Free Practice Questions for the Microsoft Certified: Windows Server Hybrid Administrator Associate AZ-802 Exam (2026 Updated)
At Marks4sure, we are dedicated to providing IT professionals with the most accurate and reliable preparation materials for the Microsoft AZ-802 exam. To support your certification journey, we have made a selection of our premium 2026 Microsoft Certified: Windows Server Hybrid Administrator Associate practice questions and answers available completely free. You can take this practice test as many times as you need. Every question includes a detailed, expertly verified explanation to ensure you fully grasp the core security concepts before test day.
You need to meet the technical requirements for User1. The solution must use the principle of least privilege. What should you do?
You need to meet the technical requirements for VM3. On which volume can you enable Data Deduplication?
Which groups can you add to Group3, and which groups can you add to Group5? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to meet the technical requirements for Server4. Which cmdlet should you run on Server1, and which cmdlet should you run on Server4? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to meet the technical requirements for Server1. Which users can currently perform the required task?
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

You need to implement a security policy solution to authorize the applications. The solution must meet the security requirements. Which service should you use to enforce the security policy, and what should you use to manage the policy settings? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You are remediating the firewall security risks to meet the security requirements. What should you configure to reduce the risks?
You are planning the migration of Archive1 to support the on-premises migration plan. What is the minimum number of IP addresses required for the node and cluster roles on Cluster3?
You are planning the migration of APP3 and APP4 to support the Azure migration plan. What should you do on Cluster1 and in Azure before you perform the migration? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You are planning the data share migration to support the on-premises migration plan. What should you use to perform the migration?
You are planning the DHCP1 migration to support the DHCP migration plan. Which two PowerShell cmdlets should you run on DHCP1, and which two PowerShell cmdlets should you run on DHCP2? To answer, drag the appropriate cmdlets to the correct servers. Each cmdlet may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

You are planning the www.fabrikam.com website migration to support the Azure migration plan. How should you configure WebApp1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You are planning the implementation of Cluster2 to support the on-premises migration plan. You need to ensure that the disks on Cluster2 meet the security requirements. In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.

You are planning the deployment of Microsoft Sentinel. Which type of Microsoft Sentinel data connector should you use to meet the security requirements?
Which three actions should you perform in sequence to meet the security requirements for Webapp1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You are planning the implementation of Azure Arc to support the planned changes. You need to configure the environment to support configuration management policies. What should you do?
You need to implement an availability solution for DHCP that meets the requirements. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
You need to configure the Group Policy settings to ensure that the Azure Virtual Desktop session hosts meet the security requirements. What should you configure?
You need to implement a name resolution solution that meets the requirements for DC3. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
You need to configure Azure File Sync to meet the file sharing requirements. What is the minimum number of sync groups you should create, and what is the minimum number of Storage Sync Services you should create? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to configure BitLocker on Server4.
On which volumes can you turn on BitLocker, and on which volumes can you turn on auto-unlock? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to identify the minimum number of Azure Site Recovery Provider installations required to protect Cluster2. What is the minimum number of installations required?
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for User1. To which group in contoso.com should you add User1?
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to promote DC4 to meet the technical requirements. Which domain controller should be online to meet the technical requirements for DC4?
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for Cluster3. What should you include in the solution?
With which servers can Server1 and Server3 communicate? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
You need to implement alerts for the domain controllers. The solution must meet the technical requirements.
What should you do on the domain controllers, and what should you create on Azure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You need to meet the technical requirements for Cluster2.
Which four actions should you perform in sequence before you can enable replication? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to meet the technical requirements for Share1. What should you use?
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

What is the effective minimum password length for User1 and Admin1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Technical requirements: Promote a new server named DC4 that runs Windows Server 2022 to a domain controller. Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault. Centrally manage performance alerts in Azure for all the domain controllers. Ensure that User1 can recover objects from the Active Directory Recycle Bin. Migrate Share1 to Server2, including all the share and folder permissions. Back up Server4 and all data to an Azure Recovery Services vault. Use Hyper-V Replica to protect the virtual machines in Cluster3. Implement BitLocker Drive Encryption (BitLocker) on Server4. Whenever possible, use the principle of least privilege. You need to back up Server4 to meet the technical requirements. What should you do first?
You have an Azure subscription that contains the Azure key vaults shown in the following table. You create a virtual machine that has the following configurations: Name: VM1; Resource group: RG1; Azure region: East US; Operating system: Windows Server. You need to enable Azure Disk Encryption for VM1. Which key vault can you use to store the encryption key for VM1? (Exhibit: key vaults table.)

Key vaults and their regions/resource groups
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a failover cluster named Cluster1 that hosts an application named App1. The General tab in App1 Properties is shown in the General exhibit: Preferred Owners lists Server1 and Server2, both unchecked, with the Up/Down reordering controls disabled; Priority is Medium; the role is Running on Server2. The Failover tab in App1 Properties is shown in the Failover exhibit: Maximum failures in the specified period is 3, Period (hours) is 6, and Failback is currently set to " Allow failback " / " Immediately. " Server1 shuts down unexpectedly. You need to ensure that when you start Server1, App1 continues to run on Server2. Solution: From the Failover settings, you select Prevent failback. Does this meet the goal?

App1 Properties - General tab

App1 Properties - Failover tab
You have a Site-to-Site VPN between an on-premises network and an Azure VPN gateway. BGP is disabled for the Site-to-Site VPN. You have an Azure virtual network named Vnet1 that contains a subnet named Subnet1. Subnet1 contains a virtual machine named Server1. You can connect to Server1 from the on-premises network. You extend the address space of Vnet1. You add a subnet named Subnet2 to Vnet1. Subnet2 uses the extended address space. You deploy an Azure virtual machine named Server2 to Subnet2. You cannot connect to Server2 from the on-premises network. Server1 can connect to Server2. You need to ensure that you can connect to Subnet2 from the on-premises network. What should you do?
You have the on-premises servers shown in the following table.
You are evaluating OSConfig and security baselines.
Which cmdlet should you use to deploy OSConfig. and which servers support OSConfig? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit

You have an on-premises server named Server1 that runs Windows Server. Server1 has the Web Server (IIS) server role installed and hosts an ASP.NET web app named App1. You have an Azure subscription. You plan to migrate App1 to a container in Azure. You need to export App1 to a ZIP file. What should you install on Server1?
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains servers that run Windows Server and store BitLocker recovery keys in AD DS. A server named Server1 starts in BitLocker recovery mode. You need to identify the BitLocker recovery key for Server1. Solution: You run ntdsutil.exe on a domain controller. Does this meet the goal?
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.
You add a user named Admin1 to the domain.
You need to ensure that Admin1 can create a Data Collector Set on Server1. The solution must follow the principle of least privilege.
To which security group should you add Admin1, and what should Admin1 use to create the Data Collector Set? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com and the servers shown in the following table. DC1: contoso.com, Domain controller Server1: contoso.com, Member server DC2: east.contoso.com, Domain controller Server2: east.contoso.com, Member server Contoso.com contains a user named User1. You add User1 to the built-in Backup Operators group in contoso.com. Which servers can User1 back up?

Server/domain table
You have two on-premises servers named Server1 and Server2 that run Windows Server. Server2 contains a Hyper-V virtual machine named VM1. You have an Azure subscription that contains a Recovery Services vault. You need to configure Azure Site Recovery to replicate workloads from the on-premises environment to Azure. What should you do first?
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an on-premises server named Server1 that runs Windows Server. You have a Microsoft Sentinel instance. You add the Windows Firewall data connector in Microsoft Sentinel. You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1. Solution: You install the Microsoft Integration Runtime on Server1. Does this meet the goal?
You have an Azure subscription that contains a virtual machine named VM1 and a Recovery Services vault named Vault1. VM1 runs Windows Server. You need to back up VM1 to Vault1 by using Azure Backup. The solution must minimize administrative effort. What should you do first?
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a root domain named contoso.com and a child domain named branch.contoso.com. The forest contains the domain controllers shown in the following table: DC1 (contoso.com; a global catalog server that holds the schema master, domain naming master, PDC emulator, RID master, and infrastructure master roles); DC2 (contoso.com; NOT a global catalog server and does NOT hold any FSMO roles); DC3 (branch.contoso.com; a global catalog server that holds the PDC emulator and RID master roles); DC4 (branch.contoso.com; NOT a global catalog server and holds the infrastructure master role). You discover that cross-domain object references in contoso.com fail to update for objects in branch.contoso.com. You need to modify the FSMO role placement. The solution must minimize administrative changes. What should you do?
You have an on-premises server named Server1 and Microsoft Sentinel instance.
You plan to collect windows Defender Firewall events from Sever1 and analyze the event data by using Microsoft Sentinel.
What should you install on Server1, and which information should you provide during the instance? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have two servers named Server1 and Server2 that run Windows Server and have the Hyper-V role installed. You plan to deploy Hyper-V Replica between Server1 and Server2. The deployment will use certificate-based authentication. You need to configure the prerequisites for the Hyper-V Replica deployment. Which two actions should you perform on each server? Each correct answer presents part of the solution.
You need to implement the planned change for Microsoft Entra users to sign in to Server1. Which PowerShell cmdlet should you run?
You need to implement the planned change for Data1. Which actions should you perform in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. NOTE: Each correct selection is worth one point.

You need to ensure that data availability on SSPace1 meets the technical requirements. What is the maximum number of physical disks that can fail on each disk without losing data? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to ensure that VM3 meets the technical requirement. What should you install first?
Which two languages can you use for Task1? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
DC1 fails.
You need to meet the technical requirements for the schema master.
Yourunntdsutil.exe.
Which five commands should you run in sequence? To answer, move the appropriate commands from the list of commands to the answer area and arrange them in the correct order?

You need to meet the technical requirement for HyperV1. Which command should you run? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to ensure that Automanage meets the technical requirements. On which Azure virtual machines should you enable Automanage?
You need to ensure that access to storage1 for the Marketing OU users meets the technical requirements. What should you implement?
You need to implement the planned change for the Azure DNS Private Resolver. Which private DNS zones can you use for name resolution?




















