Free AZ-802 practice test: 20 questions
Twenty questions across the seven AZ-802 skill areas, weighted roughly as the real exam is: five on AD DS, two on hybrid management, two on virtual machines, two on networking, four on storage and file services, two on security and three on monitoring and troubleshooting. These are original scenario questions. Find the constraint in each scenario before you look at the options.
Deploy and manage AD DS
Question 1. New user accounts fail to be created on one domain controller with an error about the RID pool, while other DCs work. The DC holding a certain FSMO role was decommissioned without transferring its roles. Which role must you seize?
- A. Schema master
- B. RID master
- C. Infrastructure master
- D. Domain naming master
Show answer
Answer: B
The RID master hands out pools of relative IDs to DCs so they can create security principals. When a DC runs out and the RID master is gone, new objects fail. The schema master and domain naming master are forest-wide and unrelated to RID pools. The infrastructure master updates cross-domain references.
Want more questions like this? Full AZ-802 practice tests →
Question 2. A domain controller is being deployed in an Azure VM. Which configuration follows Microsoft's guidance for the AD database and SYSVOL?
- A. On the OS disk with read/write caching
- B. On the temporary disk for best performance
- C. On an Azure file share mounted by the DC
- D. On a data disk with host caching set to None
Show answer
Answer: D
Microsoft recommends placing NTDS.dit, the logs and SYSVOL on a separate data disk with host caching set to None, so writes are not held in a cache. The OS disk and temporary disk are unsuitable: the OS disk uses read/write caching and the temporary disk is lost on redeployment. An Azure file share is not supported for the AD database.
Want more questions like this? Full AZ-802 practice tests →
Question 3. Replication between the Amsterdam and Singapore sites must happen only at night, while replication within each site stays immediate. What should you configure?
- A. The schedule on the site link between the two sites
- B. The cost on the site link between the two sites
- C. A preferred bridgehead server in each site
- D. SID filtering on the connection between the sites
Show answer
Answer: A
Replication between sites follows the schedule and interval of the site link that connects them, so a site link schedule limited to night hours meets the requirement. Intrasite replication uses change notification and is not affected. Site link cost chooses between routes, the bridgehead choice decides which DC replicates, and SID filtering is a trust setting.
Want more questions like this? Full AZ-802 practice tests →
Question 4. Laptops in the Sales OU must receive a mapped drive only when they are connected to the 10.5.0.0/16 network, using one GPO. What should you use?
- A. Loopback processing in Merge mode
- B. Security filtering on the GPO
- C. A Group Policy preference drive map with item-level targeting on the IP range
- D. Block inheritance on the Sales OU
Show answer
Answer: C
A Group Policy preference drive map with item-level targeting on an IP address range applies the setting only when the condition is met, within one GPO. Loopback processing changes how user settings apply, security filtering selects users or computers rather than networks, and block inheritance stops GPOs from parent containers.
Want more questions like this? Full AZ-802 practice tests →
Question 5. In a multi-domain forest, Marketing users need read access to a share in the Research domain. Following recommended group nesting, where should the permission be assigned?
- A. Directly to each Marketing user account
- B. To a domain local group in Research that contains the Marketing global group
- C. To the Marketing global group directly on the share
- D. To a universal group in the Marketing domain
Show answer
Answer: B
Recommended nesting puts users into global groups in their own domain, those groups into a domain local group in the resource domain, and the permission on the domain local group. Assigning to users directly or to a global group from another domain does not scale, and universal groups are for collecting accounts across the forest rather than holding resource permissions.
Want more questions like this? Full AZ-802 practice tests →
Manage Windows Server in a hybrid environment
Question 6. Administrators must manage Arc-enabled servers from the Azure portal with a browser-based tool that shows files, events, services and PowerShell, without deploying a gateway server. What should you use?
- A. Windows Admin Center in the Azure portal
- B. Windows Admin Center installed as an on-premises gateway
- C. Azure Bastion
- D. Azure Update Manager
Show answer
Answer: A
Windows Admin Center in the Azure portal runs as an extension on Arc-enabled servers and Azure VMs, needs no gateway of your own, and uses Azure RBAC for access. An on-premises gateway must be deployed and maintained. Azure Bastion provides RDP and SSH to Azure VMs. Update Manager handles patching only.
Want more questions like this? Full AZ-802 practice tests →
Question 7. A nightly script must clean up log files on five on-premises servers and must be managed and scheduled from Azure. What should you configure?
- A. A machine configuration policy assignment
- B. An Azure Update Manager maintenance configuration
- C. An Azure Automation runbook on a Hybrid Runbook Worker
- D. A data collection rule for the servers
Show answer
Answer: C
An Azure Automation runbook scheduled in Azure and running on a Hybrid Runbook Worker can act on on-premises servers. Machine configuration audits or enforces settings but is not for scheduled scripts. Update Manager deploys updates. A data collection rule defines monitoring data.
Want more questions like this? Full AZ-802 practice tests →
Manage virtual machines
Question 8. You must configure NIC teaming inside a guest VM that has two virtual network adapters connected to different external virtual switches. Teaming fails to configure in the guest. What must you do on the host?
- A. Create a Switch Embedded Teaming switch
- B. Enable MAC address spoofing on both adapters
- C. Enable SR-IOV on both adapters
- D. Enable AllowTeaming on both virtual network adapters
Show answer
Answer: D
For teaming inside a guest, each virtual adapter must allow it, which you enable with Set-VMNetworkAdapter -AllowTeaming On or in the adapter’s advanced features. Switch Embedded Teaming is for the host’s switch, MAC spoofing is for nested virtualization, and SR-IOV is an offload feature.
Want more questions like this? Full AZ-802 practice tests →
Question 9. Administrators must be able to RDP into Azure VMs only after requesting access, and the RDP port should be closed at all other times. Which feature fits?
- A. Azure Bastion
- B. Just-in-time VM access
- C. A public IP address with an NSG rule for port 3389
- D. An availability set
Show answer
Answer: B
Just-in-time VM access, part of Defender for Servers Plan 2, opens the management port only for an approved request and time window, then closes it. Azure Bastion avoids public exposure but does not time-limit access by request. A public IP with an NSG rule leaves the port open, and an availability set is a resilience feature.
Want more questions like this? Full AZ-802 practice tests →
Implement and manage networking
Question 10. Client computers must refuse DNS answers for secure.contoso.com that are not DNSSEC-validated. The zone is signed. What should you configure on the clients?
- A. A trust anchor on each client
- B. A conditional forwarder for secure.contoso.com
- C. An NRPT rule through Group Policy requiring DNSSEC validation
- D. A zone scope for secure.contoso.com
Show answer
Answer: C
The Name Resolution Policy Table, deployed through Group Policy, tells Windows clients to require DNSSEC validation for a namespace. A trust anchor is configured on the validating DNS server, not on clients. Conditional forwarders and zone scopes do not enforce validation.
Want more questions like this? Full AZ-802 practice tests →
Question 11. A DHCP failover relationship is in load balance mode. The administrator wants each partner to be able to serve all clients alone if the other goes down, but with a limit on how long it may extend leases on its own. Which setting controls that limit?
- A. Maximum client lead time
- B. Load balance percentage
- C. Conflict detection attempts
- D. Scope lease duration
Show answer
Answer: A
The maximum client lead time limits how far a partner can extend a lease beyond what the other partner knows about, which protects against duplicate addresses when the partners cannot communicate. The load balance percentage splits normal traffic. Conflict detection pings before leasing, and the lease duration applies to all leases.
Want more questions like this? Full AZ-802 practice tests →
Manage storage and file services
Question 12. Users should see only the folders they have permission to open when browsing a department share. What should you enable?
- A. An FSRM file screen
- B. An FSRM quota template
- C. SMB encryption on the share
- D. Access-based enumeration on the share
Show answer
Answer: D
Access-based enumeration hides files and folders a user has no permission to access. An FSRM file screen blocks file types, a quota limits space, and SMB encryption protects data in transit.
Want more questions like this? Full AZ-802 practice tests →
Question 13. Two file servers in different datacenters must keep a volume identical at block level with no data loss if the primary datacenter fails. The link latency is below 5 ms. What should you use?
- A. DFS Replication
- B. Storage Replica in synchronous mode
- C. Storage Replica in asynchronous mode
- D. Azure File Sync between both servers
Show answer
Answer: B
Storage Replica in synchronous mode writes to both volumes before acknowledging, so no data is lost on failover, and it suits low-latency links. Asynchronous mode can lose recent writes. DFS Replication and Azure File Sync replicate files rather than blocks, and neither guarantees zero data loss.
Want more questions like this? Full AZ-802 practice tests →
Question 14. A server volume that hosts Hyper-V virtual disks for a VDI deployment is running low on space. Many VMs share the same base image. What should you configure?
- A. Storage QoS policies for the VDI VMs
- B. NTFS compression on the volume
- C. Data Deduplication with the Hyper-V usage type
- D. An FSRM hard quota on the volume
Show answer
Answer: C
Data Deduplication with the Hyper-V usage type is designed for VDI virtual disks, where many files share identical blocks. Storage QoS manages IOPS, not space. File compression on NTFS does not handle open VHDX files well, and an FSRM quota only limits usage.
Want more questions like this? Full AZ-802 practice tests →
Question 15. You are creating a volume for Storage Spaces Direct that will host Hyper-V VMs and needs integrity checking and fast checkpoint merges. Which file system should you choose?
- A. ReFS
- B. NTFS
- C. exFAT
- D. FAT32
Show answer
Answer: A
ReFS is recommended for Storage Spaces Direct and Hyper-V: it supports integrity streams and block cloning, which speeds up checkpoint merges and fixed disk creation. NTFS lacks these features, FAT32 and exFAT are not suited to server workloads.
Want more questions like this? Full AZ-802 practice tests →
Secure Windows Server infrastructure
Question 16. You must restrict which applications can run on a set of file servers, but first find out what would be blocked without affecting users. What should you do?
- A. Enable SmartScreen in warn mode
- B. Deploy an App Control for Business policy in audit mode
- C. Enable exploit protection with default settings
- D. Enable Credential Guard
Show answer
Answer: B
App Control for Business policies can be deployed in audit mode, which logs what would be blocked without enforcing, so you can refine the policy before switching to enforcement. SmartScreen warns about downloads, exploit protection mitigates memory attacks, and Credential Guard protects credentials.
Want more questions like this? Full AZ-802 practice tests →
Question 17. Servers in the domain must accept management traffic only from other domain members that authenticate with Kerberos, but the DHCP servers must stay reachable without authentication. What should you configure?
- A. The domain firewall profile with inbound rules blocked
- B. The Protected Users group for all server accounts
- C. A fine-grained password policy for computer accounts
- D. An isolation rule plus an authentication exemption rule for the DHCP servers
Show answer
Answer: D
An isolation connection security rule requires IPsec authentication between domain members, and an authentication exemption rule excludes infrastructure servers such as DHCP servers. Firewall profiles decide which rules apply on which network. Protected Users and fine-grained password policies apply to accounts, not network traffic.
Want more questions like this? Full AZ-802 practice tests →
Monitor and troubleshoot
Question 18. SYSVOL is corrupted on all four domain controllers, and GPOs fail everywhere. You have one DC with a good SYSVOL copy restored from backup. What should you do to rebuild SYSVOL?
- A. A non-authoritative SYSVOL sync on all four DCs
- B. An authoritative restore of the GPO objects with ntdsutil
- C. An authoritative SYSVOL sync on the good DC and non-authoritative syncs on the others
- D. Restore the GPOs from the AD Recycle Bin
Show answer
Answer: C
When SYSVOL is broken everywhere, you perform an authoritative DFSR sync on the DC with the good copy and non-authoritative syncs on the others, so all DCs take SYSVOL from the good one. A non-authoritative sync alone would pull from a broken partner. An authoritative ntdsutil restore handles AD objects, not SYSVOL, and the Recycle Bin restores objects.
Want more questions like this? Full AZ-802 practice tests →
Question 19. You need to forecast when the data volume on a file server will run out of space, using data collected locally on the server. Which feature fits?
- A. System Insights
- B. Performance Monitor
- C. A data collector set
- D. VM insights
Show answer
Answer: A
System Insights uses local machine learning to forecast CPU, network and storage consumption, including volume capacity. Performance Monitor shows current counters, data collector sets record data for later analysis without forecasting, and VM insights requires Azure Monitor.
Want more questions like this? Full AZ-802 practice tests →
Question 20. Users receive Kerberos errors when connecting to a web application running under a service account, and NTLM works. You suspect the HTTP SPN is registered on two accounts. Which command finds duplicate SPNs?
- A. klist
- B. setspn -X
- C. nltest /sc_verify
- D. repadmin /showrepl
Show answer
Answer: B
setspn -X searches the forest for duplicate SPNs, which break Kerberos because the KDC cannot tell which account to encrypt the ticket for. klist shows the client’s tickets, nltest /sc_verify tests a secure channel, and repadmin /showrepl shows replication status.
Want more questions like this? Full AZ-802 practice tests →
How did you do?
Sixteen or more correct suggests you are close. Below fourteen, the domain guides in this section are the fastest way to find the gaps. Questions 1–5 cover AD DS, the largest domain: if you missed more than one, start with the AD DS guide. Questions 12–15 cover storage, the domain with the most objectives, and 18–20 cover troubleshooting; weak results there point to the storage guide and the troubleshooting guide.
There is no official practice assessment for AZ-802 yet. When Microsoft publishes one, take it as well. If both results point at the same domain, you know where your remaining time should go.