Courseiva
Deploy and Manage AD DSmediumMultiple ChoiceObjective-mapped

AZ-802 Deploy and Manage AD DS Practice Question

Exhibit

Get-ADDomain | Select-Object InfrastructureMaster, PDCEmulator, RIDMaster

InfrastructureMaster : DC2.contoso.com
PDCEmulator          : DC1.contoso.com
RIDMaster             : DC1.contoso.com

Refer to the exhibit. You are troubleshooting an issue where several users are unable to change their passwords, and the help desk is seeing inconsistent results when resetting them. Based on the output provided, which domain controller should you investigate first for potential failures or connectivity issues?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

DC1

The PDC Emulator is the authoritative server for password changes and the primary target for password resets within a domain. In the provided exhibit, DC1 holds the PDC Emulator role. If DC1 is offline or experiencing issues, password-related tasks will fail or show inconsistencies, making it the primary suspect for troubleshooting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • DC2

    Why it's wrong here

    DC2 holds the Infrastructure Master role, which manages cross-domain object references. While important for multi-domain environments, it plays no direct role in the password change process or the immediate processing of account lockouts, which are tasks specifically assigned to the PDC Emulator role holder.

  • DC1

    Why this is correct

    DC1 holds the PDC Emulator role, which is the primary domain controller for handling password updates and synchronization. When a user changes their password, the change is preferred to be processed by the PDC Emulator to ensure immediate consistency across the domain for authentication requests.

  • The Schema Master

    Why it's wrong here

    The Schema Master is a forest-wide role not listed in the domain-level exhibit output provided. It is responsible for structural changes to the Active Directory database and has no involvement in daily user account operations like password resets or the enforcement of account lockout policies.

  • The Domain Naming Master

    Why it's wrong here

    The Domain Naming Master manages the addition and removal of domains within the forest. It is not involved in user-level authentication or password management. Issues with this role would prevent architectural changes to the forest but would not cause the password reset symptoms described in the scenario.

About these practice questions

This AZ-802 question is part of Courseiva's 116-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.