Practice AZ-802 Secure Windows Server Infrastructure questions with full explanations on every answer.
Start practicing
Secure Windows Server Infrastructure — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
Your organization implements Just Enough Administration (JEA) to manage Windows Servers. A junior administrator needs to restart the Print Spooler service on several print servers but should not have full administrative rights. You need to identify the specific file that defines which cmdlets and external commands the junior administrator can execute. Which file should you configure?
2An administrator is concerned about man-in-the-middle attacks where an attacker intercepts and modifies SMB traffic between a Windows Server 2022 file server and its clients. Which security feature should be enforced to ensure the integrity and authenticity of the SMB traffic?
3Your company is implementing a Tiered Administration Model to secure its Windows Server infrastructure. You need to deploy Privileged Access Workstations (PAWs) for all Domain Admins. What is the primary purpose of using a PAW in this environment?
4You are configuring Windows Defender Credential Guard on a fleet of Windows Server 2022 Hyper-V hosts. You want to protect the LSA process from being accessed by unauthorized users or malware. Which hardware-based security feature must be enabled in the BIOS/UEFI and supported by the CPU for Credential Guard to operate?
5You are planning the deployment of Shielded Virtual Machines in a Windows Server 2022 environment. You need to ensure that the Fabric Administrators cannot access the data within the VMs. Which component of the Host Guardian Service (HGS) is responsible for verifying that a Hyper-V host is authorized to run a Shielded VM?
6You manage a Windows Server Update Services (WSUS) infrastructure with one upstream server and three downstream servers. You want the downstream servers to only download updates that have been approved on the upstream server. Which WSUS configuration mode should you use for the downstream servers?
7You are using Azure Update Management to manage updates for both on-premises Windows Servers and Azure VMs. You need to ensure that a specific group of on-premises servers never receives a particular update that is known to cause application compatibility issues. How should you configure this in Azure Update Management?
8You need to create a Group Managed Service Account (gMSA) for a new web application cluster running on Windows Server 2022. Which TWO prerequisites must be met before you can successfully create and use the gMSA in your Active Directory domain? (Select TWO)
9You are configuring Azure Bastion to provide secure RDP access to your Windows Server VMs in an Azure Virtual Network. Which THREE requirements must be met for a successful deployment? (Select THREE)
10You are securing Windows Admin Center (WAC) to manage your Windows Server 2022 environment. You want to implement granular access control for different IT teams. Which TWO methods can be used to control who has access to Windows Admin Center and what they can do? (Select TWO)
11Refer to the exhibit. An administrator is attempting to run a locally created, unsigned PowerShell script named 'Update-Config.ps1' on a Windows Server 2022. Based on the output of 'Get-ExecutionPolicy -List', what will happen when the administrator attempts to run the script in the current session?
12Refer to the exhibit. You are reviewing a partial Windows Defender Application Control (WDAC) policy XML file. You need to identify the behavior of this policy regarding the file 'untrusted.exe'. What will occur if a user attempts to run 'untrusted.exe'?
13Refer to the exhibit. You need to ensure that all data transmitted over SMB between your file server and domain-joined clients is encrypted. You set the configuration to True, but users report connectivity issues. What is the most likely cause?
14You are tasked with securing your Windows Server 2022 environment. Which TWO actions should you perform to implement Just Enough Administration (JEA)?
15You need to audit successful and failed attempts to modify user accounts in Active Directory. Which policy should you configure?
16You are securing a Windows Server 2022 instance against potential malware. Which THREE actions are recommended to minimize the attack surface?
17Refer to the exhibit. You are investigating why a secure connection is failing on your web server. Based on the output, what is the most likely reason?
18You need to ensure that only authorized administrative users can access the server via PowerShell Remoting. Which security control should you implement?
The Secure Windows Server Infrastructure domain covers the key concepts tested in this area of the AZ-802 exam blueprint published by Microsoft. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all AZ-802 domains — no account required.
The Courseiva AZ-802 question bank contains 18 questions in the Secure Windows Server Infrastructure domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Secure Windows Server Infrastructure domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included
Practice Session
Study Resources