Skip to content

AZ-802 Administering Windows Server Practice Questions

Prepare for AZ-802 with more than an answer.

150 questions in the full set12 sample questionsUpdated Oct 2, 2026

Unlock the full exam and previous versions

  • v1Administering Windows Server 150 questions Current
  • 98-365Legacy Windows Server Administration Fundamentals 364 questions Locked
  • AZ-800Legacy Administering Windows Server Hybrid Core Infrastructure 215 questions Locked
  • AZ-801Legacy Windows Server Hybrid Advanced Services 214 questions Locked
  1. 1

    An administrator is designing an automated patching policy in Azure Update Manager for mission-critical Windows Server workloads. Which TWO capabilities are natively supported by Azure Update Manager to optimize patch compliance and minimize service disruptions? (Select TWO)

    Show answer details

    Correct answer: A, B

    Azure Update Manager natively supports Periodic Assessment, which scans targeted machines automatically every 24 hours to detect missing updates without installing them. It also supports Hotpatching (available on supported Azure and Azure Stack HCI/Local editions), which updates in-memory code of running processes without rebooting the virtual machine, significantly minimizing downtime.

    Hotpatching is natively integrated with Azure Update Manager, enabling security patches to be applied dynamically to running memory without rebooting the host. Periodic assessment scans machines every 24 hours to maintain update compliance data.

  2. 2

    A systems administrator needs to schedule recurring maintenance windows for patching over 200 Azure Arc-enabled Windows Server instances. The fleet changes frequently as new servers are provisioned across development, staging, and production resource groups. To eliminate the overhead of manually updating machine lists within the maintenance configuration, which Azure Update Manager feature should the administrator configure?

    Show answer details

    Correct answer: C

    Azure Update Manager provides Dynamic Scoping, which allows administrators to define maintenance schedules that automatically evaluate and group virtual machines and Arc-enabled servers based on dynamic criteria such as subscriptions, resource groups, locations, and resource tags. When new servers matching the criteria are onboarded, they are automatically included in the patch maintenance window without manual intervention.

  3. 3

    An administrator is configuring a Windows Server 2025 Hyper-V host to run a virtual lab. Inside a guest virtual machine named VM-Host01, the administrator enables nested virtualization to run containerized workloads with Hyper-V isolation. While VM-Host01 is actively running, the administrator attempts to increase its assigned startup RAM from 16 GB to 32 GB using Hyper-V Manager, but the option is unavailable. What explains this restriction?

    Show answer details

    Correct answer: D

    In Hyper-V nested virtualization, dynamic memory sizing does not fluctuate while Hyper-V is running inside the guest virtual machine. Even if dynamic memory is configured, Hyper-V inside the guest cannot resize memory dynamically at runtime. Furthermore, adjusting assigned memory requires the virtual machine to be powered off completely.

  4. 4

    A security engineer implements Just-In-Time (JIT) VM access through Microsoft Defender for Cloud (Defender for Servers Plan 2) on a subnet containing sensitive Windows Server Azure virtual machines. How does JIT VM access enforce network security at the Network Security Group (NSG) level?

    Show answer details

    Correct answer: C

    Defender for Cloud JIT VM access protects management ports (such as TCP 3389 for RDP and TCP 22 for SSH) by configuring an NSG rule that denies all inbound traffic to those ports. When an authorized user requests access and is approved via Azure RBAC, JIT creates a temporary inbound allow rule with higher priority, explicitly locked down to the user's specific public IP address or IP range and valid only for the requested time window. Once the window expires, the temporary rule is removed.

  5. 5

    A system administrator is deploying a Read-Only Domain Controller (RODC) at a remote branch office for Contoso, Ltd. To ensure branch users can authenticate locally during WAN outages, the administrator configures the Password Replication Policy (PRP). A member of the Helpdesk staff, User1, is added to the Allowed RODC Password Replication Group. However, User1 is also a member of the built-in Denied RODC Password Replication Group. When User1 attempts to authenticate at the branch office during a WAN failure, authentication fails. What is the cause of this behavior?

    Show answer details

    Correct answer: B

    In Active Directory Domain Services, evaluation of the RODC Password Replication Policy (PRP) follows strict precedence where explicit Deny rules supersede Allow rules. The Denied RODC Password Replication Group is specifically designed to protect administrative and sensitive accounts from having their credentials stored in branch offices with limited physical security. Because User1 is a member of the Denied group, their credentials are never cached locally on the RODC, causing authentication to fail when the WAN link is unavailable.

  6. 6

    An enterprise architect needs to deploy an RODC at a remote manufacturing facility where no local IT staff possess domain administrative credentials. A local plant technician must complete the physical installation and promote the server. The architect pre-stages the RODC account in Active Directory using the Add-ADDSReadOnlyDomainControllerAccount cmdlet and delegates the installation to the plant technician's domain account. What administrative rights does the plant technician have once the RODC promotion is finalized?

    Show answer details

    Correct answer: D

    Staging an RODC via Add-ADDSReadOnlyDomainControllerAccount allows domain administrators to delegate the installation and day-to-day server maintenance to a standard user or group. When the delegated principal attaches the server to the staged account during promotion, they automatically become a member of the local Administrators group on that specific RODC. They do not gain administrative permissions on writable domain controllers or other domain resources.

Create an account to continue.