Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an on-premises server named Server1 that runs Windows Server. You have a Microsoft Sentinel instance. You add the Windows Firewall data connector in Microsoft Sentinel. You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1. Solution: You install the Azure Connected Machine agent on Server1. Does this meet the goal?
Correct Answer: A
For any non-Azure machine, whether on-premises or hosted in another cloud, to be used as a source for an Azure Monitor Agent-based Microsoft Sentinel data connector such as the Windows Firewall connector, the machine must first be onboarded to Azure Arc as a connected machine. Installing the Azure Connected Machine agent on Server1 is precisely the action that performs this onboarding: it registers Server1 as an Azure Arc-enabled server, giving it an Azure resource identity that can then have extensions such as the Azure Monitor Agent deployed to it and associated with a data collection rule. This Azure Arc onboarding is the documented prerequisite step described in Microsoft ' s guidance for connecting Windows-based, non- Azure servers to Sentinel ' s AMA-based data connectors, and once Server1 is Arc-enabled, the Azure Monitor Agent extension and a data collection rule targeting the Windows Firewall log source can be deployed to it to complete the log collection pipeline. Because installing the Azure Connected Machine agent is exactly the required first step for enabling this scenario, this solution meets the goal.
AZ-802 Exam Question 167
You have a server named Server1 that runs Windows Server. On Server1, you create a Data Collector Set named CollectorSet1 based on the Basic template. You need to configure CollectorSet1 to meet the following requirements: * Older performance counter logs must be overwritten by new ones. * Performance counter logging must stop if there is less than 500 MB of free disk space. What should you configure for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Correct Answer:
Explanation: Older logs overwritten: The Performance Counter properties. Stop below 500 MB free: The Data Manager properties. The individual Performance Counter data collector inside a Data Collector Set has its own Properties dialog with a File tab that includes an Overwrite option, and enabling that option causes each new logging run to overwrite the previous log file in place rather than creating a new, separately numbered file each time -- this is exactly the control needed to make older performance counter logs get replaced by newer ones. Disk-space- based retention, on the other hand, is governed at the level of the Data Collector Set as a whole through its Data Manager properties, which expose a Minimum Free Disk Space setting, alongside Maximum Folders and Maximum Root Path Size settings, that Windows evaluates against the log directory ' s volume to manage or halt further data collection once free space drops below the configured threshold. Because these two behaviors live on two entirely different property pages -- one scoped to the individual counter ' s file settings and the other scoped to the Data Collector Set ' s overall data management -- the Configuration properties option, which governs sample interval and duration settings, does not control either of these two requirements.
AZ-802 Exam Question 168
You need to meet the technical requirements for Cluster2. Which four actions should you perform in sequence before you can enable replication? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Correct Answer:
Explanation: 1. Create an Azure Recovery Services vault. 2. Create a Hyper-V site. 3. Install and register Azure Site Recovery Providers. 4. Create and associate replication policies. Setting up Azure Site Recovery for a Hyper-V cluster that is not managed by Virtual Machine Manager follows a fixed infrastructure-preparation order. An Azure Recovery Services vault must exist first, since it is the container that every later step registers against. A Hyper-V site is then created in that vault to represent the on-premises Hyper-V environment, because a Hyper-V host or cluster must belong to a site before its hosts can be registered against Azure Site Recovery. The Azure Site Recovery Provider is then installed on the Hyper-V hosts (Cluster2 ' s nodes) and registered to that site/vault, which is what actually connects the cluster nodes to Azure Site Recovery. Only once the hosts are registered can a replication policy be created and associated with the Hyper-V site, since a policy has nothing to attach to until the site and its registered hosts already exist. Installing Azure Connected Machine agents is unrelated to Hyper-V VM replication -- that agent is used for onboarding servers to Azure Arc -- and is not part of this workflow. Therefore, the correct order is: create the vault, create the Hyper-V site, install and register the Providers, and create and associate the replication policy.
AZ-802 Exam Question 169
You have two servers named Host1 and Host2 that run Windows Server and have the Hyper-V server role installed. Host2 is configured as a replica server. Host1 contains a virtual machine named VM1. You plan to use Hyper-V Replica to replicate VM1 to Host2. You need to ensure that you can restore a replica of VM1 to a specific state from the past eight hours. What should you do?
Correct Answer: A
Hyper-V Replica ' s Additional Recovery Points setting, which is configured on the Configure Recovery History page of the Enable Replication wizard when replication for VM1 is first set up, lets an administrator specify that a series of hourly recovery points, for up to a maximum of 24 hours of history, be retained on the replica server alongside the single latest, most up-to-date replica of the virtual machine. Because the requirement in this scenario is to be able to restore VM1 to a specific state from as far back as eight hours ago, the Enable Replication wizard ' s recovery points configuration must be used and set to retain at least eight hours of Additional Recovery Points, since without this setting enabled with a sufficiently long retention window, only the latest replica state would be available and no historical point-in-time restore within that eight-hour window would be possible. Enabling automatic checkpoints on VM1 ' s own properties is unrelated to Hyper-V Replica ' s separate point-in-time replica history mechanism and would not create restorable recovery points on the replica server at all, NUMA spanning is a memory-configuration setting on the Hyper-V host with no bearing whatsoever on replication or recovery points, and modifying the replication frequency only changes how often changed data is sent from Host1 to Host2, not how many historical recovery points are retained once it arrives, so configuring recovery points from the Enable Replication wizard is the only option that actually addresses this requirement.
AZ-802 Exam Question 170
You have a server named Server1 that runs Windows Server and contains two drives named C and D. Server1 hosts multiple file shares. You enable Data Deduplication on drive D and select the General purpose file server workload. You need to minimize the space consumed by files that were recently modified or deleted. What should you do?
Correct Answer: B
Data Deduplication relies on a set of scheduled jobs to keep a volume ' s chunk store efficient. The optimization job is the one that scans eligible files and replaces duplicate data with references into the chunk store, and it is what produces the initial space savings, but it does not reclaim space that becomes unused because files were later modified or deleted; over time, chunks that are no longer referenced by any current file simply accumulate in the chunk store, still consuming disk space, unless something specifically reclaims them. The garbage collection job is the dedup job dedicated to that reclamation: it identifies chunks in the chunk store that no longer have any live references (because the files that used them were deleted or overwritten with different content) and removes them, directly reducing the space consumed by data that used to belong to recently modified or deleted files. Garbage collection is configured, like the other deduplication jobs, through Set-DedupSchedule, which lets you define or adjust the job ' s schedule and priority. The scrubbing job instead checks the integrity of the chunk store and repairs corruption using redundant copies, and InputOutputScale/IO settings tune deduplication job performance rather than controlling what gets reclaimed; neither addresses the stated goal. Configuring a garbage collection job with Set-DedupSchedule is therefore the correct action.