Your network contains an Active Directory Domain Services (AD DS) domain.
You need to implement a solution that meets the following requirements:
• Ensures that the members of the Domain Admins group are allowed to sign in only to domain controllers
• Ensures that the lifetime of Kerberos Ticket Granting Ticket (TGT) for the members of the Domain Admins group is limited to one hour
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a parent domain named contoso.com and a child domain named corp.contoso.com. Both domains contain domain controllers that have the DNS Server role installed. Some domain controllers in contoso.com do NOT have the DNS Server role installed. The DNS zone for contoso.com is Active Directory-integrated and uses secure dynamic updates. The zone replicates to all the DNS servers in the forest. You need to modify the zone to meet the following requirements: - Prevent the DNS servers in corp.contoso.com from receiving contoso.com zone data. - Minimize Active Directory replication traffic. What should you do?
You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server and an Azure key vault named Vault1. VM1 has a system-assigned managed identity enabled. You need to enable Azure Disk Encryption for VM1. What should you do first?
You have a server named Server1 that runs Windows Server 2022 and is part of a three-node failover cluster. You need to upgrade Server1 to Windows Server 2025. The solution must minimize downtime for the cluster. What should you do first?
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains the users shown in the following table: User1 (Enterprise Admins group), User2 (Domain Users group). You have a workgroup server named Server1 that runs Windows Server and contains the local users shown in the following table: User3 (Administrators group), User4 (Users group). You promote Server1 to the first domain controller in a new child domain named east.contoso.com. Which users can sign in to Server1 locally?

Forest user group membership table

Server1 local user group membership table
You have a server named Server1 that runs Windows Server and has the Hyper-V server role installed. Server1 contains a virtual machine named VM1 that runs Windows Server. You need to install the Hyper-V server role on VM1. Which PowerShell command should you run first? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server 2025. All domain controllers run Windows Server 2019. The domain contains a user named User1. You need to ensure that User1 can promote Server1 to a domain controller. The solution must follow the principle of least privilege. Which groups should User1 be a member of?
You need to use a comma-separated value (CSV) file to import server inventory to Azure Migrate. Which fields are mandatory for each entry in the CSV file?
You have a server named Server1 that runs Windows Server and has the Hyper-V server role installed. You build Just Enough Administration (JEA) role capabilities and session configuration files. You need to limit which Hyper-V module cmdlets helpdesk users can use when administering Server1 remotely. How should you complete the PowerShell command? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You have an on-premises IIS web server that hosts several .NET applications. You plan to migrate the applications to Azure App Service. The applications will NOT be containerized. What should you use to perform the migration?
TESTED 03 Oct 2026