You have already completed the Test before. Hence you can not start it again.
Test is loading...
You must sign in or sign up to start the Test.
You have to finish following quiz, to start this Test:
Your results are here!! for" AZ-802 Practice Test 6 "
0 of 60 questions answered correctly
Your time:
Time has elapsed
Your Final Score is : 0
You have attempted : 0
Number of Correct Questions : 0 and scored 0
Number of Incorrect Questions : 0 and Negative marks 0
Average score
Your score
AZ-802
You have attempted: 0
Number of Correct Questions: 0 and scored 0
Number of Incorrect Questions: 0 and Negative marks 0
You can review your answers by clicking on “View Answers” option. Important Note : Open Reference Documentation Links in New Tab (Right Click and Open in New Tab).
Answer Review
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Answer
Review
Unattempted
Correct
Incorrect
Unattempted
Every question in this attempt was answered correctly.
Question 1 of 60
1. Question
You have a hybrid environment where on-premises servers need to access Azure Key Vault secrets securely. Which two methods can be used to authenticate the on-premises servers to Azure AD for Key Vault access?
Correct
Azure Arc-enabled servers can be assigned a System-Assigned Managed Identity, allowing them to authenticate like Azure resources. Alternatively, a Service Principal with a certificate is a standard method for non-Azure resources.
Incorrect
Azure Arc-enabled servers can be assigned a System-Assigned Managed Identity, allowing them to authenticate like Azure resources. Alternatively, a Service Principal with a certificate is a standard method for non-Azure resources.
Unattempted
Azure Arc-enabled servers can be assigned a System-Assigned Managed Identity, allowing them to authenticate like Azure resources. Alternatively, a Service Principal with a certificate is a standard method for non-Azure resources.
Question 2 of 60
2. Question
You are configuring a Windows Server 2022 VM in Azure. You want to enable ‘Nested Virtualization’. Which VM size series supports this feature?
Correct
Nested virtualization (running Hyper-V inside an Azure VM) requires VM sizes that support hardware virtualization such as the v3 series and newer.
Incorrect
Nested virtualization (running Hyper-V inside an Azure VM) requires VM sizes that support hardware virtualization such as the v3 series and newer.
Unattempted
Nested virtualization (running Hyper-V inside an Azure VM) requires VM sizes that support hardware virtualization such as the v3 series and newer.
Question 3 of 60
3. Question
You are managing a hybrid environment. You need to migrate a user’s local profile from an old PC to a new PC. Which legacy tool is still often used for this in enterprise environments?
Correct
USMT is a command-line utility used by IT professionals to migrate user data and settings during large-scale deployments of Windows.
Incorrect
USMT is a command-line utility used by IT professionals to migrate user data and settings during large-scale deployments of Windows.
Unattempted
USMT is a command-line utility used by IT professionals to migrate user data and settings during large-scale deployments of Windows.
Question 4 of 60
4. Question
You are configuring ‘Azure AD Password Protection’. You want to add specific words like your ‘Company Name’ to the banned list. Where do you do this?
Correct
The custom banned password list is managed globally in the Azure portal and then synchronized to your on-premises DCs.
Incorrect
The custom banned password list is managed globally in the Azure portal and then synchronized to your on-premises DCs.
Unattempted
The custom banned password list is managed globally in the Azure portal and then synchronized to your on-premises DCs.
Question 5 of 60
5. Question
You are implementing Azure AD Password Protection for your on-premises Active Directory. What are the two components you must install on-premises?
Correct
The Proxy service communicates with Azure to get the banned password lists, and the DC agent enforces those rules during password changes.
Incorrect
The Proxy service communicates with Azure to get the banned password lists, and the DC agent enforces those rules during password changes.
Unattempted
The Proxy service communicates with Azure to get the banned password lists, and the DC agent enforces those rules during password changes.
Question 6 of 60
6. Question
You are configuring Azure Backup for an Azure VM. You want to ensure the backup data is replicated to a secondary, paired region. Which storage redundancy should you choose for the Recovery Services Vault?
Correct
GRS replicates your data to a secondary region hundreds of miles away from the primary region, providing the highest level of durability for backups.
Incorrect
GRS replicates your data to a secondary region hundreds of miles away from the primary region, providing the highest level of durability for backups.
Unattempted
GRS replicates your data to a secondary region hundreds of miles away from the primary region, providing the highest level of durability for backups.
Question 7 of 60
7. Question
You are managing an Azure Virtual Network. You want to use ‘VNet Peering’ to connect two networks in different regions. What is this called?
Correct
Global VNet Peering allows you to connect Azure Virtual Networks across different regions with high bandwidth and low latency.
Incorrect
Global VNet Peering allows you to connect Azure Virtual Networks across different regions with high bandwidth and low latency.
Unattempted
Global VNet Peering allows you to connect Azure Virtual Networks across different regions with high bandwidth and low latency.
Question 8 of 60
8. Question
You are configuring a hybrid DNS solution. You want on-premises clients to be able to resolve names of resources in an Azure Private DNS Zone. What should you deploy in Azure?
Correct
Azure DNS Private Resolver is a cloud-native service that allows you to query Azure Private DNS zones from on-premises environments and vice versa.
Incorrect
Azure DNS Private Resolver is a cloud-native service that allows you to query Azure Private DNS zones from on-premises environments and vice versa.
Unattempted
Azure DNS Private Resolver is a cloud-native service that allows you to query Azure Private DNS zones from on-premises environments and vice versa.
Question 9 of 60
9. Question
You are managing an Azure Arc-enabled server. You want to ensure that the server is always compliant with the ‘PCI-DSS’ security standard. Which Azure service allows you to assign this regulatory compliance initiative?
Correct
Azure Policy allows you to assign built-in initiatives for regulatory compliance to both Azure and Arc-enabled resources.
Incorrect
Azure Policy allows you to assign built-in initiatives for regulatory compliance to both Azure and Arc-enabled resources.
Unattempted
Azure Policy allows you to assign built-in initiatives for regulatory compliance to both Azure and Arc-enabled resources.
Question 10 of 60
10. Question
You are configuring ‘Azure Site Recovery’. You want to perform a ‘Planned Failover’. What is the primary difference between a Planned and Unplanned failover?
Correct
Planned failover is used when you know a downtime is coming; it ensures the most recent data is replicated before the failover occurs.
Incorrect
Planned failover is used when you know a downtime is coming; it ensures the most recent data is replicated before the failover occurs.
Unattempted
Planned failover is used when you know a downtime is coming; it ensures the most recent data is replicated before the failover occurs.
Question 11 of 60
11. Question
You are configuring ‘Azure AD Pass-through Authentication’. Where does the actual password validation happen?
Correct
With PTA the user’s password is encrypted and sent to an on-premises agent which validates it directly against your local Active Directory.
Incorrect
With PTA the user’s password is encrypted and sent to an on-premises agent which validates it directly against your local Active Directory.
Unattempted
With PTA the user’s password is encrypted and sent to an on-premises agent which validates it directly against your local Active Directory.
Question 12 of 60
12. Question
You are managing a hybrid identity environment. You need to identify which on-premises Active Directory accounts have passwords that have never been changed. Which PowerShell cmdlet should you use?
Correct
Search-ADAccount -PasswordNeverExpires is a common command used to audit account security within an Active Directory environment.
Incorrect
Search-ADAccount -PasswordNeverExpires is a common command used to audit account security within an Active Directory environment.
Unattempted
Search-ADAccount -PasswordNeverExpires is a common command used to audit account security within an Active Directory environment.
Question 13 of 60
13. Question
You are managing an Azure Virtual Desktop environment. You want to use ‘FSLogix’ for user profiles. What happens to the user’s profile when they log out?
Correct
FSLogix captures the entire user profile into a virtual disk file that is mounted when the user logs in and unmounted when they log out.
Incorrect
FSLogix captures the entire user profile into a virtual disk file that is mounted when the user logs in and unmounted when they log out.
Unattempted
FSLogix captures the entire user profile into a virtual disk file that is mounted when the user logs in and unmounted when they log out.
Question 14 of 60
14. Question
You are configuring a Windows Server 2022 Azure Edition VM. You want to use the ‘Automanage for Windows Server’ Best Practices. Which of the following is a capability of the ‘Production’ profile in Automanage?
Correct
The Production profile in Automanage applies a comprehensive set of Azure best practices, including Backup, Monitoring, and Security configurations.
Incorrect
The Production profile in Automanage applies a comprehensive set of Azure best practices, including Backup, Monitoring, and Security configurations.
Unattempted
The Production profile in Automanage applies a comprehensive set of Azure best practices, including Backup, Monitoring, and Security configurations.
Question 15 of 60
15. Question
You are managing a hybrid DNS environment. You want to ensure that when an on-premises client queries ‘server1.azure.contoso.com’, the request is automatically sent to Azure. What should you create on your on-premises DNS server?
Correct
A Conditional Forwarder tells the on-premises DNS server to send all queries for a specific domain suffix (like azure.contoso.com) to a specific IP address (the Azure DNS Resolver).
Incorrect
A Conditional Forwarder tells the on-premises DNS server to send all queries for a specific domain suffix (like azure.contoso.com) to a specific IP address (the Azure DNS Resolver).
Unattempted
A Conditional Forwarder tells the on-premises DNS server to send all queries for a specific domain suffix (like azure.contoso.com) to a specific IP address (the Azure DNS Resolver).
Question 16 of 60
16. Question
You are implementing ‘Just Enough Administration’ (JEA) on a Windows Server. What is the primary purpose of JEA?
Correct
JEA is a security technology that enables role-based administration through restricted PowerShell endpoints.
Incorrect
JEA is a security technology that enables role-based administration through restricted PowerShell endpoints.
Unattempted
JEA is a security technology that enables role-based administration through restricted PowerShell endpoints.
Question 17 of 60
17. Question
You have a hybrid identity solution using Pass-through Authentication (PTA). Users report they cannot sign in when the primary on-premises server is offline. Which two actions should you take to ensure high availability?
Correct
Installing multiple PTA agents (up to 12) provides high availability for the authentication service. Enabling PHS as a backup ensures that if all PTA agents fail, users can still sign in using cloud-stored hashes.
Incorrect
Installing multiple PTA agents (up to 12) provides high availability for the authentication service. Enabling PHS as a backup ensures that if all PTA agents fail, users can still sign in using cloud-stored hashes.
Unattempted
Installing multiple PTA agents (up to 12) provides high availability for the authentication service. Enabling PHS as a backup ensures that if all PTA agents fail, users can still sign in using cloud-stored hashes.
Question 18 of 60
18. Question
You have an on-premises Windows Server 2022 server. You need to use the Azure portal to manage its local files and services without opening inbound firewall ports. Which two steps are required?
Correct
Azure Arc provides the management plane for non-Azure servers. By enabling the WAC extension, you get a browser-based management console in the Azure portal that communicates over the secure Arc agent outbound connection.
Incorrect
Azure Arc provides the management plane for non-Azure servers. By enabling the WAC extension, you get a browser-based management console in the Azure portal that communicates over the secure Arc agent outbound connection.
Unattempted
Azure Arc provides the management plane for non-Azure servers. By enabling the WAC extension, you get a browser-based management console in the Azure portal that communicates over the secure Arc agent outbound connection.
Question 19 of 60
19. Question
You have a hybrid network. You want to use ‘Azure Private Link’ to access an Azure Storage Account. You need to ensure that the DNS resolution works for all on-premises clients. Which two components should you use?
Correct
The Private Resolver provides an IP in the VNet that can resolve Private DNS Zones. By pointing a Conditional Forwarder on-premises to this resolver, you automate DNS resolution for the entire local network.
Incorrect
The Private Resolver provides an IP in the VNet that can resolve Private DNS Zones. By pointing a Conditional Forwarder on-premises to this resolver, you automate DNS resolution for the entire local network.
Unattempted
The Private Resolver provides an IP in the VNet that can resolve Private DNS Zones. By pointing a Conditional Forwarder on-premises to this resolver, you automate DNS resolution for the entire local network.
Question 20 of 60
20. Question
You are using ‘Azure Migrate’ to assess on-premises SQL Server instances. You need to determine the recommended Azure SQL deployment option (VM vs. MI vs. DB). Which tool provides this recommendation?
Correct
The Assessment tool within Azure Migrate evaluates SQL performance data and compatibility to suggest the most cost-effective and technically viable Azure SQL target, such as SQL Managed Instance or SQL on VM.
Incorrect
The Assessment tool within Azure Migrate evaluates SQL performance data and compatibility to suggest the most cost-effective and technically viable Azure SQL target, such as SQL Managed Instance or SQL on VM.
Unattempted
The Assessment tool within Azure Migrate evaluates SQL performance data and compatibility to suggest the most cost-effective and technically viable Azure SQL target, such as SQL Managed Instance or SQL on VM.
Question 21 of 60
21. Question
You are using Azure Migrate to move on-premises Windows Servers to Azure. You need to ensure the VMs have the ‘Azure VM Agent’ installed after migration. Which two statements are true?
Correct
While Azure Migrate attempts to install the agent, it is best practice to ensure it is present. For older or highly customized OS images, manual installation might be required to ensure that post-migration extensions (like Backup or Antivirus) work correctly.
Incorrect
While Azure Migrate attempts to install the agent, it is best practice to ensure it is present. For older or highly customized OS images, manual installation might be required to ensure that post-migration extensions (like Backup or Antivirus) work correctly.
Unattempted
While Azure Migrate attempts to install the agent, it is best practice to ensure it is present. For older or highly customized OS images, manual installation might be required to ensure that post-migration extensions (like Backup or Antivirus) work correctly.
Question 22 of 60
22. Question
You have an Azure Stack HCI cluster. You need to verify that the network configuration meets the requirements for ‘Software Defined Networking’ (SDN). Which two tools can you use to validate the environment?
Correct
The ‘Validate-DCB’ script ensures your RDMA/Lossless networking is correct. The Environment Checker is a specialized tool that performs a pre-flight check on hardware and networking to ensure compatibility with HCI and SDN.
Incorrect
The ‘Validate-DCB’ script ensures your RDMA/Lossless networking is correct. The Environment Checker is a specialized tool that performs a pre-flight check on hardware and networking to ensure compatibility with HCI and SDN.
Unattempted
The ‘Validate-DCB’ script ensures your RDMA/Lossless networking is correct. The Environment Checker is a specialized tool that performs a pre-flight check on hardware and networking to ensure compatibility with HCI and SDN.
Question 23 of 60
23. Question
You have an on-premises Hyper-V environment. You need to migrate several virtual machines to Azure using Azure Migrate. Which two discovery methods can you use to identify the virtual machines and their dependencies?
Correct
Azure Migrate supports discovery via a dedicated appliance (the preferred automated method) or by manually importing server metadata through a CSV file for initial assessment.
Incorrect
Azure Migrate supports discovery via a dedicated appliance (the preferred automated method) or by manually importing server metadata through a CSV file for initial assessment.
Unattempted
Azure Migrate supports discovery via a dedicated appliance (the preferred automated method) or by manually importing server metadata through a CSV file for initial assessment.
Question 24 of 60
24. Question
You have 10 on-premises Windows Servers onboarded to Azure Arc. You need to enable ‘Managed Identities’ for these servers so they can access Azure Key Vault without storing credentials. Which two steps are required?
Correct
Azure Arc-enabled servers support System-Assigned Managed Identities. Once enabled on the Arc resource in Azure, you must grant that specific identity the necessary permissions (RBAC) to access the Key Vault.
Incorrect
Azure Arc-enabled servers support System-Assigned Managed Identities. Once enabled on the Arc resource in Azure, you must grant that specific identity the necessary permissions (RBAC) to access the Key Vault.
Unattempted
Azure Arc-enabled servers support System-Assigned Managed Identities. Once enabled on the Arc resource in Azure, you must grant that specific identity the necessary permissions (RBAC) to access the Key Vault.
Question 25 of 60
25. Question
You have a hybrid environment with Azure File Sync. You need to move the ‘Storage Sync Service’ to a different Azure region. Which two statements describe the requirements for this move?
Correct
A Storage Sync Service cannot be moved between regions if it has active registrations. You must delete the cloud endpoints and sync groups, unregister the servers, and then recreate the hierarchy in the target region.
Incorrect
A Storage Sync Service cannot be moved between regions if it has active registrations. You must delete the cloud endpoints and sync groups, unregister the servers, and then recreate the hierarchy in the target region.
Unattempted
A Storage Sync Service cannot be moved between regions if it has active registrations. You must delete the cloud endpoints and sync groups, unregister the servers, and then recreate the hierarchy in the target region.
Question 26 of 60
26. Question
You are using Azure Site Recovery (ASR) to protect on-premises Hyper-V VMs. You need to perform a planned failover to Azure. Which two steps are part of a ‘Planned’ failover process?
Correct
A planned failover ensures zero data loss. This is achieved by shutting down the source VM to prevent data changes and then running a final synchronization to ensure the Azure replica is 100% up to date.
Incorrect
A planned failover ensures zero data loss. This is achieved by shutting down the source VM to prevent data changes and then running a final synchronization to ensure the Azure replica is 100% up to date.
Unattempted
A planned failover ensures zero data loss. This is achieved by shutting down the source VM to prevent data changes and then running a final synchronization to ensure the Azure replica is 100% up to date.
Question 27 of 60
27. Question
You have an Azure File Sync environment. You need to ensure that local users can access files even if the internet connection to Azure is temporarily unavailable. Which feature must be enabled?
Correct
Cloud Tiering ensures that the most frequently accessed files are cached locally on the Windows Server. This allows users to access ‘hot’ data directly from local disk even during an internet outage, provided the files are already cached.
Incorrect
Cloud Tiering ensures that the most frequently accessed files are cached locally on the Windows Server. This allows users to access ‘hot’ data directly from local disk even during an internet outage, provided the files are already cached.
Unattempted
Cloud Tiering ensures that the most frequently accessed files are cached locally on the Windows Server. This allows users to access ‘hot’ data directly from local disk even during an internet outage, provided the files are already cached.
Question 28 of 60
28. Question
You have 20 Azure Arc-enabled servers. You need to collect specific application logs located at C:\Logs\app.log and send them to a Log Analytics workspace. Which two steps are required?
Correct
The AMA is the modern agent for log collection. You must define a DCR that specifies the local file path (Custom Text Logs) and associate that rule with the Arc-enabled servers to begin ingestion into Log Analytics.
Incorrect
The AMA is the modern agent for log collection. You must define a DCR that specifies the local file path (Custom Text Logs) and associate that rule with the Arc-enabled servers to begin ingestion into Log Analytics.
Unattempted
The AMA is the modern agent for log collection. You must define a DCR that specifies the local file path (Custom Text Logs) and associate that rule with the Arc-enabled servers to begin ingestion into Log Analytics.
Question 29 of 60
29. Question
You have a hybrid identity solution using ‘Pass-through Authentication’ (PTA). You need to troubleshoot a scenario where users can sign in from the office but not from home. Which two Azure AD features should you investigate?
Correct
If authentication works in one location but not another, the issue is likely a policy-based restriction. Conditional Access or Identity Protection may be blocking access based on the ‘Location’ or ‘Sign-in Risk’ associated with the home network.
Incorrect
If authentication works in one location but not another, the issue is likely a policy-based restriction. Conditional Access or Identity Protection may be blocking access based on the ‘Location’ or ‘Sign-in Risk’ associated with the home network.
Unattempted
If authentication works in one location but not another, the issue is likely a policy-based restriction. Conditional Access or Identity Protection may be blocking access based on the ‘Location’ or ‘Sign-in Risk’ associated with the home network.
Question 30 of 60
30. Question
You have an Azure File Sync deployment. You need to move a large amount of data (10 TB) from an on-premises NAS to the cloud share while minimizing the impact on your limited internet bandwidth. Which two steps are recommended?
Correct
Data Box allows you to ship the bulk data to Azure. Once the data is in the Azure File share, you must run the Change Detection cmdlet to let the Sync service know that the cloud share now contains the data that needs to be ‘indexed’ for the local servers.
Incorrect
Data Box allows you to ship the bulk data to Azure. Once the data is in the Azure File share, you must run the Change Detection cmdlet to let the Sync service know that the cloud share now contains the data that needs to be ‘indexed’ for the local servers.
Unattempted
Data Box allows you to ship the bulk data to Azure. Once the data is in the Azure File share, you must run the Change Detection cmdlet to let the Sync service know that the cloud share now contains the data that needs to be ‘indexed’ for the local servers.
Question 31 of 60
31. Question
You are deploying Azure File Sync. Your local file server has 5 TB of data, but only 500 GB of local disk space available. How can you make this work?
Correct
Cloud Tiering allows you to keep only a subset of data (the most active) locally. By setting a volume free space percentage, the server will move cold files to the cloud to maintain that space.
Incorrect
Cloud Tiering allows you to keep only a subset of data (the most active) locally. By setting a volume free space percentage, the server will move cold files to the cloud to maintain that space.
Unattempted
Cloud Tiering allows you to keep only a subset of data (the most active) locally. By setting a volume free space percentage, the server will move cold files to the cloud to maintain that space.
Question 32 of 60
32. Question
A company has an on-premises Active Directory Domain Services (AD DS) domain named contoso.com. You deploy an Azure AD Connect server to sync identities. You need to implement Password Hash Synchronization (PHS) and ensure that users can reset their own passwords in Azure AD and have those changes reflect on-premises. What should you enable?
Correct
Password Writeback is a component of Azure AD Connect that allows password changes in the cloud to be written back to an existing on-premises directory in real time.
Incorrect
Password Writeback is a component of Azure AD Connect that allows password changes in the cloud to be written back to an existing on-premises directory in real time.
Unattempted
Password Writeback is a component of Azure AD Connect that allows password changes in the cloud to be written back to an existing on-premises directory in real time.
Question 33 of 60
33. Question
You are configuring ‘SMB over QUIC’ on a Windows Server 2022 Azure Edition server. You want to use a custom port instead of 443. Is this supported?
Correct
SMB over QUIC is designed to use the standard QUIC port (UDP 443) to ensure it can pass through most firewalls.
Incorrect
SMB over QUIC is designed to use the standard QUIC port (UDP 443) to ensure it can pass through most firewalls.
Unattempted
SMB over QUIC is designed to use the standard QUIC port (UDP 443) to ensure it can pass through most firewalls.
Question 34 of 60
34. Question
You are configuring a ‘Scale-Out File Server’ (SoFS). Which shared storage technology is the most common foundation for a modern SoFS on Windows Server 2022?
Correct
Storage Spaces Direct is the primary underlying storage technology used to create the highly available storage pools required for a Scale-Out File Server.
Incorrect
Storage Spaces Direct is the primary underlying storage technology used to create the highly available storage pools required for a Scale-Out File Server.
Unattempted
Storage Spaces Direct is the primary underlying storage technology used to create the highly available storage pools required for a Scale-Out File Server.
Question 35 of 60
35. Question
You are configuring Azure AD Connect Cloud Sync. You have multiple agents installed for high availability. How does the system decide which agent to use?
Correct
Cloud Sync agents are managed by the Azure cloud service which automatically distributes the workload and handles failover between active agents.
Incorrect
Cloud Sync agents are managed by the Azure cloud service which automatically distributes the workload and handles failover between active agents.
Unattempted
Cloud Sync agents are managed by the Azure cloud service which automatically distributes the workload and handles failover between active agents.
Question 36 of 60
36. Question
You are managing a Windows Server 2022 failover cluster. You want to prevent ‘flapping’ where a resource moves back and forth between nodes due to a transient failure. What should you configure?
Correct
Cluster node resiliency settings (introduced in 2016) define how the cluster handles nodes that are in a ‘Quarantine’ state to prevent flapping.
Incorrect
Cluster node resiliency settings (introduced in 2016) define how the cluster handles nodes that are in a ‘Quarantine’ state to prevent flapping.
Unattempted
Cluster node resiliency settings (introduced in 2016) define how the cluster handles nodes that are in a ‘Quarantine’ state to prevent flapping.
Question 37 of 60
37. Question
A company plans to implement Azure File Sync. They have an on-premises server with a 10 TB data set. They want to ensure that only frequently accessed files are kept on the local server while all files are stored in the cloud. Which feature should be configured?
Correct
Cloud Tiering is a feature of Azure File Sync in which frequently accessed files are cached locally and infrequently accessed files are tiered to the cloud.
Incorrect
Cloud Tiering is a feature of Azure File Sync in which frequently accessed files are cached locally and infrequently accessed files are tiered to the cloud.
Unattempted
Cloud Tiering is a feature of Azure File Sync in which frequently accessed files are cached locally and infrequently accessed files are tiered to the cloud.
Question 38 of 60
38. Question
You are managing a 4-node Storage Spaces Direct (S2D) cluster. You need to expand the storage capacity. You add two new disks to each node. What is the next step to ensure the cluster uses the new disks?
Correct
In S2D, when new compatible disks are added to the nodes, the system automatically detects them and adds them to the existing storage pool.
Incorrect
In S2D, when new compatible disks are added to the nodes, the system automatically detects them and adds them to the existing storage pool.
Unattempted
In S2D, when new compatible disks are added to the nodes, the system automatically detects them and adds them to the existing storage pool.
Question 39 of 60
39. Question
You are managing a hybrid Active Directory. You need to verify that the ‘Schema Master’ role is held by a specific Domain Controller. Which tool can you use to see this?
Correct
The Active Directory Schema snap-in (which must be registered via regsvr32) allows you to view and change the Schema Master FSMO role.
Incorrect
The Active Directory Schema snap-in (which must be registered via regsvr32) allows you to view and change the Schema Master FSMO role.
Unattempted
The Active Directory Schema snap-in (which must be registered via regsvr32) allows you to view and change the Schema Master FSMO role.
Question 40 of 60
40. Question
You are configuring Azure File Sync. You have a folder with millions of small files. You notice sync performance is slow. What is a recommended optimization?
Correct
Premium Azure File Shares (backed by SSD) offer significantly higher IOPS and lower latency which is critical for handling large numbers of small files.
Incorrect
Premium Azure File Shares (backed by SSD) offer significantly higher IOPS and lower latency which is critical for handling large numbers of small files.
Unattempted
Premium Azure File Shares (backed by SSD) offer significantly higher IOPS and lower latency which is critical for handling large numbers of small files.
Question 41 of 60
41. Question
You are deploying a Windows Server Azure Edition VM in Azure. You want to use the Hotpatching feature to reduce the number of reboots required for security updates. Which installation option must you select?
Correct
Hotpatching is supported specifically on Windows Server Azure Edition using the Server Core installation to apply security updates without requiring a reboot.
Incorrect
Hotpatching is supported specifically on Windows Server Azure Edition using the Server Core installation to apply security updates without requiring a reboot.
Unattempted
Hotpatching is supported specifically on Windows Server Azure Edition using the Server Core installation to apply security updates without requiring a reboot.
Question 42 of 60
42. Question
You are configuring ‘Azure Site Recovery’. You want to use a ‘Recovery Plan’ to run a custom PowerShell script after the VMs have failed over to Azure. Where is this script stored?
Correct
ASR recovery plans integrate with Azure Automation runbooks to execute complex orchestration steps during a failover.
Incorrect
ASR recovery plans integrate with Azure Automation runbooks to execute complex orchestration steps during a failover.
Unattempted
ASR recovery plans integrate with Azure Automation runbooks to execute complex orchestration steps during a failover.
Question 43 of 60
43. Question
You are managing a hybrid Active Directory. You want to implement ‘Self-Service Password Reset’ (SSPR). You want to ensure that when users change their password in the cloud, it updates on-premises immediately. What should you enable?
Correct
Password Writeback is the specific component of Azure AD Connect that enables bidirectional password synchronization.
Incorrect
Password Writeback is the specific component of Azure AD Connect that enables bidirectional password synchronization.
Unattempted
Password Writeback is the specific component of Azure AD Connect that enables bidirectional password synchronization.
Question 44 of 60
44. Question
You are managing a hybrid environment. You want to use the Azure portal to manage local Windows Server settings like local users, certificates, and the registry. What must you install on the local server?
Correct
Onboarding a server to Azure Arc allows you to use tools like Windows Admin Center in the Azure portal for deep OS management.
Incorrect
Onboarding a server to Azure Arc allows you to use tools like Windows Admin Center in the Azure portal for deep OS management.
Unattempted
Onboarding a server to Azure Arc allows you to use tools like Windows Admin Center in the Azure portal for deep OS management.
Question 45 of 60
45. Question
You are preparing to use Azure Site Recovery (ASR) to protect on-premises Windows VMs. You need to install the component that coordinates communication between on-premises and Azure. What should you deploy?
Correct
The Configuration Server is the on-premises component required for ASR to manage and coordinate replication of VMware or Physical/Hyper-V servers to Azure.
Incorrect
The Configuration Server is the on-premises component required for ASR to manage and coordinate replication of VMware or Physical/Hyper-V servers to Azure.
Unattempted
The Configuration Server is the on-premises component required for ASR to manage and coordinate replication of VMware or Physical/Hyper-V servers to Azure.
Question 46 of 60
46. Question
You are configuring an Azure VM for a high-performance database. You want to use ‘Ultra Disk’ storage. What is a unique feature of Ultra Disk compared to Premium SSD?
Correct
Ultra Disk allows you to tune performance parameters (IOPS/MBps) on the fly to meet fluctuating workload demands.
Incorrect
Ultra Disk allows you to tune performance parameters (IOPS/MBps) on the fly to meet fluctuating workload demands.
Unattempted
Ultra Disk allows you to tune performance parameters (IOPS/MBps) on the fly to meet fluctuating workload demands.
Question 47 of 60
47. Question
You are configuring Azure File Sync for a file server named Server1. The server has a 4 TB volume, but you only want to keep the most frequently accessed files on the local disk. What should you configure?
Correct
Cloud Tiering caches frequently accessed files locally and moves infrequently accessed files to the Azure File Share.
Incorrect
Cloud Tiering caches frequently accessed files locally and moves infrequently accessed files to the Azure File Share.
Unattempted
Cloud Tiering caches frequently accessed files locally and moves infrequently accessed files to the Azure File Share.
Question 48 of 60
48. Question
You are managing an Active Directory site with poor bandwidth. You want to ensure that domain controllers in this site only replicate during non-business hours. Where do you configure this?
Correct
In AD Sites and Services, you can modify the schedule of the Site Link to control when replication is allowed to occur.
Incorrect
In AD Sites and Services, you can modify the schedule of the Site Link to control when replication is allowed to occur.
Unattempted
In AD Sites and Services, you can modify the schedule of the Site Link to control when replication is allowed to occur.
Question 49 of 60
49. Question
You are configuring Azure Backup. You want to protect against the accidental deletion of backup data. Which feature provides a 14-day retention period for deleted backups?
Correct
Soft Delete protects backup data from accidental or malicious deletion by retaining it for 14 days after the deletion is initiated.
Incorrect
Soft Delete protects backup data from accidental or malicious deletion by retaining it for 14 days after the deletion is initiated.
Unattempted
Soft Delete protects backup data from accidental or malicious deletion by retaining it for 14 days after the deletion is initiated.
Question 50 of 60
50. Question
You are configuring ‘Azure Site Recovery’ for an on-premises VM. You want to minimize the cost of the storage used for replication. Which storage type should you use for the ‘Log’ and ‘Replica’ disks in Azure?
Correct
Standard HDD is the most cost-effective storage for the data being replicated; you can switch to faster storage during a failover.
Incorrect
Standard HDD is the most cost-effective storage for the data being replicated; you can switch to faster storage during a failover.
Unattempted
Standard HDD is the most cost-effective storage for the data being replicated; you can switch to faster storage during a failover.
Question 51 of 60
51. Question
You are managing a Windows Server 2022 cluster. You want to use ‘Shared VHDX’ files for a guest cluster. What is a requirement for the storage hosting the VHDX?
Correct
Shared VHDX (or VHD Sets) requires the underlying storage to support the shared access protocols provided by CSV or SoFS.
Incorrect
Shared VHDX (or VHD Sets) requires the underlying storage to support the shared access protocols provided by CSV or SoFS.
Unattempted
Shared VHDX (or VHD Sets) requires the underlying storage to support the shared access protocols provided by CSV or SoFS.
Question 52 of 60
52. Question
You are managing an Azure Virtual Desktop (AVD) host pool. You need to ensure users are redirected to the host with the fewest active sessions. Which load-balancing method should you use?
Correct
Breadth-first load balancing distributes new user sessions across all available session hosts in the host pool to optimize performance.
Incorrect
Breadth-first load balancing distributes new user sessions across all available session hosts in the host pool to optimize performance.
Unattempted
Breadth-first load balancing distributes new user sessions across all available session hosts in the host pool to optimize performance.
Question 53 of 60
53. Question
A user is trying to connect to an Azure VM via RDP but the connection is being blocked by a Network Security Group (NSG). You need to find out which specific NSG rule is causing the block. Which tool should you use?
Correct
IP Flow Verify checks if a packet is allowed or denied to/from a VM and identifies which security rule is responsible.
Incorrect
IP Flow Verify checks if a packet is allowed or denied to/from a VM and identifies which security rule is responsible.
Unattempted
IP Flow Verify checks if a packet is allowed or denied to/from a VM and identifies which security rule is responsible.
Question 54 of 60
54. Question
You are managing an Azure Virtual Network. You want to prevent all outbound internet traffic from your Windows Server VMs except for Windows Update. What should you use?
Correct
Service Tags (like ‘Internet’ and ‘AzureUpdate’) allow you to easily create NSG rules that allow or block traffic to specific categories of Azure services.
Incorrect
Service Tags (like ‘Internet’ and ‘AzureUpdate’) allow you to easily create NSG rules that allow or block traffic to specific categories of Azure services.
Unattempted
Service Tags (like ‘Internet’ and ‘AzureUpdate’) allow you to easily create NSG rules that allow or block traffic to specific categories of Azure services.
Question 55 of 60
55. Question
You are configuring a Site-to-Site VPN to Azure. You want to use BGP (Border Gateway Protocol) for dynamic routing. What is a requirement for the on-premises VPN device?
Correct
BGP requires the on-premises gateway to support the protocol and use an ASN to exchange route information with the Azure VPN Gateway.
Incorrect
BGP requires the on-premises gateway to support the protocol and use an ASN to exchange route information with the Azure VPN Gateway.
Unattempted
BGP requires the on-premises gateway to support the protocol and use an ASN to exchange route information with the Azure VPN Gateway.
Question 56 of 60
56. Question
You are deploying a new Active Directory domain controller in an Azure VM. Which Azure disk setting is critically recommended for the drive containing the AD database (NTDS.DIT)?
Correct
For AD DS databases, it is a best practice to disable host caching on the Azure disk to prevent potential data corruption during power loss or migration.
Incorrect
For AD DS databases, it is a best practice to disable host caching on the Azure disk to prevent potential data corruption during power loss or migration.
Unattempted
For AD DS databases, it is a best practice to disable host caching on the Azure disk to prevent potential data corruption during power loss or migration.
Question 57 of 60
57. Question
You are planning an Azure File Sync deployment. You have a local volume formatted with FAT32. What must you do before you can include a folder from this volume in a sync group?
Correct
Azure File Sync server endpoints must be located on NTFS or ReFS volumes; FAT32 is not supported.
Incorrect
Azure File Sync server endpoints must be located on NTFS or ReFS volumes; FAT32 is not supported.
Unattempted
Azure File Sync server endpoints must be located on NTFS or ReFS volumes; FAT32 is not supported.
Question 58 of 60
58. Question
You are managing a Windows Server 2022 cluster. You want to ensure that a ‘Node’ is automatically quarantined if it fails 3 times within an hour. What is this feature called?
Correct
Node Resiliency settings allow the cluster to identify and isolate ‘flapping’ nodes that are causing instability in the cluster.
Incorrect
Node Resiliency settings allow the cluster to identify and isolate ‘flapping’ nodes that are causing instability in the cluster.
Unattempted
Node Resiliency settings allow the cluster to identify and isolate ‘flapping’ nodes that are causing instability in the cluster.
Question 59 of 60
59. Question
You are managing a hybrid Active Directory. You want to use ‘Azure AD Connect Health’. What information can this tool show you?
Correct
Azure AD Connect Health provides monitoring of your identity infrastructure including synchronization status and login latency.
Incorrect
Azure AD Connect Health provides monitoring of your identity infrastructure including synchronization status and login latency.
Unattempted
Azure AD Connect Health provides monitoring of your identity infrastructure including synchronization status and login latency.
Question 60 of 60
60. Question
You are managing an Azure Virtual Desktop environment. You want to limit the maximum amount of time a user session can remain idle before being disconnected. Where is this configured?
Correct
Session time limits for AVD (and RDS) are typically managed via GPOs under Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services.
Incorrect
Session time limits for AVD (and RDS) are typically managed via GPOs under Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services.
Unattempted
Session time limits for AVD (and RDS) are typically managed via GPOs under Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services.
X
Use Page numbers below to navigate to other practice tests