Pre-Winter Special Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

Page: 1 / 8
Total 73 questions
Exam Code: AZ-802                Update: Oct 3, 2026
Exam Name: Administering Windows Server

Microsoft Administering Windows Server AZ-802 Exam Dumps: Updated Questions & Answers (October 2026)

Question # 1

Your network contains an Active Directory Domain Services (AD DS) domain.

You need to implement a solution that meets the following requirements:

• Ensures that the members of the Domain Admins group are allowed to sign in only to domain controllers

• Ensures that the lifetime of Kerberos Ticket Granting Ticket (TGT) for the members of the Domain Admins group is limited to one hour

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Question # 2

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a parent domain named contoso.com and a child domain named corp.contoso.com. Both domains contain domain controllers that have the DNS Server role installed. Some domain controllers in contoso.com do NOT have the DNS Server role installed. The DNS zone for contoso.com is Active Directory-integrated and uses secure dynamic updates. The zone replicates to all the DNS servers in the forest. You need to modify the zone to meet the following requirements: - Prevent the DNS servers in corp.contoso.com from receiving contoso.com zone data. - Minimize Active Directory replication traffic. What should you do?

A.

Change the zone replication scope to all the domain controllers in the contoso.com domain.

B.

Change the zone replication scope to all the DNS servers on the domain controllers in the forest.

C.

Change the zone replication scope to all the DNS servers on the domain controllers in the contoso.com domain.

D.

Change the zone as a secondary zone on each domain controller.

Question # 3

You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server and an Azure key vault named Vault1. VM1 has a system-assigned managed identity enabled. You need to enable Azure Disk Encryption for VM1. What should you do first?

A.

Install a BitLocker recovery certificate on VM1.

B.

From Vault1, grant VM1 permissions to use keys and secrets.

C.

From VM1, modify the local Group Policy Object (GPO) to allow BitLocker key storage.

D.

Enable confidential OS disk encryption for VM1.

Question # 4

You have a server named Server1 that runs Windows Server 2022 and is part of a three-node failover cluster. You need to upgrade Server1 to Windows Server 2025. The solution must minimize downtime for the cluster. What should you do first?

A.

Evict Server1 from the cluster.

B.

Update the functional level of the cluster.

C.

Pause Server1 and drain the workloads.

D.

Take the cluster offline.

Question # 5

Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains the users shown in the following table: User1 (Enterprise Admins group), User2 (Domain Users group). You have a workgroup server named Server1 that runs Windows Server and contains the local users shown in the following table: User3 (Administrators group), User4 (Users group). You promote Server1 to the first domain controller in a new child domain named east.contoso.com. Which users can sign in to Server1 locally?

Forest user group membership table

Server1 local user group membership table

A.

User1 only

B.

User3 only

C.

User1 and User2 only

D.

User1 and User3 only

E.

User3 and User4 only

F.

User1, User2, User3, and User4

Question # 6

You have a server named Server1 that runs Windows Server and has the Hyper-V server role installed. Server1 contains a virtual machine named VM1 that runs Windows Server. You need to install the Hyper-V server role on VM1. Which PowerShell command should you run first? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Question # 7

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server 2025. All domain controllers run Windows Server 2019. The domain contains a user named User1. You need to ensure that User1 can promote Server1 to a domain controller. The solution must follow the principle of least privilege. Which groups should User1 be a member of?

A.

Domain Admins only

B.

Enterprise Admins only

C.

Domain Admins and Schema Admins only

D.

Domain Admins, Enterprise Admins, and Schema Admins

Question # 8

You need to use a comma-separated value (CSV) file to import server inventory to Azure Migrate. Which fields are mandatory for each entry in the CSV file?

A.

Server name, Cores, OS Name, and Memory (in MB)

B.

Server name, IP addresses, Disk 1 size (in GB), and CPU utilization percentage

C.

Server name, IP addresses, OS version, and Number of disks

Question # 9

You have a server named Server1 that runs Windows Server and has the Hyper-V server role installed. You build Just Enough Administration (JEA) role capabilities and session configuration files. You need to limit which Hyper-V module cmdlets helpdesk users can use when administering Server1 remotely. How should you complete the PowerShell command? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Question # 10

You have an on-premises IIS web server that hosts several .NET applications. You plan to migrate the applications to Azure App Service. The applications will NOT be containerized. What should you use to perform the migration?

A.

Data Migration Assistant (DMA)

B.

Windows Admin Center

C.

App Service Migration Assistant

D.

Web Deploy

E.

IIS Manager

Page: 1 / 8
Total 73 questions

Most Popular Certification Exams

Payment

       

Contact us

Site Secure

mcafee secure

TESTED 03 Oct 2026