We provide the AZ-802 study materials which are easy to be mastered, professional expert team and first-rate service to make you get an easy and efficient learning and preparation for the AZ-802 test. Our product’s price is affordable and we provide the wonderful service before and after the sale to let you have a good understanding of our AZ-802 Study Materials before your purchase, you had better to have a try on our free demos.
| Section | Weight | Objectives |
|---|---|---|
| Manage virtual machines and containers | 15% | - Configure Azure Arc-enabled servers and VMs - Deploy and manage Hyper-V virtual machines - Deploy and manage containers and Kubernetes on Windows Server |
| Secure Windows Server on-premises and hybrid infrastructures | 10% | - Manage access control and permissions - Configure Windows Defender and audit policies - Implement security baselines and hardening |
| Manage Windows Servers and workloads in a hybrid environment | 20% | - Implement hybrid identity solutions - Deploy servers using Windows Admin Center and Azure Arc - Manage updates and patches across hybrid servers - Configure remote management and secure administration |
| Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments | 20% | - Install and configure domain controllers - Implement and manage Group Policy Objects - Integrate AD DS with Azure AD and Azure Arc - Manage FSMO roles and replication |
| Implement and manage an on-premises and hybrid networking infrastructure | 15% | - Configure IP addressing, DNS, and DHCP - Configure software-defined networking - Secure network traffic in hybrid environments - Implement hybrid network connectivity |
| Implement high availability and disaster recovery | 5% | - Monitor and troubleshoot Windows Server environments - Implement backup and recovery solutions - Perform server and workload migrations - Configure failover clustering - Use Azure Site Recovery for hybrid workloads |
| Manage storage and file services | 15% | - Integrate on-premises storage with Azure Storage - Configure file servers and shares - Configure data deduplication and replication - Implement Storage Spaces and Storage Spaces Direct |
>> Microsoft AZ-802 Reliable Study Guide <<
Our 2Pass4sure website try our best for the majority of examinees to provide the best and most convenient service. Under the joint efforts of everyone for many years, the passing rate of 2Pass4sure Microsoft's AZ-802 Certification Exam has reached as high as100%. If you buy our AZ-802 exam certification training materials, we will also provide one year free renewal service. Hurry up!
NEW QUESTION # 23
You have a cluster named Cluster! that contains two servers named Server! and Server2. Cluster1 has Storage Spaces Direct enabled. Cluster1 contains a virtual disk named Volume1 that is a 2-TB three-way mirror.
You discover that Volume! is full.
You connect a new 2-TB physical disk to each node of Cluster1.
You need to increase the size of Volume1. The solution must maintain resiliency.
How should you complete the script? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Newly attached drives that have not yet joined a Storage Spaces Direct pool report CanPool = $True, while drives already claimed by the pool report CanPool = $False, so filtering with -CanPool $True correctly targets only the two new 2-TB disks for Add-PhysicalDisk rather than accidentally re-selecting disks the pool already owns. The alternative filter using -CanPool $False would select existing pooled disks instead of the new ones and would fail to add any new capacity. Once the pool ' s raw capacity has grown by pooling the two new disks, Resize-Volume -FileSystemLabel Volume1 is used to grow the existing three-way-mirrored volume to consume the newly available capacity while keeping its three-way mirror resiliency setting fully intact, since resizing a volume in Storage Spaces Direct does not change its resiliency type. Among the offered target sizes, only 4 TB is larger than the current 2-TB volume and therefore actually increases Volume1 as the scenario requires; 1 TB and 2 TB would shrink or leave the volume unchanged. This two-step approach, pooling the new physical disks and then resizing the volume, is the standard S2D capacity-expansion workflow and avoids rebuilding, recreating, or migrating the volume to add space.
NEW QUESTION # 24
Your network contains three Active Directory Domain Services (AD DS) forests as shown in the following exhibit: contoso.com (with a child domain east.contoso.com) has a two-way forest trust with adatum.com; adatum.com (with a child domain west.adatum.com) also has a two-way forest trust with fabrikam.com; there is no trust relationship directly between contoso.com and fabrikam.com. The network contains the users User1 (east.contoso.com) and User2 (fabrikam.com). The network contains the security groups Group1 (Domain local, west.adatum.com), Group2 (Universal, adatum.com), and Group3 (Universal, east.contoso.
com). For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE:
Each correct selection is worth one point.
contoso.com (child: east.contoso.com) < -forest trust- > adatum.com (child: west.adatum.com) < -forest trust-
> fabrikam.com. No trust between contoso.com and fabrikam.com.
User1: east.contoso.com. User2: fabrikam.com.
Group1: Domain local, west.adatum.com. Group2: Universal, adatum.com. Group3: Universal, east.contoso.
com.
Answer:
Explanation:
Explanation:
You can add User1 to Group1: Yes. You can add User2 to Group3: No. You can grant Group2 permissions to the resources in the fabrikam.com domain: Yes.
A domain local group can accept members from any domain within its own forest, and, when a forest trust exists, from any domain in the entire trusted forest, because a forest trust extends to every domain in both forests, not just their root domains. Group1 is a domain local group in west.adatum.com (adatum.com forest), and User1 belongs to east.contoso.com, a child domain of contoso.com, which has a direct two-way forest trust with adatum.com covering both forests entirely; so User1 can be added to Group1. Group3, however, is a universal group, and universal group membership is restricted to principals from within the same single forest only, regardless of any trust - unlike domain local groups. User2 belongs to fabrikam.com, a separate forest from Group3 ' s forest (contoso.com), so User2 cannot be added to Group3 for that reason alone; there is also no trust path between contoso.com and fabrikam.com at all, since a forest trust is not transitive through an intermediate forest - adatum.com ' s separate trusts with each outer forest create no trust between them.
Granting permissions directly on a resource ' s ACL is different from group nesting, though: a universal group can be placed on an ACL in any domain that trusts its own forest, without the same-forest restriction that applies to membership. Because adatum.com (Group2 ' s forest) has a direct forest trust with fabrikam.com, Group2 can be granted permissions to resources in fabrikam.com.
NEW QUESTION # 25
You have a disaggregated cluster deployment. The deployment contains a scale-out file server (SOFS) cluster that runs Windows Server and a compute cluster that has the Hyper-V role enabled. You need to implement Storage Quality of Service (QoS). The solution must ensure that you can control the bandwidth usage between the SOFS cluster and the Hyper-V cluster. Which cmdlet should you run on each cluster? To answer, drag the appropriate cmdlets to the correct clusters. Each cmdlet may be used once, more than once, or not at all.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
SOFS: New-StorageQosPolicy; Hyper-V: Set-VMHardDiskDrive
In a disaggregated deployment, storage (the Scale-Out File Server cluster) and compute (the Hyper-V cluster) are separate clusters, and centralized Storage QoS is the supported mechanism for governing and capping the bandwidth/IOPS that VM virtual hard disks consume against that shared SOFS storage. The centralized Storage QoS policy itself -- defining minimum and/or maximum IOPS or throughput limits -- is created on the SOFS cluster using New-StorageQosPolicy; because policies are stored on the file server cluster, they can be referenced by any VM accessing CSV shares exposed by that SOFS, regardless of which Hyper-V host in the compute cluster the VM happens to run on. To actually apply a given policy to a specific VM ' s virtual hard disk, you run Set-VMHardDiskDrive on the Hyper-V cluster side, specifying the QoS policy (by - QoSPolicyID or -QoSPolicyName) on the VM ' s virtual disk attachment; the disk ' s I/O is then governed by that policy ' s bandwidth constraints regardless of Hyper-V host placement within the compute cluster. Set- VMSan is unrelated to Storage QoS; it configures Hyper-V Virtual SAN/Fibre Channel connectivity for guest clustering scenarios and plays no role in bandwidth governance between SOFS and Hyper-V clusters.
Therefore, the correct pairing is New-StorageQosPolicy on the SOFS cluster (to define the policy) and Set- VMHardDiskDrive on the Hyper-V cluster (to apply it to VM disks).
NEW QUESTION # 26
You have two servers named Server1 and Server2 that run Windows Server and have the Hyper-V role installed. You plan to deploy Hyper-V Replica between Server1 and Server2. The deployment will use certificate-based authentication. You need to configure the prerequisites for the Hyper-V Replica deployment.
Which two actions should you perform on each server? Each correct answer presents part of the solution.
Answer: B,C
Explanation:
Certificate-based (mutual-TLS) authentication for Hyper-V Replica listens for replication traffic over HTTPS, so each host must have the Hyper-V Replica HTTPS Listener (TCP-In) firewall rule enabled to accept incoming connections; the HTTP listener rule is only used for Kerberos-based authentication and doesn ' t apply here. Each host also needs a valid computer (machine) certificate installed - one that has both Server and Client Authentication EKUs, an associated private key, a subject name matching the host ' s FQDN, and a chain to a trusted root - because this is what replaces Active Directory Kerberos trust between the primary and Replica servers. A user certificate would not satisfy the machine-to-machine authentication that Hyper-V Replica performs, and creating a self-signed certificate on each host independently would not establish the shared trust chain both hosts need to validate each other ' s certificate during the replication handshake. Once both prerequisites are in place on Server1 and Server2, the Enable-VMReplication and Set-VMHost - HttpsCertificateThumbprint cmdlets (or the equivalent Hyper-V Manager wizard) can reference the installed computer certificate to complete the certificate-based replication setup.
NEW QUESTION # 27
You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server and uses Azure Disk Encryption. You need to identify which Azure key vault stores the encryption keys for VM1. The solution must minimize administrative effort. Which PowerShell cmdlet should you run?
Answer: A
Explanation:
Running Get-AzVMDiskEncryptionStatus against VM1 returns the current Azure Disk Encryption status for both its operating system disk and its data disks in a single call, and that returned status includes the key vault URL or resource ID where the encryption secrets for VM1 are actually stored, so this one cmdlet directly answers the question with no additional lookup steps required. Get-AzKeyVaultKey and Get- AzDiskEncryptionSet both require the administrator to already know which specific key vault or disk encryption set resource to query before they can return anything useful, which does not minimize effort when the goal is precisely to discover which key vault is associated with VM1 in the first place. Get-AzKeyVault, similarly, only enumerates the key vaults that exist within the subscription without tying any particular vault to VM1 ' s encryption configuration, so it would require the administrator to manually check each vault ' s contents to find the right one. Because Get-AzVMDiskEncryptionStatus ties the VM directly to its encryption key vault in a single, minimal-effort cmdlet call, it is the correct choice for identifying which key vault stores VM1 ' s encryption keys.
NEW QUESTION # 28
......
We have a group of experts dedicated to the AZ-802 exam questions for many years. And the questions and answers of our AZ-802 practice materials are closely related with the real exam. Besides, they constantly keep the updating of products to ensure the accuracy of questions. All AZ-802 Actual Exams are 100 percent assured. Besides, we price the AZ-802 actual exam with reasonable fee without charging anything expensive.
AZ-802 Exam Pass4sure: https://www.2pass4sure.com/Microsoft-Certified-Windows-Server-Hybrid-Administrator-Associate/AZ-802-actual-exam-braindumps.html