Topic 3: Misc. Questions
You have 200 Azure virtual machines.
You create a recovery plan in Azure Site Recovery to fail over all the virtual machines to an
Azure region. The plan has three manual actions.
You need to replace one of the manual actions with an automated process.
What should you use?
A. an Azure Automation runbook
B. an Azure PowerShell function
C. a Custom Script Extension on the virtual machines
You have a server that runs Windows Server. The server is configured to encrypt all
incoming traffic by using a connection security rule.
You need to ensure that Server1 can respond to the unencrypted tracert commands
initiated from computers on the same network.
What should you do from Windows Defender Firewall with Advanced Security?
A. From the IPsec Settings, configure IPsec defaults.
B. Create a new custom outbound rule that allows ICMPv4 protocol connections for all profiles.
C. Change the Firewall state of the Private profile to Off.
D. From the IPsec Settings, configure IPsec exemptions.
Your on-premises datacenter contains physical servers and Hyper-V virtual machines.
You have an Azure subscription.
You plan to use Azure Migrate to perform the following tasks:
• Migrate the physical servers to Azure virtual machines.
• Migrate the Hyper-V virtual machines to Azure.
What should you use for each task? To answer, select the appropriate options in the
answer area. NOTE: Each correct selection is worth one point.
You have a Site-to-Site VPN between an on-premises network and an Azure VPN
gateway. BGP is disabled for the Site-to-Site VPN.
You have an Azure virtual network named Vnet1 that contains a subnet named Subnet1.
Subnet1 contains a virtual machine named Server1.
You can connect to Server1 from the on-premises network.
You extend the address space of Vnet1. You add a subnet named Subnet2 to Vnet1.
Subnet2 uses the extended address space. You deploy an Azure virtual machine named
Server2 to Subnet2.
You cannot connect to Server2 from the on-premises network. Server1 can connect to
Server2.
You need to ensure that you can connect to Subnet2 from the on-premises network.
What should you do?
A. Add an additional Site-to-Site VPN between the on-premises network and Vnetl.
B. Add a private endpoint to Subnet2.
C. To Subnet2. add a route table that contains a user-defined route.
D. Update the routing information on the on-premises routers.
Your network contains an Active Directory Domain Services (AD DS) domain. The domain
contains the servers shown in the following table.
Server3 contains a share named Share1.
On Server1, DHCP has the following configurations:
Conflict detection attempts: 3
An IPv4 scope named Scope1 that has the following settings:
1.Address Pool: 172.16.10.100 - 172.16.10.130
2.Address Leases:
- 172.16.10.100 computer1.contoso.com
- 172.16.10.101 computer2.contoso.com
Reservations: 172.16.10.101 computer2.contoso.com
Policies: Policy1
You perform the following actions:
On Server1, you run
Export-DhcpServer -File \\Server3\Share1\File1.xml.
On Server2, you run
Import-DhcpServer -File \\Server3\Share1\File1.xml
-BackupPath \\Server3\Share1.
For each of the following statements, select Yes if the statement is true. Otherwise, select
No.
NOTE: Each correct selection is worth one point.
Your network contains an Active Directory Domain Services (AD DS) domain. The domain
contains a print server named Server1. All printers are deployed to users by using a Group
Policy Object (GPO) named GPO1.
You deploy a new server named Server2.
You need to decommission Server1. The solution must meet the following requirements:
Migrate the shared printers to Server2 by using the Printer Migration Wizard.
Ensure that the users use the printers on Server2.
Minimize downtime for the users.
Which four actions should you perform in sequence? To answer, move the appropriate
actions from the list of actions to the answer area and arrange them in the correct order.
Your network contains an Active Directory Domain Services (AD DS) domain. The domain
contains three servers named Server1, Server2, and Server3 that run Windows Server. All
the servers are on the same network and have network connectivity.
On Server1, Windows Defender Firewall has a connection security rule that has the
following settings:
• Rule Type: Server-to-server
• Endpoint 1: Any IP address
• Endpoint 2: Any IP address
• Requirements: Require authentication for inbound connections and request authentication
for outbound connections
• Authentication Method: Computer (Kerberos V5)
• Profile: Domain, Private, Public
• Name: Rule1
For each of the following statements, select Yes if the statement is true. Otherwise, select
No. NOTE: Each correct selection is worth one point.
You have a Storage Spaces Direct configuration that has persistent memory and contains
the data volumes shown in the following table.

On which volumes can you use direct access (DAX)?
A. Volume3 only
B. Volume4 only
C. Volume1 and Volume3 only
D. Volume2 and Volume4 only
E. Volume3 and Volume4 only
You have an on-premises server named Server1 that runs Windows Server.
You have an Azure subscription.
You plan to back up the files and folders on Server1 by using the Microsoft Azure Recovery
Services (MARS) agent.
You need to identify to which location the backups can be written and the maximum
number of scheduled backups that can be performed per day.
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point
Your network contains an Active Directory Domain Services (AD DS) domain named
contoso.com. The domain contains the organizational units (OUs) shown in the following
table.

You need to implement IPsec authentication to ensure that only authenticated computer
accounts can connect to the members in the domain. The solution must minimize
administrative effort.
Which GPOs should you apply to the Domain Controllers OU and the Domain Servers OU?
To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
| Page 5 out of 16 Pages |