You are planning the europe.fabrikam.com migration to support the on-premises migration plan-Where should you install the Password Export Server (PES) service, where should you generate the encryption key? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You need to implement a security policy solution to authorize the applications. The solution must meet the security requirements.
Which service should you use to enforce the security policy, and what should you use to manage the policy settings? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You are planning the deployment of Microsoft Sentinel.
Which type of Microsoft Sentinel data connector should you use to meet the security requirements?
You are planning the migration of APP3 and APP4 to support the Azure migration plan.
What should you do on Cluster1 and in Azure before you perform the migration? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You are planning the www.fabrikam.com website migration to support the Azure migration plan.
How should you configure WebApp1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You are remediating the firewall security risks to meet the security requirements.
What should you configure to reduce the risks?
You are planning the DHCP1 migration to support the DHCP migration plan.
Which two PowerShell cmdlets should you run on DHCP1, and which two PowerShell cmdlets should you run on DHCP2? To answer, drag the appropriate cmdlets to the correct servers. Each cmdlet may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

You have an Azure subscription that contains the virtual machines shown in the following table.

You plan to use Azure Site Recovery to replicate supported virtual machines to a secondary Azure region. Which virtual machines can be replicated by using Azure Site Recovery?
You have an Azure virtual machine named VM1 that runs Windows Server.
You plan to deploy a new line-of-business (LOB) application to VM1.
You need to ensure that the application can create child processes.
What should you configure on VM1?
You have an Azure virtual machine named VM1 that runs Windows Server.
The operating system on VM1 fails to start due to a disk error.
You need to resolve the error.
Which four commands should you run in sequence in Azure Cloud Shell? To answer, move the appropriate commands from the list of commands to the answer area and arrange them in the correct order.

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a print server named Server1. All printers are deployed to users by using a Group Policy Object (GPO) named GPO1.
You deploy a new server named Server2.
You need to decommission Server1. The solution must meet the following requirements:
Migrate the shared printers to Server2 by using the Printer Migration Wizard.
Ensure that the users use the printers on Server2.
Minimize downtime for the users.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.
You add a user named Admin1 to the domain.
You need to ensure that Admin1 can create a Data Collector Set on Server1. The solution must follow the principle of least privilege.
To which security group should you add Admin1, and what should Admin1 use to create the Data Collector Set? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a management group named MG1 that contains an Azure subscription named Sub1. Sub1 contains the resources shown in the following table.

You need to enable Microsoft Defender for Servers.
From the Azure portal, on which two resources can you enable Defender for Servers? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains 100 servers that run Windows Server and are Azure Arc-enabled.
You have an Azure subscription.
You need to automatically change the password for the built-in local administrator account on each computer in the domain. The solution must meet the following requirements:
• The password must change automatically every 30 days.
• Administrative effort must be minimized.
What should you use?
Q A. an Azure policy
O B. a Password Settings Object (PSO)
(8) C. Windows Local Administrator Password Solution (Windows LAPS)
group managed service accounts (gMSAs)
You have a Windows Server Failover Cluster (WSFQ that has the following configurations:
• Name: App1
• Owner node: Node3
• Type: Generic Application
The General settings for App1 are shown in the General exhibit. (Click the General tab.)

The Failover settings for App1 are shown in the Failover exhibit. (Click the Failover tab.)

The Advanced Policies settings for App1 are shown in the Advanced Policies exhibit. (Click the Advanced Policies tab.)

For each of the following statements, select Yes if the statement is true Otherwise, select No.
NOTE: Each correct selection is worth one point.

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a server named Server1 that runs Windows Server.
You need to ensure that only specific applications can modify the data in protected folders on Server1.
Solution: From Virus & threat protection, you configure Controlled folder access.
Does this meet the goal?
You have a server named Server1 that runs the Remote Desktop Session Host role service. Server1 has five custom applications installed.
Users who sign in to Server1 report that the server is slow. Task Manager shows that the average CPU usage on Server1 is above 90 percent. You suspect that a custom application on Server1 is consuming excessive processor capacity.
You plan to create a Data Collector Set in Performance Monitor to gather performance statistics from Server1.
You need to view the resources used by each of the five applications.
Which object should you add to the Data Collector Set?
You have an Azure Active Directory Domain Services (Azure AD DS) domain named aadds.contoso.com.
You have an Azure virtual network named Vnet1. Vnet1 contains two virtual machines named VM1 and VM2 that run Windows Server. VMI and VM2 are joined to aadds.contoso.com.
You create a new Azure virtual network named Vnet2. You add a new server named VM3 to Vnet2.
When you attempt to join VM3 to aadds.contoso.com, you get an error message that the domain cannot be found.
You need to ensure that you can join VM3 toaadds.contoso.com.

Your network contains an on-premises Active Directory Domain Services (AD DS) domain.
The domain contains the servers shown in the following table.

Server1 has the connection security rule as shown in the Server1 exhibit. (Click the Server1 tab.)

Server2 has the connection security rule as shown in the Server2 exhibit. (Click the Server2 tab.)

Server1 has the inbound firewall rules as shown in the Server1 inbound rules exhibit. (Click the Server1 inbound rules tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

You need to create a Hyper-V hyper-converged cluster that stores virtual machines by using Storage Spaces Owed
Which three actions should you perform in sequence? To answer, move the appropriate anions from the list of actions to the answer area and arrange them in the correct order.

You have two servers named Host1 and Host2 that run Windows Server and have the Hyper-V server role installed. Host2 is configured as a replica server.
Host1 contains a virtual machine named VM1.
You plan to use Hyper-V Replica to replicate VM1 to Host2.
You need to ensure that you can restore a replica of VM1 to a specific state from the past eight hours.
What should you do?
You have an on premises Hyper-V host named Server 1. Server! contains a virtual machine named VM1. You have a non-domain joined Hyper-V server named Server2 that is hosted in a remote location. You plan to replicate VM1 to Server2 by using Hyper-V Replica. You need to configure replication on Server1. Which authentication method can you use?
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a server named Server1 that runs Windows Server.
You need to ensure that only specific applications can modify the data in protected folders on Server1.
Solution: From Virus & threat protection, you configure Tamper Protection .
Does this meet the goal?
You have 20 on-premises servers, including a server named Server1, that run Windows Server. Server1 has Windows Admin Center deployed and is connected to the internet.
You have an Azure subscription.
You need to integrate Windows Admin Center with Azure so that you can use Azure services to manage and monitor the on-premises servers.
What should you do first?
Q A. Install Microsoft Entra Connect Sync on Server1.
Q B. From Server1. run the Connect-AzAceount cmdlet.
(•) C. Enable Azure Arc on each managed server.
Q D. From Server1, run the Set-AzWebApp cmdlet.
You need to configure BitLocker on Server4.
On which volumes can you turn on BitLocker, and on which volumes can you turn on auto-unlock? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

What is the effective minimum password length for User1 and Admin1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You need to meet the technical requirements for Cluster3.
What should you include in the solution?
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Which domain controller should be online to meet the technical requirements for DC4?
You are evaluating the technical requirements tor Cluster2.
What is the minimum number of Azure Site Recovery Providers that you should install?
You need to meet the technical requirements for Cluster2.
Which four actions should you perform in sequence before you can enable replication? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You need to implement alerts for the domain controllers. The solution must meet the technical requirements.
What should you do on the domain controllers, and what should you create on Azure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You need to back up Server 4 to meet the technical requirements.
What should you do first?
With which servers can Server1 and Server3 communicate? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You need to meet the technical requirements for User1.
To which group in contoso.com should you add User1?