AZ-802 Secure Windows Server Infrastructure Practice Question
You are using Azure Update Management to manage updates for both on-premises Windows Servers and Azure VMs. You need to ensure that a specific group of on-premises servers never receives a particular update that is known to cause application compatibility issues. How should you configure this in Azure Update Management?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an 'Excluded updates' list in the Update Deployment configuration.
Azure Update Management allows for granular control over update deployments through deployment schedules. When creating a deployment, you can specify excluded updates by their Knowledge Base (KB) ID. This ensures that even if an update is critical or security-related, it will not be installed on the targeted machines, preventing known compatibility problems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Modify the local Registry on each server to block the KB ID.
Why it's wrong here
While modifying the registry can block certain Windows Update behaviors, it is not the recommended or efficient way to manage exclusions in Azure Update Management. Centralized management via the Azure Portal is preferred for consistency, visibility, and ease of auditing across large numbers of managed servers in a hybrid environment.
- ✓
Create an 'Excluded updates' list in the Update Deployment configuration.
Why this is correct
The 'Exclude updates' feature in the Azure Update Management deployment settings allows administrators to enter specific KB numbers. This prevents those updates from being deployed during that specific scheduled run. This is the standard and most effective method for managing known bad updates across a group of managed servers.
- ✗
Use a Group Policy Object (GPO) to disable the Windows Update service.
Why it's wrong here
Disabling the Windows Update service would prevent all updates from being installed, which is not the goal. The requirement is to exclude only a *specific* update while allowing others to proceed. Disabling the service entirely leaves the server vulnerable to other security threats and breaks the Azure Update Management functionality.
- ✗
Uninstall the Log Analytics agent from the affected servers.
Why it's wrong here
The Log Analytics agent (or Azure Monitor agent) is required for Azure Update Management to communicate with the on-premises servers. Uninstalling it would remove the server from Azure Update Management entirely, making it impossible to manage any updates or monitor the compliance status of that machine from the Azure console.
About these practice questions
This AZ-802 question is part of Courseiva's 116-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.