We at Crack4sure are committed to giving students who are preparing for the Microsoft AZ-802 Exam the most current and reliable questions . To help people study, we've made some of our Administering Windows Server exam materials available for free to everyone. You can take the Free AZ-802 Practice Test as many times as you want. The answers to the practice questions are given, and each answer is explained.
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the users shown in the following table.

The domain has the Group Policy Objects (GPOs) shown in the following table.

The GPOs are configured to map a drive named H as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Your on-premises network contains an Active Directory Domain Services (AD DS) domain.
The domain contains four servers named Server1, Server2. Server3. and Server4 that run Windows Server.
You configure the connection security rules shown in the following table.
Server4 does NOT have any connection security rules applied.
With which servers can Server1 and Server2 establish communication after the connection security rules are applied? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains 10 servers that run Windows Server. The servers have static IP addresses. You plan to use DHCP to assign IP addresses to the servers. You need to ensure that each server always receives the same IP address. Which type of identifier should you use to create a DHCP reservation for each server?
You have a Windows Server failover cluster named Cluster1 that has a cloud witness and the nodes shown in the following table.
Cluster1 has the roles shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

You have three servers named Server1, Server2, Server3 that run Windows Server and have the Hyper-V server role installed. You plan to create a hyper-converged cluster to host Hyper-V virtual machines. You need to ensure that you can store virtual machines in Storage Spaces Direct. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. You implement a central store. You create a new Group Policy Object (GPO) named GPO1. When you attempt to edit GPO1, you see that the " Administrative Templates: Policy definitions (ADMX files) retrieved from the central store " node shows only two settings (far fewer than the normal full set of Administrative Template settings). You need to ensure that all settings are available. Solution: You delete the \\contoso.com\SYSVOL\contoso.com\Policies\PolicyDefinitions folder. Does this meet the goal?

Group Policy Management Editor showing limited Administrative Templates settings
You have a server that runs Windows Server 2025 Standard and has the Hyper-V role installed. You need to upgrade the server to Windows Server 2025 Datacenter. The solution must minimize downtime. What should you run?
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains the domain controllers shown in the following exhibit: DC1 (holds schema master, infrastructure master, and domain naming master roles), DC2 (holds PDC emulator and RID master roles), DC3 (holds no FSMO roles). You need to configure DC3 to be the authoritative time server for the domain. Which operations master role should you transfer to DC3, and which console should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.


Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains servers that run Windows Server and store BitLocker recovery keys in AD DS. A server named Server1 starts in BitLocker recovery mode. You need to identify the BitLocker recovery key for Server1. Solution: You use ADSI Edit and view the properties of the Server1 computer object. Does this meet the goal?
You have an Azure subscription that contains the storage accounts shown in the following table. In the West US Azure region, you create a storage sync service named SyncA. You plan to create a sync group named GroupA. What is the maximum number of cloud endpoints you can use with GroupA?

Storage accounts table
You have an Azure subscription that contains an Azure key vault named Vault 1.
You deploy Azure Disk Encryption.
You configure Vault to support Azure Disk Encryption.
You need to ensure that you can encrypt Azure Disk Encryption artifacts before they are written to Vault 1. The solution must provide the highest level of encryption.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You plan to deploy an Azure virtual machine that will run Windows Server. The virtual machine will host an Active Directory Domain Services (AD DS) domain controller and a drive named F: on a new virtual disk. You need to configure storage for the virtual machine. The solution must meet the following requirements: maximize resiliency for AD DS; prevent accidental data loss. How should you configure the storage? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Your company has a main office and a branch office. The two offices are connected by using a WAN link. Each office contains a firewall that filters WAN traffic. The network in the branch office contains 10 servers that run Windows Server. All servers are administered from the main office only. You plan to manage the servers in the branch office by using a Windows Admin Center gateway. On a server in the branch office, you install the Windows Admin Center gateway by using the default settings. You need to configure the firewall in the branch office to allow the required inbound connection to the Windows Admin Center gateway. Which inbound TCP port should you allow?
You have a Hyper-V failover cluster named Cluster1 that contains two nodes named Node1 and Node2, and a Hyper-V host named Host1.
You have the virtual machines shown in the following table.
The Balancer settings for Cluster1 are shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a server named Server1 that runs Windows Server. You need to ensure that only specific applications can modify the data in protected folders on Server1. Solution: From App & browser control, you configure the Exploit protection settings. Does this meet the goal?
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains the domains shown in the following table.
You are implementing Microsoft Defender for Identity sensors.
You need to install the sensors on the minimum number of domain controllers. The solution must ensure that Defender for Identity will detect all the security risks in both the domains.
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit
Exhibit
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains the servers shown in the following table. Server1 contains the printers shown in the following table. You plan to use Print Management to migrate the printers to Server2. Which printers can be migrated and retain their current configuration? (Exhibits: servers table and printers table.)

Servers

Printers on Server1
You have a server that runs Windows Server.
You need to enable the following security features:
• Core isolation
• Force randomization for images {Mandatory ASLR)
Which Windows Security tile should you use to enable each feature? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains a single-domain Active Directory Domain Services (AD DS) forest named contoso.com. The functional level of the forest is Windows Server 2012 R2. All domain controllers run Windows Server 2012 R2. Sysvol replicates by using the File Replication Service (FRS). You plan to replace the existing domain controllers with new domain controllers that will run Windows Server 2022. You need to ensure that you can add the first domain controller that runs Windows Server 2022. Solution: You upgrade the PDC emulator. Does this meet the goal?
You have three servers named Server1, Server2, and Server3 that run Windows Server. The servers have the Hyper-V server role installed and are configured in a Storage Spaces Direct cluster named Cluster1. Cluster1 hosts a virtual machine named VM1 that has Windows Admin Center installed. You manage all servers and clusters by using Windows Admin Center. You purchase an Azure subscription. You need to configure email alerts in Azure Monitor for the following: -- Disk Capacity Utilization Over 80% for 10 Minutes -- Any critical alert in the cluster system event log -- Memory Utilization over 95% for 10 minutes -- Heartbeat fewer than 5 beats for 5 Minutes -- CPU Utilization over 85% for 10 Minutes -- Any health service faults for the cluster The solution must use the minimum amount of administrative effort. What should you do?
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named DHCP1 that runs Windows Server and has the DHCP Server role installed. DHCP1 has a static IPv4 address of 10.10.10.5/24. DHCP1 is authorized in AD DS and contains an active scope for a subnet of 10.10.20.0/24. Client computers on the 10.10.20.0/24 subnet receive APIPA addresses. You verify that the DHCP Server service is running, and the scope has available IP addresses. You need to ensure that the computers on 10.10.20.0/24 can obtain IPv4 address leases from DHCP1. What should you do?
Which groups can you add to Group3, and which groups can you add to Group5? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to meet the technical requirements for Server4. Which cmdlet should you run on Server1, and which cmdlet should you run on Server4? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to meet the technical requirements for Server1. Which users can currently perform the required task?
You need to meet the technical requirements for VM2. What should you do?
You need to meet the technical requirements for the site links. Which users can perform the required task?
You need to meet the technical requirements for User1. The solution must use the principle of least privilege. What should you do?
You need to meet the technical requirements for Server3. Which users can perform the required task?
You need to meet the technical requirements for VM3. On which volume can you enable Data Deduplication?
You need to meet the technical requirements for VM1. Which cmdlet should you run first? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

What is the effective minimum password length for User1 and Admin1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for Cluster3. What should you include in the solution?
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to back up Server4 to meet the technical requirements. What should you do first?
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to promote DC4 to meet the technical requirements. Which domain controller should be online to meet the technical requirements for DC4?
You need to meet the technical requirements for Cluster2.
Which four actions should you perform in sequence before you can enable replication? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to identify the minimum number of Azure Site Recovery Provider installations required to protect Cluster2. What is the minimum number of installations required?
You need to implement alerts for the domain controllers. The solution must meet the technical requirements.
What should you do on the domain controllers, and what should you create on Azure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for Share1. What should you use?
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for User1. To which group in contoso.com should you add User1?
With which servers can Server1 and Server3 communicate? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
You need to configure BitLocker on Server4.
On which volumes can you turn on BitLocker, and on which volumes can you turn on auto-unlock? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You need to ensure that data availability on SSPace1 meets the technical requirements. What is the maximum number of physical disks that can fail on each disk without losing data? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to implement the planned change for the Azure DNS Private Resolver. Which private DNS zones can you use for name resolution?
DC1 fails.
You need to meet the technical requirements for the schema master.
Yourunntdsutil.exe.
Which five commands should you run in sequence? To answer, move the appropriate commands from the list of commands to the answer area and arrange them in the correct order?

Which two languages can you use for Task1? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
You need to configure remote administration to meet the security requirements. What should you use?
You are planning the implementation of Azure Arc to support the planned changes. You need to configure the environment to support configuration management policies. What should you do?
You need to implement an availability solution for DHCP that meets the requirements. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
You need to configure network communication between the Seattle and New York offices. The solution must meet the requirements. What should you configure? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to implement a name resolution solution that meets the requirements for DC3. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
You need to configure the Group Policy settings to ensure that the Azure Virtual Desktop session hosts meet the security requirements. What should you configure?
Which three actions should you perform in sequence to meet the security requirements for Webapp1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You need to configure Azure File Sync to meet the file sharing requirements. What is the minimum number of sync groups you should create, and what is the minimum number of Storage Sync Services you should create? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

What should you implement for the deployment of DC3?
You are planning the deployment of Microsoft Sentinel. Which type of Microsoft Sentinel data connector should you use to meet the security requirements?
You are planning the implementation of Cluster2 to support the on-premises migration plan. You need to ensure that the disks on Cluster2 meet the security requirements. In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.

You are planning the migration of APP3 and APP4 to support the Azure migration plan. What should you do on Cluster1 and in Azure before you perform the migration? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You are planning the data share migration to support the on-premises migration plan. What should you use to perform the migration?
You need to implement a security policy solution to authorize the applications. The solution must meet the security requirements. Which service should you use to enforce the security policy, and what should you use to manage the policy settings? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You are planning the migration of Archive1 to support the on-premises migration plan. What is the minimum number of IP addresses required for the node and cluster roles on Cluster3?
You are planning the www.fabrikam.com website migration to support the Azure migration plan. How should you configure WebApp1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You are remediating the firewall security risks to meet the security requirements. What should you configure to reduce the risks?
You are planning the DHCP1 migration to support the DHCP migration plan. Which two PowerShell cmdlets should you run on DHCP1, and which two PowerShell cmdlets should you run on DHCP2? To answer, drag the appropriate cmdlets to the correct servers. Each cmdlet may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

3 Months Free Update
3 Months Free Update
3 Months Free Update