certslothcertsloth
AZ-802/Topic 07

Azure / Associate · Hybrid

Monitor, diagnose and recover

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Collect evidence before repairing state.

Must remember

  • Performance Monitor and data collector sets capture counters over time; Event Viewer/logs explain discrete failures; Windows Admin Center and System Insights provide supported management/analysis views.
  • Azure Monitor uses data collection rules and supported agents; VM Insights adds performance/dependency visibility. Configure actionable alerts with owners rather than collecting everything without a purpose.
  • For slow systems, correlate CPU, memory, disk latency, network, process and time. For updates/extensions, inspect agent health, prerequisites, connectivity, logs and reboot state.
  • AD issues often involve DNS, time, secure channels and replication. Use tools such as dcdiag and repadmin to gather evidence before resetting accounts or changing topology.
  • AD Recycle Bin restores supported deleted objects when enabled and retained. Directory Services Restore Mode and appropriate system-state recovery address deeper directory recovery; SYSVOL recovery has its own procedure.
  • Kerberos, computer-account trust, BitLocker and storage recovery need the correct keys/credentials and supported steps. Rehearse recovery in isolation and verify replication and application behavior afterward.

Choose under exam pressure

Requirement Choice and reason
One domain controller has stale objects Inspect replication, DNS, sites and time before assuming the data is lost.
A deleted user must be restored Evaluate AD Recycle Bin eligibility before more disruptive directory recovery.

Traps

  • Resetting multiple identities before gathering evidence can hide the root cause.
  • Restoring a directory database without considering replication can create further inconsistency.

Active recall

1. What is a data collector set useful for?

Capturing performance evidence over an interval instead of relying on one snapshot.

2. Which tools help inspect AD health?

dcdiag, repadmin and relevant event logs, together with DNS/time checks.

3. What does DSRM enable?

Supported offline directory maintenance/recovery using the designated recovery mode and credentials.

4. Why investigate the secure channel?

A broken computer-account trust can prevent normal domain authentication.

5. What completes a recovery exercise?

Verified data, authentication, replication and dependent application function.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.