Administering Windows Server Questions and Answers
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest root domain contains a server named server1.contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?
Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains three servers that run Windows Server and have the Hyper-V server role installed. Each server has a Switch Embedded Teaming (SET) team. You need to verify that Remote Direct Memory Access (RDMA) and required Windows Server settings are configured properly on each server to support a failover cluster. What should you use?
You have a server named Server1 that runs Windows Server. You need to ensure that only specific applications can modify the data in protected folders on Server1. Solution: From App & browser control, you configure the Reputation-based protection. Does this meet the goal?
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an on-premises server named Server1 that runs Windows Server. You have a Microsoft Sentinel instance. You add the Windows Firewall data connector in Microsoft Sentinel. You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1. Solution: You install the Azure Connected Machine agent on Server1. Does this meet the goal?
Your network contains an on-premises Active Directory Domain Services (AD DS) domain. The domain contains the servers shown in the following table.
For each server. Windows Defender Firewall is configured to allow only communication between servers on the same segment. Server! has the following connection security rule:
• Name: Rule1
• Rule type: Isolation
• Requirement: Require authentication for inbound connections and request authentication for outbound connections
• Authentication method: Computer (Kerberos V5)
• Profile: Domain. Private. Public
Server2 does not have any connection security rules.
Server3 has the following connection security rule:
• Name: Rute3
• Rule type: Server-to-server
• Endpoints:
o Computers in Endpoint 1:192.168.50/24
o Computers in Endpoint 2: 192.168.1.0/24
• Requirement Request authentication (or inbound and outbound connections
• Authentication method: Computer (Kerberos V5)
• Profile: Domain. Private. Public
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Exhibit

You have on-premises Windows devices. You have an Azure subscription that contains a virtual network named VNet1. You need to create a Site-to-Site (S2S) VPN between the on-premises network and VNet1. Which three resources should you create? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
You have a Storage Spaces Direct configuration that has persistent memory and contains the data volumes shown in the following table: Volume1 (NTFS), Volume2 (ReFS). You plan to add data volumes to Storage Spaces Direct as shown in the following table: Volume3 (NTFS), Volume4 (ReFS). On which volumes can you use direct access (DAX)?

Existing data volumes

Planned data volumes
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant.
The AD DS domain contains a domain controller named DC1. DC1 does NOT have internet access.
You need to configure password security for on-premises users. The solution must meet the following requirements:
• Prevent the users from using known weak passwords.
• Prevent the users from using the company name in passwords.
What should you do? To answer, drag the appropriate configurations to the correct targets. Each configuration may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

You have a file server that runs Windows Server and has the File Server Resource Manager role service installed. The server hosts a file share named D:\Shares\Contracts.
You need to configure File Server Resource Manager (FSRM). The solution must meet the following requirements:
• Prevent users from saving .mp3 and .mp4 files.
• Automatically set the DataUse value for contract files.
• Move files that have datause-Archive and have NOT been accessed for 365 days to a folder named D:\Expired.
Which FSRM feature should you use for each requirement? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.
You need to perform the following tasks:
• Createasnapshotofcontoso.com.
• Expose the snapshot as a read-only AD DS instance.
What should you use for each task? To answer, drag the appropriate tools to the correct tasks. Each tool may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Exhibit
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. Contoso.com contains a member server named server1.contoso.com. You cannot resolve the FQDN of server1.contoso.com. You verify that Windows Defender Firewall is configured correctly and that you can ping server1.contoso.com successfully by using the server ' s IP address. You need to validate that the DNS record for server1.contoso.com exists. Which command should you run?
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains two users named Contractor1 and Admin1.
You need to configure Account options for the users. The solution must meet the following requirements:
• Contractor1 must be prevented from signing in to their client computer until an administrator enables their account.
• The credentials of Admin1 must NOT be usable by services that access network resources on behalf of users
What should you select for each user? To answer, drag the appropriate account options to the correct users. Each option may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

You have a Hyper-V failover cluster named Cluster1 that contains two nodes named Node1 and Node2, and a Hyper-V host named Host1.
You have the virtual machines shown in the following table.
The Balancer settings for Cluster1 are shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit
Your network contains an on-premises Active Directory Domain Services (AD DS) domain.
The domain contains the servers shown in the following table.
Server1 has the connection security rule as shown in the Server1 exhibit. (Click the Server1 tab.)
Server2 has the connection security rule as shown in the Server2 exhibit. (Click the Server2 tab.)
Server1 has the inbound firewall rules as shown in the Server1 inbound rules exhibit. (Click the Server1 inbound rules tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Exhibit

Exhibit

Exhibit

Exhibit

Exhibit
You have three servers named Server1, Server2, and Server3 that run Windows Server and have the Hyper-V server role installed. Server1 hosts an Azure Migrate appliance named Migrate1. You plan to migrate virtual machines to Azure. You need to ensure that any new virtual machines created on Server1, Server2, and Server3 are available in Azure Migrate. What should you do?
You have a Remote Desktop Services (RDS) farm deployment. Administrators connect to the farm by using Remote Desktop from domain-joined workstations on the internal network. You need to enable administrators to connect to the RDS farm by using Remote Desktop from the internet. The solution must prevent opening internal RDP ports to the internet. Which role should you add to the deployment?
You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server and is in the East US Azure region. The subscription contains the storage accounts shown in the following table. You plan to configure the Diagnostic settings for VM1. Which storage accounts should you specify for the settings? (Exhibit: storage accounts table.)

Storage accounts
Your network contains an Active Directory domain named contoso.com. The domain contains the computers shown in the following table: Computer1 (Windows 11), Server1 (Windows Server 2016), Server2 (Windows Server 2019), Server3 (Windows Server 2022). On Server3, you create a Group Policy Object (GPO) named GPO1 and link GPO1 to contoso.com. GPO1 includes a shortcut preference named Shortcut1 that has item-level targeting configured to apply only when the operating system is Windows Server 2022 Family. To which computer will Shortcut1 be applied?

Computer/OS table

Item-level targeting editor
You have an Azure subscription named sub1 and 500 on-premises virtual machines that run Windows Server. You plan to onboard the on-premises virtual machines to Azure Arc by running the Azure Arc deployment script. You need to create an identity that will be used by the script to authenticate access to sub1. The solution must use the principle of least privilege. How should you complete the command? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. ___ -DisplayName ' arc-for-servers ' -Role ___

You have an Azure subscription that contains two virtual machines named VM1 and VM2. VM1 runs Windows Server. VM2 runs Ubuntu Linux. You need to monitor VM1 and VM2 by using VM insights. The solution must meet the following requirements:
• Ensure that you can monitor the memory usage on VM1.
• Ensure that you run the Map feature on VM2.
The solution must minimize the number of agents required for each virtual machine.
Which agents are required on each virtual machine? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You deploy Azure Migrate to an on-premises network. You have an on-premises physical server named Server1 that runs Windows Server and has the following configuration: Operating system disk 600 GB, Data disk 3 TB, NIC Teaming: Enabled, Mobility service: installed, Windows Firewall: Enabled, Microsoft Defender Antivirus: Enabled. You need to ensure that you can use Azure Migrate to migrate Server1. Solution: You disable NIC Teaming on Server1. Does this meet the goal?
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains servers that run Windows Server and store BitLocker recovery keys in AD DS. A server named Server1 starts in BitLocker recovery mode. You need to identify the BitLocker recovery key for Server1. Solution: You run repair-bde.exe by using a BitLocker key package exported from AD DS. Does this meet the goal?
Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains three servers that run Windows Server and have the Hyper-V server role installed. Each server has a Switch Embedded Teaming (SET) team. You need to verify that Remote Direct Memory Access (RDMA) and all the required Windows Server settings are configured properly on each server. What should you use?
You have the on-premises servers shown in the following table. You have an Azure subscription. You plan to migrate the servers to Azure generation 2 virtual machines. Which servers can be migrated to Azure by using Azure Migrate?

On-premises servers, OS disk size, and BitLocker table
You have servers that have the DNS Server role installed. The servers are configured as shown in the following exhibit (Server1/Paris/contoso.com/10.1.1.1, Server2/New York/no local zone/10.2.2.2). All the client computers in the New York office use Server2 as the DNS server. You need to configure name resolution in the New York office to meet the following requirements: ensure that the client computers in New York can resolve names from contoso.com; ensure that Server2 forwards all DNS queries for internet hosts to 131.107.100.200. The solution must NOT require modifications to Server1. Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Server1 (Paris, contoso.com, 10.1.1.1) / Server2 (New York, no local zone, 10.2.2.2).
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an on-premises server named Server1 that runs Windows Server. You have a Microsoft Sentinel instance. You add the Windows Firewall data connector in Microsoft Sentinel. You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1. Solution: You install the Microsoft Integration Runtime on Server1. Does this meet the goal?
You need to meet the technical requirements for User1. The solution must use the principle of least privilege. What should you do?
You need to meet the technical requirements for the site links. Which users can perform the required task?
You need to meet the technical requirements for Server1. Which users can currently perform the required task?
You need to meet the technical requirements for VM1. Which cmdlet should you run first? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

You need to meet the technical requirements for VM3. On which volume can you enable Data Deduplication?
Which groups can you add to Group3, and which groups can you add to Group5? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to meet the technical requirements for Server4. Which cmdlet should you run on Server1, and which cmdlet should you run on Server4? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to meet the technical requirements for Server3. Which users can perform the required task?
You need to meet the technical requirements for VM2. What should you do?
What is the effective minimum password length for User1 and Admin1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for Share1. What should you use?
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for Cluster3. What should you include in the solution?
You need to configure BitLocker on Server4.
On which volumes can you turn on BitLocker, and on which volumes can you turn on auto-unlock? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You need to meet the technical requirements for Cluster2.
Which four actions should you perform in sequence before you can enable replication? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to identify the minimum number of Azure Site Recovery Provider installations required to protect Cluster2. What is the minimum number of installations required?
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to back up Server4 to meet the technical requirements. What should you do first?
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to promote DC4 to meet the technical requirements. Which domain controller should be online to meet the technical requirements for DC4?
You need to implement alerts for the domain controllers. The solution must meet the technical requirements.
What should you do on the domain controllers, and what should you create on Azure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for User1. To which group in contoso.com should you add User1?
With which servers can Server1 and Server3 communicate? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Which two languages can you use for Task1? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
You need to implement the planned change for Data1. Which actions should you perform in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. NOTE: Each correct selection is worth one point.

You need to implement the planned change for Microsoft Entra users to sign in to Server1. Which PowerShell cmdlet should you run?
You need to ensure that data availability on SSPace1 meets the technical requirements. What is the maximum number of physical disks that can fail on each disk without losing data? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You are planning the migration of APP3 and APP4 to support the Azure migration plan. What should you do on Cluster1 and in Azure before you perform the migration? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You are planning the migration of Archive1 to support the on-premises migration plan. What is the minimum number of IP addresses required for the node and cluster roles on Cluster3?
You are planning the deployment of Microsoft Sentinel. Which type of Microsoft Sentinel data connector should you use to meet the security requirements?
You are planning the data share migration to support the on-premises migration plan. What should you use to perform the migration?
You are planning the DHCP1 migration to support the DHCP migration plan. Which two PowerShell cmdlets should you run on DHCP1, and which two PowerShell cmdlets should you run on DHCP2? To answer, drag the appropriate cmdlets to the correct servers. Each cmdlet may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

You need to implement a security policy solution to authorize the applications. The solution must meet the security requirements. Which service should you use to enforce the security policy, and what should you use to manage the policy settings? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You are planning the implementation of Cluster2 to support the on-premises migration plan. You need to ensure that the disks on Cluster2 meet the security requirements. In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.

You are planning the website migration to support the Azure migration plan. How should you configure WebApp1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You are remediating the firewall security risks to meet the security requirements. What should you configure to reduce the risks?
Which three actions should you perform in sequence to meet the security requirements for Webapp1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You need to configure the Group Policy settings to ensure that the Azure Virtual Desktop session hosts meet the security requirements. What should you configure?
You are planning the implementation of Azure Arc to support the planned changes. You need to configure the environment to support configuration management policies. What should you do?
You need to configure Azure File Sync to meet the file sharing requirements. What is the minimum number of sync groups you should create, and what is the minimum number of Storage Sync Services you should create? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to implement a name resolution solution that meets the requirements for DC3. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
You need to configure remote administration to meet the security requirements. What should you use?
You need to configure network communication between the Seattle and New York offices. The solution must meet the requirements. What should you configure? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

What should you implement for the deployment of DC3?
You need to implement an availability solution for DHCP that meets the requirements. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.






























