live chatMcAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams
Pass4Test 10%OFF Discount Code

Microsoft Administering Windows Server - AZ-802 Exam Questions

QUESTION NO: 1
You have a server named Server1 that runs Windows Server and has the Hyper-V server role installed.
You need 10 limit which Hyper-V module cmdlets helpdesk users can use when administering Server 1 remotely.
You configure Just Enough Administration (JEA) and successfully build the role capabilities and session configuration files.
How should you complete the PowerShell command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:

In Just Enough Administration (JEA), you restrict what remote users can do by publishing a PowerShell session endpoint that references a session configuration file and one or more role capability files . The AZ-
800 "Administering Windows Server Hybrid Core Infrastructure" materials explain that a JEA deployment follows this order: (1) create role capability files (.psrc) in a module's RoleCapabilities folder to enumerate allowed cmdlets, functions, and parameters; (2) author a session configuration file (.pssc) -typically with New-PSSessionConfigurationFile -that maps users or groups to the role capabilities; and (3) register the endpoint with Register-PSSessionConfiguration , supplying the .pssc path and a Name for the endpoint. Only after registration can helpdesk users connect to the constrained endpoint.
Critically, among the listed cmdlets, Register-PSSessionConfiguration is the one that accepts -Name and - Path to a .pssc file, which matches the prompt ( -Path .\hypervJeaConfig __ -Name ' hypervJeaHelpDesk ' - Force ). Enter-PSSession is for connecting to an already published endpoint, and New- PSSessionConfigurationFile creates the .pssc but does not publish it. Likewise, file types .ps1 (script), .psm1 (module), and .psrc (role capability) are not valid for the -Path parameter when registering an endpoint.
Therefore, the correct completion is:
Register-PSSessionConfiguration -Path .\hypervJeaConfig.pssc -Name ' hypervJeaHelpDesk ' -Force .
QUESTION NO: 2
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains domain controllers that run Windows Server 2019 and are configured as shown in the following table. You plan to run the adprep /domainprep command. Which domain controller should be available for the command to complete?

Domain controllers and FSMO role table
Correct Answer: D
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 3
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a failover cluster named Cluster1 that hosts an application named App1. The General tab in App1 Properties is shown in the General exhibit. (Click the General tab.) The Failover tab in App1 Properties is shown in the Failover exhibit. (Click the Failover tab.) Server2 shuts down unexpectedly. You need to ensure that when you start Server2, App1 continues to run on Server2. Solution: You pause the Server1 node in Cluster1 and then start Server1. Does this meet the goal?
Correct Answer: B
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 4
You have an Azure virtual machine named VM1 that runs Windows Server. You need to perform the following tasks on VM1:
* Configure Windows Defender Firewall to allow Remote Desktop connections.
* Configure where to store the logs of the virtual machine console.
Which two settings should you use? To answer, select the settings in the answer area. NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
On an Azure VM, Remote Desktop connectivity problems caused by a Windows Defender Firewall rule that no longer allows inbound RDP traffic are repaired from the VM ' s Help > Reset password blade. Selecting Reset configuration only runs the VM Access Agent extension, which re-enables the Remote Desktop service and creates (or restores) the Windows Defender Firewall rule permitting inbound connections on TCP port
3389, without requiring an existing RDP session or direct console access to the VM. The Serial console blade, by contrast, only provides out-of-band access to the Windows Special Administration Console (SAC) over the hypervisor channel; it does not itself modify any firewall rule, and while an administrator could type netsh commands there manually, Serial console is not the setting that configures the firewall. The location where the serial console ' s text output and the VM ' s boot screenshots are persisted to a storage account is configured separately, on the Boot diagnostics blade, not on the general Diagnostic settings blade, which instead routes platform metrics and Activity Log entries to destinations such as Log Analytics or Event Hubs and plays no role in storing VM console output. Boot diagnostics must be enabled with a linked storage account before the Serial console feature becomes usable, since both the console output stream and the periodic boot screenshots are written through that same storage configuration.
QUESTION NO: 5
You have four servers that run Windows Server. Each server has the direct-attached storage (DAS) devices shown in the following table.
You need to deploy Storage Spaces Direct.
Which types of devices will be used for the cache, and what will be the default cache behavior? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit
Exhibit
Correct Answer:

Explanation:
When a Storage Spaces Direct pool contains three distinct drive tiers, in this case SSD, NVMe, and HDD as shown in the exhibit, Storage Spaces Direct automatically designates only the single fastest media type present, NVMe, as the cache devices for the pool, leaving both the SSD and HDD drives entirely to provide usable pool capacity rather than splitting cache duty across more than one tier. The default cache behavior that Storage Spaces Direct applies then differs depending on which capacity tier is being cached: cached HDD capacity drives receive full read-and-write caching, because HDDs benefit the most from having both random read and random write operations absorbed and accelerated by the much faster flash-based cache tier sitting in front of them. Cached SSD capacity drives, on the other hand, receive write-only caching, since SSD read latency is already low enough on its own that adding read caching in front of it would provide little additional performance benefit while still consuming cache capacity and adding unnecessary wear to the cache devices.
Combining these two distinct behaviors together, the documented default outcome for this specific three-tier deployment is NVMe-only caching devices with a combined cache behavior of read/write for the HDD capacity tier and write-only for the SSD capacity tier.
QUESTION NO: 6
You have a server named Server1 that runs Windows Server. Server1 has the storage pools shown in the following table. You plan to create a virtual disk named VDisk1 that will use storage tiers. Which pools can you use to create VDisk1?

Storage pools on Server1
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 7
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant. You deploy an app that adds custom attributes to the domain. From Azure Cloud Shell, you discover that you cannot query the custom attributes of users. You need to ensure that the custom attributes are available in Microsoft Entra ID. Which task should you perform from Microsoft Entra Connect first?
Correct Answer: B
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 8
Your network contains an Active Directory Domain Services (AD DS) forest. The forest functional level is Windows Server 2012 R2. The forest contains the domains shown in the following table. You create a user named Admin1. You need to ensure that Admin1 can add a new domain controller that runs Windows Server
2022 to the east.contoso.com domain. The solution must follow the principle of least privilege. To which groups should you add Admin1?

Forest domain and domain controller table
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 9
You need to meet the technical requirements for VM1. Which cmdlet should you run first? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Set-VMProcessor -VMName VM1 -ExposeVirtualizationExtensions $true
The requirement is to run virtual machines on VM1 itself, which means enabling nested virtualization so that VM1 (a guest VM hosted on Server2) can install Hyper-V and host its own virtual machines. Nested virtualization on Hyper-V requires the parent VM ' s virtual processor to expose the host ' s hardware virtualization extensions (Intel VT-x or AMD-V) through to the guest. This is done with the Set-VMProcessor cmdlet using the -ExposeVirtualizationExtensions parameter set to $true, run against VM1 from the Hyper-V host (Server2): Set-VMProcessor -VMName VM1 -ExposeVirtualizationExtensions $true. VM1 must be turned off before this setting can be applied, and after it is applied, VM1 needs the Hyper-V role installed inside the guest before it can run its own VMs. Set-VM, Set-VMBios, Set-VMHost, and Set-VMFirmware do not control virtualization extension exposure: Set-VM manages general VM configuration such as memory and name, Set-VMHost configures host-wide settings, and Set-VMFirmware/Set-VMBios control boot and firmware settings for generation 2 and generation 1 VMs respectively. Only Set-VMProcessor with - ExposeVirtualizationExtensions satisfies the stated requirement, making it the correct first step.
QUESTION NO: 10
Your network contains an Active Director/ Domain Services {AD DS) domain named contoso.com. The domain contains two sites named Site1 and Site2 and servers that run Windows Server and are configured as shown in the following table.
The domain contains a group named Group1 that contains Server3.
RODC1 has the Password Replication Policy shown in the following exhibit.

Exhibit

Exhibit

Exhibit
Exhibit
Correct Answer:

Explanation:
An RODC only caches (replicates) the password of a security principal that is explicitly permitted by its Password Replication Policy - in the exhibit, only members of the built-in Allowed RODC Password Replication Group and the custom Group1 are set to Allow, while Administrators, Account Operators, Backup Operators, Server Operators, and the Denied RODC Password Replication Group are all set to Deny.
A user who is not covered by an Allow entry authenticates through pass-through validation to a writable DC and never has credentials cached on the RODC, so User1 ' s credentials are not stored on RODC1, making statement 1 No. Because Server3 sits in Site2 alongside RODC1 and is a member of Group1 (an Allow entry), a user whose credentials are already cached there can still authenticate locally through RODC1 even if WAN connectivity to Site1 ' s writable domain controllers is lost, which is why User2 can sign in successfully during the outage, making statement 2 Yes. Interactive local sign-in to the RODC console itself is governed separately by the RODC ' s Administrator Role Separation (local Administrators group), not by the Password Replication Policy, and nothing in the scenario grants User3 that local logon right, so statement 3 is No.
QUESTION NO: 11
Which three actions should you perform in sequence to meet the security requirements for Webapp1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Correct Answer:

Explanation:
1. Create the KDS root key in AD DS. 2. Create a group managed service account (gMSA) in Active Directory. 3. Configure the IIS application pool (on WEB1 and WEB2) to run as the gMSA via a specified user account.
The requirement is that every instance of Webapp1 (running on both WEB1 and WEB2) uses the same identity, and that identity ' s password rotates automatically every 30 days, without any administrator manually resetting it. A standalone managed service account (sMSA) is tied to a single computer and cannot be shared across WEB1 and WEB2, so it does not meet the requirement. A group managed service account (gMSA) is designed exactly for this scenario: one AD-managed identity that multiple servers can use simultaneously, with the Key Distribution Service automatically rotating its password (by default every 30 days) without needing manual intervention or downtime. Before any gMSA can be created in the forest, a one- time prerequisite must exist: the KDS root key, which the Key Distribution Service uses to generate and later recompute the gMSA ' s password material. So the correct order is to first create the KDS root key, then create the gMSA object in Active Directory, and finally configure the IIS application pool on each web server to run as that gMSA using the " specified user account " identity option (entered as domain\gMSA$ with no password required, since the password is centrally managed). Creating a system- or user-assigned managed identity in Microsoft Entra ID does not apply here, since Webapp1 runs on IIS on domain-joined VMs, not as an Azure PaaS resource.
QUESTION NO: 12
Your network contains an Active Directory Domain Services (AD DS) domain. The functional level of the domain is Windows Server 2016. All domain controllers run Windows Server 2025. You need to prevent cached credentials and older authentication protocols, such as NTLM, from being used by highly privileged user accounts. What should you do?
Correct Answer: D
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 13
Your on-premises network contains an Active Directory Domain Services (AD OS) domain.
You plan to implement a failover cluster to enable a highly available file server. You are evaluating the following clustered file servers:
* File server for general use
* Scale-out file server
Which type of storage should you use for each file server? To answer, drag the appropriate storage types to the correct file servers. Each storage type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
File server for general use: A logical unit number (LUN). Scale-out file server: A Cluster Shared Volume (CSV).
A traditional, general-use clustered file server runs as an active-passive clustered role, meaning only one cluster node owns and mounts the role ' s storage at any given time, with ownership moving as a unit to another node during a failover. This storage is typically presented as NTFS-formatted storage on a logical unit number (LUN) from shared storage, since only the single owning node needs direct, exclusive access to it at any moment. A Scale-Out File Server, by contrast, is specifically designed to provide continuous, active- active availability, where every node in the cluster serves the same shares to clients simultaneously rather than only one node at a time. That concurrent, multi-node access model requires storage formatted with the Cluster Shared Volume File System, which is what allows every cluster node to read and write to the same volume at the same time without corrupting the file system, making a Cluster Shared Volume a required component of any Scale-Out File Server deployment. Neither a local data volume, which is not shared storage at all, nor a Network Attached Storage volume, which is not natively supported as backing storage for either of these two clustered file server role types, is the correct choice for either scenario.
QUESTION NO: 14
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains two servers named Server1 and Server2. Server1 runs Windows Server 2019 and hosts multiple printers. Server2 runs Windows Server 2025. Both servers have the Print and Document Services server role installed. You need to migrate the printers hosted on Server1 to Server2. The solution must minimize administrative effort.
What tools can you use?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 15
Your network contains two VLANs for client computers and one VLAN for a datacenter. Each VLAN is assigned an IPv4 subnet. Currently, all the client computers use static IP addresses. You plan to deploy a DHCP server to the VLAN in the datacenter. You need to use the DHCP server to provide IP configurations to all the client computers. What is the minimum number of scopes and DHCP relays you should create? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Scopes: 2. Relays: 2.
A DHCP scope corresponds to a single IP subnet, and the DHCP server must have one scope defined for each distinct client subnet it will service; since there are two separate client VLANs, each with its own IPv4 subnet, the server needs two scopes; the datacenter ' s own subnet does not need a scope because no client computers are located there. DHCP relies on broadcast traffic (DHCPDISCOVER) that routers do not forward between subnets by default, and the DHCP server itself sits in a third subnet (the datacenter VLAN), separate from both client VLANs. For each client VLAN ' s broadcast traffic to reach that remote DHCP server, a DHCP relay agent (or IP helper configuration) must be enabled on the router interface for that VLAN; because there are two client VLANs, each needing its own relay pointed at the DHCP server ' s address, two relay agents are required. The datacenter VLAN needs no relay of its own, since the DHCP server lives there directly and can hear local broadcasts natively (though there are no clients there to generate any). Therefore the minimum is two scopes and two relays.