You plan to deploy the Azure Monitor agent to 100 on-premises servers that run Windows Server. Which parameters should you provide when you install the agent?
Correct Answer: A
The Azure Monitor Agent cannot be deployed to a non-Azure, on-premises Windows Server until that server has first been onboarded as an Azure Arc-enabled server; the agent is then installed and managed as an Azure Arc VM extension, with its actual data destinations configured afterward through separate Data Collection Rules. For onboarding a large fleet such as 100 on-premises servers at once, Microsoft ' s documented at-scale method is to run the Connected Machine agent installation script non-interactively, authenticating using an Azure service principal ' s client (application) ID and client secret, which avoids requiring 100 separate interactive sign-ins to complete the onboarding. A Log Analytics workspace ID and key were the credentials used by the legacy, now-retired Log Analytics agent, but the current Azure Monitor Agent does not accept a workspace ID or key at install time at all; a storage account name and access key, and a connection string for an Azure SQL database, play no role whatsoever in either Arc onboarding or Azure Monitor Agent installation. Therefore, the client ID and secret of an Azure service principal are the parameters that should be provided.
AZ-802 Exam Question 92
You have an Azure subscription. The subscription contains two virtual machines named VM1 and VM2 that run Windows Server. You need to use Azure Network Watcher to meet the following requirements; * Identify security rules that prevent network traffic from reaching VM1. * Identify the source region of packets sent to VM2. What should you use for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation: Identify security rules that prevent network traffic from reaching VM1: IP flow verify. Identify the source region of packets sent to VM2: Traffic Analytics. IP flow verify, a diagnostic capability within Azure Network Watcher, tests a specific traffic flow described by its source, destination, port, and protocol against the effective network security group rules applied to a virtual machine ' s network interface, and it reports back exactly which security rule allows or denies that packet. This makes it the correct tool for pinpointing why network traffic is being prevented from reaching VM1, since it identifies the specific rule responsible for the block rather than just confirming that a block exists. Traffic Analytics, a Network Watcher capability built on top of NSG flow logs, aggregates and visualizes network traffic patterns over time, including geographic and topology information about where traffic is coming from, which makes it the appropriate tool for identifying the source region of packets sent to VM2. Neither capability can substitute for the other: IP flow verify does not report traffic geography, and Traffic Analytics does not perform a rule-by-rule evaluation of a specific flow, so each requirement maps to exactly one of these two Network Watcher tools.
AZ-802 Exam Question 93
You have two on-premises servers named Server1 and Server2 that run Windows Server. Server2 contains a Hyper-V virtual machine named VM1. You have an Azure subscription that contains a Recovery Services vault. You need to configure Azure Site Recovery to replicate workloads from the on-premises environment to Azure. What should you do first?
Correct Answer: D
For Hyper-V-to-Azure replication that is not managed through System Center Virtual Machine Manager, the Azure Site Recovery Provider and the accompanying Recovery Services agent are host-level components that must be installed and registered on every Hyper-V host that will participate in replication, not on the individual guest virtual machines those hosts happen to run. Since VM1 runs on Server2, the first action in this on-premises-to-Azure Site Recovery scenario is to run the AzureSiteRecoveryProvider.exe setup on Server2 itself and complete the registration wizard against the Recovery Services vault already created in Azure, supplying the vault ' s registration key downloaded from the portal. Once that registration succeeds, Server2 ' s Hyper-V site becomes visible as a protectable source within the vault in Azure, and individual virtual machines hosted on it, such as VM1, can then have replication enabled directly from the portal ' s Site Recovery blade. Running the provider setup on VM1 itself would be meaningless, since the provider is a host- level component that talks to the Hyper-V management layer rather than something installed inside a guest OS, and running the unrelated AzureBackupAgentInstaller.exe, on either VM1 or Server2, would only configure the separate MARS backup agent rather than registering the host for Site Recovery replication.
AZ-802 Exam Question 94
You need to implement the planned change for Microsoft Entra users to sign in to Server1. Which PowerShell cmdlet should you run?
Correct Answer: C
Enabling Microsoft Entra ID sign-in on an Azure VM running Windows is implemented through a VM extension named AADLoginForWindows, published by Microsoft.Azure.ActiveDirectory. This extension installs the components needed for the VM to accept Microsoft Entra credentials for RDP sign-in and, when combined with Azure RBAC roles such as Virtual Machine Administrator Login, controls who is authorized to sign in. VM extensions in Azure are deployed and managed with the Set-AzVMExtension cmdlet, which is how this specific extension gets installed onto Server1. Set-AzVM modifies general virtual machine properties, such as size or OS profile settings, but has no mechanism for installing extensions. Add- ADComputerServiceAccount and New-ADComputer are on-premises Active Directory cmdlets used to manage computer objects and service accounts in AD DS; they have no relevance to an Azure VM ' s sign-in method and would not apply here since Server1 ' s sign-in requirement is being satisfied by Microsoft Entra ID, not by joining a domain. Set-AzVMExtension is therefore the correct cmdlet.
AZ-802 Exam Question 95
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a server named Server1 that runs Windows Server 2022 and has the DHCP Server role. Server1 contains a single DHCP scope named Scope1. You deploy five printers to the network. You need to ensure that the printers are always assigned the same IP address. Solution: You create a DHCP address exclusion for each printer. Does this meet the requirement?
Correct Answer: B
A DHCP exclusion range removes one or more specific addresses from the pool that the DHCP server is allowed to hand out to any client at all -- an excluded address is simply never offered in a lease to anyone. Excluding the five addresses intended for the printers does not bind those specific addresses to the printers ' MAC addresses, and it does not cause the DHCP server to actually assign those addresses to the printers as DHCP clients; in fact, since the addresses are excluded from the leasable pool, a printer configured to obtain an address via DHCP would never receive one of the excluded addresses through DHCP at all -- it would simply be issued some other, non-excluded address from the scope, exactly like any other client, with no guarantee of consistency between renewals. Exclusions are useful for reserving addresses for devices that are configured statically outside of DHCP entirely (so DHCP never hands those same addresses to a different, unrelated client), not for ensuring a DHCP client consistently receives one specific address. Because an exclusion provides no MAC-to-IP binding and does not achieve consistent assignment to the printers via DHCP, creating a DHCP address exclusion for each printer does not meet the requirement.