Pre-Winter Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Microsoft AZ-802 Dumps

Page: 1 / 51
Total 510 questions

Administering Windows Server Questions and Answers

Question 1

Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest root domain contains a server named server1.contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?

Options:

A.

Change the trust to a one-way external trust.

B.

Add fabrikam\Group1 to the local Users group on server1.contoso.com.

C.

Enable SID filtering for the trust.

D.

Enable Selective authentication for the trust.

Question 2

Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains three servers that run Windows Server and have the Hyper-V server role installed. Each server has a Switch Embedded Teaming (SET) team. You need to verify that Remote Direct Memory Access (RDMA) and required Windows Server settings are configured properly on each server to support a failover cluster. What should you use?

Options:

A.

the Validate-Dcb cmdlet

B.

Server Manager

C.

the Get-NetAdapter cmdlet

D.

Failover Cluster Manager

Question 3

You have a server named Server1 that runs Windows Server. You need to ensure that only specific applications can modify the data in protected folders on Server1. Solution: From App & browser control, you configure the Reputation-based protection. Does this meet the goal?

Options:

A.

Yes

B.

No

Question 4

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an on-premises server named Server1 that runs Windows Server. You have a Microsoft Sentinel instance. You add the Windows Firewall data connector in Microsoft Sentinel. You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1. Solution: You install the Azure Connected Machine agent on Server1. Does this meet the goal?

Options:

A.

Yes

B.

No

Question 5

Your network contains an on-premises Active Directory Domain Services (AD DS) domain. The domain contains the servers shown in the following table.

For each server. Windows Defender Firewall is configured to allow only communication between servers on the same segment. Server! has the following connection security rule:

• Name: Rule1

• Rule type: Isolation

• Requirement: Require authentication for inbound connections and request authentication for outbound connections

• Authentication method: Computer (Kerberos V5)

• Profile: Domain. Private. Public

Server2 does not have any connection security rules.

Server3 has the following connection security rule:

• Name: Rute3

• Rule type: Server-to-server

• Endpoints:

o Computers in Endpoint 1:192.168.50/24

o Computers in Endpoint 2: 192.168.1.0/24

• Requirement Request authentication (or inbound and outbound connections

• Authentication method: Computer (Kerberos V5)

• Profile: Domain. Private. Public

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

as

Exhibit

as

Options:

Question 6

You have on-premises Windows devices. You have an Azure subscription that contains a virtual network named VNet1. You need to create a Site-to-Site (S2S) VPN between the on-premises network and VNet1. Which three resources should you create? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options:

A.

a network security group (NSG)

B.

an Azure NAT gateway

C.

an Azure Route Server

D.

a VPN connection

E.

a virtual network gateway

F.

a local network gateway

Question 7

You have a Storage Spaces Direct configuration that has persistent memory and contains the data volumes shown in the following table: Volume1 (NTFS), Volume2 (ReFS). You plan to add data volumes to Storage Spaces Direct as shown in the following table: Volume3 (NTFS), Volume4 (ReFS). On which volumes can you use direct access (DAX)?

as

Existing data volumes

as

Planned data volumes

Options:

A.

Volume3 only

B.

Volume4 only

C.

Volume1 and Volume3 only

D.

Volume2 and Volume4 only

E.

Volume3 and Volume4 only

Question 8

You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant.

The AD DS domain contains a domain controller named DC1. DC1 does NOT have internet access.

You need to configure password security for on-premises users. The solution must meet the following requirements:

• Prevent the users from using known weak passwords.

• Prevent the users from using the company name in passwords.

What should you do? To answer, drag the appropriate configurations to the correct targets. Each configuration may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

as

Options:

Question 9

You have a file server that runs Windows Server and has the File Server Resource Manager role service installed. The server hosts a file share named D:\Shares\Contracts.

You need to configure File Server Resource Manager (FSRM). The solution must meet the following requirements:

• Prevent users from saving .mp3 and .mp4 files.

• Automatically set the DataUse value for contract files.

• Move files that have datause-Archive and have NOT been accessed for 365 days to a folder named D:\Expired.

Which FSRM feature should you use for each requirement? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

as

Options:

Question 10

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.

You need to perform the following tasks:

• Createasnapshotofcontoso.com.

• Expose the snapshot as a read-only AD DS instance.

What should you use for each task? To answer, drag the appropriate tools to the correct tasks. Each tool may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

as

Exhibit

Options:

Question 11

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. Contoso.com contains a member server named server1.contoso.com. You cannot resolve the FQDN of server1.contoso.com. You verify that Windows Defender Firewall is configured correctly and that you can ping server1.contoso.com successfully by using the server ' s IP address. You need to validate that the DNS record for server1.contoso.com exists. Which command should you run?

Options:

A.

tracert

B.

ipconfig

C.

pathping

D.

nslookup

Question 12

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains two users named Contractor1 and Admin1.

You need to configure Account options for the users. The solution must meet the following requirements:

• Contractor1 must be prevented from signing in to their client computer until an administrator enables their account.

• The credentials of Admin1 must NOT be usable by services that access network resources on behalf of users

What should you select for each user? To answer, drag the appropriate account options to the correct users. Each option may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

as

Options:

Question 13

You have a Hyper-V failover cluster named Cluster1 that contains two nodes named Node1 and Node2, and a Hyper-V host named Host1.

You have the virtual machines shown in the following table.

The Balancer settings for Cluster1 are shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

as

Exhibit

as

Exhibit

as

Exhibit

Options:

Question 14

Your network contains an on-premises Active Directory Domain Services (AD DS) domain.

The domain contains the servers shown in the following table.

Server1 has the connection security rule as shown in the Server1 exhibit. (Click the Server1 tab.)

Server2 has the connection security rule as shown in the Server2 exhibit. (Click the Server2 tab.)

Server1 has the inbound firewall rules as shown in the Server1 inbound rules exhibit. (Click the Server1 inbound rules tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

as

Exhibit

as

Exhibit

as

Exhibit

as

Exhibit

as

Exhibit

Options:

Question 15

You have three servers named Server1, Server2, and Server3 that run Windows Server and have the Hyper-V server role installed. Server1 hosts an Azure Migrate appliance named Migrate1. You plan to migrate virtual machines to Azure. You need to ensure that any new virtual machines created on Server1, Server2, and Server3 are available in Azure Migrate. What should you do?

Options:

A.

On Migrate1, add a discovery source.

B.

On the DNS server used by Migrate1, create a GlobalName zone.

C.

On Migrate1, set the Startup Type of the Computer Browser service to Automatic.

D.

On the network that has Migrate1 deployed, deploy a WINS server.

Question 16

You have a Remote Desktop Services (RDS) farm deployment. Administrators connect to the farm by using Remote Desktop from domain-joined workstations on the internal network. You need to enable administrators to connect to the RDS farm by using Remote Desktop from the internet. The solution must prevent opening internal RDP ports to the internet. Which role should you add to the deployment?

Options:

A.

Remote Desktop Connection Broker (RD Connection Broker)

B.

Remote Desktop Virtualization Host (RD Virtualization Host)

C.

Remote Desktop Session Host (RD Session Host)

D.

Remote Desktop Web Access (RD Web Access)

E.

Remote Desktop Gateway (RD Gateway)

Question 17

You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server and is in the East US Azure region. The subscription contains the storage accounts shown in the following table. You plan to configure the Diagnostic settings for VM1. Which storage accounts should you specify for the settings? (Exhibit: storage accounts table.)

as

Storage accounts

Options:

A.

storage1 only

B.

storage1 and storage2 only

C.

storage1 and storage4 only

D.

storage1, storage2, and storage3 only

E.

storage1, storage2, storage3, and storage4

Question 18

Your network contains an Active Directory domain named contoso.com. The domain contains the computers shown in the following table: Computer1 (Windows 11), Server1 (Windows Server 2016), Server2 (Windows Server 2019), Server3 (Windows Server 2022). On Server3, you create a Group Policy Object (GPO) named GPO1 and link GPO1 to contoso.com. GPO1 includes a shortcut preference named Shortcut1 that has item-level targeting configured to apply only when the operating system is Windows Server 2022 Family. To which computer will Shortcut1 be applied?

as

Computer/OS table

as

Item-level targeting editor

Options:

A.

Server3 only

B.

Computer1 and Server3 only

C.

Server2 and Server3 only

D.

Server1, Server2, and Server3 only

Question 19

You have an Azure subscription named sub1 and 500 on-premises virtual machines that run Windows Server. You plan to onboard the on-premises virtual machines to Azure Arc by running the Azure Arc deployment script. You need to create an identity that will be used by the script to authenticate access to sub1. The solution must use the principle of least privilege. How should you complete the command? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. ___ -DisplayName ' arc-for-servers ' -Role ___

as

Options:

Question 20

You have an Azure subscription that contains two virtual machines named VM1 and VM2. VM1 runs Windows Server. VM2 runs Ubuntu Linux. You need to monitor VM1 and VM2 by using VM insights. The solution must meet the following requirements:

• Ensure that you can monitor the memory usage on VM1.

• Ensure that you run the Map feature on VM2.

The solution must minimize the number of agents required for each virtual machine.

Which agents are required on each virtual machine? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 21

You deploy Azure Migrate to an on-premises network. You have an on-premises physical server named Server1 that runs Windows Server and has the following configuration: Operating system disk 600 GB, Data disk 3 TB, NIC Teaming: Enabled, Mobility service: installed, Windows Firewall: Enabled, Microsoft Defender Antivirus: Enabled. You need to ensure that you can use Azure Migrate to migrate Server1. Solution: You disable NIC Teaming on Server1. Does this meet the goal?

Options:

A.

Yes

B.

No

Question 22

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains servers that run Windows Server and store BitLocker recovery keys in AD DS. A server named Server1 starts in BitLocker recovery mode. You need to identify the BitLocker recovery key for Server1. Solution: You run repair-bde.exe by using a BitLocker key package exported from AD DS. Does this meet the goal?

Options:

A.

Yes

B.

No

Question 23

Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains three servers that run Windows Server and have the Hyper-V server role installed. Each server has a Switch Embedded Teaming (SET) team. You need to verify that Remote Direct Memory Access (RDMA) and all the required Windows Server settings are configured properly on each server. What should you use?

Options:

A.

Server Manager

B.

the Validate-Dcb cmdlet

C.

the Get-NetAdapter cmdlet

D.

Failover Cluster Manager

Question 24

You have the on-premises servers shown in the following table. You have an Azure subscription. You plan to migrate the servers to Azure generation 2 virtual machines. Which servers can be migrated to Azure by using Azure Migrate?

as

On-premises servers, OS disk size, and BitLocker table

Options:

A.

Server1 only

B.

Server2 only

C.

Server1 and Server2 only

D.

Server2 and Server3 only

E.

Server1, Server2, and Server3

Question 25

You have servers that have the DNS Server role installed. The servers are configured as shown in the following exhibit (Server1/Paris/contoso.com/10.1.1.1, Server2/New York/no local zone/10.2.2.2). All the client computers in the New York office use Server2 as the DNS server. You need to configure name resolution in the New York office to meet the following requirements: ensure that the client computers in New York can resolve names from contoso.com; ensure that Server2 forwards all DNS queries for internet hosts to 131.107.100.200. The solution must NOT require modifications to Server1. Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

as

Server1 (Paris, contoso.com, 10.1.1.1) / Server2 (New York, no local zone, 10.2.2.2).

Options:

A.

a forwarder

B.

a conditional forwarder

C.

a delegation

D.

a secondary zone

E.

a reverse lookup zone

Question 26

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an on-premises server named Server1 that runs Windows Server. You have a Microsoft Sentinel instance. You add the Windows Firewall data connector in Microsoft Sentinel. You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1. Solution: You install the Microsoft Integration Runtime on Server1. Does this meet the goal?

Options:

A.

Yes

B.

No

Question 27

You need to meet the technical requirements for User1. The solution must use the principle of least privilege. What should you do?

Options:

A.

Add User1 to the Server Operators group in contoso.com.

B.

Create a delegation on contoso.com.

C.

Add User1 to the Account Operators group in contoso.com.

D.

Create a delegation on OU3.

Question 28

You need to meet the technical requirements for the site links. Which users can perform the required task?

Options:

A.

Admin1 only

B.

Admin1 and Admin3 only

C.

Admin1 and Admin2 only

D.

Admin3 only

E.

Admin1, Admin2, and Admin3

Question 29

You need to meet the technical requirements for Server1. Which users can currently perform the required task?

Options:

A.

Admin1 only

B.

Admin3 only

C.

Admin1 and Admin3 only

D.

Admin1, Admin2, and Admin3

Question 30

You need to meet the technical requirements for VM1. Which cmdlet should you run first? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

as

Options:

Question 31

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

as

Options:

Question 32

You need to meet the technical requirements for VM3. On which volume can you enable Data Deduplication?

Options:

A.

D and E only

B.

C, D, E, and F

C.

D only

D.

C and D only

E.

D, E, and F only

Question 33

Which groups can you add to Group3, and which groups can you add to Group5? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

as

Options:

Question 34

You need to meet the technical requirements for Server4. Which cmdlet should you run on Server1, and which cmdlet should you run on Server4? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

as

Options:

Question 35

You need to meet the technical requirements for Server3. Which users can perform the required task?

Options:

A.

Admin1 only

B.

Admin3 only

C.

Admin1 and Admin2 only

D.

Admin1 and Admin3 only

E.

Admin1, Admin2, and Admin3

Question 36

You need to meet the technical requirements for VM2. What should you do?

Options:

A.

Implement shielded virtual machines.

B.

Enable the Guest Services integration service.

C.

Implement Credential Guard.

D.

Enable Enhanced Session Mode.

Question 37

What is the effective minimum password length for User1 and Admin1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Exhibit

Options:

Question 38

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for Share1. What should you use?

Options:

A.

Storage Migration Service

B.

File Server Resource Manager (FSRM)

C.

Server Manager

D.

Storage Replica

Question 39

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for Cluster3. What should you include in the solution?

Options:

A.

Enable integration services on all the virtual machines.

B.

Add a Windows Server server role.

C.

Configure a fault domain for the cluster.

D.

Add a failover cluster role.

Question 40

You need to configure BitLocker on Server4.

On which volumes can you turn on BitLocker, and on which volumes can you turn on auto-unlock? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 41

You need to meet the technical requirements for Cluster2.

Which four actions should you perform in sequence before you can enable replication? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

as

Options:

Question 42

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to identify the minimum number of Azure Site Recovery Provider installations required to protect Cluster2. What is the minimum number of installations required?

Options:

A.

2

B.

4

C.

12

D.

16

Question 43

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

as

Options:

Question 44

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to back up Server4 to meet the technical requirements. What should you do first?

Options:

A.

Deploy Microsoft Azure Backup Server (MABS).

B.

Configure Windows Server Backup.

C.

Install the Microsoft Azure Recovery Services (MARS) agent.

D.

Configure Storage Replica.

Question 45

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to promote DC4 to meet the technical requirements. Which domain controller should be online to meet the technical requirements for DC4?

Options:

A.

DC1

B.

DC2

C.

DC3

Question 46

You need to implement alerts for the domain controllers. The solution must meet the technical requirements.

What should you do on the domain controllers, and what should you create on Azure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 47

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for User1. To which group in contoso.com should you add User1?

Options:

A.

Domain Admins

B.

Account Operators

C.

Schema Admins

D.

Backup Operators

Question 48

With which servers can Server1 and Server3 communicate? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Exhibit

Options:

Question 49

Which two languages can you use for Task1? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options:

A.

Java

B.

Bicep

C.

JavaScript

D.

Python

E.

PowerShell

Question 50

You need to implement the planned change for Data1. Which actions should you perform in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. NOTE: Each correct selection is worth one point.

as

Options:

Question 51

You need to implement the planned change for Microsoft Entra users to sign in to Server1. Which PowerShell cmdlet should you run?

Options:

A.

Add-ADComputerServiceAccount

B.

Set-AzVM

C.

Set-AzVMExtension

D.

New-ADComputer

Question 52

You need to ensure that data availability on SSPace1 meets the technical requirements. What is the maximum number of physical disks that can fail on each disk without losing data? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

as

Options:

Question 53

You are planning the migration of APP3 and APP4 to support the Azure migration plan. What should you do on Cluster1 and in Azure before you perform the migration? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

as

Options:

Question 54

You are planning the migration of Archive1 to support the on-premises migration plan. What is the minimum number of IP addresses required for the node and cluster roles on Cluster3?

Options:

A.

2

B.

3

C.

4

D.

5

Question 55

You are planning the deployment of Microsoft Sentinel. Which type of Microsoft Sentinel data connector should you use to meet the security requirements?

Options:

A.

Threat Intelligence - TAXII

B.

Microsoft Entra ID

C.

Microsoft Defender for Cloud

D.

Microsoft Defender for Identity

Question 56

You are planning the data share migration to support the on-premises migration plan. What should you use to perform the migration?

Options:

A.

Storage Migration Service

B.

Microsoft File Server Migration Toolkit

C.

File Server Resource Manager (FSRM)

D.

Windows Server Migration Tools

Question 57

You are planning the DHCP1 migration to support the DHCP migration plan. Which two PowerShell cmdlets should you run on DHCP1, and which two PowerShell cmdlets should you run on DHCP2? To answer, drag the appropriate cmdlets to the correct servers. Each cmdlet may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

as

Options:

Question 58

You need to implement a security policy solution to authorize the applications. The solution must meet the security requirements. Which service should you use to enforce the security policy, and what should you use to manage the policy settings? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

as

Options:

Question 59

You are planning the implementation of Cluster2 to support the on-premises migration plan. You need to ensure that the disks on Cluster2 meet the security requirements. In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.

as

Options:

Question 60

You are planning the website migration to support the Azure migration plan. How should you configure WebApp1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

as

Options:

Question 61

You are remediating the firewall security risks to meet the security requirements. What should you configure to reduce the risks?

Options:

A.

a Group Policy Object (GPO)

B.

adaptive network hardening in Microsoft Defender for Cloud

C.

a network security group (NSG) in Sub1

D.

an Azure Firewall policy

Question 62

Which three actions should you perform in sequence to meet the security requirements for Webapp1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

as

Options:

Question 63

You need to configure the Group Policy settings to ensure that the Azure Virtual Desktop session hosts meet the security requirements. What should you configure?

Options:

A.

security filtering for the link of GPO4

B.

security filtering for the link of GPO1

C.

loopback processing in GPO4

D.

the Enforced property for the link of GPO1

E.

loopback processing in GPO1

F.

the Enforced property for the link of GPO4

Question 64

You are planning the implementation of Azure Arc to support the planned changes. You need to configure the environment to support configuration management policies. What should you do?

Options:

A.

Hybrid join all the servers to Microsoft Entra ID.

B.

Create a hybrid runbook worker in Azure Automation.

C.

Deploy the Azure Connected Machine agent to all the servers.

D.

Deploy the Azure Monitor agent to all the servers.

Question 65

You need to configure Azure File Sync to meet the file sharing requirements. What is the minimum number of sync groups you should create, and what is the minimum number of Storage Sync Services you should create? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

as

Options:

Question 66

You need to implement a name resolution solution that meets the requirements for DC3. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options:

A.

Create an Azure private DNS zone named corp.fabrikam.com.

B.

Create a virtual network link in the corp.fabrikam.com Azure private DNS zone.

C.

Create an Azure DNS zone named corp.fabrikam.com.

D.

Configure the DNS Servers settings for Vnet1.

E.

Enable autoregistration in the corp.fabrikam.com Azure private DNS zone.

F.

On DC3, install the DNS Server role.

G.

Configure a conditional forwarder on DC3.

Question 67

You need to configure remote administration to meet the security requirements. What should you use?

Options:

A.

just-in-time (JIT) VM access

B.

Microsoft Entra Privileged Identity Management (PIM)

C.

the Remote Desktop extension for Azure Cloud Services

D.

an Azure Bastion host

Question 68

You need to configure network communication between the Seattle and New York offices. The solution must meet the requirements. What should you configure? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

as

Options:

Question 69

What should you implement for the deployment of DC3?

Options:

A.

Microsoft Entra Domain Services

B.

Microsoft Entra Application Proxy

C.

an Azure virtual machine

D.

a Microsoft Entra administrative unit

Question 70

You need to implement an availability solution for DHCP that meets the requirements. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options:

A.

On DHCP1, create a scope that contains 25 percent of the IP addresses from Scope2.

B.

On the router in each office, configure a DHCP relay.

C.

On DHCP2, configure a scope that contains 25 percent of the IP addresses from Scope1.

D.

On each DHCP server, install the Failover Clustering feature and add the DHCP cluster role.

E.

On each DHCP scope, configure DHCP failover.

Page: 1 / 51
Total 510 questions