight is an arbitrary small number and does not represent an architectural limitation of the Microsoft iSCSI Initiator component.
Unattempted
The Microsoft iSCSI Software Initiator allows a Windows Server host to act as an iSCSI client connecting to storage arrays (iSCSI Targets). The software initiator supports connecting to multiple simultaneous targets and creating multiple sessions per target. There is no artificial hard-coded limit restricting the initiator to a small static number of target connections; instead, maximum operational concurrency is bound by available system memory, network interface throughput, and underlying storage processing capabilities.
Therefore, Option B is the correct answer.
Details:
Option A is incorrect: The Microsoft iSCSI Initiator is fully multi-session capable. It can establish concurrent TCP/IP sessions to many different targets across single or multiple storage portals simultaneously.
Option B is correct: Windows Server supports multiple simultaneous iSCSI target sessions using the software initiator. Scalability and connection throughput are primarily bounded by host hardware resources (such as CPU utilization, RAM, and network bandwidth) rather than an explicit hard software cap on the initiator side.
Option C is incorrect: While 255 (or 256) is a common limit for certain target-side capabilities or specific SAN device implementations (e.g., maximum LUN IDs per target or iSCSI Target Server limits), it is not a fixed software restriction governing how many total external targets the Windows iSCSI software initiator can connect to.
Option D is incorrect: Windows Server iSCSI Initiator supports far more than eight simultaneous targets. Eight is an arbitrary small number and does not represent an architectural limitation of the Microsoft iSCSI Initiator component.
Question 51 of 60
51. Question
You are deploying Azure File Sync. You need to ensure that the most frequently accessed files remain on the local server while older files are moved to Azure. Which two settings should you configure?
Correct
Cloud Tiering is the feature that enables hybrid storage. The Volume Free Space and Date policies determine which files are tiered to the cloud versus kept on the local disk.
Incorrect
Cloud Tiering is the feature that enables hybrid storage. The Volume Free Space and Date policies determine which files are tiered to the cloud versus kept on the local disk.
Unattempted
Cloud Tiering is the feature that enables hybrid storage. The Volume Free Space and Date policies determine which files are tiered to the cloud versus kept on the local disk.
Question 52 of 60
52. Question
You are configuring a hybrid network. You want to use ‘Azure Private Link’ to access a Storage Account from an on-premises server over a VPN. Which two components are necessary to ensure the name ‘storage1.blob.core.windows.net’ resolves to the private IP?
Correct
The Private Endpoint provides the internal IP. To ensure on-premises servers use that IP instead of the public one, you must forward DNS queries from your local DNS server to an Azure DNS Private Resolver (or similar proxy) that can see the Private DNS Zone.
Incorrect
The Private Endpoint provides the internal IP. To ensure on-premises servers use that IP instead of the public one, you must forward DNS queries from your local DNS server to an Azure DNS Private Resolver (or similar proxy) that can see the Private DNS Zone.
Unattempted
The Private Endpoint provides the internal IP. To ensure on-premises servers use that IP instead of the public one, you must forward DNS queries from your local DNS server to an Azure DNS Private Resolver (or similar proxy) that can see the Private DNS Zone.
Question 53 of 60
53. Question
You are configuring an Azure Stack HCI cluster and need to choose a witness type for a two-node configuration. Which two options are valid?
Correct
For a two-node cluster, a Cloud Witness (using Azure Storage) or a File Share Witness (on a separate server) is required to prevent split-brain scenarios. A Disk Witness is rarely used in HCI because the storage is local to the nodes.
Incorrect
For a two-node cluster, a Cloud Witness (using Azure Storage) or a File Share Witness (on a separate server) is required to prevent split-brain scenarios. A Disk Witness is rarely used in HCI because the storage is local to the nodes.
Unattempted
For a two-node cluster, a Cloud Witness (using Azure Storage) or a File Share Witness (on a separate server) is required to prevent split-brain scenarios. A Disk Witness is rarely used in HCI because the storage is local to the nodes.
Question 54 of 60
54. Question
You are configuring Azure Stack HCI networking using Network ATC. You want to define a ‘Storage’ intent for your network adapters. Which two settings does Network ATC automatically configure when this intent is applied?
Correct
Network ATC simplifies deployment by automatically configuring complex settings like RDMA and VLAN tagging based on the ‘Intent’ (Storage, Management, or Compute) you assign to the physical adapters.
Incorrect
Network ATC simplifies deployment by automatically configuring complex settings like RDMA and VLAN tagging based on the ‘Intent’ (Storage, Management, or Compute) you assign to the physical adapters.
Unattempted
Network ATC simplifies deployment by automatically configuring complex settings like RDMA and VLAN tagging based on the ‘Intent’ (Storage, Management, or Compute) you assign to the physical adapters.
Question 55 of 60
55. Question
You are managing a hybrid environment with Azure Arc-enabled servers. You want to ensure that all servers are automatically enrolled in Microsoft Defender for Cloud. Which two Azure features should you use?
Correct
Auto-provisioning in Defender for Cloud ensures the necessary extensions are installed. Azure Policy (the ‘Deploy if not exists’ effect) is used to enforce this compliance across all Arc-enabled resources automatically.
Incorrect
Auto-provisioning in Defender for Cloud ensures the necessary extensions are installed. Azure Policy (the ‘Deploy if not exists’ effect) is used to enforce this compliance across all Arc-enabled resources automatically.
Unattempted
Auto-provisioning in Defender for Cloud ensures the necessary extensions are installed. Azure Policy (the ‘Deploy if not exists’ effect) is used to enforce this compliance across all Arc-enabled resources automatically.
Question 56 of 60
56. Question
You are configuring a hybrid network. You want to use ‘Azure Private Link’ to access an ‘Azure Key Vault’. You need to ensure the on-premises servers resolve the Key Vault FQDN to the private IP. Which two components are needed?
Correct
The Private Resolver is the recommended way to bridge on-premises DNS to Azure Private DNS Zones. The local DNS server forwards the request to the resolver, which then returns the Private Endpoint’s internal IP address.
Incorrect
The Private Resolver is the recommended way to bridge on-premises DNS to Azure Private DNS Zones. The local DNS server forwards the request to the resolver, which then returns the Private Endpoint’s internal IP address.
Unattempted
The Private Resolver is the recommended way to bridge on-premises DNS to Azure Private DNS Zones. The local DNS server forwards the request to the resolver, which then returns the Private Endpoint’s internal IP address.
Question 57 of 60
57. Question
You are troubleshooting a VPN Gateway connection between on-premises and Azure. Users report that they can connect but cannot reach certain subnets in Azure. Which two configurations should you verify?
Correct
The Local Network Gateway defines the on-premises routes known to Azure. If subnets are missing there, or if ‘Allow Gateway Transit’ is not enabled on a peered VNet, traffic will not be routed to those destinations.
Incorrect
The Local Network Gateway defines the on-premises routes known to Azure. If subnets are missing there, or if ‘Allow Gateway Transit’ is not enabled on a peered VNet, traffic will not be routed to those destinations.
Unattempted
The Local Network Gateway defines the on-premises routes known to Azure. If subnets are missing there, or if ‘Allow Gateway Transit’ is not enabled on a peered VNet, traffic will not be routed to those destinations.
Question 58 of 60
58. Question
You are managing a hybrid identity environment. You need to ensure that users can access Azure resources using their on-premises credentials, even if the on-premises Active Directory is unavailable for 48 hours. Which two components/features should you implement?
Correct
PHS provides the highest availability because the password hashes are stored in Azure AD. If using PTA, you must specifically enable PHS as a fallback so users can sign in if the on-premises agents or domain controllers are unreachable.
Incorrect
PHS provides the highest availability because the password hashes are stored in Azure AD. If using PTA, you must specifically enable PHS as a fallback so users can sign in if the on-premises agents or domain controllers are unreachable.
Unattempted
PHS provides the highest availability because the password hashes are stored in Azure AD. If using PTA, you must specifically enable PHS as a fallback so users can sign in if the on-premises agents or domain controllers are unreachable.
Question 59 of 60
59. Question
You are implementing Azure File Sync. You need to migrate files from an on-premises server to an Azure File share and preserve the NTFS permissions (ACLs). Which two methods support this during the initial migration?
Correct
To preserve NTFS ACLs during migration, you must use tools that support metadata preservation, such as Robocopy (to a locally mounted share over VPN/ExpressRoute) or Azure Data Box.
Incorrect
To preserve NTFS ACLs during migration, you must use tools that support metadata preservation, such as Robocopy (to a locally mounted share over VPN/ExpressRoute) or Azure Data Box.
Unattempted
To preserve NTFS ACLs during migration, you must use tools that support metadata preservation, such as Robocopy (to a locally mounted share over VPN/ExpressRoute) or Azure Data Box.
Question 60 of 60
60. Question
You are troubleshooting ‘Azure AD Connect’ Health. You receive an alert about ‘Expired Secret’ for the Health agent. Where must you update the credentials to resolve this?
Correct
If the Health agent’s registration token or credentials expire, you must re-register the agent using PowerShell. This generates a new secret/token that allows the agent to resume sending health telemetry to the portal.
Incorrect
If the Health agent’s registration token or credentials expire, you must re-register the agent using PowerShell. This generates a new secret/token that allows the agent to resume sending health telemetry to the portal.
Unattempted
If the Health agent’s registration token or credentials expire, you must re-register the agent using PowerShell. This generates a new secret/token that allows the agent to resume sending health telemetry to the portal.
X
Use Page numbers below to navigate to other practice tests