我々のAZ-802問題集はPDF版、ソフト版とオンライン版を含めて、認証試験のすべての問題を全面的に含めています。このAZ-802問題集の正確率は100%になっています。AZ-802試験を準備しているあなたは無料のサンプルをダウンロードして利用して、あなたはこのふさわしいAZ-802問題集を発見することができます。
| Section | Objectives |
|---|---|
| Secure and manage Windows Server environments | - Identity and access management
|
| Compute, storage, and virtualization | - Virtual machines and containers
|
| Networking and high availability | - Networking infrastructure
|
| Hybrid infrastructure management | - Monitoring and update management
|
多くの求職者は、労働市場で競争上の優位性を獲得し、Microsoft企業が急いで獲得する最もホットな人々になりたいと考えています。しかし、貴重なAZ-802証明書を増やす必要があることを理解したい場合。 AZ-802証明書は、労働市場界で高い評価を得ており、優秀な才能の証明として広く認識されており、その1つであり、AZ-802テストにスムーズに合格したい場合は、AZ-802プラクティスを選択できます質問。
質問 # 329
You have a server named DHCP1 that runs Windows Server and has the DHCP Server role installed. DHCP1 hosts an activated IPv4 scope for a subnet of 192.168.15.0/24. You have a CSV file named PrinterReservations.csv that contains the following columns: ClientId, ScopeId, IPAddress, MacAddress. All the IP addresses in PrinterReservations.csv are within the scope range and are currently available. You need to create DHCP reservations for 20 printers by using PrinterReservations.csv. The solution must minimize administrative effort. Which PowerShell command should you run?
正解:C
解説:
Add-DhcpServerv4Reservation is the DHCP Server PowerShell module cmdlet that creates a single IPv4 client reservation on a specified DHCP server, and it accepts pipeline input, so importing PrinterReservations.
csv with Import-Csv and piping the resulting objects directly into Add-DhcpServerv4Reservation lets the cmdlet consume each row ' s ScopeId, IPAddress, and ClientId (MAC address) values to create all 20 reservations in a single pipelined command, which is the minimum-effort approach since it avoids writing any loop or per-row logic. Set-DhcpServerv4Reservation is used only to modify properties of a reservation that already exists, such as its description or client type, not to create new reservations, so piping CSV rows into it would fail outright since none of the reservations exist yet. Add-DhcpServerv4ExclusionRange creates an exclusion range that prevents the DHCP server from ever leasing addresses in that range to any client, which is the opposite of a reservation (which still requires the address to be leasable specifically to one identified client) and would actually break the ability to service these printers via DHCP. The fourth option ' s ForEach- Object with Add-DhcpServerv4Filter is scoped to the MAC address allow/deny filtering feature, an unrelated security control for permitting or blocking specific hardware addresses from obtaining any lease at all, not a mechanism for creating per-client static IP reservations from a CSV of address assignments.
質問 # 330
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.
The domain contains a server named Server1 that runs Windows Server. Server1 hosts a primary DNS zone named secure.contoso.com.
You need to implement DNSSEC validation for all queries in the secure.contoso.com zone. The solution must ensure that Windows client computers reject responses when DNSSEC validation cannot be completed.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
正解:
解説:
Explanation:
DNSSEC requires both an authoritative signed zone and client-side policy that requires validation. Because Server1 hosts the primary authoritative secure.contoso.com zone, the zone must first be signed so DNS responses contain the DNSSEC records and signatures needed for validation. Windows clients then need a Name Resolution Policy Table (NRPT) rule scoped to secure.contoso.com with DNSSEC enabled and validation required. Microsoft documents the DnsSecValidationRequired setting specifically for an NRPT rule; when validation is mandatory, an answer that cannot be validated is not accepted as a successful secure response. Merely signing the zone is insufficient to force clients to reject unvalidated answers, while an NRPT rule cannot validate an unsigned zone. Therefore, the two configurations must be used together.
質問 # 331
Your on-premises network contains a single-domain Active Directory Domain Services (AD DS) forest. You have a Microsoft Entra tenant named contoso.com. The AD DS forest syncs with the Microsoft Entra tenant by using Microsoft Entra Connect. You need to ensure that users in the forest that have a custom attribute of NoSync are excluded from synchronization. How should you configure the Microsoft Entra Connect cloudFiltered attribute, and which tool should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
正解:
解説:
Explanation:
Attribute: True; Tool: Synchronization Rules Editor
The cloudFiltered attribute is a Boolean flag in the Microsoft Entra Connect metaverse that determines whether an object is eligible for export to Microsoft Entra ID: when an object ' s cloudFiltered value is set to True, that object is excluded from being exported/synchronized to the cloud, regardless of whatever other attributes it has. To selectively exclude only the users who carry the custom attribute value NoSync, an administrator must author a custom inbound synchronization rule that scopes exactly those objects (using a scoping filter on the custom attribute equal to " NoSync " ) and then maps a constant value of True into the cloudFiltered attribute for objects that match that scope; objects that don ' t match the filter keep their default cloudFiltered value (False) and continue to sync normally. This kind of custom attribute-based scoping and attribute-flow authoring can only be done with the Synchronization Rules Editor, the tool specifically built for creating and editing inbound/outbound synchronization rules in Microsoft Entra Connect. ADSI Edit is a low- level raw LDAP-attribute editor for AD DS objects and has no concept of Microsoft Entra Connect synchronization rules or the metaverse. The Microsoft Entra Connect wizard configures top-level sync settings (such as which OUs or domains to include, filtering by OU, and basic feature toggles) but does not expose custom attribute-based scoping or attribute-flow rule authoring. Therefore, cloudFiltered must be set to True for matching objects, configured through the Synchronization Rules Editor.
質問 # 332
You have an Azure virtual network named VNet1. VNet1 contains a virtual machine named VM1 that runs Windows Server and has only a private IP address.
Administrators connect to VM1 from corporate workstations that use the Azure portal in a browser. The corporate firewall allows only outbound HTTPS traffic over TCP port 443.
You need to provide interactive access to VM1. The solution must meet the following requirements:
* Prevent assigning a public IP address to VM1.
* Use the existing firewall configuration.
What should you do?
正解:C
解説:
Azure Bastion is designed for browser-based RDP and SSH access to Azure VMs without assigning a public IP address to the target VM. Microsoft documents that administrators can connect through the Azure portal to a VM using its private IP address, with no RDP client, agent, or public VM IP required. The browser-side Bastion connection uses HTTPS/HTML5 over TCP 443, which fits the existing corporate firewall rule that permits only outbound HTTPS. Installing RD Gateway directly on VM1 would change the workload and still require gateway design and exposure. Azure Route Server is a routing-control service, not an interactive administration service. JIT VM access controls when management ports are opened but does not itself provide a browser-based 443 tunnel. Therefore, Azure Bastion is the appropriate solution. Microsoft Learn
質問 # 333
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
正解:
解説:
Explanation:
Statement 1: No. Statement 2: Yes. Statement 3: No.
Password-policy (Account Policy) settings inside a GPO behave differently depending on where the GPO is linked. For domain user accounts, only Account Policy settings defined in a GPO linked at the domain level (or in a fine-grained Password Settings Object) take effect; Account Policy settings in a GPO linked to an OU are ignored for domain accounts and instead apply only to the local SAM password policy of computer objects located in that OU. GPO1 (minimum length 14) is linked to OU1, where Admin1 ' s user object resides, but because it is linked to an OU rather than the domain, it has no effect on Admin1 ' s domain account password requirement. Admin1 ' s domain password is governed only by the Default Domain Policy (minimum length 10), so statement 1 is false. User1 is likewise a domain account subject only to the Default Domain Policy ' s minimum length of 10, so statement 2 is true. GPO2 (minimum length 8) is linked to the Member Servers OU, which contains Server1 as a computer object; this makes GPO2 the effective local password policy for local accounts created on Server1 (overriding the Default Domain Policy locally), not the domain policy ' s 10-character minimum. Therefore a new local account on Server1 needs only eight characters, not ten, making statement 3 false.
質問 # 334
......
現在の仕事に満足していますか。自分がやっていることに満足していますか。自分のレベルを高めたいですか。では、仕事に役に立つスキルをもっと身に付けましょう。もちろん、IT業界で働いているあなたはIT認定試験を受けて資格を取得することは一番良い選択です。それはより良く自分自身を向上させることができますから。もっと大切なのは、あなたもより多くの仕事のスキルをマスターしたことを証明することができます。では、はやくMicrosoftのAZ-802認定試験を受験しましょう。この試験はあなたが自分の念願を達成するのを助けることができます。試験に合格する自信を持たなくても大丈夫です。CertJukenへ来てあなたがほしいヘルパーと試験の準備ツールを見つけることができますから。CertJukenの資料はきっとあなたがAZ-802試験の認証資格を取ることを助けられます。
AZ-802赤本合格率: https://www.certjuken.com/AZ-802-exam.html