AZ-802 sample questions with answers

10 free practice questions for the Exam AZ-802: Administering Windows Server exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Deploy and manage AD DS

Best For You Organics must move a service that runs as an ordinary domain user account to a delegated Managed Service Account. All the hosts and domain controllers involved run Windows Server 2025. Which sequence should you use?

  1. A.

    Create a group managed service account first and convert it to a dMSA with Set-ADServiceAccount.

  2. B.

    Install the dMSA on the host with Install-ADServiceAccount and change the service logon, because no migration is required.

  3. C.

    Create the dMSA, run Start-ADServiceAccountMigration naming the user account as the superseded account, let the service refresh its tickets, then run Complete-ADServiceAccountMigration.

  4. D.

    Create the dMSA, run Complete-ADServiceAccountMigration immediately, and then delete the original user account.

Show answer

Answer: C

A dMSA migration is a two-stage operation: Start-ADServiceAccountMigration links the superseded user account to the dMSA, and Complete-ADServiceAccountMigration finishes the change once tickets have refreshed.

  • A. Migration from a gMSA or a standalone managed service account to a dMSA is explicitly not supported.
  • B. Without migration the dMSA does not inherit the original account's access and the original password stays enabled.
  • C. It follows the documented start, learn, complete sequence that transfers access and then disables the original account.
  • D. Completing at once skips the stage in which the dMSA learns the machine identities, and hosts can then fail to authenticate.
Question 2Deploy and manage AD DS

Wide World Importers has one domain with six domain controllers. Five of them host the global catalog, and WWI-DC6 cannot host it because of a storage limit. Cross-domain group members show stale names after objects are renamed elsewhere in the forest, and the AD Recycle Bin is not enabled. What should you do?

  1. A.

    Transfer the infrastructure master role to the domain controller that also holds the PDC emulator role.

  2. B.

    Move the infrastructure master role to WWI-DC6, the only domain controller that does not host the global catalog.

  3. C.

    Create a second infrastructure master for the domain so that two servers share the work of updating references.

  4. D.

    Seize the infrastructure master role on a global catalog server and then run repadmin /syncall across the domain.

Show answer

Answer: B

An infrastructure master that runs on a global catalog server stops updating cross-domain references, so the role belongs on the one domain controller that is not a global catalog server.

  • A. That server hosts the global catalog, so moving the role there keeps the symptom and adds load to the busiest role holder.
  • B. The role only performs its work on a domain controller that is not a global catalog server, which is WWI-DC6.
  • C. Operations master roles are single-master by definition; a domain has exactly one infrastructure master.
  • D. Seizure is reserved for a holder that will not return, and a global catalog destination reproduces the same problem.
Question 3Deploy and manage AD DS

The Phone Company acquired a business whose forest root is tpcnorth.local. A two-way forest trust exists. Users in the acquired forest sign in with the UPN suffix tpc-north.com, and they report that applications in the main forest reject that suffix while their default suffix works. You must make the alternative suffix usable across the trust. Which two actions should you perform? (Choose TWO.)

Choose 2.

  1. A.

    Create a conditional forwarder for tpc-north.com on the DNS servers of the main forest.

  2. B.

    Add tpc-north.com as an alternative UPN suffix on the Active Directory Domains and Trusts object of the acquired forest.

  3. C.

    In the properties of the forest trust, enable name suffix routing for the *.tpc-north.com suffix.

  4. D.

    Convert the forest trust to an external trust between the two forest root domains.

  5. E.

    Disable SID filtering on the trust by running netdom trust with the /enablesidhistory:yes option.

Show answer

Answer: B, C

The suffix must exist in the acquired forest and be routed over the forest trust, so you add the alternative UPN suffix and enable name suffix routing for it.

  • A. A conditional forwarder resolves DNS names; Kerberos referrals for a UPN suffix are driven by the trust's routed name list.
  • B. The alternative UPN suffix must exist in the acquired forest before it can be advertised and routed across the trust.
  • C. A suffix that is not part of the partner's DNS namespace is listed as disabled on the trust and must be enabled for routing.
  • D. External trusts are non-transitive and do not support name suffix routing, so converting the trust removes the capability entirely.
  • E. SID filtering controls whether SID history is honoured across the trust and has no bearing on UPN suffix routing.
Question 4Deploy and manage AD DS

A read-only domain controller is stolen overnight from a depot at City Power & Light. Its Password Replication Policy allowed 40 user accounts and 25 computer accounts to cache credentials, and the revealed list on the RODC computer account confirms that most of them were cached. What should you do?

  1. A.

    Move the 65 accounts into the Denied RODC Password Replication Group and leave the RODC computer account in place for auditing.

  2. B.

    Run Uninstall-ADDSDomainController with -ForceRemoval against the missing server from a hub domain controller in the same site.

  3. C.

    Reset the krbtgt account password of the domain twice and then restart the Netlogon service on every remaining domain controller.

  4. D.

    Delete the RODC computer account and reset the passwords of every user and computer account whose password was cached on it.

Show answer

Answer: D

The documented response to a stolen RODC is to remove its account from the directory and reset the passwords of all users and computers whose credentials it had cached.

  • A. The Denied list only affects future caching; the secrets already on the stolen disk remain valid.
  • B. -ForceRemoval is a local demotion switch that must run on the server itself, which is no longer available.
  • C. A double krbtgt reset addresses a forest-level compromise and leaves the cached user and computer passwords untouched.
  • D. It removes the compromised server from the directory and performs the documented reset of every cached credential.
Question 5Deploy and manage AD DS

Separate forests, linked by a two-way forest trust, belong to Munson's Pickles and Preserves Farm and School of Fine Art. Auditors from the school must reach exactly two file servers in the farm forest and nothing else. Farm administrators must be able to add more servers later without changing the trust. What should you configure?

  1. A.

    Enable SID filtering quarantine on the trust and add the auditors to a domain local group on each file server.

  2. B.

    Set the incoming trust to selective authentication and grant the auditors the Allowed to Authenticate permission on the two server computer objects.

  3. C.

    Replace the forest trust with two external trusts and enable name suffix routing for the auditors' UPN suffix.

  4. D.

    Set the incoming trust to forest-wide authentication and deny the auditors the Access this computer from the network right on all other servers.

Show answer

Answer: B

Selective authentication blocks all cross-forest access by default, and the Allowed to Authenticate permission opens it per computer object.

  • A. SID filtering mitigates SID history injection across trusts; it does not restrict which computers a trusted principal may authenticate to.
  • B. Selective authentication denies by default, and the Allowed to Authenticate right on each computer object grants access server by server.
  • C. External trusts are non-transitive domain-to-domain trusts and do not support name suffix routing, which is a forest trust feature.
  • D. It is a deny-list approach that must be maintained on every current and future server, the opposite of the stated requirement.
Question 6Deploy and manage AD DS

City Power & Light is deploying a read-only domain controller in the Limerick office. A branch technician who is not a member of Domain Admins must finish the promotion on site, and the domain controller options must be decided in advance by the identity team in the datacentre. What should you do?

  1. A.

    Grant the technician the Allowed to Authenticate permission on the branch server's computer object and promote the server for them remotely.

  2. B.

    Have the technician join the server to the domain and then add its computer account to the Allowed RODC Password Replication Group.

  3. C.

    Stage the RODC account with Add-ADDSReadOnlyDomainControllerAccount and -DelegatedAdministratorAccountName, then have the technician attach the server with Install-ADDSDomainController -UseExistingAccount.

  4. D.

    Add the technician's account to the Enterprise Read-only Domain Controllers group and ask them to run Install-ADDSDomainController -ReadOnlyReplica.

Show answer

Answer: C

A staged RODC deployment separates the two phases: a domain administrator creates the RODC account and names a delegated administrator, and that delegated user attaches the server to the existing account.

  • A. Allowed to Authenticate is a selective authentication permission on a computer object and grants no promotion capability.
  • B. The Allowed RODC Password Replication Group governs credential caching, not who may promote a domain controller.
  • C. It is the documented two-phase staged deployment, and the delegated administrator named at staging can complete the attach.
  • D. Enterprise Read-only Domain Controllers is populated automatically when RODCs are created and confers no right to promote a server.
Question 7Deploy and manage AD DS

Install-ADServiceAccount fails with an access denied error on a new web server that must run a service as a group managed service account named gmsa-web. A KDS root key already exists. Which two actions should you perform? (Choose TWO.)

Choose 2.

  1. A.

    Add the web server's computer account to the security group that is listed in the PrincipalsAllowedToRetrieveManagedPassword property of gmsa-web.

  2. B.

    Set ManagedPasswordIntervalInDays on gmsa-web to 30 so that the password can be retrieved.

  3. C.

    Restart the web server so that its Kerberos ticket reflects its new group membership.

  4. D.

    Add gmsa-web to the local Administrators group on the web server.

  5. E.

    Run Add-KdsRootKey -EffectiveImmediately on the web server before installing the account.

Show answer

Answer: A, C

Only the principals named in PrincipalsAllowedToRetrieveManagedPassword can fetch a gMSA password, and when membership is granted through a group the host must restart before its ticket carries that membership.

  • A. Retrieval is authorised by PrincipalsAllowedToRetrieveManagedPassword, so the host must be in that list, directly or through a group.
  • B. The password interval is fixed at creation and has no bearing on who may retrieve the password.
  • C. A computer's group membership is reflected in its Kerberos ticket only after a restart, so the retrieval keeps failing until then.
  • D. Local administrator rights are unrelated to fetching the managed password and grant unnecessary privilege.
  • E. A KDS root key already exists, and the cmdlet is run on a domain controller; re-creating a key causes its own problems.
Question 8Deploy and manage AD DS

Blue Yonder Airlines will promote two Azure virtual machines as additional domain controllers for its existing on-premises domain, which is reached across a site-to-site VPN. Replication to and from the Azure machines must be scheduled independently of the datacentre. What should you do before the promotion?

  1. A.

    Enable the Database 32k pages optional feature so the new domain controllers build a 32k page database.

  2. B.

    Promote both virtual machines into a new forest and then create a two-way forest trust to the on-premises forest.

  3. C.

    Deploy Microsoft Entra Domain Services in the subscription and join the two virtual machines to the managed domain.

  4. D.

    Create a site for the Azure region, add a subnet object for the Azure address space to it, and connect it with a site link.

Show answer

Answer: D

Azure is another location in the same forest, so it needs its own site, a subnet object for its address space, and a site link whose schedule and interval govern replication across the VPN.

  • A. The page size feature is unrelated to site placement and requires every domain controller in the forest to be 32k capable first.
  • B. A separate forest with a trust does not extend the existing domain and changes the identity design entirely.
  • C. Microsoft Entra Domain Services is a separate Microsoft-managed domain; you cannot promote your own domain controllers into it.
  • D. A site, a subnet object for the Azure address space and a site link give correct placement, client affinity and a scheduled replication path.
Question 9Deploy and manage AD DS

Contoso has an external trust to a partner domain named partner.local. Access tokens that cross the trust must carry only security identifiers that belong to partner.local itself. Which command should you run in the Contoso domain?

  1. A.

    netdom trust contoso.com /domain:partner.local /transitive:no

  2. B.

    netdom trust contoso.com /domain:partner.local /selectiveauth:yes

  3. C.

    netdom trust contoso.com /domain:partner.local /enablesidhistory:yes

  4. D.

    netdom trust contoso.com /domain:partner.local /quarantine:yes

Show answer

Answer: D

The quarantine attribute, better known as SID filtering, makes the trusting domain accept only SIDs from the directly trusted domain and discard every other SID presented across the trust.

  • A. /transitive applies only to non-Windows Kerberos realm trusts and has no effect on an external trust.
  • B. Selective authentication limits which computers can be reached; it does not filter the SIDs inside a token.
  • C. That option allows SID history across the trust, which widens rather than narrows the SIDs that are honoured.
  • D. /quarantine:yes accepts only SIDs from the directly trusted domain, which is exactly the stated requirement.
Question 10Deploy and manage AD DS

Bellows College is placing two domain controllers on Azure virtual machines so that an application hosted in Azure can authenticate locally. The college requires that no directory write can be lost if the virtual machine host fails unexpectedly. You must decide where the Active Directory database, log files and SYSVOL are stored. What should you do?

  1. A.

    Place the database, logs and SYSVOL on the temporary disk that Azure provides for each virtual machine size.

  2. B.

    Attach a managed data disk with host caching set to None and place the database, logs and SYSVOL on that disk.

  3. C.

    Keep the database, logs and SYSVOL on the operating system disk, which uses Read/write host caching.

  4. D.

    Attach a managed data disk with host caching set to ReadOnly and place the database, logs and SYSVOL on that disk.

Show answer

Answer: B

Domain controllers in Azure must keep NTDS.dit, the logs and SYSVOL on a data disk whose host caching is None, so that writes are acknowledged only after they reach durable storage.

  • A. The temporary disk is ephemeral and its contents are destroyed when the virtual machine is deallocated or moved to another host.
  • B. A data disk with caching set to None is write-through, which preserves the write ordering the AD DS database requires.
  • C. The operating system disk uses Read/write caching, which can acknowledge writes that have not reached durable storage and risks database corruption.
  • D. ReadOnly caching still serves reads from a cache that AD DS cannot control and is not the supported setting for directory data.

Keep going with 502 more AZ-802 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

AZ-802 sample questions with answers (10 free) · CertifyCloudx