Topic 3: Misc. Questions
Your on-premises network contains an Active Directory Domain Services (AD DS) forest
named contoso.com. The forest contains the domains shown in the following table.

You create a user named User1 that has the following attributes:

You plan to move User1 to OU3 by using the Active Directory Migration Tool (ADMT).
Which attributes will change if User1 moves to OU3?
A. distinguishedName only
B. objectsioonly
C. objectGUID, and objectSID Only
D. distinguishedHame, objectSID, and whenCreated Only
Your network contains an Active Directory Domain Services (AD DS) domain The domain
contains an organizational unit (OU) named OU1 and a user named User1.
You plan to deploy a Hyper V failover cluster named Cluster1.
You need to prestage the account for Cluster! and ensure that User1 can deploy Cluster1.
The solution must follow the principle of least privilege.
Which action should you perform, and which permissions should you grant to User1 for
Cluster1? To answer, select the appropriate options in the answer area
NOTE: Each correct selection is worth one point.
You have an on-premises virtual machine named VM1 that runs Windows Server. You
have an Azure subscription.
You plan to use an Azure Site Recovery replication policy to replicate VM1 to Azure. You
need to ensure that changes on VM1 are replicated as often as possible. To what should
you set the Copy frequency setting for the policy?
A. 15 Seconds
B. 30 Seconds
C. 1 Minute
D. 5 Minutes
Your network contains an Active Directory Domain Services (AD DS) domain. You plan to
protect high-privilege domain credentials by specifying the following:
• The lifetime of the Kerberos Ticket Granting Ticket (TGT)
• The conditions required for devices to request a TGT
What should you use, and what should you create? To answer, select the appropriate
options in the answer area.
NOTE: Each correct selection is worth one point.
You have an Azure subscription that contains an Azure key vault named Vault 1.
You deploy Azure Disk Encryption.
You configure Vault to support Azure Disk Encryption.
You need to ensure that you can encrypt Azure Disk Encryption artifacts before they are
written to Vault 1. The solution must provide the highest level of encryption.
How should you complete the command? To answer, select the appropriate options in the
answer area.
NOTE: Each correct selection is worth one point.
You have an on-premises file server named Server1 that runs Windows Server.
You have an Azure subscription.
Server1 contains a file share named Share1.
You need to migrate Share1 to an Azure virtual machine.
What should you use?
A. Storage Replica
B. Windows Admin Center
C. Server Manager
D. Azure Migrate
You have an Azure subscription. The subscription contains a Log Analytics workspace
named Workspace1 and 100 virtual machines that run Windows Server.
You enable Microsoft Defender for Servers Plan 2 and configure Defender for Servers to
monitor for Windows file and registry changes on the virtual machines.
You need to query the detected file and registry changes. Which table should you query?
A. ASimFileEventLogs
B. MDCDetectionFimEvents
C. ASimRegistryEventlogs
D. DeviceRegistryEvents
You have a Windows Server 2022 Storage Spaces Direct cluster named Cluster1. Cluster1
has four nodes that contain virtual machines.
You need to perform an in-place upgrade of Cluster! to Windows Server 2025. The solution
must ensure that the virtual machines are always available during the upgrade.
In which order should you perform the actions? To answer, move all actions from the list of
actions to the answer area and arrange them in the correct order.
You have an Azure subscription that contains the Azure key vaults shown in the following
table.

You create a virtual machine that has the following configurations
• Name:VM1
• Resource group: RG1
• Azure region: East US
• Operating system: Windows Server
You need to enable Azure Disk Encryption for VM1. Which key vault can you use to store
the encryption key for VM1?
A. Vault1 only
B. Vault1 or Vault2 only
C. Vault1 orVault3only
D. Vault1, Vault2, Vault3, or Vault4
Your network contains an Active Directory Domain Services (AD DS) domain. The domain
contains a domain controller named DC!
The domain uses Microsoft Entra Connect sync with a Microsoft Entra tenant and uses
Microsoft Entra Password Protection to enforce a custom banned password list
You deploy a new domain controller named DC2 to the domain.
You discover that the custom banned password list is applied inconsistently and often
allows banned passwords to be used.
You need to ensure that the custom banned password list is always enforced.
What should you do on DC2?
A. Install the Microsoft Entra Password Protection DC agent.
B. Install the Microsoft Entra provisioning agent
C. Install the Microsoft Entra Password Protection proxy service.
D. Provide access to the https://login.microsoftonline.com and https://enterpriseregistration.windows.net URLs.
E. Install the Azure Monitor Agent
| Page 3 out of 28 Pages |