Updated for July 2026 Exam Objectives

AZ-802 Practice Test

Microsoft Certified: Windows Server Hybrid Administrator Associate

AZ-802 is the current path to the Windows Server Administrator Associate certification β€” deep, scenario-heavy questions on AD DS, hybrid Azure Arc management, storage, and security.

Our 500 questions are calibrated to match the complexity of the real AZ-802 exam. Scenario-based questions on RODC deployment, Storage Spaces Direct, Azure Arc onboarding, DHCP failover, and Windows Server hardening β€” so exam day feels familiar. AZ-802 replaces AZ-800 and AZ-801, which retire September 30, 2026, making it the single exam that matters now for this credential.

Start Free Practice β€” 40 Questions

No credit card required. Upgrade to full 500 questions for $19.99 when ready.

500 Exam-Style Questions
90% Pass Rate
7-Day Money-Back Guarantee

Is this for you?

Your AZ-802 exam is in the next 2-4 weeks
You've studied the concepts but aren't sure you'll pass
You want questions harder than the real exam
You want to understand why answers are correct, not just memorize

This is NOT for you if:

You're looking for braindumps or exam leaks
You haven't started studying the concepts yet
Most successful candidates start practice 2-3 weeks before their exam
Updated for the July 2026 exam blueprint

AZ-802 Exam Details

What to expect on exam day

Questions

40

Duration

120 minutes

Passing Score

700

Exam Cost

$165

Exam Domains Covered

Master all topics tested on the AZ-802 exam

1

Deploy and manage AD DS (20-25%)

2

Manage Windows Server instances and workloads in a hybrid environment (10-15%)

3

Manage virtual machines (10-15%)

4

Implement and manage an on-premises and hybrid networking infrastructure (10-15%)

5

Manage storage and file services (15-20%)

6

Secure Windows Server infrastructure (10-15%)

7

Monitor and troubleshoot Windows Server environments (15-20%)

Test Yourself Right Now

Try 5 real practice questions β€” no signup needed

🎯

5 Free AZ-802 Questions

See how ready you are for the AZ-802 exam. Each question includes a detailed explanation so you learn as you go.

No account requiredTakes 2-3 minutesInstant results

Sample AZ-802 Practice Questions

10 real questions from the free AZ-802bank. Pick an answer in your head, then open β€œShow answer” for the explanation.

  1. 1. Which cmdlet adds a security group to the Allowed list of an RODC's password replication policy so that its members' passwords can be cached on that RODC?

    • A. Set-ADAccountPassword
    • B. Add-ADDomainControllerPasswordReplicationPolicy
    • C. New-ADReplicationSite
    • D. Grant-ADAuthenticationPolicySiloAccess
    Show answer

    Correct answer: B

    Add-ADDomainControllerPasswordReplicationPolicy adds users, computers, or groups to either the allowed or denied list of a specified RODC's password replication policy. Set-ADAccountPassword changes a single account's password, New-ADReplicationSite creates a site object, and Grant-ADAuthenticationPolicySiloAccess is unrelated to RODC password caching.

  2. 2. You need to promote a new writable domain controller at a branch office connected to the hub site by a low-bandwidth, metered WAN link. The hub site already has several domain controllers. You want to avoid replicating the entire directory database across the WAN link during promotion, and you cannot physically ship removable media to the branch office. What should you do?

    • A. Run Install-ADDSDomainController directly against the hub-site domain as the replication source, and rely on intersite compression to shrink the initial replication traffic.
    • B. Use Ntdsutil to create an Install From Media (IFM) snapshot on a hub-site domain controller, copy the IFM folder to the branch server over the network during off-peak hours, then run Install-ADDSDomainController with -InstallationMediaPath.
    • C. Pre-stage an RODC account for the branch site with Add-ADDSReadOnlyDomainControllerAccount, then attach the branch server to that staged account using -UseExistingAccount.
    • D. Export the hub domain controller's virtual hard disk over the network and import it as a new virtual machine acting as a domain controller at the branch office.
    Show answer

    Correct answer: B

    Install From Media (IFM) lets a new domain controller build its database from a local media set instead of pulling the full directory over the WAN, and the media can be moved over the network rather than on physical disks. Option A still requires replicating the full naming context over the WAN despite compression. Option C changes the outcome to a read-only DC, which was not requested. Option D copies a virtualized DC's VHD, which is explicitly unsupported and risks USN rollback.

  3. 3. Within a single AD DS site containing eight writable domain controllers, administrators notice that replication changes reach every domain controller even if one intermediate domain controller in the chain temporarily goes offline. What replication topology characteristic explains this resilience?

    • A. Intrasite replication uses a linear chain topology with a single point of failure at each end.
    • B. Intrasite replication relies exclusively on SMTP as a fallback transport whenever RPC fails.
    • C. Intrasite replication uses the same spanning-tree topology as intersite replication, which has no redundant paths.
    • D. Intrasite replication connections between writable domain controllers form a bidirectional ring, with additional shortcut connections added in larger sites to reduce latency and provide redundancy.
    Show answer

    Correct answer: D

    Within a site, the KCC arranges writable domain controllers into a bidirectional ring and adds shortcut connections in larger sites, so changes can still reach every domain controller through the other direction of the ring even if one intermediate domain controller is temporarily unavailable. A linear chain would create single points of failure, SMTP is not used as an automatic RPC fallback for intrasite replication, and the spanning-tree layering with no redundant paths describes intersite replication, not intrasite replication.

  4. 4. What is the primary security benefit of deploying a Read-Only Domain Controller (RODC) at a branch office with limited physical security?

    • A. The RODC holds a read-only copy of the AD DS database and, by default, caches no user credentials, limiting exposure if the server is stolen.
    • B. The RODC automatically encrypts the entire NTDS.dit file using BitLocker as part of promotion.
    • C. The RODC cannot be joined to the domain, removing it from the security boundary.
    • D. The RODC provides the same write access to AD DS as a writable domain controller, with extra audit logging.
    Show answer

    Correct answer: A

    By default no account passwords replicate to a newly promoted RODC, and security-sensitive accounts are explicitly denied from ever caching their passwords there, so theft of the server exposes little usable credential data. BitLocker is not enabled automatically as part of RODC promotion, an RODC is still a full domain member, and it accepts no writes at all rather than matching a writable DC.

  5. 5. A consultant with only Domain Admins rights in a child domain (not the forest root domain) attempts to create a new forest trust from the forest root domain to a partner forest and the operation fails with an access-denied error. What is the most likely reason?

    • A. Creating a forest trust requires membership in Domain Admins in the forest root domain, or in Enterprise Admins - membership in a child domain's Domain Admins group is not sufficient.
    • B. Forest trusts can be created exclusively by members of Schema Admins.
    • C. The consultant must first be added to the Denied RODC Password Replication Group.
    • D. Forest trusts require the target forest to lower its forest functional level to Windows 2000.
    Show answer

    Correct answer: A

    Creating a forest trust requires membership in Domain Admins in the forest root domain, or in Enterprise Admins; being a Domain Admin in a child domain does not carry that authority. Schema Admins and the Denied RODC Password Replication Group have no role in trust creation, and forest trusts require a reasonably current functional level rather than a legacy Windows 2000 level.

Show 5 more questions
  1. 6. In a forest that contains only a single Active Directory domain, which domain controller should hold the infrastructure master role?

    • A. A domain controller that is not a global catalog server, matching the general multi-domain placement guideline
    • B. The domain controller that also holds the schema master role, since Microsoft ties infrastructure master placement to schema master placement
    • C. The domain controller located in the forest root site, per site-topology best practice
    • D. Any domain controller in the domain - placement of the infrastructure master doesn't matter because there are no phantom objects to update
    Show answer

    Correct answer: D

    In a single-domain forest there are no cross-domain phantom references, so the infrastructure master has no work to do and can run on any domain controller, including a global catalog server. The multi-domain non-GC placement rule, a tie to the schema master, and a tie to the forest root site are all placement myths that don't apply to this scenario.

  2. 7. When you deploy a domain controller on an Azure virtual machine, which disk type should you use for the operating system disk?

    • A. A persistent managed disk
    • B. An ephemeral OS disk
    • C. A temporary disk (D: drive)
    • D. A Premium SSD v2 data disk configured for the NTDS database
    Show answer

    Correct answer: A

    A persistent managed disk lets the domain controller recover automatically from host maintenance events without requiring re-promotion. Ephemeral OS disks are explicitly not recommended for domain controllers, the temporary disk is not persistent across redeployments, and the NTDS database belongs on a separate persistent data disk rather than the OS disk.

  3. 8. During a security review of a branch office RODC, you discover that an administrator previously removed the Domain Admins group from the Denied RODC Password Replication Group so that a break-glass domain admin account could authenticate locally during WAN outages. What is the most significant risk this change introduces?

    • A. The RODC will stop replicating the AD DS schema partition from writable domain controllers.
    • B. The RODC's own krbtgt account will be shared with other RODCs across the domain.
    • C. If the RODC is physically compromised, an attacker could potentially obtain a cached credential for a highly privileged domain-wide account.
    • D. The Allowed RODC Password Replication Group will be automatically emptied to compensate.
    Show answer

    Correct answer: C

    The Denied RODC Password Replication Group ships with high-privilege accounts and groups such as Domain Admins so their passwords can never be cached on a branch office RODC; removing that protection exposes a domain-wide credential to theft if the RODC hardware is compromised. Schema replication is unaffected by password replication policy, each RODC is issued its own unique krbtgt account rather than sharing one, and there is no automatic mechanism that empties the Allowed list in response.

  4. 9. Which Active Directory object type associates a range of IP addresses with a specific AD DS site so that domain controller and client location can be determined by network location?

    • A. Site link
    • B. Subnet
    • C. Connection object
    • D. Bridgehead server
    Show answer

    Correct answer: B

    A subnet object associates a range of IP addresses with a site, allowing AD DS to place domain controllers and route client requests based on network location. A site link represents the logical path used for replication between sites, a connection object represents a specific inbound replication link, and a bridgehead server is a domain controller role selected to relay intersite replication, none of which map IP ranges to sites.

  5. 10. Which built-in process running on every domain controller automatically builds and adjusts the AD DS replication topology, both within a site and between sites?

    • A. Net Logon
    • B. Local Security Authority (LSA)
    • C. Knowledge Consistency Checker (KCC)
    • D. Windows Time service
    Show answer

    Correct answer: C

    The Knowledge Consistency Checker runs on every domain controller and automatically generates and dynamically adjusts the intrasite and intersite replication topology as domain controllers, sites, costs, and schedules change. Net Logon maintains the secure channel used for authentication and trust processing, the LSA validates security tokens and audits access, and the Windows Time service handles time synchronization, none of which build replication topology.

Why Practice with MSCertQuiz?

Microsoft Learn teaches concepts. We prepare you for the actual exam.

1

Scenario-based questions on RODC deployment, FSMO role troubleshooting, and multi-forest trust configuration β€” not just definitions

2

Deep coverage of hybrid management: Azure Arc onboarding, Windows Admin Center, Azure Update Manager, and Azure Automation runbooks

3

Calibrated slightly harder than the real exam β€” so AZ-802 exam day feels easier than practice

4

Updated for the current AZ-802 exam objectives β€” the single, current path to the Windows Server Administrator Associate credential now that AZ-800/AZ-801 are retiring

Objectives last checked against Microsoft Learn: July 10, 2026

Not sure if you're ready for the AZ-802 exam?

Take the free AZ-802 Readiness Check β†’

What Our Users Say

90% pass rate β€” Based on users who completed at least 2 practice exams

β€œThe RODC and FSMO role questions were exactly the kind of scenario depth the real exam tests. Passed AZ-802 with 780 β€” glad I didn't wait for AZ-800/AZ-801 to retire.”

JH

Jordan H.

AZ-802 Certified

β€œSolid coverage of the Azure Arc and hybrid management domain, which was the weakest part of my on-prem-only background. That section alone was worth it.”

PC

Priya C.

Passed AZ-802 first try

β€œStorage Spaces Direct and DFS questions matched the real exam's difficulty closely. Explanations actually taught me why, not just which letter was correct.”

MW

Marcus W.

AZ-802 Certified

Choose Your Plan

Start free, upgrade when you're ready to get serious

Free

Good for exploring the platform

$0
  • 40 practice questions
  • Practice mode only
  • Progress tracking
  • No exam simulation mode
Start Free

AZ-802 Full Access

Best if your exam is in the next 2-4 weeks

$19.99one-time
  • 500 practice questions
  • Practice & Exam modes
  • Detailed explanations
  • Lifetime access
Get AZ-802 Access β€” $19.99

7-day money-back guarantee

BEST VALUE

Pro β€” All Certs

Best if you're planning multiple Microsoft exams

$14.99/month
  • ALL certifications included
  • Unlimited questions
  • New certs added free
  • Cancel anytime
View Pro Plans

Save 30% vs buying individually

Your AZ-802Exam Won't Wait

Candidates who complete at least 2 full mock exams pass at significantly higher rates than those who only study passively.

Don't risk $165 on the real exam without testing yourself first.

Start Free Practice Now

No credit card required β€’ 40 free questions β€’ Upgrade for $19.99 when ready

Official Microsoft Resources

Our practice questions are aligned with official Microsoft exam objectives. We recommend studying with Microsoft Learn first, then using MSCertQuiz to test your readiness.

View Official AZ-802 Exam Details

AZ-802 Frequently Asked Questions

Everything you need to know about the AZ-802 Windows Server certification

What is AZ-802?
AZ-802 (Administering Windows Server) is a Microsoft Associate-level certification exam that validates the skills needed to deploy, manage, and troubleshoot Windows Server across on-premises, cloud, and hybrid environments. It covers AD DS, Hyper-V virtual machines, hybrid management with Azure Arc, storage and file services, networking, security hardening, and monitoring using tools like Windows Admin Center, PowerShell, and Azure Monitor.
How is AZ-802 different from AZ-800 and AZ-801?
AZ-800 (Administering Windows Server Hybrid Core Infrastructure) and AZ-801 (Configuring Windows Server Hybrid Advanced Services) were the previous two-exam path to the Windows Server Administrator Associate certification. AZ-802 consolidates that scope into a single exam and is the current, active path to the credential β€” AZ-800 and AZ-801 are retiring on September 30, 2026, so AZ-802 is the exam that matters going forward.
How much does the AZ-802 exam cost?
The AZ-802 exam costs $165 USD. As with other Microsoft role-based exams, pricing can vary slightly by region and Microsoft occasionally offers discount vouchers through Learn events or partner programs.
How long is the AZ-802 exam and what is the passing score?
The AZ-802 exam runs 120 minutes and uses Microsoft's standard scaled scoring, with a passing score of 700 out of 1000. With roughly 40-60 questions in that window, expect around 2-3 minutes per question, including scenario-based items that take longer to work through.
What topics are covered in AZ-802?
AZ-802 covers seven domains: Deploy and manage AD DS (20-25%) β€” domain controllers, RODCs, FSMO roles, multi-site/multi-forest trusts, and Group Policy; Manage Windows Server instances and workloads in a hybrid environment (10-15%) β€” Windows Admin Center, PowerShell remoting, and Azure Arc; Manage virtual machines (10-15%) β€” Hyper-V configuration and Azure VM management; Implement and manage an on-premises and hybrid networking infrastructure (10-15%) β€” DNS and DHCP; Manage storage and file services (15-20%) β€” Azure Files, DFS, Storage Spaces Direct, and BitLocker; Secure Windows Server infrastructure (10-15%) β€” exploit protection, Credential Guard, and AD DS hardening; and Monitor and troubleshoot Windows Server environments (15-20%) β€” Performance Monitor, Azure Monitor, and AD troubleshooting.
Is AZ-802 in beta?
Yes, AZ-802 is currently a beta exam. Beta exams are fully valid for certification β€” Microsoft uses the beta period to calibrate question difficulty and scoring before the exam moves to general availability. There is no downside to taking it now; in fact it's currently the only active path to the Windows Server Administrator Associate certification, since AZ-800/AZ-801 retire September 30, 2026.
What are the prerequisites for AZ-802?
There are no enforced prerequisites to register for AZ-802, but Microsoft recommends candidates have hands-on experience administering Windows Server, Active Directory Domain Services, Hyper-V, and basic familiarity with Azure services such as Azure Arc, Azure Monitor, and Azure Update Manager. Prior experience with on-premises AD DS environments is especially valuable given the exam's weighting.
Is AZ-802 worth it for my career?
Yes. Windows Server administration remains a core skill for enterprise IT β€” most organizations still run substantial on-premises or hybrid infrastructure alongside their cloud footprint. The Windows Server Administrator Associate certification (earned via AZ-802) signals you can manage that hybrid reality: AD DS, Hyper-V, storage, and security, plus the Azure Arc and hybrid tooling that connects on-premises servers to the cloud.
How long should I study for AZ-802?
Most candidates with existing Windows Server administration experience need 6-10 weeks of focused preparation. Prioritize AD DS (20-25% of the exam) and storage/file services and monitoring (15-20% each) β€” together these make up over half the exam. If you're newer to Azure Arc and hybrid management tooling, budget extra time for that domain since it's less familiar to traditional on-premises admins.