You have already completed the Test before. Hence you can not start it again.
Test is loading...
You must sign in or sign up to start the Test.
You have to finish following quiz, to start this Test:
Your results are here!! for" AZ-802 Practice Test 5 "
0 of 60 questions answered correctly
Your time:
Time has elapsed
Your Final Score is : 0
You have attempted : 0
Number of Correct Questions : 0 and scored 0
Number of Incorrect Questions : 0 and Negative marks 0
Average score
Your score
AZ-802
You have attempted: 0
Number of Correct Questions: 0 and scored 0
Number of Incorrect Questions: 0 and Negative marks 0
You can review your answers by clicking on “View Answers” option. Important Note : Open Reference Documentation Links in New Tab (Right Click and Open in New Tab).
Answer Review
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Answer
Review
Unattempted
Correct
Incorrect
Unattempted
Every question in this attempt was answered correctly.
Question 1 of 60
1. Question
You are managing a Storage Spaces Direct cluster. You want to create a new volume. Which file system is highly recommended for S2D to take advantage of features like block-cloning?
Correct
ReFS (Resilient File System) is the recommended file system for S2D because it offers superior performance and data integrity features.
Incorrect
ReFS (Resilient File System) is the recommended file system for S2D because it offers superior performance and data integrity features.
Unattempted
ReFS (Resilient File System) is the recommended file system for S2D because it offers superior performance and data integrity features.
Question 2 of 60
2. Question
You are managing an Azure Stack HCI cluster. You need to implement ‘Thin Provisioning’ for your volumes to optimize storage utilization. Which tool is recommended to create and manage these volumes?
Correct
Windows Admin Center is the primary tool for HCI management and natively supports thin provisioning during volume creation. While Failover Cluster Manager can manage the resources, WAC provides the most streamlined experience for HCI-specific storage features.
Incorrect
Windows Admin Center is the primary tool for HCI management and natively supports thin provisioning during volume creation. While Failover Cluster Manager can manage the resources, WAC provides the most streamlined experience for HCI-specific storage features.
Unattempted
Windows Admin Center is the primary tool for HCI management and natively supports thin provisioning during volume creation. While Failover Cluster Manager can manage the resources, WAC provides the most streamlined experience for HCI-specific storage features.
Question 3 of 60
3. Question
You are troubleshooting Azure AD Connect ‘Health’. You notice that the ‘Sync’ health is not reporting data to the Azure portal. Which two services should you check on the Azure AD Connect server?
Correct
The Health agent relies on two specific Windows services to monitor the sync engine and transmit those metrics to Azure. If either the Monitoring or Insights service is stopped, the Health dashboard will appear empty or stale.
Incorrect
The Health agent relies on two specific Windows services to monitor the sync engine and transmit those metrics to Azure. If either the Monitoring or Insights service is stopped, the Health dashboard will appear empty or stale.
Unattempted
The Health agent relies on two specific Windows services to monitor the sync engine and transmit those metrics to Azure. If either the Monitoring or Insights service is stopped, the Health dashboard will appear empty or stale.
Question 4 of 60
4. Question
You are managing a Windows Server 2022 cluster on Azure Stack HCI. You need to ensure that the cluster can continue to operate if a single node and a separate disk in another node fail simultaneously. Which two storage resiliency types meet this requirement?
Correct
Three-way mirroring and Nested resiliency (specifically nested mirroring) provide the multi-fault tolerance required to survive the loss of a full node plus an additional disk or node failure.
Incorrect
Three-way mirroring and Nested resiliency (specifically nested mirroring) provide the multi-fault tolerance required to survive the loss of a full node plus an additional disk or node failure.
Unattempted
Three-way mirroring and Nested resiliency (specifically nested mirroring) provide the multi-fault tolerance required to survive the loss of a full node plus an additional disk or node failure.
Question 5 of 60
5. Question
You are troubleshooting Azure AD Connect Cloud Sync. You notice that some users are not being provisioned to the cloud. Which two locations should you check for logs?
Correct
Cloud Sync is managed primarily from the cloud; therefore, the Provisioning logs in the portal are the primary source. Locally, the agent logs errors to the Windows Event Viewer under ‘Applications and Service Logs’.
Incorrect
Cloud Sync is managed primarily from the cloud; therefore, the Provisioning logs in the portal are the primary source. Locally, the agent logs errors to the Windows Event Viewer under ‘Applications and Service Logs’.
Unattempted
Cloud Sync is managed primarily from the cloud; therefore, the Provisioning logs in the portal are the primary source. Locally, the agent logs errors to the Windows Event Viewer under ‘Applications and Service Logs’.
Question 6 of 60
6. Question
You are managing an Azure Virtual Desktop (AVD) environment. You need to store user profiles using FSLogix profile containers. Which storage solution provides the best integration and performance for hybrid environments using SMB?
Correct
Azure Files (especially Premium tier) is the recommended storage for FSLogix profiles in AVD because it supports SMB and AD DS authentication.
Incorrect
Azure Files (especially Premium tier) is the recommended storage for FSLogix profiles in AVD because it supports SMB and AD DS authentication.
Unattempted
Azure Files (especially Premium tier) is the recommended storage for FSLogix profiles in AVD because it supports SMB and AD DS authentication.
Question 7 of 60
7. Question
You are managing a Windows Server 2022 file server. You want to track WHO deleted a specific file last week. What must you have enabled?
Correct
To track file deletions you must enable ‘Audit File System’ in your security policy and then enable auditing on the specific folder’s properties.
Incorrect
To track file deletions you must enable ‘Audit File System’ in your security policy and then enable auditing on the specific folder’s properties.
Unattempted
To track file deletions you must enable ‘Audit File System’ in your security policy and then enable auditing on the specific folder’s properties.
Question 8 of 60
8. Question
You are configuring Azure File Sync. You want to ensure that even if the local server is destroyed, you can immediately point a new server to the same files in Azure. What should you do?
Correct
The Cloud Endpoint in Azure holds the master copy of the data. Registering a new server and adding it as a Server Endpoint allows for rapid data recovery.
Incorrect
The Cloud Endpoint in Azure holds the master copy of the data. Registering a new server and adding it as a Server Endpoint allows for rapid data recovery.
Unattempted
The Cloud Endpoint in Azure holds the master copy of the data. Registering a new server and adding it as a Server Endpoint allows for rapid data recovery.
Question 9 of 60
9. Question
You are managing a hybrid Active Directory. You want to implement ‘Password Writeback’. Where is this feature configured?
Correct
Password Writeback is enabled within the ‘Optional Features’ section of the Azure AD Connect configuration.
Incorrect
Password Writeback is enabled within the ‘Optional Features’ section of the Azure AD Connect configuration.
Unattempted
Password Writeback is enabled within the ‘Optional Features’ section of the Azure AD Connect configuration.
Question 10 of 60
10. Question
You are configuring Azure AD Connect. You want to implement ‘Seamless Single Sign-On’. What is a requirement for the client computers?
Correct
Seamless SSO requires the user to be on a domain-joined device connected to the corporate network to automatically sign them in.
Incorrect
Seamless SSO requires the user to be on a domain-joined device connected to the corporate network to automatically sign them in.
Unattempted
Seamless SSO requires the user to be on a domain-joined device connected to the corporate network to automatically sign them in.
Question 11 of 60
11. Question
You are managing a hybrid DNS environment. You want your Azure VMs to resolve names of servers in your on-premises domain ‘corp.contoso.com’. What should you configure in Azure?
Correct
An Azure DNS Private Resolver with an outbound endpoint and a forwarding rule can send queries for specific domains to your on-premises DNS servers.
Incorrect
An Azure DNS Private Resolver with an outbound endpoint and a forwarding rule can send queries for specific domains to your on-premises DNS servers.
Unattempted
An Azure DNS Private Resolver with an outbound endpoint and a forwarding rule can send queries for specific domains to your on-premises DNS servers.
Question 12 of 60
12. Question
You are configuring a site-to-site VPN between your on-premises data center and an Azure Virtual Network. Which Windows Server role should you install on a server to act as the VPN gateway if you are not using a hardware appliance?
Correct
The Remote Access role (including Routing and Remote Access Service or RRAS) allows a Windows Server to function as a VPN gateway.
Incorrect
The Remote Access role (including Routing and Remote Access Service or RRAS) allows a Windows Server to function as a VPN gateway.
Unattempted
The Remote Access role (including Routing and Remote Access Service or RRAS) allows a Windows Server to function as a VPN gateway.
Question 13 of 60
13. Question
You are managing an Azure Virtual Desktop environment. You need to store user profile containers using FSLogix. Which storage service is recommended for low latency and integration with Active Directory?
Correct
Azure Files (specifically with AD DS or Azure AD DS authentication) is the standard storage solution for FSLogix profiles.
Incorrect
Azure Files (specifically with AD DS or Azure AD DS authentication) is the standard storage solution for FSLogix profiles.
Unattempted
Azure Files (specifically with AD DS or Azure AD DS authentication) is the standard storage solution for FSLogix profiles.
Question 14 of 60
14. Question
You are configuring Azure Site Recovery. You want to group multiple VMs together so they fail over at the same time and maintain data consistency. What should you create?
Correct
Recovery Plans in ASR allow you to group VMs, define the order of failover, and add manual or automated steps (like scripts).
Incorrect
Recovery Plans in ASR allow you to group VMs, define the order of failover, and add manual or automated steps (like scripts).
Unattempted
Recovery Plans in ASR allow you to group VMs, define the order of failover, and add manual or automated steps (like scripts).
Question 15 of 60
15. Question
You are configuring a new Storage Spaces Direct (S2D) cluster. You have a mix of SSDs and HDDs. How does S2D use these drives by default?
Correct
S2D automatically uses the fastest drives (SSDs/NVMe) for a read/write cache and slower drives (HDDs) for persistent data storage.
Incorrect
S2D automatically uses the fastest drives (SSDs/NVMe) for a read/write cache and slower drives (HDDs) for persistent data storage.
Unattempted
S2D automatically uses the fastest drives (SSDs/NVMe) for a read/write cache and slower drives (HDDs) for persistent data storage.
Question 16 of 60
16. Question
You are managing an Azure Stack HCI cluster. You need to configure ‘Cluster-Aware Updating’ (CAU). You want to ensure that the cluster automatically retries the update process if a node fails to reboot. Which two settings should you configure in the CAU profile?
Correct
The ‘MaxRetriesPerNode’ setting defines how many times CAU will attempt to patch/reboot a node. ‘StopAfterFailures’ allows you to define a threshold where the entire update run should cease to prevent widespread downtime if a systemic issue occurs.
Incorrect
The ‘MaxRetriesPerNode’ setting defines how many times CAU will attempt to patch/reboot a node. ‘StopAfterFailures’ allows you to define a threshold where the entire update run should cease to prevent widespread downtime if a systemic issue occurs.
Unattempted
The ‘MaxRetriesPerNode’ setting defines how many times CAU will attempt to patch/reboot a node. ‘StopAfterFailures’ allows you to define a threshold where the entire update run should cease to prevent widespread downtime if a systemic issue occurs.
Question 17 of 60
17. Question
You are configuring a Windows Server hybrid environment. You need to ensure that administrative tasks performed via Windows Admin Center are logged for auditing purposes. Which type of logging should you enable within Windows Admin Center settings?
Correct
Windows Admin Center uses PowerShell under the hood; enabling PowerShell logging captures the scripts and commands executed by the tool for auditing.
Incorrect
Windows Admin Center uses PowerShell under the hood; enabling PowerShell logging captures the scripts and commands executed by the tool for auditing.
Unattempted
Windows Admin Center uses PowerShell under the hood; enabling PowerShell logging captures the scripts and commands executed by the tool for auditing.
Question 18 of 60
18. Question
You are deploying a 2-node failover cluster in a remote branch office. You do not have a third server for a file share witness and no local SAN. How should you configure quorum?
Correct
A Cloud Witness is the recommended quorum tie-breaker for 2-node clusters that have internet connectivity and no third physical site.
Incorrect
A Cloud Witness is the recommended quorum tie-breaker for 2-node clusters that have internet connectivity and no third physical site.
Unattempted
A Cloud Witness is the recommended quorum tie-breaker for 2-node clusters that have internet connectivity and no third physical site.
Question 19 of 60
19. Question
You are configuring a ‘Scale-Out File Server’ (SoFS) cluster. What is the primary use case for an SoFS?
Correct
SoFS is designed for ‘continuously available’ storage for server applications like Hyper-V and SQL Server; it is not recommended for standard user home folders.
Incorrect
SoFS is designed for ‘continuously available’ storage for server applications like Hyper-V and SQL Server; it is not recommended for standard user home folders.
Unattempted
SoFS is designed for ‘continuously available’ storage for server applications like Hyper-V and SQL Server; it is not recommended for standard user home folders.
Question 20 of 60
20. Question
A user reports they cannot access a shared folder. You suspect the NTFS permissions are correct but the Share permissions are restrictive. Which statement is true regarding the relationship between Share and NTFS permissions?
Correct
When accessing a file through a network share Windows calculates both the Share and NTFS permissions and applies the most restrictive result.
Incorrect
When accessing a file through a network share Windows calculates both the Share and NTFS permissions and applies the most restrictive result.
Unattempted
When accessing a file through a network share Windows calculates both the Share and NTFS permissions and applies the most restrictive result.
Question 21 of 60
21. Question
You are configuring a Site-to-Site VPN between an on-premises network and Azure. The on-premises VPN device has a dynamic public IP address. Which Azure VPN Gateway type should you use?
Correct
Route-based gateways are required for features like IKEv2 and are more flexible for handling dynamic IP changes and multi-site connections.
Incorrect
Route-based gateways are required for features like IKEv2 and are more flexible for handling dynamic IP changes and multi-site connections.
Unattempted
Route-based gateways are required for features like IKEv2 and are more flexible for handling dynamic IP changes and multi-site connections.
Question 22 of 60
22. Question
You are managing a hybrid Windows Server environment. You need to monitor the performance of on-premises servers using Azure Monitor. You have installed the Azure Connected Machine agent. What is the next step to collect performance counters into a Log Analytics workspace?
Correct
Data Collection Rules (DCRs) define what data should be collected from Azure Arc-enabled servers and where that data should be sent.
Incorrect
Data Collection Rules (DCRs) define what data should be collected from Azure Arc-enabled servers and where that data should be sent.
Unattempted
Data Collection Rules (DCRs) define what data should be collected from Azure Arc-enabled servers and where that data should be sent.
Question 23 of 60
23. Question
You are configuring ‘Cloud Tiering’ in Azure File Sync. You set the ‘Volume Free Space’ policy to 20%. The volume size is 1 TB. What happens when the local volume reaches 850 GB of used space?
Correct
The policy ensures that a specific percentage of space remains free by offloading ‘cold’ files to the cloud.
Incorrect
The policy ensures that a specific percentage of space remains free by offloading ‘cold’ files to the cloud.
Unattempted
The policy ensures that a specific percentage of space remains free by offloading ‘cold’ files to the cloud.
Question 24 of 60
24. Question
You are configuring ‘Azure File Sync’. You have a server in a remote location with very slow internet. What should you use to perform the initial bulk data transfer to Azure?
Correct
Azure Data Box allows you to ship a physical device to an Azure data center for high-speed offline data ingestion into your storage account.
Incorrect
Azure Data Box allows you to ship a physical device to an Azure data center for high-speed offline data ingestion into your storage account.
Unattempted
Azure Data Box allows you to ship a physical device to an Azure data center for high-speed offline data ingestion into your storage account.
Question 25 of 60
25. Question
You are configuring Azure AD Connect. You want to ensure that if a user’s account is disabled in the on-premises Active Directory, their access to cloud resources is revoked immediately. Which feature handles this?
Correct
Azure AD Connect synchronizes changes (including account status) from on-premises to Azure AD during its regular sync intervals (default 30 mins).
Incorrect
Azure AD Connect synchronizes changes (including account status) from on-premises to Azure AD during its regular sync intervals (default 30 mins).
Unattempted
Azure AD Connect synchronizes changes (including account status) from on-premises to Azure AD during its regular sync intervals (default 30 mins).
Question 26 of 60
26. Question
You are managing a hybrid environment. You need to enable ‘Desktop Analytics’ to plan a Windows 11 deployment. Which tool is used to collect the hardware and app compatibility data?
Correct
Configuration Manager is typically used to connect on-premises device data to the cloud-based Desktop Analytics service.
Incorrect
Configuration Manager is typically used to connect on-premises device data to the cloud-based Desktop Analytics service.
Unattempted
Configuration Manager is typically used to connect on-premises device data to the cloud-based Desktop Analytics service.
Question 27 of 60
27. Question
You are managing a Windows Server 2022 cluster. You need to perform maintenance on Node1. What is the correct first step in Failover Cluster Manager?
Correct
Pausing and Draining roles moves all running workloads to other nodes in the cluster before you begin maintenance.
Incorrect
Pausing and Draining roles moves all running workloads to other nodes in the cluster before you begin maintenance.
Unattempted
Pausing and Draining roles moves all running workloads to other nodes in the cluster before you begin maintenance.
Question 28 of 60
28. Question
You are implementing Azure File Sync. You have multiple offices. You want users in the London office to access a local cache of the ‘Finance’ share, while users in the New York office access a local cache of the same ‘Finance’ share. How should you configure the Sync Groups?
Correct
A single Sync Group defines the topology for a set of files. It contains one Cloud Endpoint (the Azure File Share) and multiple Server Endpoints (one for each physical location).
Incorrect
A single Sync Group defines the topology for a set of files. It contains one Cloud Endpoint (the Azure File Share) and multiple Server Endpoints (one for each physical location).
Unattempted
A single Sync Group defines the topology for a set of files. It contains one Cloud Endpoint (the Azure File Share) and multiple Server Endpoints (one for each physical location).
Question 29 of 60
29. Question
You are configuring a Site-to-Site VPN. You need to ensure the connection is ‘highly available’. What is the best practice in Azure?
Correct
An Active-Active gateway configuration provides two separate tunnel endpoints each with its own public IP for maximum redundancy.
Incorrect
An Active-Active gateway configuration provides two separate tunnel endpoints each with its own public IP for maximum redundancy.
Unattempted
An Active-Active gateway configuration provides two separate tunnel endpoints each with its own public IP for maximum redundancy.
Question 30 of 60
30. Question
You are configuring a Windows Server 2022 failover cluster. You want to ensure that certain VMs never run on the same physical host to ensure high availability. What should you configure?
Correct
Anti-affinity rules (configured via PowerShell) allow you to ensure that specific clustered roles are kept on separate nodes.
Incorrect
Anti-affinity rules (configured via PowerShell) allow you to ensure that specific clustered roles are kept on separate nodes.
Unattempted
Anti-affinity rules (configured via PowerShell) allow you to ensure that specific clustered roles are kept on separate nodes.
Question 31 of 60
31. Question
You are configuring Azure AD Connect. You want to implement ‘Staged Rollout’ to move users from Federation (AD FS) to Password Hash Synchronization (PHS). Which two actions should you take?
Correct
Staged Rollout allows you to test cloud authentication for a subset of users while the domain remains Federated. You enable the feature in the portal and then populate the specific rollout group with test users.
Incorrect
Staged Rollout allows you to test cloud authentication for a subset of users while the domain remains Federated. You enable the feature in the portal and then populate the specific rollout group with test users.
Unattempted
Staged Rollout allows you to test cloud authentication for a subset of users while the domain remains Federated. You enable the feature in the portal and then populate the specific rollout group with test users.
Question 32 of 60
32. Question
You are managing an Azure Stack HCI cluster. You need to monitor the ‘health’ of the physical disks. Which tool provides the most detailed view of ‘Storage Spaces Direct’ (S2D) disk health and bus status?
Correct
While other tools show basic status, Windows Admin Center is purpose-built for HCI. It provides a specialized ‘Drives’ dashboard under the Storage section that shows the physical health, temperature, and wear level of S2D disks.
Incorrect
While other tools show basic status, Windows Admin Center is purpose-built for HCI. It provides a specialized ‘Drives’ dashboard under the Storage section that shows the physical health, temperature, and wear level of S2D disks.
Unattempted
While other tools show basic status, Windows Admin Center is purpose-built for HCI. It provides a specialized ‘Drives’ dashboard under the Storage section that shows the physical health, temperature, and wear level of S2D disks.
Question 33 of 60
33. Question
You are migrating a legacy on-premises application to Azure. The application requires access to a Windows file share that uses SMB. You want to use Azure File Sync. Which two steps are required to initialize the cloud tiering and sync process?
Correct
Azure File Sync requires a cloud-based destination (Azure File share) and the installation of the local agent on the server that will act as the endpoint for synchronization.
Incorrect
Azure File Sync requires a cloud-based destination (Azure File share) and the installation of the local agent on the server that will act as the endpoint for synchronization.
Unattempted
Azure File Sync requires a cloud-based destination (Azure File share) and the installation of the local agent on the server that will act as the endpoint for synchronization.
Question 34 of 60
34. Question
You are troubleshooting Azure AD Connect ‘Password Hash Sync’ (PHS). Users report that when they change their password on-premises, it takes several hours to sync. Which two actions can you take to force a PHS update?
Correct
Running a Delta sync cycle forces the engine to check for changes. The ‘Invoke-ADSyncDiagnostics’ script is specifically designed to troubleshoot and trigger the password synchronization process if it has stalled.
Incorrect
Running a Delta sync cycle forces the engine to check for changes. The ‘Invoke-ADSyncDiagnostics’ script is specifically designed to troubleshoot and trigger the password synchronization process if it has stalled.
Unattempted
Running a Delta sync cycle forces the engine to check for changes. The ‘Invoke-ADSyncDiagnostics’ script is specifically designed to troubleshoot and trigger the password synchronization process if it has stalled.
Question 35 of 60
35. Question
You are configuring a hybrid network. You want to use ‘Azure Private Link’ to access an ‘Azure SQL Managed Instance’ from on-premises. Which two DNS solutions are valid to ensure the FQDN resolves to the Private Endpoint IP?
Correct
Using a Private Resolver is the scalable, automated approach for hybrid DNS. For smaller environments, manually creating A-records on the local DNS server for the specific service FQDN is a valid (though high-maintenance) solution.
Incorrect
Using a Private Resolver is the scalable, automated approach for hybrid DNS. For smaller environments, manually creating A-records on the local DNS server for the specific service FQDN is a valid (though high-maintenance) solution.
Unattempted
Using a Private Resolver is the scalable, automated approach for hybrid DNS. For smaller environments, manually creating A-records on the local DNS server for the specific service FQDN is a valid (though high-maintenance) solution.
Question 36 of 60
36. Question
You are managing an Azure Stack HCI cluster. You need to optimize the storage performance for a SQL Server workload. Which two technologies should you implement?
Correct
RDMA (Remote Direct Memory Access) significantly reduces CPU overhead for storage traffic. Mirror-accelerated parity provides the performance of mirroring for writes and the capacity efficiency of parity for colder data.
Incorrect
RDMA (Remote Direct Memory Access) significantly reduces CPU overhead for storage traffic. Mirror-accelerated parity provides the performance of mirroring for writes and the capacity efficiency of parity for colder data.
Unattempted
RDMA (Remote Direct Memory Access) significantly reduces CPU overhead for storage traffic. Mirror-accelerated parity provides the performance of mirroring for writes and the capacity efficiency of parity for colder data.
Question 37 of 60
37. Question
You are managing several Azure Arc-enabled servers. You want to use ‘Azure Automanage’ to apply best practices. Which two ‘Custom’ configuration profiles can you create if the built-in ones don’t meet your needs?
Correct
Automanage Custom Profiles allow you to pick and choose which Azure management services (Backup, Insights, Guest Config) are applied to your servers, providing more flexibility than the standard Production or Dev/Test profiles.
Incorrect
Automanage Custom Profiles allow you to pick and choose which Azure management services (Backup, Insights, Guest Config) are applied to your servers, providing more flexibility than the standard Production or Dev/Test profiles.
Unattempted
Automanage Custom Profiles allow you to pick and choose which Azure management services (Backup, Insights, Guest Config) are applied to your servers, providing more flexibility than the standard Production or Dev/Test profiles.
Question 38 of 60
38. Question
You are troubleshooting a migration using ‘Azure Migrate’. A Windows Server 2016 VM is failing to replicate. You suspect the issue is related to the ‘Mobility Service’ installation. Which two manual methods can you use to install the agent for a physical server migration?
Correct
While the appliance can push the agent, a manual installation is often used for troubleshooting. This involves downloading the installer and using the project’s registration key to link the agent to the Azure Migrate project.
Incorrect
While the appliance can push the agent, a manual installation is often used for troubleshooting. This involves downloading the installer and using the project’s registration key to link the agent to the Azure Migrate project.
Unattempted
While the appliance can push the agent, a manual installation is often used for troubleshooting. This involves downloading the installer and using the project’s registration key to link the agent to the Azure Migrate project.
Question 39 of 60
39. Question
You are deploying the Azure Monitor Agent (AMA) to 100 hybrid servers. You need to ensure they all use the same configuration for collecting performance data. Which two actions are required?
Correct
The AMA relies on Data Collection Rules (DCRs) to define what data to collect. Once a DCR is created, it must be associated with the specific Arc-enabled servers (the targets) to take effect.
Incorrect
The AMA relies on Data Collection Rules (DCRs) to define what data to collect. Once a DCR is created, it must be associated with the specific Arc-enabled servers (the targets) to take effect.
Unattempted
The AMA relies on Data Collection Rules (DCRs) to define what data to collect. Once a DCR is created, it must be associated with the specific Arc-enabled servers (the targets) to take effect.
Question 40 of 60
40. Question
You are configuring a hybrid network with a VPN Gateway. You want to ensure that if the primary VPN tunnel fails, the traffic automatically switches to a secondary tunnel. Which two configurations support this?
Correct
Route-based gateways are required for multi-tunnel or redundant configurations. BGP is the protocol used to detect a tunnel failure and automatically reroute traffic to the available path without manual intervention.
Incorrect
Route-based gateways are required for multi-tunnel or redundant configurations. BGP is the protocol used to detect a tunnel failure and automatically reroute traffic to the available path without manual intervention.
Unattempted
Route-based gateways are required for multi-tunnel or redundant configurations. BGP is the protocol used to detect a tunnel failure and automatically reroute traffic to the available path without manual intervention.
Question 41 of 60
41. Question
You are deploying a new Azure Stack HCI cluster. You need to ensure the networking is compliant with ‘Network ATC’ requirements. Which two statements describe the benefits of using Network ATC?
Correct
Network ATC (Intent-based networking) ensures that all nodes have an identical network configuration and continuously monitors the nodes to correct any ‘drift’ that occurs after the initial setup.
Incorrect
Network ATC (Intent-based networking) ensures that all nodes have an identical network configuration and continuously monitors the nodes to correct any ‘drift’ that occurs after the initial setup.
Unattempted
Network ATC (Intent-based networking) ensures that all nodes have an identical network configuration and continuously monitors the nodes to correct any ‘drift’ that occurs after the initial setup.
Question 42 of 60
42. Question
You are configuring Azure Stack HCI networking using ‘Network ATC’. You want to ensure that ‘Storage’ traffic uses a specific VLAN. Which two steps should you take?
Correct
Network ATC allows you to specify the VLAN for storage traffic as part of the intent definition. However, the physical network infrastructure (switches) must also be configured to allow or tag that specific VLAN for the traffic to flow.
Incorrect
Network ATC allows you to specify the VLAN for storage traffic as part of the intent definition. However, the physical network infrastructure (switches) must also be configured to allow or tag that specific VLAN for the traffic to flow.
Unattempted
Network ATC allows you to specify the VLAN for storage traffic as part of the intent definition. However, the physical network infrastructure (switches) must also be configured to allow or tag that specific VLAN for the traffic to flow.
Question 43 of 60
43. Question
You are configuring a hybrid network using an Azure VPN Gateway. You need to ensure that on-premises users can resolve names for Azure Resources in a Private DNS zone. Which two components should you deploy in Azure?
Correct
To resolve Azure Private DNS names from on-premises, you need the Azure DNS Private Resolver. Specifically, you must configure an ‘inbound endpoint’ which provides an IP address that your on-premises DNS servers can use as a forwarder target.
Incorrect
To resolve Azure Private DNS names from on-premises, you need the Azure DNS Private Resolver. Specifically, you must configure an ‘inbound endpoint’ which provides an IP address that your on-premises DNS servers can use as a forwarder target.
Unattempted
To resolve Azure Private DNS names from on-premises, you need the Azure DNS Private Resolver. Specifically, you must configure an ‘inbound endpoint’ which provides an IP address that your on-premises DNS servers can use as a forwarder target.
Question 44 of 60
44. Question
You are setting up a hybrid network. You want to ensure that all DNS queries for ‘.azure.com’ from on-premises are resolved by Azure Private DNS. Which two components are required?
Correct
The Azure DNS Private Resolver provides an inbound endpoint in Azure. You then configure a Conditional Forwarder on your local DNS server to point all queries for the Azure namespace to that inbound IP address.
Incorrect
The Azure DNS Private Resolver provides an inbound endpoint in Azure. You then configure a Conditional Forwarder on your local DNS server to point all queries for the Azure namespace to that inbound IP address.
Unattempted
The Azure DNS Private Resolver provides an inbound endpoint in Azure. You then configure a Conditional Forwarder on your local DNS server to point all queries for the Azure namespace to that inbound IP address.
Question 45 of 60
45. Question
You are managing a hybrid storage environment. You want to use ‘Azure Storage Mover’ to migrate data from an on-premises SMB share to an Azure File share. Which component must be installed on-premises?
Correct
Azure Storage Mover requires a specialized agent, typically deployed as a VMware or Hyper-V virtual appliance on-premises, to handle the data transfer and communication with the Storage Mover service in Azure.
Incorrect
Azure Storage Mover requires a specialized agent, typically deployed as a VMware or Hyper-V virtual appliance on-premises, to handle the data transfer and communication with the Storage Mover service in Azure.
Unattempted
Azure Storage Mover requires a specialized agent, typically deployed as a VMware or Hyper-V virtual appliance on-premises, to handle the data transfer and communication with the Storage Mover service in Azure.
Question 46 of 60
46. Question
A company plans to use Azure Relay to connect an on-premises web service to an Azure Logic App. You need to ensure that the on-premises service can be accessed without opening inbound firewall ports. Which two actions are necessary to implement this?
Correct
Azure Relay Hybrid Connections allow for a secure, outbound-only connection from the on-premises network to the cloud, eliminating the need for inbound firewall rules while providing a relay point for the Logic App.
Incorrect
Azure Relay Hybrid Connections allow for a secure, outbound-only connection from the on-premises network to the cloud, eliminating the need for inbound firewall rules while providing a relay point for the Logic App.
Unattempted
Azure Relay Hybrid Connections allow for a secure, outbound-only connection from the on-premises network to the cloud, eliminating the need for inbound firewall rules while providing a relay point for the Logic App.
Question 47 of 60
47. Question
You are implementing Azure File Sync for a large department. You need to ensure that the synchronization is as efficient as possible and that you can recover from a server failure quickly. Which two actions should you take to optimize the initial sync and disaster recovery?
Correct
Pre-seeding data with AzCopy reduces the time spent on initial sync over the network. The ‘Offline Data Transfer’ feature (using Azure Data Box) is specifically designed for large initial data migrations to Azure File Sync.
Incorrect
Pre-seeding data with AzCopy reduces the time spent on initial sync over the network. The ‘Offline Data Transfer’ feature (using Azure Data Box) is specifically designed for large initial data migrations to Azure File Sync.
Unattempted
Pre-seeding data with AzCopy reduces the time spent on initial sync over the network. The ‘Offline Data Transfer’ feature (using Azure Data Box) is specifically designed for large initial data migrations to Azure File Sync.
Question 48 of 60
48. Question
You are managing several Azure Arc-enabled servers. You need to run a PowerShell script on all of them to update a local configuration file. Which two Azure features allow you to do this without a VPN?
Correct
The Custom Script Extension is the simplest way to push a script via Arc. For more complex, ongoing automation, a Hybrid Runbook Worker allows the Azure Automation service to execute jobs directly on the local server.
Incorrect
The Custom Script Extension is the simplest way to push a script via Arc. For more complex, ongoing automation, a Hybrid Runbook Worker allows the Azure Automation service to execute jobs directly on the local server.
Unattempted
The Custom Script Extension is the simplest way to push a script via Arc. For more complex, ongoing automation, a Hybrid Runbook Worker allows the Azure Automation service to execute jobs directly on the local server.
Question 49 of 60
49. Question
You are configuring a Windows Server hybrid environment and want to use Azure File Sync. You need to ensure that the server endpoints are highly available. Which two configurations are supported for high availability?
Correct
Azure File Sync supports Windows Server Failover Clusters and Azure Stack HCI. However, it is not compatible with DFS-R on the same volume, as both services attempt to manage the file metadata and replication.
Incorrect
Azure File Sync supports Windows Server Failover Clusters and Azure Stack HCI. However, it is not compatible with DFS-R on the same volume, as both services attempt to manage the file metadata and replication.
Unattempted
Azure File Sync supports Windows Server Failover Clusters and Azure Stack HCI. However, it is not compatible with DFS-R on the same volume, as both services attempt to manage the file metadata and replication.
Question 50 of 60
50. Question
You are configuring Azure Stack HCI networking. You need to ensure high availability for the management and compute traffic. Which two technologies should you combine for the physical network adapters?
Correct
Switch Embedded Teaming (SET) is the recommended teaming solution for Azure Stack HCI to provide HA, while RDMA (via RoCE or iWARP) is critical for high-performance storage and cluster heartbeat traffic.
Incorrect
Switch Embedded Teaming (SET) is the recommended teaming solution for Azure Stack HCI to provide HA, while RDMA (via RoCE or iWARP) is critical for high-performance storage and cluster heartbeat traffic.
Unattempted
Switch Embedded Teaming (SET) is the recommended teaming solution for Azure Stack HCI to provide HA, while RDMA (via RoCE or iWARP) is critical for high-performance storage and cluster heartbeat traffic.
Question 51 of 60
51. Question
You are configuring ‘Azure Site Recovery’ (ASR) for on-premises servers. You want to ensure that VMs can be failed over to a specific ‘Isolated’ virtual network for testing. Which two settings should you configure in the ‘Compute and Network’ properties of the replicated item?
Correct
ASR allows you to specify a separate VNet for ‘Test Failover’ purposes. This ensures that the test VM does not conflict with production workloads or IP addresses while verifying the recovery plan.
Incorrect
ASR allows you to specify a separate VNet for ‘Test Failover’ purposes. This ensures that the test VM does not conflict with production workloads or IP addresses while verifying the recovery plan.
Unattempted
ASR allows you to specify a separate VNet for ‘Test Failover’ purposes. This ensures that the test VM does not conflict with production workloads or IP addresses while verifying the recovery plan.
Question 52 of 60
52. Question
You are managing an Azure Stack HCI cluster. You need to update the operating system on all nodes while ensuring that virtual machines remain highly available during the process. Which two tools or features should you use?
Correct
Cluster-Aware Updating (CAU) automates the process of putting nodes in maintenance mode and moving VMs (Live Migration) before patching. Windows Admin Center provides the recommended graphical interface to orchestrate these HCI updates.
Incorrect
Cluster-Aware Updating (CAU) automates the process of putting nodes in maintenance mode and moving VMs (Live Migration) before patching. Windows Admin Center provides the recommended graphical interface to orchestrate these HCI updates.
Unattempted
Cluster-Aware Updating (CAU) automates the process of putting nodes in maintenance mode and moving VMs (Live Migration) before patching. Windows Admin Center provides the recommended graphical interface to orchestrate these HCI updates.
Question 53 of 60
53. Question
You are managing a hybrid identity solution. You need to ensure that when a user account is disabled in the on-premises Active Directory, the corresponding user cannot sign in to Microsoft 365 within 30 minutes. Which two features or settings should you verify?
Correct
The Delta Sync schedule (defaulting to 30 mins) ensures the account status is updated in the cloud. Continuous Access Evaluation (CAE) allows Microsoft 365 services to revoke access in near real-time when an account is disabled or a password is reset.
Incorrect
The Delta Sync schedule (defaulting to 30 mins) ensures the account status is updated in the cloud. Continuous Access Evaluation (CAE) allows Microsoft 365 services to revoke access in near real-time when an account is disabled or a password is reset.
Unattempted
The Delta Sync schedule (defaulting to 30 mins) ensures the account status is updated in the cloud. Continuous Access Evaluation (CAE) allows Microsoft 365 services to revoke access in near real-time when an account is disabled or a password is reset.
Question 54 of 60
54. Question
You are configuring a hybrid network with a VPN Gateway. You want to use ‘Azure Private Link’ to access a SQL database. Which two statements are true regarding Private Link over VPN?
Correct
Private Link allows you to access Azure services via a Private Endpoint (an internal IP). This traffic travels over the VPN/ExpressRoute, meaning you never use the service’s public IP or need to open public firewall ports.
Incorrect
Private Link allows you to access Azure services via a Private Endpoint (an internal IP). This traffic travels over the VPN/ExpressRoute, meaning you never use the service’s public IP or need to open public firewall ports.
Unattempted
Private Link allows you to access Azure services via a Private Endpoint (an internal IP). This traffic travels over the VPN/ExpressRoute, meaning you never use the service’s public IP or need to open public firewall ports.
Question 55 of 60
55. Question
You are implementing Azure AD Application Proxy to provide remote access to an internal web application. Which two authentication methods are supported for ‘Pre-authentication’?
Correct
Application Proxy supports ‘Azure AD’ pre-authentication (forcing sign-in before reaching the app) or ‘Pass-through’ (letting the app handle its own auth). While KCD is used for the backend, it is not a pre-authentication type.
Incorrect
Application Proxy supports ‘Azure AD’ pre-authentication (forcing sign-in before reaching the app) or ‘Pass-through’ (letting the app handle its own auth). While KCD is used for the backend, it is not a pre-authentication type.
Unattempted
Application Proxy supports ‘Azure AD’ pre-authentication (forcing sign-in before reaching the app) or ‘Pass-through’ (letting the app handle its own auth). While KCD is used for the backend, it is not a pre-authentication type.
Question 56 of 60
56. Question
You are configuring ‘Azure AD Connect’ for a multi-forest environment. You need to ensure that a single user with accounts in two different forests is represented as a single object in Microsoft Entra ID. Which attribute should you use for ‘consistency’ across forests?
Correct
Using mS-DS-ConsistencyGuid is the recommended best practice for the source anchor. It allows for a consistent identity even if the user is moved between forests or if their UPN changes, preventing duplicate objects in the cloud.
Incorrect
Using mS-DS-ConsistencyGuid is the recommended best practice for the source anchor. It allows for a consistent identity even if the user is moved between forests or if their UPN changes, preventing duplicate objects in the cloud.
Unattempted
Using mS-DS-ConsistencyGuid is the recommended best practice for the source anchor. It allows for a consistent identity even if the user is moved between forests or if their UPN changes, preventing duplicate objects in the cloud.
Question 57 of 60
57. Question
You are managing an Azure Stack HCI cluster. You need to configure ‘Network ATC’ to manage the networking intents. You want to combine ‘Compute’ and ‘Storage’ traffic on the same physical adapters. Which two steps are part of this process?
Correct
Network ATC allows you to define a single intent that covers multiple traffic types. For storage traffic, the physical NICs must support RDMA to ensure performance and compatibility with the ATC-defined configuration.
Incorrect
Network ATC allows you to define a single intent that covers multiple traffic types. For storage traffic, the physical NICs must support RDMA to ensure performance and compatibility with the ATC-defined configuration.
Unattempted
Network ATC allows you to define a single intent that covers multiple traffic types. For storage traffic, the physical NICs must support RDMA to ensure performance and compatibility with the ATC-defined configuration.
Question 58 of 60
58. Question
You are troubleshooting ‘Azure AD Connect’ Password Hash Sync. You find that passwords are not syncing for a specific set of users. Which two factors should you investigate?
Correct
Password Hash Sync will not process accounts if the ‘User must change password at next logon’ flag is set or if the service account lacks the ‘Replicating Directory Changes’ permission on those specific user objects.
Incorrect
Password Hash Sync will not process accounts if the ‘User must change password at next logon’ flag is set or if the service account lacks the ‘Replicating Directory Changes’ permission on those specific user objects.
Unattempted
Password Hash Sync will not process accounts if the ‘User must change password at next logon’ flag is set or if the service account lacks the ‘Replicating Directory Changes’ permission on those specific user objects.
Question 59 of 60
59. Question
You are managing an Azure Stack HCI cluster. You need to implement ‘Storage Replica’ to replicate a volume to a single standalone Windows Server 2022 in a different site. Which two replication types are supported?
Correct
Storage Replica supports ‘Server-to-Server’ (two standalone nodes) and ‘Cluster-to-Server’ (an entire cluster replicating to a single destination node for DR), in addition to the standard Cluster-to-Cluster configuration.
Incorrect
Storage Replica supports ‘Server-to-Server’ (two standalone nodes) and ‘Cluster-to-Server’ (an entire cluster replicating to a single destination node for DR), in addition to the standard Cluster-to-Cluster configuration.
Unattempted
Storage Replica supports ‘Server-to-Server’ (two standalone nodes) and ‘Cluster-to-Server’ (an entire cluster replicating to a single destination node for DR), in addition to the standard Cluster-to-Cluster configuration.
Question 60 of 60
60. Question
You are configuring Azure AD Connect. You need to ensure that only users located in a specific Organizational Unit (OU) are synchronized to Azure. Which filtering method should you use?
Correct
OU-based filtering is the most common and efficient way to control sync scope during the initial installation or by modifying the connector properties in the Synchronization Service Manager.
Incorrect
OU-based filtering is the most common and efficient way to control sync scope during the initial installation or by modifying the connector properties in the Synchronization Service Manager.
Unattempted
OU-based filtering is the most common and efficient way to control sync scope during the initial installation or by modifying the connector properties in the Synchronization Service Manager.
X
Use Page numbers below to navigate to other practice tests