About the Exam

This exam measures the ability to secure Windows Server on-premises and hybrid infrastructures, implement and manage high availability, implement disaster recovery, migrate servers and workloads, and monitor and troubleshoot Windows Server environments. It is intended for experienced Windows Server Hybrid Administrators who work with on-premises and hybrid environments. Passing demonstrates you can administer Windows Server as a workload across on-premises and Azure hybrid scenarios using tools such as Windows Admin Center, PowerShell, Azure Arc, Azure Policy, Azure Monitor, Azure Update Manager, Microsoft Defender for Identity, and Microsoft Defender for Cloud.

Exam Topics

  • Secure Windows Server on-premises and hybrid infrastructures25–30%
  • Implement and manage Windows Server high availability10–15%
  • Implement Disaster Recovery10–15%
  • Migrate servers and workloads20–25%
  • Monitor and troubleshoot Windows Server environments20–25%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 15, 2026 at 8:29 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Monitor and troubleshoot Windows Server environments

You have the servers shown in the following table.

Question Image

You need to make sure that you can verify network connectivity from Server1 to Server2 by using the ping command.

What should you do first?

Explanation

ICMP Echo Request traffic from ping arrives at Server2 as inbound traffic. Server2 must allow that inbound ICMPv4 traffic; enabling the built-in File and Printer Sharing (Echo Request – ICMPv4-In) firewall rule permits it. Windows Defender Firewall allows outbound traffic by default unless a blocking rule applies, so an outbound echo rule on Server1 is not the required first action.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Secure Windows Server on-premises and hybrid infrastructures

You have an Azure subscription containing the Azure key vaults shown in the following table.

Question Image

You create a virtual machine with the following configuration:

  • Name: VM1
  • Resource group: RG1
  • Azure region: East US
  • Operating system: Windows Server

You need to enable Azure Disk Encryption for VM1.

Which key vault can you use to store VM1's encryption key?

Explanation

Azure Disk Encryption requires the key vault and the virtual machine to be in the same Azure region and subscription. Vault1 and Vault3 are both in East US; the key vault can be in a different resource group from the virtual machine.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Migrate servers and workloads

You have an on-premises server named Server1 that runs Windows Server. Server1 has the Web Server (IIS) server role installed and hosts an ASP.NET web application named App1.

You have an Azure subscription.

You plan to migrate App1 to an Azure container.

You need to export App1 to a ZIP file.

What should you install on Server1?

Explanation

Web Deploy packages an IIS web application for deployment and supports exporting the application as a ZIP package. Microsoft’s IIS guidance lists the Web Deployment Tool as a prerequisite for exporting an application package and shows saving the package as a .zip file.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Secure Windows Server on-premises and hybrid infrastructures

Existing Environment

The network contains an Active Directory Domain Services (AD DS) domain named contoso.com.

Domain controllers

NameOperating systemOperation master role
DC1Windows Server 2012 R2RID master, schema master
DC2Windows Server 2016PDC emulator, infrastructure master
DC3Windows Server 2016Domain naming master

Users and groups

NameOrganizational unit (OU)/ContainerMember of
User1OU1Group2, Group4
User2UsersGroup2
User3OU1Group3, Group4
Admin1OU1Domain Admins

Password policies

NameMinimum password lengthLinked to
Default Domain Policy8contoso.com
GPO110OU1

The domain contains the following fine-grained password policies (PSOs):

NamePrecedenceMinimum password lengthDirectly applies to
PSO1109Group2
PSO22011Group4

Member servers

NameDescription
Server1Contains a share named Share1
Server2None
Server3None
Server4Has Remote Desktop enabled

Connection security rules

NameEndpoint1Endpoint2Authentication mode
Server1AnyAnyRequest inbound and outbound
Server2AnyAnyRequire inbound and request outbound
Server3AnyAnyRequire inbound and outbound
DC1AnyAnyRequest inbound and outbound
DC2AnyAnyRequest inbound and outbound
DC3AnyAnyRequest inbound and outbound

Effective user rights on the servers

PolicySecurity setting
Access this computer from the networkGroup1, Administrators, Backup Operators, Everyone, Users
Deny access to this computer from the networkGroup4
Allow log on through Remote Desktop ServicesGroup2, Administrators, Remote Desktop Users
Deny log on through Remote Desktop ServicesGroup3

Server4 disks

DiskVolumeSizeFile systemNotes
Disk 0System Reserved100 MBNTFSSystem, Active
Disk 0C:126.39 GBNTFSBoot, page file, crash dump (operating system volume)
Disk 0Recovery523 MB—Recovery partition
Disk 1D: (Data)127.00 GBNTFSPrimary partition
Disk 2E: (Data)127.00 GBReFSPrimary partition
Disk 3F: (Data)127.00 GBReFSPrimary partition

Failover clusters

NameNumber of nodesNumber of virtual machines
Cluster1618
Cluster2412
Cluster326

You need to configure BitLocker on Server4.

Choose the volumes on which you can enable BitLocker and those on which you can enable auto-unlock.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Monitor and troubleshoot Windows Server environments

Your network has an Active Directory domain containing a domain controller named DC1 and a Windows Server computer named Server1.

You need to enable event log subscriptions that forward events from DC1 to Server1.

Which command should you use to enable the Windows Event Collector service, and on which server or servers should you run it?

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home