Topic 3: Misc. Questions

Your on-premises network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains the domains shown in the following table.

You create a user named User1 that has the following attributes:

You plan to move User1 to OU3 by using the Active Directory Migration Tool (ADMT). Which attributes will change if User1 moves to OU3?

A. distinguishedName only

B. objectsioonly

C. objectGUID, and objectSID Only

D. distinguishedHame, objectSID, and whenCreated Only

D.   distinguishedHame, objectSID, and whenCreated Only

Your network contains an Active Directory Domain Services (AD DS) domain The domain contains an organizational unit (OU) named OU1 and a user named User1.

You plan to deploy a Hyper V failover cluster named Cluster1.

You need to prestage the account for Cluster! and ensure that User1 can deploy Cluster1. The solution must follow the principle of least privilege.

Which action should you perform, and which permissions should you grant to User1 for Cluster1? To answer, select the appropriate options in the answer area

NOTE: Each correct selection is worth one point.


You have an on-premises virtual machine named VM1 that runs Windows Server. You have an Azure subscription.

You plan to use an Azure Site Recovery replication policy to replicate VM1 to Azure. You need to ensure that changes on VM1 are replicated as often as possible. To what should you set the Copy frequency setting for the policy?

A. 15 Seconds

B. 30 Seconds

C. 1 Minute

D. 5 Minutes

B.   30 Seconds

Your network contains an Active Directory Domain Services (AD DS) domain. You plan to protect high-privilege domain credentials by specifying the following:

• The lifetime of the Kerberos Ticket Granting Ticket (TGT)
• The conditions required for devices to request a TGT

What should you use, and what should you create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


You have an Azure subscription that contains an Azure key vault named Vault 1.

You deploy Azure Disk Encryption.

You configure Vault to support Azure Disk Encryption.

You need to ensure that you can encrypt Azure Disk Encryption artifacts before they are written to Vault 1. The solution must provide the highest level of encryption.

How should you complete the command? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.


You have an on-premises file server named Server1 that runs Windows Server.

You have an Azure subscription.

Server1 contains a file share named Share1.

You need to migrate Share1 to an Azure virtual machine.

What should you use?

A. Storage Replica

B. Windows Admin Center

C. Server Manager

D. Azure Migrate

B.   Windows Admin Center

You have an Azure subscription. The subscription contains a Log Analytics workspace named Workspace1 and 100 virtual machines that run Windows Server.

You enable Microsoft Defender for Servers Plan 2 and configure Defender for Servers to monitor for Windows file and registry changes on the virtual machines.

You need to query the detected file and registry changes. Which table should you query?

A. ASimFileEventLogs

B. MDCDetectionFimEvents

C. ASimRegistryEventlogs

D. DeviceRegistryEvents

B.   MDCDetectionFimEvents

You have a Windows Server 2022 Storage Spaces Direct cluster named Cluster1. Cluster1 has four nodes that contain virtual machines.

You need to perform an in-place upgrade of Cluster! to Windows Server 2025. The solution must ensure that the virtual machines are always available during the upgrade.

In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.


You have an Azure subscription that contains the Azure key vaults shown in the following table.

You create a virtual machine that has the following configurations

• Name:VM1
• Resource group: RG1
• Azure region: East US
• Operating system: Windows Server

You need to enable Azure Disk Encryption for VM1. Which key vault can you use to store the encryption key for VM1?

A. Vault1 only

B. Vault1 or Vault2 only

C. Vault1 orVault3only

D. Vault1, Vault2, Vault3, or Vault4

C.   Vault1 orVault3only

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a domain controller named DC!

The domain uses Microsoft Entra Connect sync with a Microsoft Entra tenant and uses Microsoft Entra Password Protection to enforce a custom banned password list

You deploy a new domain controller named DC2 to the domain.

You discover that the custom banned password list is applied inconsistently and often allows banned passwords to be used.

You need to ensure that the custom banned password list is always enforced.

What should you do on DC2?

A. Install the Microsoft Entra Password Protection DC agent.

B. Install the Microsoft Entra provisioning agent

C. Install the Microsoft Entra Password Protection proxy service.

D. Provide access to the https://login.microsoftonline.com and https://enterpriseregistration.windows.net URLs.

E. Install the Azure Monitor Agent

A.   Install the Microsoft Entra Password Protection DC agent.

Page 3 out of 28 Pages