IT업계에 종사하시는 분은 국제공인 IT인증자격증 취득이 얼마나 힘든지 알고 계실것입니다. 특히 시험이 영어로 되어있어 부담을 느끼시는 분도 계시는데 DumpTOP를 알게 된 이상 이런 고민은 버리셔도 됩니다. DumpTOP의Microsoft AZ-802덤프는 모두 영어버전으로 되어있어Microsoft AZ-802시험의 가장 최근 기출문제를 분석하여 정답까지 작성해두었기에 문제와 답만 외우시면 시험합격가능합니다.
| Section | Objectives |
|---|---|
| Topic 1: Implement and manage high availability | - Failover clustering
|
| Topic 2: Secure Windows Server hybrid infrastructures | - Identity and access management
|
| Topic 3: Networking and storage infrastructure | - Storage management
|
| Topic 4: Disaster recovery and migration | - Backup and restore
|
| Topic 5: Monitoring and troubleshooting | - System monitoring
|
| Topic 6: Manage hybrid compute and virtualization | - Containers
|
Microsoft인증 AZ-802 시험은 최근 제일 인기있는 인증시험입니다. IT업계에 종사하시는 분들은 자격증취득으로 자신의 가치를 업그레이드할수 있습니다. Microsoft인증 AZ-802 시험은 유용한 IT자격증을 취득할수 있는 시험중의 한과목입니다. DumpTOP에서 제공해드리는Microsoft인증 AZ-802 덤프는 여러분들이 한방에 시험에서 통과하도록 도와드립니다. 덤프를 공부하는 과정은 IT지식을 더 많이 배워가는 과정입니다. 시험대비뿐만아니라 많은 지식을 배워드릴수 있는 덤프를DumpTOP에서 제공해드립니다. DumpTOP덤프는 선택하시면 성공을 선택한것입니다.
질문 # 327
You have two servers named Server1 and Server2 that run Windows Server. You perform the following actions: on Server1, you create an Application Control policy named Policy1 that contains a rule to allow all the executables in a folder named D:\Folder1; you add a rule to Policy1 to trust a folder named
\\Server2\Folder2; you deploy Policy1. You need to verify that Policy1 is applied to Server1. Which Event Viewer log should you review?
정답:C
설명:
Application Control policies (Windows Defender Application Control / App Control for Business) log every policy-load, allow, and block decision to the CodeIntegrity/Operational event log, including the event that confirms a policy has been successfully refreshed and is being enforced on the local computer. AppLocker ' s MSI and Script log only records AppLocker rule evaluations, which is a separate feature from Application Control policies, and the DeviceManagement-Enterprise-Diagnostic-Provider log relates to MDM enrollment diagnostics, not application control enforcement. Reviewing CodeIntegrity/Operational on Server1 is therefore the correct way to confirm Policy1 has taken effect, since the event log records the policy ' s GUID and version each time it is loaded, letting an administrator match the deployed policy to the one actually running on Server1 ' s code integrity subsystem. Event ID 3099 in that log specifically indicates a policy was refreshed successfully, while block events such as 3077 or 3089 would appear there too if an executable outside the allowed rules were later denied.
질문 # 328
You have two on-premises Hyper-V hosts named Server1 and Server2. Server1 contains two virtual machines named VM1 and VM2. Server2 contains three virtual machines named VM21, VM22, and VM23. You have an Azure subscription. You plan to use Azure Site Recovery to replicate all the virtual machines to Azure.
You need to deploy the Microsoft Azure Site Recovery Provider to the on-premises infrastructure. What is the minimum number of providers you should install?
정답:B
설명:
The Microsoft Azure Site Recovery Provider is installed once per Hyper-V host (or, if the hosts are System Center Virtual Machine Manager-managed, once on the VMM server) rather than per virtual machine.
Because Server1 and Server2 are two independent, standalone Hyper-V hosts that each need to be registered with the Recovery Services vault to replicate their respective VMs, the Provider must be installed on each host individually, so the minimum number of Provider installations required is two, regardless of the fact that Server1 hosts two VMs and Server2 hosts three. After the Provider and the accompanying Recovery Services agent are installed and registered on both hosts, all five virtual machines across Server1 and Server2 become visible in the vault and can be enabled for replication individually, without any additional per-VM provider deployment. If Server1 and Server2 had instead been managed by a single VMM server, only one Provider installation on the VMM server itself would have been required, since VMM centralizes host registration with the vault on behalf of every Hyper-V host it manages.
질문 # 329
Your network contains two Active Directory Domain Services (AD DS) forests named contoso.com and fabrikam.com. Contoso.com contains three child domains named amer.contoso.com, apac.contoso.com, and emea.contoso.com. Fabrikam.com contains a child domain named apac.fabrikam.com. A bidirectional forest trust exists between contoso.com and fabrikam.com. You need to provide users in the contoso.com forest with access to the resources in the fabrikam.com forest. The solution must meet the following requirements: users in contoso.com must only be added directly to groups in the contoso.com forest; permissions to access the resources in fabrikam.com must only be granted directly to groups in the fabrikam.com forest; the number of groups must be minimized. Which type of groups should you use to organize the users and to assign permissions? To answer, drag the appropriate group types to the correct requirements. Each group type may be used once, more than once, or not at all.
정답:
설명:
Explanation:
Organize users: Domain global. Assign permissions: Domain local.
This scenario is the classic AGDLP model (Accounts into Global groups into Domain Local groups, granted Permissions) extended across a forest trust. Contoso.com users must be added only to groups that live in the contoso.com forest, which points to a domain global group created in one of the contoso.com domains; global groups are specifically designed to hold user accounts from their own domain and to be referenced elsewhere, including across a trust. That global group is then nested inside a domain local group created in a fabrikam.
com domain, and permissions to the fabrikam.com resources are granted directly to that domain local group
- satisfying the requirement that permission grants happen only on fabrikam.com groups. Domain local groups can accept members from any domain in a trusted forest when a forest trust exists, which is exactly what allows the contoso.com global group to be nested inside the fabrikam.com domain local group despite the forest boundary. This achieves both constraints using only two groups total (one global, one domain local), which is the minimum possible, since eliminating either group would violate one of the two placement requirements (users must stay in a contoso.com group; permissions must land on a fabrikam.com group). A universal group is not needed and would not, by itself, reduce the group count below two.
질문 # 330
You have an on-premises server that runs Windows Server and contains a file share named Share1. You have an Azure subscription that contains an Azure Files share named azshare1 and an Azure File Sync instance named Sync1. Sync1 syncs Share1 with azshare1. You need to delete Sync1. Which four resources should you delete in sequence? To answer, move the appropriate resources from the list of resources to the answer area and arrange them in the correct order.
정답:
설명:
Explanation:
1. The cloud endpoint. 2. The server endpoint. 3. The sync group. 4. Sync1.
A Storage Sync Service (Sync1) cannot be deleted while it still contains an active sync group, and a sync group cannot be deleted while it still has a cloud endpoint or server endpoint attached to it, so the topology must be dismantled from the bottom up before the top-level Sync1 resource can be removed. The cloud endpoint (the link between the sync group and the Azure file share, azshare1) and the server endpoint (the link between the sync group and the on-premises path, Share1) are both direct children of the sync group and must both be removed before the now-empty sync group itself can be deleted; removing the cloud endpoint does not delete the underlying Azure file share azshare1 itself, only the sync association, so azshare1 does not need to be deleted at all to remove Sync1 and is correctly left out of the sequence. Once both endpoints are gone, the sync group has nothing left syncing through it and can be deleted, and once the Storage Sync Service has no remaining sync groups, Sync1 itself can finally be deleted. " The management group " is an unrelated Azure governance/organizational construct with no relationship to Storage Sync Service resources and plays no role in this sequence. Therefore, the correct order is: delete the cloud endpoint, delete the server endpoint, delete the sync group, and finally delete Sync1.
질문 # 331
Your network contains an Active Directory Domain Services (AD DS) domain. You plan to protect high- privilege domain credentials by specifying the following:
* The lifetime of the Kerberos Ticket Granting Ticket (TGT)
* The conditions required for devices to request a TGT
What should you use, and what should you create? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Exhibit
정답:
설명:
Explanation:
Authentication policies, created and managed from the Active Directory Administrative Center ' s Authentication node, let an administrator set a maximum Kerberos ticket-granting-ticket lifetime for user, computer, or service accounts and define access-control conditions (device group membership or device claims) that a client must satisfy before a TGT is issued to it. This is distinct from an authentication policy silo, which groups accounts together to apply a shared policy rather than defining the TGT lifetime and device conditions itself. Because the requirement is specifically to set a TGT lifetime and device request conditions for high-privilege accounts, an authentication policy authored in ADAC is the object that implements both settings. Once the authentication policy is created, it is applied to the target high-privilege accounts (often through a policy silo membership for organizational grouping), and the domain controllers evaluate the policy
' s TGT lifetime and device claims during Kerberos authentication before issuing or renewing a ticket for those accounts.
질문 # 332
......
지금 사회에 능력자들은 아주 많습니다.it인재들도 더욱더 많아지고 있습니다.많은 it인사들은 모두 관연 it인증시험에 참가하여 자격증취득을 합니다.자기만의 자리를 확실히 지키고 더 높은 자리에 오르자면 필요한 스펙이니까요.AZ-802시험은Microsoft인증의 중요한 시험이고 또 많은 it인사들은Microsoft자격증을 취득하려고 노력하고 있습니다.
AZ-802합격보장 가능 덤프: https://www.dumptop.com/Microsoft/AZ-802-dump.html