Microsoft AZ-802 - Administering Windows Server
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains five servers that run Windows Server. The network also contains two workgroup servers that run Windows Server. You need to implement a connection security rule between the member servers and the workgroup servers. Which authentication method should you use?
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant. You plan to deploy 100 new Azure virtual machines that will run Windows Server. You need to ensure that each new virtual machine is joined to the AD DS domain. What should you use?
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the organizational units (OUs) shown in the following table.
In the domain, you create the Group Policy Objects (GPOs) shown in the following table.
You need to implement IPsec authentication to ensure that only authenticated computer accounts can connect to the members in the domain. The solution must minimize administrative effort.
Which GPOs should you apply to the Domain Controllers OU and the Domain Servers OU? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit
You have a server named Server1 that runs Windows Server. You install a custom app named App1 that is accessed by using TCP port 52310. Users report that they cannot access App1. You confirm that App1 is running on Server1. You need to ensure that the users can access App1. The solution must only provide access to App1 on Server1. What should you do in Windows Defender Firewall with Advanced Security?
Your network contains an Active Directory Domain Services (AD DS) domain. All domain members have Microsoft Defender Credential Guard with UEFI lock configured in the domain. You deploy a server named Server1 that runs Windows Server. You disable Credential Guard on Server1. You need to ensure that Server1 is MOST subject to Credential Guard restrictions. What should you do next?
You have a Hyper-V failover cluster named Cluster1 at a main datacenter. Cluster1 contains two nodes that have the Hyper-V server role installed. Cluster1 hosts 10 highly available virtual machines. You have a cluster named Cluster2 in a disaster recovery site. Cluster2 contains two nodes that have the Hyper-V server role installed. You plan to use Hyper-V Replica to replicate the virtual machines from Cluster1 to Cluster2. What should you do? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You have a server named DHCP1 that runs Windows Server and has the DHCP Server role installed. DHCP1 hosts an activated IPv4 scope for a subnet of 192.168.15.0/24. You have a CSV file named PrinterReservations.csv that contains the following columns: ClientId, ScopeId, IPAddress, MacAddress. All the IP addresses in PrinterReservations.csv are within the scope range and are currently available. You need to create DHCP reservations for 20 printers by using PrinterReservations.csv. The solution must minimize administrative effort. Which PowerShell command should you run?
You have two Azure virtual networks named Vnet1 and Vnet2. You have a Windows 10 device named Client1 that connects to Vnet1 by using a Point-to-Site (P2S) IKEv2 VPN. You implement virtual network peering between Vnet1 and Vnet2. Vnet1 allows gateway transit; Vnet2 uses the remote gateway. You discover that Client1 cannot communicate with Vnet2. You need to ensure that Client1 can communicate with Vnet2. Solution: You download and reinstall the VPN client configuration. Does this meet the goal?
Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contos.com. The domain contains the accounts shown in the following table.
The domain is configured to store BitLocker recovery keys in Active Directory.
* Admin1 turns on BitLocker Drive Encryption (BitLocker) for volume C on Server1.
* Admin1 moves Server1 to OU1.
* Admin2 turns on BitLocker for removable volume E on Server2.
* Admin2 moves removable volume E from Server2 to Server1 and unlocks the volume.
On which Active Directory object can you each BitLocker recovery key? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth on point.


You have an on-premises server named Server1 that runs Windows Server and has internet connectivity. You have an Azure subscription. You need to monitor Server1 by using Azure Monitor. Which resources should you create in the subscription, and what should you install on Server1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.





