Practice AZ-802 Mock - Exam AZ-802 Syllabus

With the help of AZ-802 guide questions, you can conduct targeted review on the topics which to be tested before the exam, and then you no longer have to worry about the problems that you may encounter a question that you are not familiar with during the exam. With AZ-802 Learning Materials, you will not need to purchase any other review materials. Please be assured that with the help of AZ-802 learning materials, you will be able to successfully pass the exam.

Microsoft AZ-802 Exam Syllabus Topics:

SectionWeightObjectives
Topic 1: Manage virtual machines and containers15%- Deploy and manage Hyper-V virtual machines
- Deploy and manage containers and Kubernetes on Windows Server
- Configure Azure Arc-enabled servers and VMs
Topic 2: Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments20%- Integrate AD DS with Azure AD and Azure Arc
- Install and configure domain controllers
- Implement and manage Group Policy Objects
- Manage FSMO roles and replication
Topic 3: Implement and manage an on-premises and hybrid networking infrastructure15%- Implement hybrid network connectivity
- Secure network traffic in hybrid environments
- Configure IP addressing, DNS, and DHCP
- Configure software-defined networking
Topic 4: Manage Windows Servers and workloads in a hybrid environment20%- Configure remote management and secure administration
- Deploy servers using Windows Admin Center and Azure Arc
- Manage updates and patches across hybrid servers
- Implement hybrid identity solutions
Topic 5: Secure Windows Server on-premises and hybrid infrastructures10%- Manage access control and permissions
- Configure Windows Defender and audit policies
- Implement security baselines and hardening
Topic 6: Manage storage and file services15%- Configure data deduplication and replication
- Implement Storage Spaces and Storage Spaces Direct
- Configure file servers and shares
- Integrate on-premises storage with Azure Storage
Topic 7: Implement high availability and disaster recovery5%- Configure failover clustering
- Use Azure Site Recovery for hybrid workloads
- Perform server and workload migrations
- Monitor and troubleshoot Windows Server environments
- Implement backup and recovery solutions

>> Practice AZ-802 Mock <<

Exam AZ-802 Syllabus - AZ-802 Certification Training

Since the content of the examination is also updating daily, you will need real and latest Microsoft AZ-802 Exam Dumps to prepare successfully for the AZ-802 certification exam in a short time. People who don't study from updated Administering Windows Server (AZ-802) questions fail the examination and loss time and money.

Microsoft Administering Windows Server Sample Questions (Q387-Q392):

NEW QUESTION # 387
You have an Azure subscription. Your on-premises network connects to Azure by using an Azure VPN gateway named VPN1. You need to monitor the Azure gateway health probe for VPN1. Which TCP port should you use?

Answer: C

Explanation:
Azure virtual network gateways expose an internal health probe on TCP port 8081 that Azure infrastructure uses to verify that the gateway instance is healthy; this port is documented as part of gateway troubleshooting and must not be blocked for the gateway to be monitored and managed correctly. Ports such as 443, 1723, and
3389 are associated with HTTPS, PPTP VPN, and RDP respectively, and 65500 falls outside the actual health- probe port used by the gateway manager, so none of those apply to monitoring the VPN gateway ' s own health probe. If a network security group, on-premises firewall, or custom routing rule blocks port 8081 to the gateway subnet, Azure ' s platform health checks fail even though the VPN tunnel itself may still be passing traffic, which is why this specific port must be excluded from any traffic filtering applied to the GatewaySubnet. Microsoft ' s troubleshooting guidance for Site-to-Site VPN connectivity issues explicitly calls out verifying that port 8081 is reachable to the gateway ' s private IP addresses as an early diagnostic step, since a blocked health probe can itself trigger gateway failover behavior unrelated to the underlying tunnel configuration.


NEW QUESTION # 388
You have a Site-to-Site VPN between an on-premises network and an Azure VPN gateway. BGP is disabled for the Site-to-Site VPN. You have an Azure virtual network named Vnet1 that contains a subnet named Subnet1. Subnet1 contains a virtual machine named Server1. You can connect to Server1 from the on- premises network. You extend the address space of Vnet1. You add a subnet named Subnet2 to Vnet1.
Subnet2 uses the extended address space. You deploy an Azure virtual machine named Server2 to Subnet2.
You cannot connect to Server2 from the on-premises network. Server1 can connect to Server2. You need to ensure that you can connect to Subnet2 from the on-premises network. What should you do?

Answer: B

Explanation:
With BGP disabled, the Site-to-Site connection relies entirely on statically defined routes rather than on dynamic route propagation between the on-premises network and Azure. When Subnet2 is added within Vnet1 ' s extended address space, Azure ' s own side of the tunnel already knows about it automatically, since it is simply part of the connected virtual network, but the on-premises routers have no static route telling them that traffic destined for Subnet2 ' s address range should be sent across the VPN tunnel to Azure at all.
Server1 is able to reach Server2 because that traffic stays entirely inside the Azure virtual network and never needs to cross the tunnel, but on-premises hosts have no configured path to the new subnet until the on- premises routing tables, and the local VPN device ' s configuration if applicable, are updated to include a route for Subnet2 ' s range pointed at the tunnel. Adding another Site-to-Site tunnel, a private endpoint, or a user-defined route table inside Subnet2 does nothing to address the missing route on the on-premises side, which is the actual point of failure described in the scenario.


NEW QUESTION # 389
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. Contoso.
com contains a member server named server1.contoso.com. You cannot resolve the FQDN of server1.contoso.
com. You verify that Windows Defender Firewall is configured correctly and that you can ping server1.
contoso.com successfully by using the server ' s IP address. You need to validate that the DNS record for server1.contoso.com exists. Which command should you run?

Answer: D

Explanation:
Since name resolution of server1.contoso.com is failing even though the host is reachable by IP address and the firewall is confirmed to be configured correctly, the next step is to query DNS directly rather than test network connectivity again. The nslookup command queries a DNS server for the record associated with a name (or performs a reverse lookup) and reports whether the expected A/AAAA record exists, which is exactly what is needed to validate the DNS record for server1.contoso.com. tracert and pathping test the network path/latency to a destination, and ipconfig only displays or manages the local machine ' s own IP configuration, none of which validate a DNS record on the DNS server itself. Running nslookup server1.
contoso.com against the domain ' s DNS server will either return the expected IP address, confirming the record exists and pointing to a client-side caching or configuration issue, or return an error indicating the record is missing or stale, which would direct troubleshooting toward AD-integrated DNS replication or the record ' s TTL and scavenging settings.


NEW QUESTION # 390
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. After you answer a question in this section, you will NOT be able to return to it. Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. You need to identify which server is the PDC emulator for the domain. Solution:
From Active Directory Domains and Trusts, you right-click Active Directory Domains and Trusts in the console tree, and then select Operations Master. Does this meet the goal?

Answer: A

Explanation:
Each Active Directory MMC snap-in only exposes the specific FSMO role or roles that fall within its area of responsibility. Active Directory Domains and Trusts manages forest-level trust relationships and domain
/forest functional levels, and the single Operations Master dialog it provides - reached by right-clicking the root node of the console - shows only the Domain Naming Master, which is a forest-wide role responsible for adding or removing domains from the forest. It does not show the PDC Emulator, the RID Master, or the Infrastructure Master, all of which are domain-wide roles surfaced instead through Active Directory Users and Computers by right-clicking the domain object and selecting Operations Masters, then viewing the PDC tab specifically. Because the proposed action opens the Operations Master dialog from Active Directory Domains and Trusts rather than from Active Directory Users and Computers, it will report only the Domain Naming Master and gives no information about who holds the PDC Emulator role. Since the stated goal is specifically to identify the PDC Emulator, and this console cannot show that role under any circumstance, the solution does not meet the goal.


NEW QUESTION # 391
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an on-premises server named Server1 that runs Windows Server. You have a Microsoft Sentinel instance. You add the Windows Firewall data connector in Microsoft Sentinel. You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1. Solution: You install the Azure Connected Machine agent on Server1. Does this meet the goal?

Answer: B

Explanation:
For any non-Azure machine, whether on-premises or hosted in another cloud, to be used as a source for an Azure Monitor Agent-based Microsoft Sentinel data connector such as the Windows Firewall connector, the machine must first be onboarded to Azure Arc as a connected machine. Installing the Azure Connected Machine agent on Server1 is precisely the action that performs this onboarding: it registers Server1 as an Azure Arc-enabled server, giving it an Azure resource identity that can then have extensions such as the Azure Monitor Agent deployed to it and associated with a data collection rule. This Azure Arc onboarding is the documented prerequisite step described in Microsoft ' s guidance for connecting Windows-based, non- Azure servers to Sentinel ' s AMA-based data connectors, and once Server1 is Arc-enabled, the Azure Monitor Agent extension and a data collection rule targeting the Windows Firewall log source can be deployed to it to complete the log collection pipeline. Because installing the Azure Connected Machine agent is exactly the required first step for enabling this scenario, this solution meets the goal.


NEW QUESTION # 392
......

In modern society, we are busy every day. So the individual time is limited. The fact is that if you are determined to learn, nothing can stop you! You are lucky enough to come across our AZ-802 exam materials. Our AZ-802 study guide can help you improve in the shortest time. Even you do not know anything about the AZ-802 Exam. It absolutely has no problem. You just need to accept about twenty to thirty hoursโ€™ guidance of our AZ-802 learning prep, it is easy for you to take part in the exam.

Exam AZ-802 Syllabus: https://www.passsureexam.com/AZ-802-pass4sure-exam-dumps.html