Administering Windows Server Free Sample Questions

Create a free account to browse all 12 sample questions. The full practice test includes 150 questions. Use the simulator for timed and flashcard mode. Or, view more alternate versions 98-365 364 Questions AZ-800 215 Questions AZ-801 214 Questions.

Try Simulator

AZ-802 Sample Questions

  1. Question 1

    Q1

    A system administrator is deploying a Read-Only Domain Controller (RODC) at a remote branch office for Contoso, Ltd. To ensure branch users can authenticate locally during WAN outages, the administrator configures the Password Replication Policy (PRP). A member of the Helpdesk staff, User1, is added to the Allowed RODC Password Replication Group. However, User1 is also a member of the built-in Denied RODC Password Replication Group. When User1 attempts to authenticate at the branch office during a WAN failure, authentication fails. What is the cause of this behavior?

    Show answer & explanation

    Correct answer: B

    In Active Directory Domain Services, evaluation of the RODC Password Replication Policy (PRP) follows strict precedence where explicit Deny rules supersede Allow rules. The Denied RODC Password Replication Group is specifically designed to protect administrative and sensitive accounts from having their credentials stored in branch offices with limited physical security. Because User1 is a member of the Denied group, their credentials are never cached locally on the RODC, causing authentication to fail when the WAN link is unavailable.

  2. Question 2

    Q2

    An enterprise architect needs to deploy an RODC at a remote manufacturing facility where no local IT staff possess domain administrative credentials. A local plant technician must complete the physical installation and promote the server. The architect pre-stages the RODC account in Active Directory using the Add-ADDSReadOnlyDomainControllerAccount cmdlet and delegates the installation to the plant technician's domain account. What administrative rights does the plant technician have once the RODC promotion is finalized?

    Show answer & explanation

    Correct answer: D

    Staging an RODC via Add-ADDSReadOnlyDomainControllerAccount allows domain administrators to delegate the installation and day-to-day server maintenance to a standard user or group. When the delegated principal attaches the server to the staged account during promotion, they automatically become a member of the local Administrators group on that specific RODC. They do not gain administrative permissions on writable domain controllers or other domain resources.

  3. Question 3

    Q3

    True or False: If an administrator clears the Global Catalog check box during the deployment of a Read-Only Domain Controller (RODC) in a multi-domain forest and Universal Group Membership Caching (UGMC) is not enabled for the branch site, users whose passwords are validly cached on the RODC will fail to sign in if the wide area network (WAN) connection to the central hub site is severed.

    Show answer & explanation

    Correct answer: B

    In a multi-domain forest, authenticating user accounts requires resolving universal group memberships across all domains, which requires contacting a Global Catalog (GC) server. If the RODC is not designated as a Global Catalog and Universal Group Membership Caching (UGMC) is disabled on the branch site, the RODC must forward universal group resolution queries over the WAN to an external GC. If the WAN link fails, universal group memberships cannot be verified, causing user logons to fail even if password hashes are cached locally.

  4. Question 4

    Q4

    Contoso Pharmaceuticals operates three physical datacenters represented by AD DS sites: SiteA (Hub), SiteB (Branch), and SiteC (Branch). Network routing policies forbid direct IP communication between SiteB and SiteC; all intersite traffic must traverse SiteA. An administrator clears the 'Bridge all site links' option in Active Directory Sites and Services to reflect this physical constraint. Site links Link-AB (cost 10) and Link-AC (cost 15) currently exist. What must the administrator configure in AD DS to allow directory changes to replicate transitively between SiteB and SiteC via SiteA, and what is the cumulative replication cost?

    Show answer & explanation

    Correct answer: D

    When 'Bridge all site links' is disabled (standard in non-fully routed networks), site links operate as isolated conduits without implicit transitivity. To establish a transitive replication pathway between SiteB and SiteC across intermediate SiteA, an administrator must create an explicit site link bridge containing Link-AB and Link-AC. The KCC calculates replication routing costs across a site link bridge by summing the individual costs of all included member links (10 + 15 = 25).

    graph LR SiteB[SiteB: Branch] ---|Link-AB Cost: 10| SiteA[SiteA: Hub] SiteA ---|Link-AC Cost: 15| SiteC[SiteC: Branch] subgraph Site Link Bridge: Bridge-BAC Link-AB Link-AC end
  5. Question 5

    Q5

    A hybrid cloud infrastructure consists of an on-premises datacenter hosting two writable domain controllers (DC01 and DC02) and an Azure virtual network hosting a Read-Only Domain Controller (RODC01). An administrator inspects the Knowledge Consistency Checker (KCC) connection objects generated for intersite replication. How does intersite replication operate between the hub site bridgehead servers and the branch RODC?

    Show answer & explanation

    Correct answer: D

    Active Directory intersite replication involving an RODC is strictly unidirectional. Because the RODC database is read-only, writable bridgehead domain controllers never pull directory changes from an RODC. The KCC automatically generates one-way inbound connection objects on the RODC, pulling updates from writable bridgehead servers in the hub site.

  6. Question 6

    Q6

    Background

    Litware, Inc. is a manufacturing company with a central headquarters in Chicago and recently opened regional branch offices in Denver and Austin. The Active Directory forest consists of a single domain named corp.litware.com. The Chicago headquarters houses four Windows Server 2025 domain controllers configured in an AD DS site named HQ-Chicago.

    Current Situation

    The Denver branch office was provisioned with two dedicated Windows Server 2025 domain controllers (DEN-DC01 and DEN-DC02) placed on the local subnet 10.120.0.0/20. A new AD DS site named Branch-Denver was created, and both domain controllers were moved into Branch-Denver. WAN bandwidth between Denver and Chicago is constrained to a 50 Mbps link with high latency.

    Problem Statement

    Users logging into workstations on the 10.120.4.0/24 subnet at the Denver facility report severe delays during interactive logon. Network trace logs reveal that workstation DC Locator queries consistently resolve to domain controllers in HQ-Chicago rather than DEN-DC01 or DEN-DC02. Domain controllers in Denver are healthy, and DNS records for corp.litware.com are registering properly.

    What should the directory services engineer do to ensure Denver workstations authenticate against their local domain controllers?

    Show answer & explanation

    Correct answer: C

    The Active Directory DC Locator mechanism matches the client's IP address against configured subnet objects in Active Directory Sites and Services to determine the client's site. When a workstation's IP (such as 10.120.4.50 within 10.120.0.0/20) does not match any defined subnet object, the client is deemed site-agnostic and may authenticate against any DC in the domain, including remote DCs in HQ-Chicago. Defining the subnet object and associating it with Branch-Denver ensures Denver workstations query and authenticate against local DCs.

    flowchart TD Client[Denver Workstation: 10.120.4.50] -->|DC Locator Query| DNS[DNS Server] DNS -->|Returns DC IP List| Client Client -->|Netlogon Ping to DC| DC_HQ[HQ-Chicago DC] DC_HQ -->|Evaluates Client Subnet| SubnetCheck{Subnet Object in AD?} SubnetCheck -->|No Subnet Defined| Fallback[Returns Random/HQ DC - High Latency] SubnetCheck -->|Mapped to Branch-Denver| LocalDC[Redirects to DEN-DC01/02 - Fast Logon]

Register free to unlock 6 more sample questions

Create a free account to continue with the rest of the AZ-802 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 943 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon