Topic 3: Misc. Questions

You have a server that runs Windows Server. The server is configured to encrypt all incoming traffic by using a connection security rule.

You need to ensure that Server1 can respond to the unencrypted tracert commands initiated from computers on the same network.

What should you do from Windows Defender Firewall with Advanced Security?

A. From the IPsec Settings, configure IPsec defaults.

B. Create a new custom outbound rule that allows ICMPv4 protocol connections for all profiles.

C. Change the Firewall state of the Private profile to Off.

D. From the IPsec Settings, configure IPsec exemptions.

D.   From the IPsec Settings, configure IPsec exemptions.

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1. You deploy a read-only domain controller (RODC) named RODC1. You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege. What should you use?

A. dsmgmt.exe

B. dsamain.exe

C. net user

D. Active Directory Sites and Services

A.   dsmgmt.exe

You have an on-premises server named Server1 that runs Windows Server.

You have an Azure subscription that uses Microsoft Defender for Cloud.

You need to onboard Server1 to Defender for Cloud.

Which actions should you perform in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.


You have a server that runs Windows Server and hosts an app named Appl.

You need to prevent App1 from accessing external SMTP servers. The solution must meet the following requirements:

• Minimize the impact on AppVs access to external HTTP servers.
• Minimize the impact on other apps on (he server.
• Minimize administrative effort

What should you implement in Windows Defender Firewall?

A. an outbound program rule

B. an inbound custom rule

C. an outbound custom rule

D. an inbound program rule

E. an outbound port rule

C.   an outbound custom rule

You have a Hyper-V failover cluster named Ousted. Cluster1 contains a virtual machine named VM1 that runs Windows Server. VM1 contains a Windows service named Service1.

You need to ensure that Cluster1 performs a recovery action if Service1 fails.

What should you do? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


You have an Azure virtual machine named VM1 that runs Windows Server. You need to perform the following tasks on VM1:

• Configure Windows Defender Firewall to allow Remote Desktop connections.
• Configure where to store the logs of the virtual machine console.

Which two settings should you use? To answer, select the settings in the answer area.

NOTE: Each correct selection is worth one point.


You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server.

The network interface for VM1 is disabled in the operating system.

You need to enable the network interface by using the Azure Serial Console.

How should you complete the command? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


You have a failover cluster named Cluster! that contains two Windows Server nodes named Server1 and Server2. Cluster! hosts highly available Hyper-V virtual machines.

You have a member server named Server3 that runs Windows Server.

You need to implement Cluster-Aware Updating (CUA) on Cluster! and configure Server3 to manage CUA. The solution must minimize administrative effort.

What should you install on Server3?

A. the Windows Server Update Services server role

B. the Failover Cluster Automation Server feature

C. Windows Admin Center

D. the Host Guardian Service server role

B.   the Failover Cluster Automation Server feature

You have a server named Server1 that runs Windows Server.

For Server1, you enable the default App Control for Business policies in audit mode.

You need to ensure that specific third-party applications installed on Server1 are allowed to run by using App Control for Business.

Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.


Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a file server named Server 1 that hosts multiple shared folders.

You have an Azure subscription.

You need to migrate the files stored on Server! to Azure by using an Azure Data Box gateway.

To which storage services can you migrate the files?

A. Azure Files only

B. Azure files and Azure Storage page blobs only

C. Azure Files and Azure Storage block blobs only

D. Azure Files. Azure Storage page blobs, and Azure Storage block blobs

D.   Azure Files. Azure Storage page blobs, and Azure Storage block blobs

Page 2 out of 28 Pages