AZ-802 Sample Questions & Answers
Expect questions on securing the Windows Server infrastructure, managing virtual machines in Hyper-V and Azure, hybrid networking and storage, monitoring and troubleshooting Active Directory, and administering workloads through Azure services.
Launch the full AZ-802 simulator →Showing 6 of 12 free samples.
- Question 1Advanced
Deploy and manage AD DS · Configure and manage AD DS replication
Contoso Pharmaceuticals operates three physical datacenters represented by AD DS sites: SiteA (Hub), SiteB (Branch), and SiteC (Branch). Network routing policies forbid direct IP communication between SiteB and SiteC; all intersite traffic must traverse SiteA. An administrator clears the 'Bridge all site links' option in Active Directory Sites and Services to reflect this physical constraint. Site links Link-AB (cost 10) and Link-AC (cost 15) currently exist. What must the administrator configure in AD DS to allow directory changes to replicate transitively between SiteB and SiteC via SiteA, and what is the cumulative replication cost?
Show answer & explanation
Correct answer: D
When 'Bridge all site links' is disabled (standard in non-fully routed networks), site links operate as isolated conduits without implicit transitivity. To establish a transitive replication pathway between SiteB and SiteC across intermediate SiteA, an administrator must create an explicit site link bridge containing Link-AB and Link-AC. The KCC calculates replication routing costs across a site link bridge by summing the individual costs of all included member links (10 + 15 = 25).
graph LR SiteB[SiteB: Branch] ---|Link-AB Cost: 10| SiteA[SiteA: Hub] SiteA ---|Link-AC Cost: 15| SiteC[SiteC: Branch] subgraph Site Link Bridge: Bridge-BAC Link-AB Link-AC end - Question 2Intermediate
Deploy and manage AD DS · Configure and manage AD DS replication
A hybrid cloud infrastructure consists of an on-premises datacenter hosting two writable domain controllers (DC01 and DC02) and an Azure virtual network hosting a Read-Only Domain Controller (RODC01). An administrator inspects the Knowledge Consistency Checker (KCC) connection objects generated for intersite replication. How does intersite replication operate between the hub site bridgehead servers and the branch RODC?
Show answer & explanation
Correct answer: D
Active Directory intersite replication involving an RODC is strictly unidirectional. Because the RODC database is read-only, writable bridgehead domain controllers never pull directory changes from an RODC. The KCC automatically generates one-way inbound connection objects on the RODC, pulling updates from writable bridgehead servers in the hub site.
- Question 3Intermediate
Deploy and manage AD DS · Configure and manage AD DS sites
Background
Litware, Inc. is a manufacturing company with a central headquarters in Chicago and recently opened regional branch offices in Denver and Austin. The Active Directory forest consists of a single domain named corp.litware.com. The Chicago headquarters houses four Windows Server 2025 domain controllers configured in an AD DS site named HQ-Chicago.
Current Situation
The Denver branch office was provisioned with two dedicated Windows Server 2025 domain controllers (DEN-DC01 and DEN-DC02) placed on the local subnet 10.120.0.0/20. A new AD DS site named Branch-Denver was created, and both domain controllers were moved into Branch-Denver. WAN bandwidth between Denver and Chicago is constrained to a 50 Mbps link with high latency.
Problem Statement
Users logging into workstations on the 10.120.4.0/24 subnet at the Denver facility report severe delays during interactive logon. Network trace logs reveal that workstation DC Locator queries consistently resolve to domain controllers in HQ-Chicago rather than DEN-DC01 or DEN-DC02. Domain controllers in Denver are healthy, and DNS records for corp.litware.com are registering properly.
What should the directory services engineer do to ensure Denver workstations authenticate against their local domain controllers?
Show answer & explanation
Correct answer: C
The Active Directory DC Locator mechanism matches the client's IP address against configured subnet objects in Active Directory Sites and Services to determine the client's site. When a workstation's IP (such as 10.120.4.50 within 10.120.0.0/20) does not match any defined subnet object, the client is deemed site-agnostic and may authenticate against any DC in the domain, including remote DCs in HQ-Chicago. Defining the subnet object and associating it with Branch-Denver ensures Denver workstations query and authenticate against local DCs.
flowchart TD Client[Denver Workstation: 10.120.4.50] -->|DC Locator Query| DNS[DNS Server] DNS -->|Returns DC IP List| Client Client -->|Netlogon Ping to DC| DC_HQ[HQ-Chicago DC] DC_HQ -->|Evaluates Client Subnet| SubnetCheck{Subnet Object in AD?} SubnetCheck -->|No Subnet Defined| Fallback[Returns Random/HQ DC - High Latency] SubnetCheck -->|Mapped to Branch-Denver| LocalDC[Redirects to DEN-DC01/02 - Fast Logon] - Question 4Intermediate
Deploy and manage AD DS · Deploy Read-Only Domain Controllers (RODCs)
To pre-create (stage) a Read-Only Domain Controller computer account in Active Directory Domain Services and delegate its promotion permissions to a non-administrative user before shipping the server hardware to a branch office, an administrator should execute the PowerShell cmdlet _____.
Show answer & explanation
Correct answer: C
The Add-ADDSReadOnlyDomainControllerAccount cmdlet stages an RODC account in Active Directory Domain Services. It permits setting parameters such as -DomainControllerAccountName, -SiteName, and -DelegatedAdministratorAccountName so that a designated non-admin user can attach the physical server to the account using Install-ADDSDomainController -UseExistingAccount.
- Question 5Intermediate
Manage Windows Server instances and workloads in a hybrid environment · Manage updates by using Azure Update Manager
A cloud infrastructure engineer is evaluating patch management solutions for 45 on-premises Windows Server 2025 machines connected via Azure Arc and 30 Azure virtual machines. The organization mandates that the patching platform must provide native Azure Role-Based Access Control (RBAC) governance without incurring extra compute overhead or requiring persistent dedicated database workspaces. How does Azure Update Manager meet these architectural requirements?
Show answer & explanation
Correct answer: D
Azure Update Manager is designed as a standalone, native Azure management service for operating system lifecycle management across Azure VMs and Arc-enabled servers. Unlike legacy solutions such as Azure Automation Update Management, Azure Update Manager does not require an Azure Automation account or a Log Analytics workspace. Permissions and access control are handled natively at per-resource scope using Azure RBAC.
- Question 6IntermediateSelect 2
Manage Windows Server instances and workloads in a hybrid environment · Manage updates by using Azure Update Manager
An administrator is designing an automated patching policy in Azure Update Manager for mission-critical Windows Server workloads. Which TWO capabilities are natively supported by Azure Update Manager to optimize patch compliance and minimize service disruptions? (Select TWO)
Show answer & explanation
Correct answers: A, B
Azure Update Manager natively supports Periodic Assessment, which scans targeted machines automatically every 24 hours to detect missing updates without installing them. It also supports Hotpatching (available on supported Azure and Azure Stack HCI/Local editions), which updates in-memory code of running processes without rebooting the virtual machine, significantly minimizing downtime.
Hotpatching is natively integrated with Azure Update Manager, enabling security patches to be applied dynamically to running memory without rebooting the host. Periodic assessment scans machines every 24 hours to maintain update compliance data.
Ready for the real thing?
The full AZ-802 simulator has every exam-style question, timed mode, and instant scoring.