What should you implement for the deployment of DC3?
Correct Answer: C
DC3 is explicitly described as a domain controller named dc3.corp.fabrikam.com that will exist inside Vnet1, meaning it must be a genuine, writable domain controller for Fabrikam ' s existing corp.fabrikam.com AD DS forest, replicating with DC1 and DC2. The only way to run an actual domain controller for an existing on- premises forest inside Azure is to deploy a regular Azure virtual machine, place it on Vnet1, install the AD DS role on it, and promote it as an additional domain controller for corp.fabrikam.com. Microsoft Entra Domain Services is a fundamentally different, fully managed service: it creates its own separate, standalone managed domain and does not add a domain controller to, or replicate directly with, an existing on-premises forest, so it cannot be used to deploy " DC3 " as described. Microsoft Entra Application Proxy publishes on- premises web applications to external users and has nothing to do with domain controller placement. A Microsoft Entra administrative unit is a container used to scope administrative permissions over Microsoft Entra objects and is unrelated to deploying infrastructure. Therefore, an Azure virtual machine, promoted to a domain controller, is the correct implementation for DC3.
AZ-802 Exam Question 72
You have two Azure virtual networks named Vnet1 and Vnet2. You have a Windows 10 device named Client1 that connects to Vnet1 by using a Point-to-Site (P2S) IKEv2 VPN. You implement virtual network peering between Vnet1 and Vnet2. Vnet1 allows gateway transit; Vnet2 uses the remote gateway. You discover that Client1 cannot communicate with Vnet2. You need to ensure that Client1 can communicate with Vnet2. Solution: You download and reinstall the VPN client configuration. Does this meet the goal?
Correct Answer: A
When a network topology change occurs after a Point-to-Site VPN client is already connected -- such as enabling gateway transit through virtual network peering after Client1 ' s original connection was established -- the Windows VPN client configuration package must be downloaded again from the virtual network gateway and reinstalled on the client for it to learn the new routes to the newly reachable peered network. Downloading and reinstalling the VPN client configuration on Client1 refreshes the routing information embedded in that package so that it now includes routes into Vnet2, which is exactly the documented remediation Microsoft describes for this scenario. Because the peering and gateway transit settings on Vnet1 and Vnet2 were already configured correctly before this solution was applied, refreshing Client1 ' s configuration package is sufficient on its own to restore connectivity, without needing any additional changes to BGP, gateway SKU, or network security group rules. This solution therefore meets the goal of ensuring Client1 can communicate with Vnet2.
AZ-802 Exam Question 73
You need to use a comma-separated value (CSV) file to import server inventory to Azure Migrate. Which fields are mandatory for each entry in the CSV file?
Correct Answer: A
Azure Migrate ' s CSV import path for building a business case or an assessment requires exactly four mandatory columns for every server entry: Server name, Cores, Memory in MB, and OS name, and the OS name value must match one of the specific supported OS name strings that Azure Migrate recognizes, or the import validation fails for that row. Every other column available in the official import template -- including IP addresses, disk sizes, disk counts, and CPU or OS version details -- is optional and only improves the accuracy of the resulting sizing and cost assessment rather than being required for the row to import successfully. Servers added through this CSV import path can only be used for assessment purposes; they cannot later be migrated directly from this inventory method, since migration requires discovery through an actual appliance instead. Because only server name, cores, OS name, and memory are enforced as mandatory by Azure Migrate ' s own import validation, that combination is the correct answer, while the other two options each include at least one optional field alongside fields that are not the actual mandatory set.
AZ-802 Exam Question 74
You have an Azure virtual machine named VM1. You install an application on VM1, and then restart the virtual machine. After the restart, you get the following error message: " Boot failure. Reboot and Select proper Boot Device or Insert Boot Media in selected Boot Device. " You need to mount the operating system disk offline from VM1 to a temporary virtual machine to troubleshoot the issue. Which command should you run in Azure CLI?
Correct Answer: A
The az vm repair create command creates a brand-new, temporary repair virtual machine and automatically attaches a copy of the problem VM ' s operating system disk to that repair VM as a data disk, which is precisely the documented technique for mounting an unbootable virtual machine ' s OS disk offline onto another machine so that boot configuration data, drivers, or registry settings can be inspected and corrected without needing the original VM to actually boot. The az vm boot-diagnostics enable command only turns on console output and screenshot capture for boot diagnostics; it does nothing to mount a disk elsewhere and would not help troubleshoot a disk that already fails to boot at all. The az vm capture command generalizes a virtual machine into a reusable image, which is a destructive operation on the source VM and is unrelated to offline disk troubleshooting. The az vm disk attach command requires the disk to already be detached from its original VM and does not, by itself, create a repair VM or copy the disk for the administrator, making the repair-create command the complete, purpose-built solution here.
AZ-802 Exam Question 75
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains servers that run Windows Server and store BitLocker recovery keys in AD DS. A server named Server1 starts in BitLocker recovery mode. You need to identify the BitLocker recovery key for Server1. Solution: You run ntdsutil.exe on a domain controller. Does this meet the goal?
Correct Answer: B
ntdsutil.exe is a command-line management utility for the AD DS database itself, used for tasks such as performing authoritative restores, seizing or transferring FSMO roles, database integrity checks and defragmentation, managing application directory partitions, and Directory Services Restore Mode password resets; it has no built-in command, menu, or capability for browsing individual object attributes such as the ms-FVE-RecoveryPassword value stored on a msFVE-RecoveryInformation child object, and it provides no interface at all for reading or exporting BitLocker recovery data. Retrieving a BitLocker recovery password stored in AD DS requires either the BitLocker Recovery Password Viewer snap-in for Active Directory Users and Computers, which adds a dedicated tab to a computer object ' s properties specifically to display associated recovery passwords, or direct inspection of the msFVE-RecoveryInformation child objects through a general-purpose LDAP tool such as ADSI Edit or an equivalent PowerShell query against the directory; ntdsutil operates at the database/role-management level and simply has no code path that surfaces this attribute value to an administrator. Because running ntdsutil.exe on a domain controller does not read, display, or export any BitLocker recovery password, and no combination of its available commands can be used to obtain one, this solution does not meet the stated goal of identifying Server1 ' s recovery key.