Microsoft Administering Windows Server - AZ-802 Exam Practice Test
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a domain controller named DC1. The domain uses Microsoft Entra Connect sync with a Microsoft Entra tenant and uses Microsoft Entra Password Protection to enforce a custom banned password list. You deploy a new domain controller named DC2 to the domain. You discover that the custom banned password list is applied inconsistently and often allows banned passwords to be used. You need to ensure that the custom banned password list is always enforced. What should you do on DC2?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
You have an Azure virtual machine named Server1 that runs a network management application. Server1 has the following network configurations: * Network interface: Nic1 * IP address: 10.1.1.1/24 * Connected to:
Vnet1/Subnet1 You need to connect Server1 to an additional subnet named Vnet1/Subnet2. What should you do?
Vnet1/Subnet1 You need to connect Server1 to an additional subnet named Vnet1/Subnet2. What should you do?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
You have two Azure virtual machines named VM1 and VM2. VM1 is backed up to an Azure Recovery Services vault daily and retains backups for 30 days.
You need to restore an individual file named C:\Data\Important.docx from VM1 to VM2. The solution must minimize administrative effort.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Exhibit
Exhibit
You need to restore an individual file named C:\Data\Important.docx from VM1 to VM2. The solution must minimize administrative effort.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Exhibit
Exhibit
Correct Answer:

Explanation:
1. Download the file recovery script for VM1. 2. Run the file recovery script on VM2. 3. Copy the file by using File Explorer. 4. Unmount the disks.
Azure Backup ' s file-level recovery for Azure virtual machines works by generating a script from a specific recovery point stored in the Recovery Services vault; once that script is downloaded and executed on a target machine, it mounts the recovery point ' s disks there as local volumes. To restore a single file from VM1 ' s backup onto VM2 with the least administrative effort, an administrator first downloads the file recovery script generated for the desired VM1 recovery point, then runs that script directly on VM2 -- the target machine where the file needs to end up -- which mounts the recovery point ' s volumes locally on VM2. Once the volumes are mounted and visible, the desired file is copied using ordinary File Explorer navigation, browsing to the mounted recovery point volume and copying Important.docx to its destination on VM2. Finally, the mounted disks are unmounted to clean up the temporary recovery point volumes once the file has been retrieved. This approach avoids restoring the entire virtual machine or provisioning any separate infrastructure just to retrieve one file, minimizing administrative effort as required.
You have a server named Server1. You plan to use Storage Spaces to expand the storage available to Server1.
You attach eight physical disks to Server1. Four disks are HDDs and four are SSDs. You need to create a volume on Server1 that will use the storage on all the new disks. The solution must provide the fastest read performance for frequently used files. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You attach eight physical disks to Server1. Four disks are HDDs and four are SSDs. You need to create a volume on Server1 that will use the storage on all the new disks. The solution must provide the fastest read performance for frequently used files. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Correct Answer:

Explanation:
1. Create a storage pool. 2. Create a virtual disk. 3. Create a simple volume.
Storage Spaces virtualizes physical disks into a storage pool and then carves virtual disks out of that pool; it does not use the legacy Disk Management concept of converting disks to " dynamic " disks, so those options are distractors that play no role in a Storage Spaces workflow. The first real step is to create a storage pool containing all eight physical disks (four HDDs and four SSDs together), which makes the combined capacity of every disk available to virtual disks created from that pool. The second step is to create a virtual disk from the pool; because the pool contains two distinct media types, creating the virtual disk with storage tiers enabled lets Storage Spaces automatically place and keep frequently accessed ( " hot " ) data on the faster SSD tier while colder data resides on the larger, slower HDD tier, which is exactly what maximizes read performance for frequently used files while still using the capacity of every disk in the pool. The third step is to create a simple volume on top of that virtual disk, formatting it with a file system and drive letter so it becomes usable storage; a simple volume (no resiliency) is appropriate here since the requirement is about read speed rather than fault tolerance, and " spanned volume " is again a legacy Disk Management dynamic- disk term that does not apply to a Storage Spaces virtual disk. The correct sequence is therefore: create the storage pool, create the tiered virtual disk, then create the simple volume.
Your network contains three Active Directory Domain Services (AD DS) forests as shown in the following exhibit: contoso.com (with a child domain east.contoso.com) has a two-way forest trust with adatum.com; adatum.com (with a child domain west.adatum.com) also has a two-way forest trust with fabrikam.com; there is no trust relationship directly between contoso.com and fabrikam.com. The network contains the users User1 (east.contoso.com) and User2 (fabrikam.com). The network contains the security groups Group1 (Domain local, west.adatum.com), Group2 (Universal, adatum.com), and Group3 (Universal, east.contoso.
com). For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE:
Each correct selection is worth one point.

contoso.com (child: east.contoso.com) < -forest trust- > adatum.com (child: west.adatum.com) < -forest trust-
> fabrikam.com. No trust between contoso.com and fabrikam.com.

User1: east.contoso.com. User2: fabrikam.com.

Group1: Domain local, west.adatum.com. Group2: Universal, adatum.com. Group3: Universal, east.contoso.
com.

com). For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE:
Each correct selection is worth one point.

contoso.com (child: east.contoso.com) < -forest trust- > adatum.com (child: west.adatum.com) < -forest trust-
> fabrikam.com. No trust between contoso.com and fabrikam.com.

User1: east.contoso.com. User2: fabrikam.com.

Group1: Domain local, west.adatum.com. Group2: Universal, adatum.com. Group3: Universal, east.contoso.
com.

Correct Answer:

Explanation:
You can add User1 to Group1: Yes. You can add User2 to Group3: No. You can grant Group2 permissions to the resources in the fabrikam.com domain: Yes.
A domain local group can accept members from any domain within its own forest, and, when a forest trust exists, from any domain in the entire trusted forest, because a forest trust extends to every domain in both forests, not just their root domains. Group1 is a domain local group in west.adatum.com (adatum.com forest), and User1 belongs to east.contoso.com, a child domain of contoso.com, which has a direct two-way forest trust with adatum.com covering both forests entirely; so User1 can be added to Group1. Group3, however, is a universal group, and universal group membership is restricted to principals from within the same single forest only, regardless of any trust - unlike domain local groups. User2 belongs to fabrikam.com, a separate forest from Group3 ' s forest (contoso.com), so User2 cannot be added to Group3 for that reason alone; there is also no trust path between contoso.com and fabrikam.com at all, since a forest trust is not transitive through an intermediate forest - adatum.com ' s separate trusts with each outer forest create no trust between them.
Granting permissions directly on a resource ' s ACL is different from group nesting, though: a universal group can be placed on an ACL in any domain that trusts its own forest, without the same-forest restriction that applies to membership. Because adatum.com (Group2 ' s forest) has a direct forest trust with fabrikam.com, Group2 can be granted permissions to resources in fabrikam.com.
Your on-premises datacenter contains physical servers and Hyper-V virtual machines.
You have an Azure subscription.
You plan to use Azure Migrate to perform the following tasks:
* Migrate the physical servers to Azure virtual machines.
* Migrate the Hyper-V virtual machines to Azure.
What should you use for each task? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You have an Azure subscription.
You plan to use Azure Migrate to perform the following tasks:
* Migrate the physical servers to Azure virtual machines.
* Migrate the Hyper-V virtual machines to Azure.
What should you use for each task? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Migrate the physical servers to Azure virtual machines: Migration and modernization. Migrate the Hyper-V virtual machines to Azure: Migration and modernization.
Inside the Azure Migrate hub, the Migration and modernization tool, also known as Azure Migrate: Server Migration, is the single unified tool that handles both agent-based replication of physical servers, as well as virtual machines from other clouds, and agentless replication of on-premises Hyper-V virtual machines directly into Azure virtual machines. Because both tasks in this scenario, migrating physical servers and migrating Hyper-V VMs, fall within the scope of this same tool, Migration and modernization is the correct choice for each answer position. Azure Data Box is used for large-scale offline bulk data transfers rather than for live server or VM migration, Data Migration Assistant is scoped specifically to assessing and migrating SQL Server databases, and Movere is a discovery and inventory tool used to assess an environment before migration rather than an engine that performs the actual migration. None of those three tools perform the server or VM migration itself, so Migration and modernization is the only option among those listed that correctly answers both parts of this question.
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4.
Whenever possible, use the principle of least privilege. You need to meet the technical requirements for User1. To which group in contoso.com should you add User1?
Whenever possible, use the principle of least privilege. You need to meet the technical requirements for User1. To which group in contoso.com should you add User1?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
You have a server named Server1 that runs Windows Server.
On Server1, you create a Data Collector Set named CollectorSet1 based on the Basic template.
You need to configure CollectorSet1 to meet the following requirements:
* Older performance counter logs must be overwritten by new ones.
* Performance counter logging must stop if there is less than 500 MB of free disk space.
What should you configure for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

On Server1, you create a Data Collector Set named CollectorSet1 based on the Basic template.
You need to configure CollectorSet1 to meet the following requirements:
* Older performance counter logs must be overwritten by new ones.
* Performance counter logging must stop if there is less than 500 MB of free disk space.
What should you configure for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Older logs overwritten: The Performance Counter properties. Stop below 500 MB free: The Data Manager properties.
The individual Performance Counter data collector inside a Data Collector Set has its own Properties dialog with a File tab that includes an Overwrite option, and enabling that option causes each new logging run to overwrite the previous log file in place rather than creating a new, separately numbered file each time -- this is exactly the control needed to make older performance counter logs get replaced by newer ones. Disk-space- based retention, on the other hand, is governed at the level of the Data Collector Set as a whole through its Data Manager properties, which expose a Minimum Free Disk Space setting, alongside Maximum Folders and Maximum Root Path Size settings, that Windows evaluates against the log directory ' s volume to manage or halt further data collection once free space drops below the configured threshold. Because these two behaviors live on two entirely different property pages -- one scoped to the individual counter ' s file settings and the other scoped to the Data Collector Set ' s overall data management -- the Configuration properties option, which governs sample interval and duration settings, does not control either of these two requirements.
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains the following servers: Server1 (has the DFS Namespaces role service installed); Server2 (has the DFS Namespaces role service installed); Server3 (hosts a file share named \\Server3\Share1); Server4 (hosts a file share named \\Server4\Share2). You need to publish both file shares in a single DFS namespace named Corp.
Corp must remain available if either Server1 or Server2 is unavailable. What should you do?
Corp must remain available if either Server1 or Server2 is unavailable. What should you do?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
You have three servers named Server1, Server2, and Server3 that run Windows Server and have the Hyper-V server role installed. Server1 hosts an Azure Migrate appliance named Migrate1. You plan to migrate virtual machines to Azure. You need to ensure that any new virtual machines created on Server1, Server2, and Server3 are available in Azure Migrate. What should you do?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server. Server1 has the Web Server (IIS) role installed and hosts a web app named App1. App1 uses Windows authentication. You have an Azure subscription. You plan to migrate App1 to Azure App Service. You need to ensure that App1 can support Windows authentication in App Service. What should you configure first?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
You need to meet the technical requirement for HyperV1. Which command should you run? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.


Correct Answer:

Explanation:
hvc.exe, ssh User2@VM2
The requirement is to use a direct SSH session to manage all the supported virtual machines on HyperV1, without relying on a network path to the guest. Hyper-V provides hvc.exe, a helper used as an SSH ProxyCommand, that opens an SSH session to a virtual machine over the VMBus (the internal Hyper-V socket
/console channel) rather than over the network, which works even when the guest has no reachable IP configuration and only default management tools installed, matching the stated environment. Direct SSH management this way requires the guest to run an SSH server; of the three VMs, only VM2 runs Red Hat Enterprise Linux, which includes OpenSSH server support out of the box, so it is the only VM realistically " supported " for this direct SSH scenario as described, and the account to use is User2, the local account that exists on VM2. VM1 and VM3 both run Windows Server, so " direct SSH, " as intended by this requirement, targets the Linux guest. Connect-PSSession and Connect-WSMan are PowerShell remoting tools, not SSH, and mstsc.exe launches a graphical Remote Desktop session rather than a console-mode SSH session, so none of those alternatives fit. The correct combination is hvc.exe used as the SSH proxy, connecting as User2@VM2.