Courseiva
Secure Windows Server InfrastructuremediumMultiple ChoiceObjective-mapped

AZ-802 Secure Windows Server Infrastructure Practice Question

Your company is implementing a Tiered Administration Model to secure its Windows Server infrastructure. You need to deploy Privileged Access Workstations (PAWs) for all Domain Admins. What is the primary purpose of using a PAW in this environment?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

To provide a dedicated environment that is isolated from the risks of email and web browsing.

A Privileged Access Workstation (PAW) provides a dedicated, hardened environment for sensitive administrative tasks. By isolating high-privilege credentials from common threats like email, web browsing, and general-purpose applications, PAWs significantly reduce the risk of credential theft. This isolation is a critical defense-in-depth strategy for protecting high-value accounts in an Active Directory forest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • To allow administrators to browse the internet safely while performing server updates.

    Why it's wrong here

    PAWs are strictly prohibited from general internet browsing to minimize the attack surface. Their purpose is the exact opposite: they provide a locked-down environment where risky activities like web browsing and checking email are disabled to prevent malware from compromising the administrative session or stealing highly sensitive credentials from memory.

  • To provide a dedicated environment that is isolated from the risks of email and web browsing.

    Why this is correct

    The core objective of a PAW is to isolate administrative functions from the most common attack vectors, such as phishing and drive-by downloads. By using a hardened, dedicated machine for administrative tasks, the likelihood of a Domain Admin's credentials being compromised by malware residing on a standard workstation is greatly reduced.

  • To enable multiple users to share a single high-privilege account across the organization.

    Why it's wrong here

    Sharing high-privilege accounts is a violation of security best practices and the principle of accountability. PAWs are intended to secure the access method of individual administrators, not to facilitate account sharing. Each administrator should use their own unique, privileged credentials on a PAW to ensure proper auditing and access control.

  • To automatically synchronize local administrator passwords across all domain controllers.

    Why it's wrong here

    Password synchronization is typically handled by Active Directory or specialized tools like Local Administrator Password Solution (LAPS). PAWs are hardware or virtual machines used by humans to perform tasks; they are not a mechanism for managing or synchronizing account passwords across the server infrastructure or the wider domain environment.

About these practice questions

Courseiva writes every AZ-802 question from scratch — 116 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.