AZ-802 Practice Exam: Windows Server Hybrid Administrator Associate
The hybrid admin cert: make on-prem Windows Server and Azure play nicely together.
What you'll be tested on
- Hybrid Identity
- Hybrid Networking
- Hybrid Compute and Storage
- Security and Compliance
Sample AZ-802 questions
Overview - Contoso, Ltd. is a company that has a main office in Seattle and two branch offices in Los Angeles and Montreal. Existing Environment - AD DS Environment - The network contains an on-premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com. The forest contains the domain controllers shown in the following table. All the domain controllers are global catalog servers. Server Infrastructure - The network contains the servers shown in the following table. A server named Server4 runs Windows Server and is in a workgroup. Windows Defender Firewall on Server4 uses the private profile. Server2 hosts three virtual machines named VM1, VM2, and VM3. VM3 is a file server that stores data in the volumes shown in the following table. Group Policies - The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table. Existing Identities - The forest contains the users shown in the following table. The forest contains the groups shown in the following table. | Name | Domain | Active Directory site | |------|--------|----------------------| | DC1 | contoso.com | Seattle | | DC2 | contoso.com | Los Angeles | | DC3 | canada.contoso.com | Montreal | | DC4 | contoso.com | Montreal | | DC5 | canada.contoso.com | Seattle | | Name | Organizational unit (OU) | Server role | Domain | Active Directory site | |---|---|---|---|---| | Server1 | Member Servers | None | canada.contoso.com | Montreal | | Server2 | Member Servers | Hyper-V | canada.contoso.com | Montreal | | Server3 | Member Servers | None | canada.contoso.com | Montreal | | Name | File system | |------|-------------| | C | NTFS | | D | NTFS | | E | ReFS | | F | ExFAT | | Name | Minimum password length | Linked to | |---|---|---| | GPO1 | 14 | OU1 | | GPO2 | 8 | Member Servers | | Default Domain Policy | 10 | contoso.com | | Name | In OU | Member of | |---|---|---| | Contoso\Admin1 | Contoso\OU1 | Contoso\Enterprise Admins | | Contoso\Admin2 | Contoso\OU1 | Contoso\Domain Admins | | Canada\Admin3 | Canada\OU2 | Canada\Domain Admins | | Contoso\User1 | Contoso\OU3 | Contoso\Domain Users | | Name | Domain | Type | |---|---|---| | Group1 | contoso.com | Universal security group | | Group2 | contoso.com | Global security group | | Group3 | contoso.com | Domain local security group | | Group4 | canada.contoso.com | Global distribution group | | Group5 | canada.contoso.com | Global distribution group | | Group6 | canada.contoso.com | Domain local distribution group | Current Problems - When an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out, another administrator can connect to the console session as the currently signed-in user. Requirements - Technical Requirements - Contoso identifies the following technical requirements: Change the replication schedule for all site links to 30 minutes. Promote Server1 to a domain controller in canada.contoso.com. Install and authorize Server3 as a DHCP server. Ensure that User1 can manage the membership of all the groups in Contoso\OU3. Ensure that you can manage Server4 from Server1 by using PowerShell remoting. Ensure that you can run virtual machines on VM1. Force users to provide credentials when they connect to VM2. On VM3, enable Data Deduplication on all volumes that support the feature. You need to meet the technical requirements for Server3. Which users can perform the required tasks?
- Admin1 only
- Admin3 only
- Admin1 and Admin2 only
- Admin1 and Admin3 only
- Admin1, Admin2, and Admin3
Show answer
D — Admin1 and Admin3 onlyIn the case study, only Admin1 and Admin3 hold the group memberships and permissions needed to perform the required administrative task. Admin1 has the rights granted through the contoso.com groups listed in the identities tables, and Admin3 has equivalent rights in the canada.contoso.com domain. Admin2 lacks the required role or group membership, so Admin2 cannot complete the action. Options that include Admin2, or that omit either Admin1 or Admin3, are wrong because they either grant the task to an unauthorized account or exclude an account that does meet the requirements.
Overview - Contoso, Ltd. is a company that has a main office in Seattle and two branch offices in Los Angeles and Montreal. Existing Environment - AD DS Environment - The network contains an on-premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com. The forest contains the domain controllers shown in the following table. All the domain controllers are global catalog servers. Server Infrastructure - The network contains the servers shown in the following table. A server named Server4 runs Windows Server and is in a workgroup. Windows Defender Firewall on Server4 uses the private profile. Server2 hosts three virtual machines named VM1, VM2, and VM3. VM3 is a file server that stores data in the volumes shown in the following table. Group Policies - The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table. Existing Identities - The forest contains the users shown in the following table. The forest contains the groups shown in the following table. | Name | Domain | Active Directory site | |------|--------|----------------------| | DC1 | contoso.com | Seattle | | DC2 | contoso.com | Los Angeles | | DC3 | canada.contoso.com | Montreal | | DC4 | contoso.com | Montreal | | DC5 | canada.contoso.com | Seattle | | Name | Organizational unit (OU) | Server role | Domain | Active Directory site | |---|---|---|---|---| | Server1 | Member Servers | None | canada.contoso.com | Montreal | | Server2 | Member Servers | Hyper-V | canada.contoso.com | Montreal | | Server3 | Member Servers | None | canada.contoso.com | Montreal | | Name | File system | |------|-------------| | C | NTFS | | D | NTFS | | E | ReFS | | F | ExFAT | | Name | Minimum password length | Linked to | |---|---|---| | GPO1 | 14 | OU1 | | GPO2 | 8 | Member Servers | | Default Domain Policy | 10 | contoso.com | | Name | In OU | Member of | |---|---|---| | Contoso\Admin1 | Contoso\OU1 | Contoso\Enterprise Admins | | Contoso\Admin2 | Contoso\OU1 | Contoso\Domain Admins | | Canada\Admin3 | Canada\OU2 | Canada\Domain Admins | | Contoso\User1 | Contoso\OU3 | Contoso\Domain Users | | Name | Domain | Type | |---|---|---| | Group1 | contoso.com | Universal security group | | Group2 | contoso.com | Global security group | | Group3 | contoso.com | Domain local security group | | Group4 | canada.contoso.com | Global distribution group | | Group5 | canada.contoso.com | Global distribution group | | Group6 | canada.contoso.com | Domain local distribution group | Current Problems - When an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out, another administrator can connect to the console session as the currently signed-in user. Requirements - Technical Requirements - Contoso identifies the following technical requirements: Change the replication schedule for all site links to 30 minutes. Promote Server1 to a domain controller in canada.contoso.com. Install and authorize Server3 as a DHCP server. Ensure that User1 can manage the membership of all the groups in Contoso\OU3. Ensure that you can manage Server4 from Server1 by using PowerShell remoting. Ensure that you can run virtual machines on VM1. Force users to provide credentials when they connect to VM2. On VM3, enable Data Deduplication on all volumes that support the feature. You need to meet the technical requirements for User1. The solution must use the principle of least privilege. What should you do?
- Add User1 to the Account Operators group in contoso.com.
- Create a delegation on contoso.com.
- Add User1 to the Server Operators group in contoso.com.
- Create a delegation on OU3.
Show answer
D — Create a delegation on OU3.In the case study, only Admin1 and Admin3 hold the group memberships and permissions needed to perform the required administrative task. Admin1 has the rights granted through the contoso.com groups listed in the identities tables, and Admin3 has equivalent rights in the canada.contoso.com domain. Admin2 lacks the required role or group membership, so Admin2 cannot complete the action. Options that include Admin2, or that omit either Admin1 or Admin3, are wrong because they either grant the task to an unauthorized account or exclude an account that does meet the requirements.
Overview - Contoso, Ltd. is a company that has a main office in Seattle and two branch offices in Los Angeles and Montreal. Existing Environment - AD DS Environment - The network contains an on-premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com. The forest contains the domain controllers shown in the following table. All the domain controllers are global catalog servers. Server Infrastructure - The network contains the servers shown in the following table. A server named Server4 runs Windows Server and is in a workgroup. Windows Defender Firewall on Server4 uses the private profile. Server2 hosts three virtual machines named VM1, VM2, and VM3. VM3 is a file server that stores data in the volumes shown in the following table. Group Policies - The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table. Existing Identities - The forest contains the users shown in the following table. The forest contains the groups shown in the following table. | Name | Domain | Active Directory site | |------|--------|----------------------| | DC1 | contoso.com | Seattle | | DC2 | contoso.com | Los Angeles | | DC3 | canada.contoso.com | Montreal | | DC4 | contoso.com | Montreal | | DC5 | canada.contoso.com | Seattle | | Name | Organizational unit (OU) | Server role | Domain | Active Directory site | |---|---|---|---|---| | Server1 | Member Servers | None | canada.contoso.com | Montreal | | Server2 | Member Servers | Hyper-V | canada.contoso.com | Montreal | | Server3 | Member Servers | None | canada.contoso.com | Montreal | | Name | File system | |------|-------------| | C | NTFS | | D | NTFS | | E | ReFS | | F | ExFAT | | Name | Minimum password length | Linked to | |---|---|---| | GPO1 | 14 | OU1 | | GPO2 | 8 | Member Servers | | Default Domain Policy | 10 | contoso.com | | Name | In OU | Member of | |---|---|---| | Contoso\Admin1 | Contoso\OU1 | Contoso\Enterprise Admins | | Contoso\Admin2 | Contoso\OU1 | Contoso\Domain Admins | | Canada\Admin3 | Canada\OU2 | Canada\Domain Admins | | Contoso\User1 | Contoso\OU3 | Contoso\Domain Users | | Name | Domain | Type | |---|---|---| | Group1 | contoso.com | Universal security group | | Group2 | contoso.com | Global security group | | Group3 | contoso.com | Domain local security group | | Group4 | canada.contoso.com | Global distribution group | | Group5 | canada.contoso.com | Global distribution group | | Group6 | canada.contoso.com | Domain local distribution group | Current Problems - When an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out, another administrator can connect to the console session as the currently signed-in user. Requirements - Technical Requirements - Contoso identifies the following technical requirements: Change the replication schedule for all site links to 30 minutes. Promote Server1 to a domain controller in canada.contoso.com. Install and authorize Server3 as a DHCP server. Ensure that User1 can manage the membership of all the groups in Contoso\OU3. Ensure that you can manage Server4 from Server1 by using PowerShell remoting. Ensure that you can run virtual machines on VM1. Force users to provide credentials when they connect to VM2. On VM3, enable Data Deduplication on all volumes that support the feature. You need to meet the technical requirements for Server1. Which users can currently perform the required tasks?
- Admin1 only
- Admin3 only
- Admin1 and Admin3 only
- Admin1, Admin2, and Admin3
Show answer
C — Admin1 and Admin3 onlyDelegating control on OU3 follows the principle of least privilege: User1 receives only the specific permissions needed for objects in that organizational unit and nothing more. Adding User1 to Account Operators or Server Operators would grant broad domain-wide rights over accounts or servers, which far exceeds the requirement. Creating a delegation at the contoso.com domain root would flow to every OU in the domain, again granting more access than necessary. Using the Delegation of Control Wizard on OU3 targets exactly the required scope and nothing else.
Access plans
| Access | Price |
|---|---|
| 3 months | |
| 1 year | |
| Lifetime |
Free preview inside — try 5 questions before you pay anything.
FAQ
How many practice questions are in this AZ-802 bank?
38 questions covering the current AZ-802 Windows Server Hybrid Administrator Associate syllabus, every one with the correct answer and an explanation.How long is the real AZ-802 exam?
The official AZ-802 exam gives you 100 minutes. Our timed exam mode uses the same limit so the pace feels familiar.What does AZ-802 access cost?
Plans start at $3.99 for 3 months. One payment, no subscription — and far cheaper than retaking the real exam.