You have an Azure virtual machine named VM1 that runs Windows Server and has the following configuration: size D2s_v4; operating system disk 127-GiB standard SSD; data disk 128-GiB standard SSD; virtual machine generation Gen 2. You plan to perform the following changes to VM1: change the virtual machine size to D4s_v4; detach the data disk; add a new standard SSD. Which changes require downtime for VM1?
Correct Answer: C
Changing a running VM ' s size (SKU) generally requires Azure to move the VM to hardware that supports the target size and reallocate its compute resources, which means the VM must be stopped (deallocated) before the resize is applied and then started again on the new size; this makes a size change from D2s_v4 to D4s_v4 an operation that requires downtime. By contrast, data disks in Azure can be hot-added and hot- removed from a running VM: detaching an existing data disk and attaching a new managed disk are both online operations that Azure supports without stopping the VM, because they only change the VM ' s storage attachment configuration rather than its compute allocation. Because detaching the data disk and adding a new standard SSD can each be completed while VM1 keeps running, neither of those two actions requires downtime, which rules out every answer option that includes them. Only the virtual machine size change forces a stop/start cycle, so ' changing the virtual machine size only ' is the set of changes that requires downtime for VM1. This distinction - compute/SKU changes needing a restart versus storage attach/detach operations being available online - is a key operational planning point when scheduling maintenance windows for production VMs.
AZ-802 Exam Question 107
You have a server named DHCP1 that runs Windows Server and has the DHCP Server role installed. DHCP1 hosts an activated IPv4 scope for a subnet of 192.168.15.0/24. You have a CSV file named PrinterReservations.csv that contains the following columns: ClientId, ScopeId, IPAddress, MacAddress. All the IP addresses in PrinterReservations.csv are within the scope range and are currently available. You need to create DHCP reservations for 20 printers by using PrinterReservations.csv. The solution must minimize administrative effort. Which PowerShell command should you run?
Correct Answer: B
Add-DhcpServerv4Reservation is the DHCP Server PowerShell module cmdlet that creates a single IPv4 client reservation on a specified DHCP server, and it accepts pipeline input, so importing PrinterReservations. csv with Import-Csv and piping the resulting objects directly into Add-DhcpServerv4Reservation lets the cmdlet consume each row ' s ScopeId, IPAddress, and ClientId (MAC address) values to create all 20 reservations in a single pipelined command, which is the minimum-effort approach since it avoids writing any loop or per-row logic. Set-DhcpServerv4Reservation is used only to modify properties of a reservation that already exists, such as its description or client type, not to create new reservations, so piping CSV rows into it would fail outright since none of the reservations exist yet. Add-DhcpServerv4ExclusionRange creates an exclusion range that prevents the DHCP server from ever leasing addresses in that range to any client, which is the opposite of a reservation (which still requires the address to be leasable specifically to one identified client) and would actually break the ability to service these printers via DHCP. The fourth option ' s ForEach- Object with Add-DhcpServerv4Filter is scoped to the MAC address allow/deny filtering feature, an unrelated security control for permitting or blocking specific hardware addresses from obtaining any lease at all, not a mechanism for creating per-client static IP reservations from a CSV of address assignments.
AZ-802 Exam Question 108
You have an Azure subscription. Your on-premises network connects to Azure by using an Azure VPN gateway named VPN1. You need to monitor the Azure gateway health probe for VPN1. Which TCP port should you use?
Correct Answer: D
Azure virtual network gateways expose an internal health probe on TCP port 8081 that Azure infrastructure uses to verify that the gateway instance is healthy; this port is documented as part of gateway troubleshooting and must not be blocked for the gateway to be monitored and managed correctly. Ports such as 443, 1723, and 3389 are associated with HTTPS, PPTP VPN, and RDP respectively, and 65500 falls outside the actual health- probe port used by the gateway manager, so none of those apply to monitoring the VPN gateway ' s own health probe. If a network security group, on-premises firewall, or custom routing rule blocks port 8081 to the gateway subnet, Azure ' s platform health checks fail even though the VPN tunnel itself may still be passing traffic, which is why this specific port must be excluded from any traffic filtering applied to the GatewaySubnet. Microsoft ' s troubleshooting guidance for Site-to-Site VPN connectivity issues explicitly calls out verifying that port 8081 is reachable to the gateway ' s private IP addresses as an early diagnostic step, since a blocked health probe can itself trigger gateway failover behavior unrelated to the underlying tunnel configuration.
AZ-802 Exam Question 109
You need to implement a security policy solution to authorize the applications. The solution must meet the security requirements. Which service should you use to enforce the security policy, and what should you use to manage the policy settings? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation: Enforce the security policy: Microsoft Defender Application Control. Manage the policy settings: Group Policy Objects (GPOs). Windows Defender Application Control (WDAC) is the platform feature that enforces which applications are authorized to install or run on a Windows Server, directly meeting the stated requirement that only authorized applications can be installed or run on the servers in the forest. Microsoft Defender Application Guard isolates untrusted browsing sessions in a container and Microsoft Defender Credential Guard protects credential material from theft -- neither controls which applications are permitted to execute. Microsoft Defender for Endpoint is an endpoint detection-and-response platform that detects and responds to threats rather than enforcing a whitelist of permitted applications. Because the servers described are on-premises, domain-joined machines rather than Intune-managed, Microsoft Entra-joined devices, the WDAC policy settings here must be managed through Group Policy Objects distributed via AD DS, not through Intune. Configuration profiles in Microsoft Intune and compliance policies in Microsoft Intune are both cloud-management mechanisms that apply only to devices enrolled in and managed by Intune, which these on-premises, domain-joined servers are not. Therefore, WDAC is the enforcing service and Group Policy Objects are the correct management mechanism for these on-premises servers.
AZ-802 Exam Question 110
You have 20 on-premises servers, including a server named Server1, that run Windows Server. Server1 has Windows Admin Center deployed and is connected to the internet. You have an Azure subscription. You need to integrate Windows Admin Center with Azure so that you can use Azure services to manage and monitor the on-premises servers. What should you do first?
Correct Answer: C
To manage and monitor on-premises servers with Azure services from Windows Admin Center, the servers themselves need to be represented as Azure resources, which is accomplished by Azure Arc-enabling them, a process Windows Admin Center streamlines directly from its server connection list once the gateway itself is registered against an Azure subscription. Registering an appliance is the step that actually creates that Azure Arc registration for each managed server, projecting it into Azure Resource Manager so Azure-native services such as Azure Monitor, Update Manager, and Microsoft Defender for Cloud can subsequently be applied to it from the Windows Admin Center console. Installing Microsoft Entra Connect Sync addresses identity synchronization between an on-premises AD DS domain and a Microsoft Entra tenant, not server management integration, and has no bearing on connecting Windows Admin Center to Azure services. Creating a private endpoint secures network access to a specific Azure PaaS resource and deploying an Azure Network Adapter extends an on-premises network segment into Azure, neither of which is a prerequisite for the Azure Arc registration that Windows Admin Center ' s Azure integration is actually built on. Registering the servers as Azure Arc-enabled appliances is therefore the necessary first step.