Courseiva

AZ-802 · topic practice

Secure Windows Server Infrastructure practice questions

Practise Microsoft Windows Server Administrator Associate Secure Windows Server Infrastructure practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Secure Windows Server Infrastructure

What the exam tests

What to know about Secure Windows Server Infrastructure

Secure Windows Server Infrastructure questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Secure Windows Server Infrastructure exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Secure Windows Server Infrastructure questions

20 questions · select your answer, then reveal the explanation

You are configuring BitLocker Network Unlock for a cluster of Windows Server 2022 nodes. The servers are equipped with TPM 2.0 and are connected to a wired network. You have already installed the BitLocker Network Unlock feature on a Windows Deployment Services (WDS) server. What is the next requirement to ensure that the servers automatically unlock their OS drives upon rebooting while connected to the internal network?

To monitor for unauthorized access to sensitive files on a Windows Server 2022 file server, you decide to enable auditing. Which category of the Advanced Audit Policy must be configured to track when a user successfully opens a file on a monitored share?

You are hardening a Windows Server 2022 instance. You need to implement Credential Guard to protect NTLM and Kerberos credentials from memory-based attacks. Which prerequisite must be met on the server?

You want to prevent the usage of weak encryption protocols, specifically SSL 3.0 and TLS 1.0, on your Windows Server. How should you proceed?

You are hardening your server's disk security. You need to ensure that data at rest is encrypted. Which feature should you enable?

Your organization implements Just Enough Administration (JEA) to manage Windows Servers. A junior administrator needs to restart the Print Spooler service on several print servers but should not have full administrative rights. You need to identify the specific file that defines which cmdlets and external commands the junior administrator can execute. Which file should you configure?

An administrator is concerned about man-in-the-middle attacks where an attacker intercepts and modifies SMB traffic between a Windows Server 2022 file server and its clients. Which security feature should be enforced to ensure the integrity and authenticity of the SMB traffic?

Your company is implementing a Tiered Administration Model to secure its Windows Server infrastructure. You need to deploy Privileged Access Workstations (PAWs) for all Domain Admins. What is the primary purpose of using a PAW in this environment?

You are configuring Windows Defender Credential Guard on a fleet of Windows Server 2022 Hyper-V hosts. You want to protect the LSA process from being accessed by unauthorized users or malware. Which hardware-based security feature must be enabled in the BIOS/UEFI and supported by the CPU for Credential Guard to operate?

You are planning the deployment of Shielded Virtual Machines in a Windows Server 2022 environment. You need to ensure that the Fabric Administrators cannot access the data within the VMs. Which component of the Host Guardian Service (HGS) is responsible for verifying that a Hyper-V host is authorized to run a Shielded VM?

You manage a Windows Server Update Services (WSUS) infrastructure with one upstream server and three downstream servers. You want the downstream servers to only download updates that have been approved on the upstream server. Which WSUS configuration mode should you use for the downstream servers?

You are using Azure Update Management to manage updates for both on-premises Windows Servers and Azure VMs. You need to ensure that a specific group of on-premises servers never receives a particular update that is known to cause application compatibility issues. How should you configure this in Azure Update Management?

You need to create a Group Managed Service Account (gMSA) for a new web application cluster running on Windows Server 2022. Which TWO prerequisites must be met before you can successfully create and use the gMSA in your Active Directory domain? (Select TWO)

You are configuring Azure Bastion to provide secure RDP access to your Windows Server VMs in an Azure Virtual Network. Which THREE requirements must be met for a successful deployment? (Select THREE)

You are securing Windows Admin Center (WAC) to manage your Windows Server 2022 environment. You want to implement granular access control for different IT teams. Which TWO methods can be used to control who has access to Windows Admin Center and what they can do? (Select TWO)

Refer to the exhibit. An administrator is attempting to run a locally created, unsigned PowerShell script named 'Update-Config.ps1' on a Windows Server 2022. Based on the output of 'Get-ExecutionPolicy -List', what will happen when the administrator attempts to run the script in the current session?

Exhibit

Scope          ExecutionPolicy
-----          ---------------
MachinePolicy  Undefined
UserPolicy     Undefined
Process        Bypass
CurrentUser    Undefined
LocalMachine   AllSigned

Refer to the exhibit. You are reviewing a partial Windows Defender Application Control (WDAC) policy XML file. You need to identify the behavior of this policy regarding the file 'untrusted.exe'. What will occur if a user attempts to run 'untrusted.exe'?

Exhibit

<FileRules>
  <Allow ID="ID_ALLOW_A" FriendlyName="Allow Signed" FileName="*" MinimumFileVersion="1.0.0.0">
    <FileAttrib ID="ID_FILE_ATTRIB_A" Hash="A1B2C3D4E5F6" />
  </Allow>
  <Deny ID="ID_DENY_B" FriendlyName="Block Unsigned" FileName="untrusted.exe" />
</FileRules>
<SigningScenarios>
  <SigningScenario Value="12" ID="ID_SIGNING_SCENARIO_WINDOWS" FriendlyName="Windows">
    <ProductSigners />
  </SigningScenario>
</SigningScenarios>

Refer to the exhibit. You need to ensure that all data transmitted over SMB between your file server and domain-joined clients is encrypted. You set the configuration to True, but users report connectivity issues. What is the most likely cause?

Exhibit

Get-SmbServerConfiguration | Select-Object -Property EnableSMBEncryption

EnableSMBEncryption : False

You are tasked with securing your Windows Server 2022 environment. Which TWO actions should you perform to implement Just Enough Administration (JEA)?

You need to audit successful and failed attempts to modify user accounts in Active Directory. Which policy should you configure?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Secure Windows Server Infrastructure sessions

Start a Secure Windows Server Infrastructure only practice session

Every question in these sessions is drawn from the Secure Windows Server Infrastructure domain — nothing else.

Related practice questions

Related AZ-802 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AZ-802 exam test about Secure Windows Server Infrastructure?
Secure Windows Server Infrastructure questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Secure Windows Server Infrastructure questions in a focused session?
Yes — the session launcher on this page draws every question from the Secure Windows Server Infrastructure domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AZ-802 topics?
Use the topic links above to move to related areas, or go back to the AZ-802 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AZ-802 exam covers. They are not copied from any real exam or dump site.