過去数年にわたって、何百人もの業界の専門家を集め、数え切れないほどの困難を克服し、最終的に完全な学習製品であるAZ-802テスト回答を作成しました。カスタマーサービスは24時間ご利用いただけます。メールまたはオンラインでいつでもご連絡いただけます。さらに、AZ-802テストトレントを購入するためのすべての顧客情報は、厳重に機密保持されます。お客様のプライバシーを第三者に開示することも、営利目的で使用することもありません。次に、製品の詳細を紹介します。
| Section | Weight | Objectives |
|---|---|---|
| Secure Windows Server on-premises and hybrid infrastructures | 10% | - Configure Windows Defender and audit policies - Implement security baselines and hardening - Manage access control and permissions |
| Manage Windows Servers and workloads in a hybrid environment | 20% | - Configure remote management and secure administration - Manage updates and patches across hybrid servers - Implement hybrid identity solutions - Deploy servers using Windows Admin Center and Azure Arc |
| Implement and manage an on-premises and hybrid networking infrastructure | 15% | - Configure IP addressing, DNS, and DHCP - Implement hybrid network connectivity - Configure software-defined networking - Secure network traffic in hybrid environments |
| Implement high availability and disaster recovery | 5% | - Implement backup and recovery solutions - Monitor and troubleshoot Windows Server environments - Configure failover clustering - Use Azure Site Recovery for hybrid workloads - Perform server and workload migrations |
| Manage virtual machines and containers | 15% | - Deploy and manage Hyper-V virtual machines - Configure Azure Arc-enabled servers and VMs - Deploy and manage containers and Kubernetes on Windows Server |
| Manage storage and file services | 15% | - Configure file servers and shares - Implement Storage Spaces and Storage Spaces Direct - Configure data deduplication and replication - Integrate on-premises storage with Azure Storage |
| Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments | 20% | - Integrate AD DS with Azure AD and Azure Arc - Install and configure domain controllers - Manage FSMO roles and replication - Implement and manage Group Policy Objects |
資格試験の意味は、いくつかの点で、さまざまな専門分野での能力を示すAZ-802資格を取得する受験者の能力を証明することです。 AZ-802学習ガイド教材を選択すると、限られた学習時間でより多くの価値を創造し、より多くの知識を学び、受験できる試験を受けることができます。資格のあるAZ-802試験を通じて、これは私たちのAZ-802の実際の質問であり、すべてのユーザーの共通の目標であり、私たちは信頼できるヘルパーなので、このような良い機会をお見逃しなく。
質問 # 19
With which servers can Server1 and Server3 communicate? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Exhibit
正解:
解説:
Explanation:
Server1 can communicate with: Server2, Server3, and Server4. Server3 can communicate with: Server1 and Server2 only.
Server4 has no isolation connection security rule configured at all, so it never attempts or performs IPsec authentication with any peer. Server1 ' s rule only requests IPsec in both directions rather than requiring it, meaning that if IPsec negotiation does not occur -- as with Server4, which has no IPsec capability configured
-- the connection still falls back to succeed in the clear; Server1 can therefore reach Server2, Server3, and Server4. Server3 ' s rule requires IPsec in both directions, meaning a connection only succeeds if IPsec authentication is actually negotiated. Server3 can successfully negotiate IPsec with Server1 (whose " request " setting means it will still respond to and complete an IPsec negotiation when the peer requires it) and with Server2 (which requires inbound and requests outbound IPsec, and likewise supports negotiation), so both of those connections succeed. Server3 cannot successfully negotiate IPsec with Server4, since Server4 has no IPsec capability configured at all, and Server3 ' s " require " setting blocks any connection that cannot be authenticated via IPsec. Therefore, Server1 can communicate with Server2, Server3, and Server4, while Server3 can communicate with only Server1 and Server2.
質問 # 20
You have the resources shown in the following table. Your on-premises network is connected to VNet1 by using a Site-to-Site VPN. The network traffic sent from Server1 fails to reach VM1. You need to review the contents of the network traffic sent from Server1 to VM1. What should you do first? (Exhibit: resources table.)
Resources
正解:C
解説:
Reviewing the actual contents of packets exchanged between two endpoints, rather than just connection metadata like source and destination addresses or allow/deny outcomes, calls for a packet-capture capability positioned at the point where the traffic actually originates, which in this scenario is the on-premises server, Server1, rather than anywhere inside Azure. NSG flow logs on NSG1 only record 5-tuple flow information and allow or deny decisions for traffic crossing that network security group in Azure, and enabling Windows Firewall logging directly on Server1 similarly records connection attempts and firewall decisions rather than the actual packet contents, so neither option satisfies the stated requirement to inspect what is inside the traffic. Server2 already has Windows Admin Center installed and can manage Server1 remotely without needing a separate WAC installation on Server1 itself, and Windows Admin Center ' s Packet Monitoring extension, built on the built-in pktmon utility, can capture traffic leaving Server1 toward VM1 and, once exported, fully decode it for inspection. Azure Network Watcher ' s packet capture feature, by comparison, is implemented as an extension that runs on an Azure virtual machine and cannot be pointed at an on-premises server like Server1 at all, making it unusable for capturing traffic at its actual on-premises source in this scenario.
質問 # 21
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
正解:
解説:
Explanation:
Signing in over Remote Desktop requires a user to hold the " Allow log on through Remote Desktop Services
" right and the " Access this computer from the network " right, and to be excluded from any matching Deny counterpart, since an explicit Deny always overrides an Allow granted through any other group membership.
User1 is a member of Group2 (granted the Remote Desktop Services logon right) but is also a member of Group4, which is explicitly denied " Access this computer from the network " on Server4 -- that network- access denial blocks the RDP connection outright regardless of the Everyone-based network-access Allow or the RDS logon right, so User1 is denied. User2 belongs only to Group2: Group2 grants the RDS logon right, User2 is covered by the Everyone-based network-access Allow, and User2 is not a member of either Group3 or Group4, so neither Deny applies and User2 can sign in successfully. User3 is a member of Group3, which is explicitly denied " Allow log on through Remote Desktop Services " on Server4 -- that denial blocks the RDP logon right itself, so User3 cannot sign in regardless of network-access rights (and User3 is also in Group4, which independently denies network access as well). Therefore, only User2 can successfully sign in to Server4 using Remote Desktop.
質問 # 22
You have a Group Policy Object (GPO) named GPO1 that contains user settings only. You plan to apply GPO1 to a global security group named Group1. You link GPO1 to the domain, and you remove all the permissions granted to the Authenticated Users group. You need to configure permissions for GPO1 to meet the following requirements: GPO1 must apply only to the users in Group1; the solution must use the principle of least privilege. Which permissions should you grant to Group1 and the Domain Computers group? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
正解:
解説:
Explanation:
Group1: Apply group policy and Read. Domain Computers: Read only.
By default, Authenticated Users (which includes both user and computer accounts) is granted Read and Apply Group Policy on every new GPO, which is what lets any computer download and evaluate it and lets any signed-in user actually receive its settings; removing that default grant means both permissions must be explicitly re-established for exactly the principals that need them, and no more. Group1 contains the users who must actually receive GPO1 ' s user settings, so it needs both Read (to let the GPO be retrieved and evaluated at all) and Apply Group Policy (to let its settings actually take effect for those users); granting only one would leave the GPO unreadable, or readable but inert, for Group1 ' s members. Domain Computers is different: even though GPO1 contains only User Configuration settings, Group Policy processing on a computer still needs to enumerate and download every GPO linked to its scope in order to evaluate applicability (security filtering, WMI filters) before it can tell whether a given logged-on user should receive it. If Domain Computers has no Read permission at all, computers cannot process GPO1, which breaks correct evaluation for the very users in Group1 who sign in to those computers. Granting Domain Computers only Read - not Apply Group Policy, since GPO1 has no computer settings to apply and granting Apply would exceed least privilege - lets computers process the GPO correctly while ensuring only Group1 ' s members ever receive its settings.
質問 # 23
You have three Hyper-V hosts named Server 1, Server2, and Server 3 that run Windows Server Server1 hosts a virtual machine named VM1.
You enable Hyper-V Replica to replicate VM1 to Server2 and set the replication frequency to 30 seconds.
You need to extend the replication and create a second replica of VM1.
On which Hyper-V hosts can you configure the replication, and what is the minimum replication frequency you can use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
正解:
解説:
Explanation:
Hyper-V hosts: Server2 only. Replication frequency: 5 minutes.
Hotspot map data: < map > < m x1= " 446 " x2= " 564 " y1= " 82 " y2= " 104 " ss= " 0 " a= " 0 " / > < m x1= " 442 " x2= " 544 " y1= " 255 " y2= " 277 " ss= " 0 " a= " 0 " / > < /map > Extended replication in Hyper-V Replica can only be configured from the current Replica virtual machine, so with VM1 already replicating from Server1 (primary) to Server2 (replica), the option to extend replication to a third host is available only on Server2; it cannot be initiated from the primary host or from a host that is not yet part of the replication relationship. Extended replication also does not support the 30-second frequency available for the primary replication relationship; its replication frequency is limited to 5 minutes or 15 minutes, and the extended frequency cannot be lower than the frequency already configured between the primary and the first replica. Since the primary-to-replica frequency here is 30 seconds, the lowest frequency selectable for the extended replica is 5 minutes, and Server3 would be chosen as the destination for this second replica once the extend-replication wizard is launched from Server2. Attempting to launch that wizard from Server1 instead would not offer the extend-replication option at all, since Server1 is the primary, not the current Replica, for VM1 ' s existing replication relationship.
質問 # 24
......
JPNTestのAZ-802 問題集はあなたがAZ-802認定試験に準備するときに最も欠かせない資料です。この問題集の価値は試験に関連する他の参考書の総合の価値に相当します。このアサーションは過言ではありません。JPNTestの問題集を利用してからこのすべてが真であることがわかります。
AZ-802専門知識: https://www.jpntest.com/shiken/AZ-802-mondaishu