Courseiva
Secure Windows Server InfrastructuremediumMultiple ChoiceObjective-mapped

AZ-802 Secure Windows Server Infrastructure Practice Question

You are using Azure Update Management to manage updates for both on-premises Windows Servers and Azure VMs. You need to ensure that a specific group of on-premises servers never receives a particular update that is known to cause application compatibility issues. How should you configure this in Azure Update Management?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create an 'Excluded updates' list in the Update Deployment configuration.

Azure Update Management allows for granular control over update deployments through deployment schedules. When creating a deployment, you can specify excluded updates by their Knowledge Base (KB) ID. This ensures that even if an update is critical or security-related, it will not be installed on the targeted machines, preventing known compatibility problems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Modify the local Registry on each server to block the KB ID.

    Why it's wrong here

    While modifying the registry can block certain Windows Update behaviors, it is not the recommended or efficient way to manage exclusions in Azure Update Management. Centralized management via the Azure Portal is preferred for consistency, visibility, and ease of auditing across large numbers of managed servers in a hybrid environment.

  • Create an 'Excluded updates' list in the Update Deployment configuration.

    Why this is correct

    The 'Exclude updates' feature in the Azure Update Management deployment settings allows administrators to enter specific KB numbers. This prevents those updates from being deployed during that specific scheduled run. This is the standard and most effective method for managing known bad updates across a group of managed servers.

  • Use a Group Policy Object (GPO) to disable the Windows Update service.

    Why it's wrong here

    Disabling the Windows Update service would prevent all updates from being installed, which is not the goal. The requirement is to exclude only a *specific* update while allowing others to proceed. Disabling the service entirely leaves the server vulnerable to other security threats and breaks the Azure Update Management functionality.

  • Uninstall the Log Analytics agent from the affected servers.

    Why it's wrong here

    The Log Analytics agent (or Azure Monitor agent) is required for Azure Update Management to communicate with the on-premises servers. Uninstalling it would remove the server from Azure Update Management entirely, making it impossible to manage any updates or monitor the compliance status of that machine from the Azure console.

About these practice questions

This AZ-802 question is part of Courseiva's 116-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.