We provide 24-hours online customer service which replies the client’s questions and doubts about our AZ-802 training quiz and solve their problems. Our professional personnel provide long-distance assistance online. Our expert team will check the update AZ-802 learning prep and will send the update version automatically to the clients. So the clients can enjoy the convenience of our wonderful service and the benefits brought by our superior AZ-802 guide materials.
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Manage storage and file services | 15% | - Implement Storage Spaces and Storage Spaces Direct - Configure file servers and shares - Configure data deduplication and replication - Integrate on-premises storage with Azure Storage |
| Topic 2: Implement and manage an on-premises and hybrid networking infrastructure | 15% | - Secure network traffic in hybrid environments - Configure IP addressing, DNS, and DHCP - Implement hybrid network connectivity - Configure software-defined networking |
| Topic 3: Manage virtual machines and containers | 15% | - Configure Azure Arc-enabled servers and VMs - Deploy and manage Hyper-V virtual machines - Deploy and manage containers and Kubernetes on Windows Server |
| Topic 4: Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments | 20% | - Implement and manage Group Policy Objects - Install and configure domain controllers - Manage FSMO roles and replication - Integrate AD DS with Azure AD and Azure Arc |
| Topic 5: Secure Windows Server on-premises and hybrid infrastructures | 10% | - Implement security baselines and hardening - Manage access control and permissions - Configure Windows Defender and audit policies |
| Topic 6: Manage Windows Servers and workloads in a hybrid environment | 20% | - Deploy servers using Windows Admin Center and Azure Arc - Configure remote management and secure administration - Implement hybrid identity solutions - Manage updates and patches across hybrid servers |
| Topic 7: Implement high availability and disaster recovery | 5% | - Configure failover clustering - Perform server and workload migrations - Use Azure Site Recovery for hybrid workloads - Monitor and troubleshoot Windows Server environments - Implement backup and recovery solutions |
Once the clients order our AZ-802 cram training materials we will send the AZ-802 exam questions quickly by mails. The clients abroad only need to fill in correct mails and then they get our AZ-802 training guide conveniently. Our AZ-802 cram training materials provide the version with the language domestically and the version with the foreign countries' language so that the clients at home and abroad can use our AZ-802 Study Tool conveniently. And after study for 20 to 30 hours, you can pass the AZ-802 exam with ease.
NEW QUESTION # 45
You have an on-premises Hyper-V host named Server1. Server1 contains a virtual machine named VM1. You have a non-domain joined Hyper-V server named Server2 that is hosted in a remote location. You plan to replicate VM1 to Server2 by using Hyper-V Replica. You need to configure replication on Server1. Which authentication method can you use?
Answer: B
Explanation:
Hyper-V Replica supports two authentication methods: Kerberos (integrated Windows authentication) over an unencrypted HTTP connection, which requires both the primary and replica servers to be domain-joined and mutually trusted, or certificate-based authentication over an encrypted HTTPS connection. Because Server2 is a non-domain-joined, remotely located Hyper-V host, Kerberos authentication is not available, so replication from Server1 must be configured to use certificate-based authentication, which also has the advantage of encrypting replication traffic in transit over the connection to the remote location. Setting this up requires issuing or importing a matching certificate on both Server1 and Server2, configuring the Replica server to accept HTTPS connections on the Hyper-V Replica listener, and specifying the certificate thumbprint when enabling replication for VM1, none of which is required for the simpler but domain-dependent Kerberos option. Because the certificates must chain to a mutually trusted root and Server2 is not part of the same AD DS forest, the certificates are typically issued by a third-party or shared internal certificate authority that both hosts already trust independently of any Active Directory relationship.
NEW QUESTION # 46
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. You are planning the deployment of DNS to a new network. You have three internal DNS servers as shown in the following exhibit (Server1/Montreal/10.
0.1.10/contoso.local, Server2/Toronto/10.0.2.10/east.contoso.local, Server3/Seattle/10.0.3.10/west.contoso.
local). The contoso.local zone contains zone delegations for east.contoso.local and west.contoso.local. All the DNS servers use root hints. You need to ensure that all the DNS servers can resolve the names of all the internal namespaces and internet hosts. Solution: On Server2, you create a conditional forwarder for west.
contoso.local. On Server3, you create a conditional forwarder for east.contoso.local. Does this meet the goal?
Server1 (Montreal, 10.0.1.10, contoso.local) / Server2 (Toronto, 10.0.2.10, east.contoso.local) / Server3 (Seattle, 10.0.3.10, west.contoso.local); contoso.local delegates east.contoso.local and west.contoso.local.
Answer: B
Explanation:
This solution lets Server2 reach the sibling zone west.contoso.local (by forwarding to Server3) and lets Server3 reach the sibling zone east.contoso.local (by forwarding to Server2), but it never gives either server a way to resolve the parent zone, contoso.local, which is hosted only on Server1. Neither Server2 nor Server3 is configured with any forwarder, conditional or otherwise, that targets contoso.local or points at Server1 at all, so any query for a name that lives directly in the parent zone (as opposed to one of the two delegated child zones) has no resolution path from either server. Root hints, which both servers already use, only provide internet resolution and have no knowledge of the internal, non-public contoso.local namespace. Because the stated goal explicitly requires that all the DNS servers can resolve the names of all the internal namespaces - which includes the parent zone contoso.local, not just the two child zones - and this solution leaves that zone completely unreachable from Server2 and Server3, the solution does not meet the goal. A complete solution would need to additionally forward to Server1 for the contoso.local namespace itself.
NEW QUESTION # 47
You need to implement the planned change for the Azure DNS Private Resolver. Which private DNS zones can you use for name resolution?
Answer: E
Explanation:
Private1 is deployed with its inbound endpoint in VNet1, and an Azure DNS Private Resolver inbound endpoint can resolve only private DNS zones that are virtual-network-linked to the same virtual network where the resolver itself sits; it cannot resolve a zone just because it exists in the same subscription, or because that zone happens to be linked to a different, unrelated virtual network. Per the private DNS zone table, Zone1.com is linked to VNet1, Zone2.com is linked to VNet2, and Zone3.com has no virtual network link at all. Because Private1 ' s inbound endpoint lives in VNet1, only Zone1.com, the zone actually linked to VNet1, can be resolved through it. Zone2.com cannot be resolved by Private1 because it is linked only to VNet2, a separate virtual network with no stated peering or additional resolver configuration connecting it to VNet1; and Zone3.com cannot be resolved by any resolver in any virtual network because it has no virtual network link whatsoever, meaning no virtual network can consult it through the normal Azure-provided DNS resolution path. Extending resolution to Zone2.com would require either a separate resolver deployed in VNet2, or peering combined with a forwarding ruleset and outbound endpoint, neither of which is described as being configured here. Therefore only Zone1.com can currently be resolved.
NEW QUESTION # 48
You have an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with Microsoft Entra ID by using Microsoft Entra Connect. You enable password protection for contoso.com.
You need to prevent users from including the word Contoso as part of their password. What should you use?
Answer: A
Explanation:
Microsoft Entra Password Protection lets an organization extend the global banned-password list with a custom banned-password list containing organization-specific terms, such as a company name, product names, or local landmarks. For an on-premises AD DS domain, the custom banned-password list itself is still authored and managed centrally in the cloud, in the Microsoft Entra admin center, under Protect & Secure > Authentication methods > Password protection. Once configured there, the list is downloaded and cached by the Microsoft Entra Password Protection DC agents running on the domain ' s writable domain controllers, which enforce the policy locally against password set and change operations, even though the domain itself is on-premises. Active Directory Users and Computers has no interface for managing banned-password lists; it only manages AD objects such as users, groups, and OUs. Synchronization Service Manager is the on- premises troubleshooting console for the Microsoft Entra Connect sync engine and has no role in password policy configuration. Windows Admin Center is a management gateway for Windows Server infrastructure (roles, features, storage, and so on) and likewise does not expose password-protection policy settings.
Therefore, to add " Contoso " to the custom banned-password list and have it enforced across the domain, an administrator must sign in to the Microsoft Entra admin center and configure the custom banned-password list there, letting the on-premises DC agents pick up and apply the updated list.
NEW QUESTION # 49
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains three servers named Server1, Server2, and Server3 that run Windows Server. All the servers are on the same network and have network connectivity.
On Server1, Windows Defender Firewall has a connection security rule that has the following settings:
* Rule Type: Server-to-server
* Endpoint 1: Any IP address
* Endpoint 2: Any IP address
* Requirements: Require authentication for inbound connections and request authentication for outbound connections
* Authentication Method: Computer (Kerberos V5)
* Profile: Domain, Private, Public
* Name: Rule1
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
When Server1 establishes a network connection with Server2, the connection is encrypted: No. Server2 can establish a network connection with Server3: Yes. When Server3 establishes a network connection with Server1, the connection is encrypted: No.
Rule1 exists only on Server1 and is configured to require authentication for inbound connections while only requesting authentication for outbound connections, using Computer (Kerberos V5) as its authentication method, but it does not specify Require encryption anywhere in its settings. Requiring or requesting authentication in a connection security rule only causes IPsec to negotiate and verify the identity of the two endpoints; it does not turn on encryption for the resulting connection unless the rule, or the IPsec settings backing it, explicitly specifies that encryption itself is required. Because Rule1 authenticates but does not encrypt, both a connection Server1 establishes outbound to Server2 and a connection Server3 establishes inbound to Server1 are authenticated using Kerberos V5 but are still sent in clear text, making both of those encryption-related statements false. Server2 and Server3 have no connection security rule of their own configured at all, so nothing on either of those two servers restricts, requires, or even attempts to authenticate traffic directly between them, meaning Server2 is able to freely establish a network connection with Server3 without any authentication or encryption involved, making that statement true.
NEW QUESTION # 50
......
Candidates are looking for valid AZ-802 questions which belong to AZ-802 urgently. If you need valid exam questions and answers, our high quality is standing out. We are confident that our AZ-802 training online materials and services are competitive. Every year we spend much money and labor relationship on remaining competitive. We are trying to offer the best high passing-rate AZ-802 Training Online materials with low price. Our exam materials will help you pass exam one shot without any doubt.
AZ-802 Exam Introduction: https://www.dumpcollection.com/AZ-802_braindumps.html