StudyToCert

All certifications / AZ-802 / Cheat sheet

AZ-802 AZ-802 cheat sheet

Every exam tip and key term from the free AZ-802 lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Deploy and manage AD DS (21%)

Exam tips

Key terms

DSRM
Directory Services Restore Mode: a special boot mode for offline AD maintenance, protected by a local password set during promotion.
IFM
Install from media: promoting a DC from an ntdsutil-created copy of the database so initial replication does not cross the WAN.
RODC
Read-only domain controller: holds a read-only directory copy and caches only passwords allowed by its Password Replication Policy.
Password Replication Policy
The allow and deny lists that decide which accounts' credentials an RODC may cache.
Host caching
An Azure disk setting (None, ReadOnly, ReadWrite); DC data disks holding NTDS should use None.
FSMO role
A single-master operation in AD assigned to one DC per forest or domain.
RID master
Allocates pools of relative IDs to DCs so each new user, group or computer gets a unique SID.
PDC emulator
Domain-wide role handling time synchronization, urgent password changes, lockouts and GPO editing by default.
Transfer
A graceful role move while both the old and new holders are online.
Seize
A forced role takeover when the old holder is permanently unavailable; the old DC must not return.
Site
An AD object representing a set of well-connected subnets, used for client DC selection and replication scheduling.
Site link cost
A relative value AD sums along paths; the lowest total cost path is preferred.
Site link bridge
A way to make site links transitive; the default Bridge all site links setting makes all links transitive.
KCC
Knowledge Consistency Checker: the process on each DC that builds the replication topology automatically.
repadmin /replsummary
A command that summarizes replication status, failures and largest deltas for all DCs.
Trusting domain
The domain holding resources that accepts authentication from another domain.
Forest trust
A transitive trust between two forest root domains covering every domain in both forests.
Shortcut trust
A manual transitive trust inside one forest that shortens Kerberos referral paths between distant domains.
Selective authentication
A trust setting requiring the Allowed to authenticate permission on each computer before trusted users can reach it.
SID filtering
Removing foreign SIDs, including sIDHistory values, from tokens crossing a trust to block privilege escalation.
Domain local group
A group whose permissions apply only in its own domain but which can contain members from any trusted domain.
Global group
A group containing members only from its own domain that can be used for permissions across the forest.
Universal group
A group with members from any domain in the forest, usable anywhere, with membership replicated to the global catalog.
gMSA
Group managed service account: a service identity whose password AD rotates and releases only to authorized hosts.
KDS root key
The domain key that Key Distribution Services uses to generate gMSA passwords; required once before the first gMSA.
PSO
Password Settings Object: a fine-grained password and lockout policy applied to users or global security groups.
Precedence
The PSO attribute that resolves conflicts; the lowest value wins, and a directly linked PSO beats group-linked ones.
Resultant password policy
The single policy that actually applies to a user, shown by Get-ADUserResultantPasswordPolicy.
AD Recycle Bin
An optional forest feature that preserves all attributes of deleted objects so they can be restored online.
Tombstone
A deleted object stripped of most attributes, kept only so the deletion can replicate before garbage collection.
Entra Connect Sync
An on-premises sync server with the full hybrid feature set; one active server per tenant.
Staging mode
A Connect Sync server that imports and syncs but does not export, used for failover and testing changes.
Entra Cloud Sync
Sync configured in the cloud using lightweight on-premises provisioning agents; suits multiple or disconnected forests.
Pass-through authentication
Sign-in method where on-premises agents validate passwords against AD DS in real time.
Seamless SSO
Kerberos-based automatic sign-in to Entra ID for domain-joined devices on the corporate network, using the AZUREADSSOACC account.
LSDOU
Group Policy application order: Local, Site, Domain, OU; later GPOs win conflicts.
Enforced
A GPO link option that prevents blocking and makes the GPO win over lower-level GPOs.
Block Inheritance
An OU or domain setting that stops non-enforced GPOs from parent containers applying.
Loopback processing
Applying user settings based on the computer's GPOs, in Replace or Merge mode.
Central Store
The PolicyDefinitions folder in SYSVOL that provides shared ADMX templates to all admins.
ADMT
Active Directory Migration Tool: migrates users, groups, computers and service accounts between domains or forests.
SID history
The sIDHistory attribute holding an account's previous SIDs so old resource permissions keep working after migration.
Security translation
ADMT step that replaces old SIDs with new ones in ACLs, profiles and group memberships on resources.
Password Export Server
A service installed on a source DC that lets ADMT migrate user passwords.
Functional level
Domain- or forest-wide setting that unlocks AD features and limits which DC OS versions may be present.

Domain 2: Manage Windows Server instances and workloads in a hybrid environment (11%)

Exam tips

Key terms

Gateway mode
WAC installed on Windows Server and shared by multiple administrators through their browsers.
Desktop mode
WAC installed on a Windows client for a single local user.
Extension
A plug-in that adds a tool or solution to Windows Admin Center, managed from the extension feed.
Resource-based constrained delegation
Kerberos setting on a target computer allowing a named account, such as the WAC gateway, to delegate to it.
WAC in the Azure portal
Managing Azure VMs or Arc-enabled servers through Windows Admin Center from the portal, with Entra ID sign-in and Azure RBAC.
WinRM
Windows Remote Management: the service and protocol that carries PowerShell remoting on ports 5985 and 5986.
Invoke-Command
Runs a script block on one or many remote computers in parallel and returns the results.
Role capability file
A .psrc file defining the cmdlets, functions and commands a JEA role may use.
Session configuration file
A .pssc file defining a JEA endpoint: session type, run-as identity, transcripts and group-to-role mappings.
Virtual account
A temporary local administrator identity created for a JEA session and discarded when it ends.
Connected Machine agent
The agent installed on non-Azure servers that connects them to Azure Arc over outbound HTTPS.
azcmagent
The command-line tool for connecting, checking and configuring the Arc agent.
Service principal
An Entra ID application identity used by scripts to onboard servers without interactive sign-in.
Azure Connected Machine Onboarding
A built-in role that allows onboarding Arc machines but not managing them.
VM extension
A small add-on application Azure deploys and manages on a VM or Arc-enabled server.
Policy assignment
The binding of a policy definition or initiative to a scope with parameters and exclusions.
Initiative
A group of policy definitions assigned and tracked together.
DeployIfNotExists
A policy effect that deploys a related resource when it is missing; needs a managed identity and remediation for existing resources.
Remediation task
A job that applies DeployIfNotExists or Modify changes to resources that already existed when the policy was assigned.
Machine configuration
Azure Policy's in-guest auditing and configuration of OS settings on Azure VMs and Arc-enabled servers.
Periodic assessment
Automatic recurring check (about every 24 hours) for missing updates on a machine.
One-time update
An immediate, ad hoc update installation on selected machines.
Maintenance configuration
A scheduled update policy with window, recurrence, update selection and reboot settings, applied to machines or dynamic scopes.
Dynamic scope
Rule-based machine selection for a maintenance configuration using subscription, resource group, location, OS or tags.
Hotpatching
Applying security updates in memory without a reboot, between quarterly baseline cumulative updates.
Automation account
The Azure resource that holds runbooks, schedules, modules and shared assets.
Runbook
A PowerShell, Python or graphical script run by Azure Automation; only the published version runs in production.
Webhook
An HTTPS URL that starts a specific runbook when called, shown only once at creation.
Hybrid runbook worker
A machine you manage that runs Automation jobs locally so runbooks can reach on-premises resources.
Hybrid worker group
A set of hybrid workers; jobs targeted to the group run on any available member.
Orchestrator
The Windows Server running Storage Migration Service that coordinates inventory, transfer and cutover.
Inventory
The SMS phase that collects shares, files, security and configuration from the source server.
Transfer
The SMS phase that copies data, shares, permissions and local accounts to the destination, repeatable for deltas.
Cut over
The SMS phase that moves the source's name and IP addresses to the destination and renames the source.
SMS Proxy
An optional service on the destination that improves transfer performance.
Azure Migrate project
The container in Azure that holds discovered servers, assessments and migration status.
Azure Migrate appliance
An on-premises VM or server that discovers servers agentlessly and collects performance and dependency data.
Performance-based sizing
Assessment sizing from measured utilization rather than allocated resources.
Mobility service
The agent installed on physical or other-cloud servers for agent-based replication.
Test migration
Creating a copy of the migrated VM in an isolated network to validate before the real cutover.
In-place upgrade
Upgrading the OS on the existing server while keeping roles, settings and data.
Export-DhcpServer
PowerShell cmdlet exporting DHCP configuration and optionally leases to an XML file.
Add-DhcpServerInDC
Authorizes a DHCP server in AD so it may hand out leases in the domain.
printbrm
Command-line printer backup and restore tool used for print server migration.
Web Deploy
Microsoft tool (msdeploy) that syncs or packages IIS sites, configuration and content between servers.

Domain 3: Manage virtual machines (12%)

Exam tips

Key terms

Generation 2 VM
A UEFI-based Hyper-V VM with SCSI boot, Secure Boot and vTPM support; generation cannot be changed later.
Dynamic memory
Hyper-V feature that adjusts VM RAM between minimum and maximum based on demand, with startup memory and buffer settings.
Integration services
Guest components such as shutdown, time sync, heartbeat, data exchange, backup and guest services that communicate over VMBus.
Enhanced session mode
VMConnect sessions over RDP through the VMBus, adding clipboard, drives and device redirection.
Virtual TPM
An emulated TPM 2.0 device for a generation 2 VM, protected by a key protector.
Nested virtualization
Running Hyper-V inside a VM so that VM can host its own VMs.
ExposeVirtualizationExtensions
Set-VMProcessor parameter that passes hardware virtualization features into a VM.
MAC address spoofing
Allowing a VM adapter to send frames with MAC addresses other than its own, needed for inner VM networking.
PowerShell Direct
Running PowerShell in a VM from its Hyper-V host over VMBus with no network required.
VMBus
The high-speed channel between a Hyper-V host and its guests used by integration services and PowerShell Direct.
VHDX
Hyper-V disk format supporting up to 64 TB, 4 KB sectors, corruption-resistant metadata and TRIM.
Fixed-size disk
A virtual disk that allocates its full size at creation for predictable performance.
Dynamically expanding disk
A virtual disk that grows as data is written, up to its configured maximum.
Differencing disk
A child disk storing only changes relative to a read-only parent.
VHD Set
A .vhds shared disk format for guest clusters supporting online resize, host backup and Hyper-V Replica.
Standard checkpoint
Captures disk plus memory and device state; restores the VM exactly as it was, but not application-consistent.
Production checkpoint
Uses VSS or a file system freeze for an application-consistent point in time without memory; restores to a cold boot.
AVHDX
The differencing disk file created for each checkpoint to hold new writes.
Checkpoint merge
Background process that folds AVHDX changes into the parent when a checkpoint is deleted.
VM-GenerationID
A value that lets a virtualized DC detect it has been rolled back and protect AD replication.
External switch
A virtual switch bound to a physical NIC so VMs can reach the physical network.
Internal switch
A virtual switch connecting VMs and the host, with no physical network access.
Private switch
A virtual switch connecting only VMs to each other; the host is excluded.
Switch Embedded Teaming
NIC teaming built into the Hyper-V virtual switch, up to eight identical adapters, switch-independent.
DHCP guard
A VM adapter setting that blocks DHCP server messages from unauthorized VMs.
Live migration
Moving a running VM between Hyper-V hosts with no noticeable downtime.
Shared-nothing live migration
Live migration of a VM and its storage between hosts without shared storage.
Storage migration
Moving a running VM's disks and files to new storage on the same host.
CredSSP
Default live migration authentication; requires signing in to the source host to start the move.
Kerberos constrained delegation
AD setting allowing hosts to delegate for cifs and Microsoft Virtual System Migration Service, enabling remote migration starts.
Replica server
The Hyper-V host that receives replicated VM changes and can run the VM after failover.
Replication frequency
How often changes are sent: every 30 seconds, 5 minutes or 15 minutes.
Recovery point
A saved point in time on the replica that you can fail over to; additional hourly points can be kept.
Planned failover
Failover initiated from the primary with the VM shut down, sending all changes so no data is lost.
Hyper-V Replica Broker
Failover cluster role that allows a cluster to act as a replica server.
RPO
Recovery point objective: the maximum tolerable data loss, measured as time.
RTO
Recovery time objective: the maximum tolerable time to restore service.
Recovery Services vault
The Azure resource that stores Site Recovery and Backup configuration and data.
Recovery plan
An ordered set of machine groups with scripts and manual steps that fail over together.
Reprotect
Reversing replication after failover so the VM is protected back toward the original site before failback.
Azure Hybrid Benefit
Using eligible on-premises Windows Server licenses in Azure to pay only the base compute rate.
Sysprep /generalize
Removes machine-specific data such as the SID so an image can be deployed many times.
Azure Compute Gallery
A service that stores image definitions and versions, replicates them across regions and shares them.
Image definition
The logical grouping in a gallery that describes an image (OS, generation, generalized or specialized).
Azure Edition
Windows Server Datacenter: Azure Edition, available on Azure, supporting hotpatching.

Domain 4: Implement and manage an on-premises and hybrid networking infrastructure (12%)

Exam tips

Key terms

Primary zone
A zone holding the writable copy of DNS data, in a file or in AD.
Secondary zone
A read-only copy of a zone kept current by zone transfers from a master server.
Stub zone
A zone holding only SOA, NS and glue A records to locate another zone's authoritative servers.
Replication scope
The set of DCs that receive an AD-integrated zone: forest, domain, domain partition or a custom partition.
Secure dynamic updates
Dynamic registration allowed only by authenticated domain members, available only on AD-integrated zones.
Forwarder
An upstream DNS server that receives all queries the local server cannot resolve itself.
Conditional forwarder
A rule sending queries for one specific domain to designated DNS servers.
Root hints
The list of root name servers used for iterative resolution when forwarders are absent or unavailable.
DNS policy
A rule that allows, denies, ignores or redirects queries based on criteria such as client subnet or time of day.
Zone scope
An alternate set of records within a zone, selected by DNS policies.
DNSSEC
Extensions that add digital signatures to DNS data so resolvers can verify authenticity and integrity.
RRSIG
A record containing the signature over a set of DNS records.
Trust anchor
A preconfigured public key or DS record a resolver trusts as the start of a DNSSEC validation chain.
Key Master
The DNS server responsible for generating and rolling over keys for a signed zone.
NRPT
Name Resolution Policy Table: client rules, delivered by Group Policy, that require DNSSEC validation or direct queries for specific namespaces.
Private DNS zone
An Azure DNS zone that resolves only from virtual networks linked to it, not from the internet.
Virtual network link
The connection between a private zone and a VNet that lets the VNet resolve the zone and optionally auto-register VM records.
Auto-registration
A link setting that makes Azure create and maintain A records for VMs in the linked VNet; allowed for only one private zone per VNet.
Inbound endpoint
A Private Resolver IP address in the VNet that on-premises DNS servers forward queries to for Azure private names.
Outbound endpoint and forwarding ruleset
The Private Resolver components that forward queries for chosen domains from Azure to other DNS servers, such as on-premises DCs.
Scope
A range of IP addresses for one subnet, with a subnet mask, lease duration and options, from which DHCP leases addresses.
Reservation
A scope entry that always gives the same IP address to a client identified by its MAC address.
Exclusion range
Addresses inside a scope that DHCP will never lease, used for statically configured devices.
DHCP relay agent
A router feature or service that forwards broadcast DHCP requests from a remote subnet to a DHCP server as unicast.
Authorization
Registering a domain-member DHCP server in AD so it is allowed to lease addresses; requires Enterprise Admins rights by default.
DHCP failover
A relationship between two DHCP servers that replicate IPv4 lease information so either can serve the same scopes.
Load balance mode
The default failover mode in which both servers actively lease addresses, split by a configurable percentage.
Hot standby mode
A failover mode with one active and one standby server; the standby holds a reserve percentage of addresses for immediate use.
MCLT
Maximum Client Lead Time: the period a server can extend leases beyond its partner's knowledge, and the wait before full takeover after partner down.
IPAM
IP Address Management: a Windows Server feature that centrally discovers, monitors, manages and audits DHCP, DNS and IP address space.
Address space
The CIDR range or ranges assigned to a VNet, from which its subnets are allocated.
Reserved addresses
The five addresses Azure keeps in every subnet: the network address, the first three host addresses and the broadcast address.
Static private IP
A NIC IP configuration setting that pins a chosen private address to the NIC so it never changes until you change it.
Custom DNS servers
DNS server addresses configured on a VNet or NIC that Azure's DHCP gives to VMs instead of Azure-provided DNS.
Site-to-site VPN
An IPsec/IKE tunnel over the internet between an on-premises VPN device and an Azure VPN gateway, connecting entire networks.
Local network gateway
An Azure resource describing the on-premises VPN device's public IP and the on-premises address prefixes.
Point-to-site VPN
A VPN from an individual computer to a VNet, authenticated by certificate, Entra ID or RADIUS.
ExpressRoute
A private connection to Microsoft through a connectivity provider that bypasses the public internet; not encrypted by default.
Azure Network Adapter
A Windows Admin Center feature that connects a single Windows Server to a VNet using a point-to-site VPN it sets up for you.

Domain 5: Manage storage and file services (16%)

Exam tips

Key terms

Storage Sync Service
The top-level Azure resource that registered servers join and that holds sync groups.
Sync group
A definition of one synchronized data set, made of one cloud endpoint and one or more server endpoints.
Cloud endpoint
The Azure file share that acts as the central copy in a sync group; each group has exactly one.
Server endpoint
A path on a registered Windows Server that participates in a sync group.
Cloud tiering
A server endpoint feature that keeps hot files local and replaces cold files with stubs that recall content from Azure on access.
AD DS authentication for Azure Files
A configuration that represents the storage account as an AD object so domain users can access SMB shares with Kerberos.
Share-level permissions
Azure RBAC roles assigned on a file share that control whether an identity can connect and with what maximum access.
Storage File Data SMB Share Elevated Contributor
The share role that allows read, write, delete and modifying NTFS permissions.
NTFS permissions
Directory and file ACLs enforced inside the share, set with Explorer or icacls just as on a Windows file server.
SMB encryption
An SMB 3.x feature that encrypts file traffic end to end, enabled per share or server-wide.
SMB signing
Cryptographic signing of SMB messages that detects tampering and blocks relay attacks, without hiding content.
SMB over QUIC
SMB carried over QUIC on UDP 443 with TLS 1.3, allowing secure file access over the internet without a VPN.
SMBv1
The original SMB dialect, insecure and deprecated, which should be audited, disabled and removed.
Hard vs soft quota
A hard quota blocks writes at the limit; a soft quota only sends notifications.
Active vs passive file screen
An active screen blocks saving matching files; a passive screen allows it but notifies or logs.
Domain-based namespace
A DFS namespace stored in AD, accessed via the domain name and hosted on one or more namespace servers.
Referral
The list of folder targets a DFS namespace returns to a client, ordered by site cost so the closest target is tried first.
DFS Replication
A multi-master engine that replicates folders between servers using remote differential compression and a staging area.
Storage pool
A group of physical disks from which Storage Spaces virtual disks are created.
Two-way vs three-way mirror
Mirror resiliency keeping two copies (tolerates one disk failure) or three copies (tolerates two).
Thin provisioning
Creating a virtual disk larger than available space and allocating capacity only as data is written.
ReFS
Resilient File System, which checksums metadata (and data with integrity streams), self-repairs with Storage Spaces mirrors and supports fast block cloning.
Data Deduplication
A post-process feature that stores duplicate data chunks once per volume, with usage types Default, HyperV and Backup.
Validation
The Test-Cluster checks of hardware and configuration; a passing report is required for a supported cluster.
Quorum
The majority of votes (nodes plus witness) a cluster needs to stay running, preventing split brain.
Disk witness
A small shared clustered disk that holds a vote and a copy of the cluster database.
Cloud witness
An Azure Storage blob used as the quorum tie-breaker, needing only a storage account and outbound HTTPS.
Cluster-Aware Updating
A feature that updates cluster nodes one at a time while roles move, in self-updating or remote-updating mode.
Storage Spaces Direct
Software-defined storage that pools local drives across 2 to 16 cluster nodes into highly available volumes.
Cache tier
The fastest drives in an S2D node, automatically used to cache writes (and reads too when capacity drives are HDDs) for the slower capacity drives.
Cluster Shared Volume
A clustered volume that all nodes can read and write at the same time, used by Hyper-V and SOFS.
Nested resiliency
A two-node S2D option that survives a node failure and a drive failure simultaneously.
Scale-Out File Server
An active-active clustered file server role on CSVs for application data, using continuously available SMB shares.
Storage Replica
Block-level volume replication over SMB 3 between servers or clusters, requiring data and log volumes on both sides.
Synchronous replication
Writes are acknowledged only after reaching both sites, giving zero RPO but requiring low latency.
Asynchronous replication
Writes are acknowledged at the source and sent later, allowing long distances with a non-zero RPO.
Stretch cluster
One failover cluster split across two sites with replicated storage, supporting automatic failover between sites.
VHD Set
The .vhds shared virtual disk format for guest clusters, stored on CSV or SOFS and supporting online resize and host backup.

Domain 6: Secure Windows Server infrastructure (12%)

Exam tips

Key terms

Security baseline
A Microsoft-recommended set of security configuration settings for a product and role.
Security Compliance Toolkit
A free set of baselines as GPO backups plus tools such as Policy Analyzer and LGPO.exe.
OSConfig
A Windows Server 2025 security configuration platform, managed with PowerShell, that applies role-based baselines.
Drift control
OSConfig's periodic check that automatically resets changed baseline settings to their desired values.
Policy Analyzer
An SCT tool that compares GPOs or local policy against baselines and flags differences and conflicts.
Virtualization-based security
Hyper-V-backed isolation that creates a secure memory region the normal OS kernel cannot access.
Credential Guard
A VBS feature that stores NTLM hashes and Kerberos TGTs in the isolated LSAIso process to defeat credential dumping.
LSA protection
Running LSASS as a Protected Process Light so unsigned or non-protected code cannot read its memory or inject into it.
HVCI (memory integrity)
A VBS feature that validates kernel-mode code integrity inside the secure environment before it runs.
App Control for Business
The Windows code integrity based application control feature, formerly WDAC, that governs drivers and user-mode code device-wide.
Audit mode
A policy mode that logs what would be blocked (event 3076) without blocking, used to test policies before enforcing.
Supplemental policy
An App Control policy that extends a base policy to allow additional applications.
Managed installer
A trusted deployment tool whose installed software App Control automatically allows.
AppLocker
An older user-mode application control feature with per-user or per-group rules, requiring the Application Identity service.
Windows LAPS
A built-in Windows feature that sets unique, rotated local admin passwords and backs them up to AD DS or Entra ID.
Update-LapsADSchema
The cmdlet that extends the AD schema with the Windows LAPS attributes.
Set-LapsADComputerSelfPermission
Grants computers in an OU permission to write their own LAPS password to AD.
Password encryption
An AD backup option that encrypts stored passwords so only authorized decryptors can read them; needs Windows Server 2016 DFL.
Post-authentication actions
Automatic reset, sign-out or restart after the managed account is used and a grace period passes.
Tier 0
The identity tier: domain controllers, AD and systems that control them; its credentials must never be exposed on lower tiers.
Protected Users
A global group whose members cannot use NTLM, DES or RC4, cached credentials or delegation, and get short-lived TGTs.
Privileged access workstation
A dedicated hardened device used only for administration of sensitive systems.
Authentication policy silo
An AD object that limits where members of a silo can obtain Kerberos tickets, restricting privileged accounts to specified hosts.
Firewall profile
Domain, Private or Public: a set of firewall settings chosen per network adapter based on the detected network.
Allow the connection if it is secure
A rule action that allows traffic only when protected by IPsec authentication and optionally encryption.
Connection security rule
A rule telling Windows when and how to use IPsec between computers, such as isolation or server-to-server.
Authentication exemption
A connection security rule that exempts listed hosts from IPsec requirements.
Main mode and quick mode
The IPsec negotiation phases: main mode authenticates peers, quick mode sets up protection for data.
Defender for Cloud
Azure's security posture management and workload protection service for Azure, hybrid and multicloud resources.
Defender for Servers Plan 2
The server protection plan that adds features such as JIT VM access and file integrity monitoring to Plan 1.
Recommendation
A Defender for Cloud finding describing a security weakness on a resource and how to remediate it.
Secure score
A measure of security posture that rises as you remediate recommendations.
Just-in-time VM access
A feature that blocks management ports by default and opens them only for approved requests, source IPs and time windows.
BitLocker
Windows full-volume encryption, usually protected by a TPM, with recovery passwords that should be backed up to AD DS.
BitLocker Network Unlock
A feature that automatically unlocks BitLocker-protected servers at boot when they are on the trusted wired corporate network.
Server-side encryption
Always-on encryption of Azure managed disks at rest, with platform-managed or customer-managed keys.
Encryption at host
Azure encryption performed on the VM's host, covering temp disks and disk caches as well as data flowing to storage.
Azure Disk Encryption
The older option using BitLocker inside the guest with keys in Key Vault, announced for retirement.

Domain 7: Monitor and troubleshoot Windows Server environments (16%)

Exam tips

Key terms

Performance counter
A named measurement (object, instance, counter) such as Processor(_Total)\% Processor Time.
Data collector set
A saved configuration that records counters, traces and configuration data to log files on demand or on a schedule.
Baseline
A recording of normal performance used as a reference for troubleshooting and capacity planning.
Performance counter alert
A DCS type that takes an action when a counter crosses a defined threshold.
Resource Monitor
A real-time tool showing CPU, memory, disk and network usage per process, with handle search and wait chain analysis.
Custom view
A saved Event Viewer filter across one or more logs, exportable as XML.
Windows Event Forwarding
A built-in feature that forwards selected events from source computers to a collector over WinRM.
Collector-initiated subscription
A subscription in which the collector pulls events from computers listed in the subscription.
Source-initiated subscription
A subscription in which sources, configured by Group Policy, push events to the collector; best for many computers.
Event Log Readers
A built-in local group whose members can read event logs, used to grant a collector access.
Windows Admin Center
A browser-based, locally deployed tool for managing servers, clusters and hybrid services.
System Insights
A Windows Server feature that runs local machine learning models to forecast resource capacity.
Capability
A System Insights prediction module, such as CPU capacity forecasting or volume consumption forecasting.
Capability action
A script attached with Set-InsightsCapabilityAction that runs automatically when a capability returns a given status.
Azure Monitor agent
The current agent that collects guest OS logs and performance data, deployed as an extension on Azure VMs and Arc servers.
Data collection rule
An Azure resource defining what data to collect from associated machines and where to send it.
Log Analytics workspace
The Azure Monitor data store for logs, queried with KQL and billed mainly by ingestion.
VM insights
A prebuilt Azure Monitor solution showing VM and Arc server performance, with an optional dependency map.
Action group
A reusable set of notifications and actions triggered by Azure Monitor alerts.
Test-NetConnection
A PowerShell cmdlet that tests ping, TCP port connectivity and route tracing to a host.
Resolve-DnsName
A PowerShell cmdlet for DNS lookups that can target a specific server, record type or DNS-only resolution.
DNS client cache
Locally stored DNS answers, including negative ones, kept until their TTL expires; cleared with ipconfig /flushdns.
APIPA
Automatic Private IP Addressing: a 169.254.x.x address Windows assigns when DHCP fails.
Hosts file
A local file mapping names to IPs that takes priority over DNS queries in the client resolution path.
Get-WindowsUpdateLog
A cmdlet that converts Windows Update trace files into a readable WindowsUpdate.log.
PDC emulator (forest root)
The authoritative time source for an AD forest, which should sync with a reliable external time source.
w32tm
The command-line tool for configuring, querying and resyncing the Windows Time service.
klist
A command that lists or purges the Kerberos tickets cached for the current logon session.
azcmagent check
An Arc agent command that tests connectivity to the Azure endpoints required by the agent and its extensions.
Boot diagnostics
A feature that captures the VM's screenshot and serial log during boot for troubleshooting.
Serial Console
A text console to the VM's serial port, reaching the Windows Special Administration Console without networking.
Run Command
A feature that runs scripts inside the VM through the Azure VM agent, without network access.
Redeploy
Moving a VM to a new Azure host while keeping its disks; temporary disk data is lost.
SAC
Special Administration Console: the Windows text-mode console reachable through Serial Console.
DSRM
Directory Services Restore Mode: a DC boot mode without AD DS running, used for database restores with a local DSRM password.
Non-authoritative restore
Restoring a DC's AD database that then receives newer changes from replication partners.
Authoritative restore
Marking restored objects with higher version numbers via ntdsutil so they replicate out and overwrite partners.
Tombstone lifetime
How long deleted objects are kept as tombstones; backups older than this must not be restored.
msDFSR-Options
The SYSVOL subscription attribute set to 1 on the DC chosen as authoritative in a DFSR SYSVOL restore.
Windows Server Backup
The built-in VSS-based backup feature for full server, volumes, files, system state and bare-metal recovery.
System state backup
A backup of the registry, boot files and role databases such as AD DS and SYSVOL, used to recover AD.
Bare-metal recovery
A backup containing system state and all volumes required to boot, used to rebuild a server on new hardware.
MARS agent
The Azure Recovery Services agent that backs up files, folders and system state from a Windows machine directly to a Recovery Services vault.
MABS
Microsoft Azure Backup Server: a DPM-based on-premises backup server with local disk storage and Azure retention for application workloads.
Study AZ-802 for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the AZ-802 study plan