AZ-802 Practice Test
Microsoft Certified: Windows Server Hybrid Administrator Associate
AZ-802 is the current path to the Windows Server Administrator Associate certification β deep, scenario-heavy questions on AD DS, hybrid Azure Arc management, storage, and security.
Our 500 questions are calibrated to match the complexity of the real AZ-802 exam. Scenario-based questions on RODC deployment, Storage Spaces Direct, Azure Arc onboarding, DHCP failover, and Windows Server hardening β so exam day feels familiar. AZ-802 replaces AZ-800 and AZ-801, which retire September 30, 2026, making it the single exam that matters now for this credential.
Start Free Practice β 40 QuestionsNo credit card required. Upgrade to full 500 questions for $19.99 when ready.
Is this for you?
This is NOT for you if:
AZ-802 Exam Details
What to expect on exam day
Questions
40
Duration
120 minutes
Passing Score
700
Exam Cost
$165
Exam Domains Covered
Master all topics tested on the AZ-802 exam
Deploy and manage AD DS (20-25%)
Manage Windows Server instances and workloads in a hybrid environment (10-15%)
Manage virtual machines (10-15%)
Implement and manage an on-premises and hybrid networking infrastructure (10-15%)
Manage storage and file services (15-20%)
Secure Windows Server infrastructure (10-15%)
Monitor and troubleshoot Windows Server environments (15-20%)
Test Yourself Right Now
Try 5 real practice questions β no signup needed
5 Free AZ-802 Questions
See how ready you are for the AZ-802 exam. Each question includes a detailed explanation so you learn as you go.
Sample AZ-802 Practice Questions
10 real questions from the free AZ-802bank. Pick an answer in your head, then open βShow answerβ for the explanation.
1. Which cmdlet adds a security group to the Allowed list of an RODC's password replication policy so that its members' passwords can be cached on that RODC?
- A. Set-ADAccountPassword
- B. Add-ADDomainControllerPasswordReplicationPolicy
- C. New-ADReplicationSite
- D. Grant-ADAuthenticationPolicySiloAccess
Show answer
Correct answer: B
Add-ADDomainControllerPasswordReplicationPolicy adds users, computers, or groups to either the allowed or denied list of a specified RODC's password replication policy. Set-ADAccountPassword changes a single account's password, New-ADReplicationSite creates a site object, and Grant-ADAuthenticationPolicySiloAccess is unrelated to RODC password caching.
2. You need to promote a new writable domain controller at a branch office connected to the hub site by a low-bandwidth, metered WAN link. The hub site already has several domain controllers. You want to avoid replicating the entire directory database across the WAN link during promotion, and you cannot physically ship removable media to the branch office. What should you do?
- A. Run Install-ADDSDomainController directly against the hub-site domain as the replication source, and rely on intersite compression to shrink the initial replication traffic.
- B. Use Ntdsutil to create an Install From Media (IFM) snapshot on a hub-site domain controller, copy the IFM folder to the branch server over the network during off-peak hours, then run Install-ADDSDomainController with -InstallationMediaPath.
- C. Pre-stage an RODC account for the branch site with Add-ADDSReadOnlyDomainControllerAccount, then attach the branch server to that staged account using -UseExistingAccount.
- D. Export the hub domain controller's virtual hard disk over the network and import it as a new virtual machine acting as a domain controller at the branch office.
Show answer
Correct answer: B
Install From Media (IFM) lets a new domain controller build its database from a local media set instead of pulling the full directory over the WAN, and the media can be moved over the network rather than on physical disks. Option A still requires replicating the full naming context over the WAN despite compression. Option C changes the outcome to a read-only DC, which was not requested. Option D copies a virtualized DC's VHD, which is explicitly unsupported and risks USN rollback.
3. Within a single AD DS site containing eight writable domain controllers, administrators notice that replication changes reach every domain controller even if one intermediate domain controller in the chain temporarily goes offline. What replication topology characteristic explains this resilience?
- A. Intrasite replication uses a linear chain topology with a single point of failure at each end.
- B. Intrasite replication relies exclusively on SMTP as a fallback transport whenever RPC fails.
- C. Intrasite replication uses the same spanning-tree topology as intersite replication, which has no redundant paths.
- D. Intrasite replication connections between writable domain controllers form a bidirectional ring, with additional shortcut connections added in larger sites to reduce latency and provide redundancy.
Show answer
Correct answer: D
Within a site, the KCC arranges writable domain controllers into a bidirectional ring and adds shortcut connections in larger sites, so changes can still reach every domain controller through the other direction of the ring even if one intermediate domain controller is temporarily unavailable. A linear chain would create single points of failure, SMTP is not used as an automatic RPC fallback for intrasite replication, and the spanning-tree layering with no redundant paths describes intersite replication, not intrasite replication.
4. What is the primary security benefit of deploying a Read-Only Domain Controller (RODC) at a branch office with limited physical security?
- A. The RODC holds a read-only copy of the AD DS database and, by default, caches no user credentials, limiting exposure if the server is stolen.
- B. The RODC automatically encrypts the entire NTDS.dit file using BitLocker as part of promotion.
- C. The RODC cannot be joined to the domain, removing it from the security boundary.
- D. The RODC provides the same write access to AD DS as a writable domain controller, with extra audit logging.
Show answer
Correct answer: A
By default no account passwords replicate to a newly promoted RODC, and security-sensitive accounts are explicitly denied from ever caching their passwords there, so theft of the server exposes little usable credential data. BitLocker is not enabled automatically as part of RODC promotion, an RODC is still a full domain member, and it accepts no writes at all rather than matching a writable DC.
5. A consultant with only Domain Admins rights in a child domain (not the forest root domain) attempts to create a new forest trust from the forest root domain to a partner forest and the operation fails with an access-denied error. What is the most likely reason?
- A. Creating a forest trust requires membership in Domain Admins in the forest root domain, or in Enterprise Admins - membership in a child domain's Domain Admins group is not sufficient.
- B. Forest trusts can be created exclusively by members of Schema Admins.
- C. The consultant must first be added to the Denied RODC Password Replication Group.
- D. Forest trusts require the target forest to lower its forest functional level to Windows 2000.
Show answer
Correct answer: A
Creating a forest trust requires membership in Domain Admins in the forest root domain, or in Enterprise Admins; being a Domain Admin in a child domain does not carry that authority. Schema Admins and the Denied RODC Password Replication Group have no role in trust creation, and forest trusts require a reasonably current functional level rather than a legacy Windows 2000 level.
Show 5 more questions
6. In a forest that contains only a single Active Directory domain, which domain controller should hold the infrastructure master role?
- A. A domain controller that is not a global catalog server, matching the general multi-domain placement guideline
- B. The domain controller that also holds the schema master role, since Microsoft ties infrastructure master placement to schema master placement
- C. The domain controller located in the forest root site, per site-topology best practice
- D. Any domain controller in the domain - placement of the infrastructure master doesn't matter because there are no phantom objects to update
Show answer
Correct answer: D
In a single-domain forest there are no cross-domain phantom references, so the infrastructure master has no work to do and can run on any domain controller, including a global catalog server. The multi-domain non-GC placement rule, a tie to the schema master, and a tie to the forest root site are all placement myths that don't apply to this scenario.
7. When you deploy a domain controller on an Azure virtual machine, which disk type should you use for the operating system disk?
- A. A persistent managed disk
- B. An ephemeral OS disk
- C. A temporary disk (D: drive)
- D. A Premium SSD v2 data disk configured for the NTDS database
Show answer
Correct answer: A
A persistent managed disk lets the domain controller recover automatically from host maintenance events without requiring re-promotion. Ephemeral OS disks are explicitly not recommended for domain controllers, the temporary disk is not persistent across redeployments, and the NTDS database belongs on a separate persistent data disk rather than the OS disk.
8. During a security review of a branch office RODC, you discover that an administrator previously removed the Domain Admins group from the Denied RODC Password Replication Group so that a break-glass domain admin account could authenticate locally during WAN outages. What is the most significant risk this change introduces?
- A. The RODC will stop replicating the AD DS schema partition from writable domain controllers.
- B. The RODC's own krbtgt account will be shared with other RODCs across the domain.
- C. If the RODC is physically compromised, an attacker could potentially obtain a cached credential for a highly privileged domain-wide account.
- D. The Allowed RODC Password Replication Group will be automatically emptied to compensate.
Show answer
Correct answer: C
The Denied RODC Password Replication Group ships with high-privilege accounts and groups such as Domain Admins so their passwords can never be cached on a branch office RODC; removing that protection exposes a domain-wide credential to theft if the RODC hardware is compromised. Schema replication is unaffected by password replication policy, each RODC is issued its own unique krbtgt account rather than sharing one, and there is no automatic mechanism that empties the Allowed list in response.
9. Which Active Directory object type associates a range of IP addresses with a specific AD DS site so that domain controller and client location can be determined by network location?
- A. Site link
- B. Subnet
- C. Connection object
- D. Bridgehead server
Show answer
Correct answer: B
A subnet object associates a range of IP addresses with a site, allowing AD DS to place domain controllers and route client requests based on network location. A site link represents the logical path used for replication between sites, a connection object represents a specific inbound replication link, and a bridgehead server is a domain controller role selected to relay intersite replication, none of which map IP ranges to sites.
10. Which built-in process running on every domain controller automatically builds and adjusts the AD DS replication topology, both within a site and between sites?
- A. Net Logon
- B. Local Security Authority (LSA)
- C. Knowledge Consistency Checker (KCC)
- D. Windows Time service
Show answer
Correct answer: C
The Knowledge Consistency Checker runs on every domain controller and automatically generates and dynamically adjusts the intrasite and intersite replication topology as domain controllers, sites, costs, and schedules change. Net Logon maintains the secure channel used for authentication and trust processing, the LSA validates security tokens and audits access, and the Windows Time service handles time synchronization, none of which build replication topology.
AZ-802 study resources
Why Practice with MSCertQuiz?
Microsoft Learn teaches concepts. We prepare you for the actual exam.
Scenario-based questions on RODC deployment, FSMO role troubleshooting, and multi-forest trust configuration β not just definitions
Deep coverage of hybrid management: Azure Arc onboarding, Windows Admin Center, Azure Update Manager, and Azure Automation runbooks
Calibrated slightly harder than the real exam β so AZ-802 exam day feels easier than practice
Updated for the current AZ-802 exam objectives β the single, current path to the Windows Server Administrator Associate credential now that AZ-800/AZ-801 are retiring
Not sure if you're ready for the AZ-802 exam?
Take the free AZ-802 Readiness Check βWhat Our Users Say
90% pass rate β Based on users who completed at least 2 practice exams
βThe RODC and FSMO role questions were exactly the kind of scenario depth the real exam tests. Passed AZ-802 with 780 β glad I didn't wait for AZ-800/AZ-801 to retire.β
Jordan H.
AZ-802 Certified
βSolid coverage of the Azure Arc and hybrid management domain, which was the weakest part of my on-prem-only background. That section alone was worth it.β
Priya C.
Passed AZ-802 first try
βStorage Spaces Direct and DFS questions matched the real exam's difficulty closely. Explanations actually taught me why, not just which letter was correct.β
Marcus W.
AZ-802 Certified
Choose Your Plan
Start free, upgrade when you're ready to get serious
Free
Good for exploring the platform
- 40 practice questions
- Practice mode only
- Progress tracking
- No exam simulation mode
AZ-802 Full Access
Best if your exam is in the next 2-4 weeks
- 500 practice questions
- Practice & Exam modes
- Detailed explanations
- Lifetime access
7-day money-back guarantee
Pro β All Certs
Best if you're planning multiple Microsoft exams
- ALL certifications included
- Unlimited questions
- New certs added free
- Cancel anytime
Save 30% vs buying individually
Your AZ-802Exam Won't Wait
Candidates who complete at least 2 full mock exams pass at significantly higher rates than those who only study passively.
Don't risk $165 on the real exam without testing yourself first.
Start Free Practice NowNo credit card required β’ 40 free questions β’ Upgrade for $19.99 when ready
Official Microsoft Resources
Our practice questions are aligned with official Microsoft exam objectives. We recommend studying with Microsoft Learn first, then using MSCertQuiz to test your readiness.
View Official AZ-802 Exam DetailsAZ-802 Frequently Asked Questions
Everything you need to know about the AZ-802 Windows Server certification
What is AZ-802?
How is AZ-802 different from AZ-800 and AZ-801?
How much does the AZ-802 exam cost?
How long is the AZ-802 exam and what is the passing score?
What topics are covered in AZ-802?
Is AZ-802 in beta?
What are the prerequisites for AZ-802?
Is AZ-802 worth it for my career?
How long should I study for AZ-802?
Also Preparing For
Candidates studying AZ-802 often prepare for these certifications next.