You must enforce that all Arc-enabled Windows Server machines have the Local Administrator Password Solution (LAPS) policy configured and remediate drift automatically. What should you configure to ensure both audit and remediation occur at scale?
Choose an answer
Tap an option to check your answer.
Correct answer: Assign a Guest Configuration policy definition that audits and applies the LAPS configuration, ensure the policy assignment has a managed identity, and create a remediation task targeting noncompliant Arc-enabled servers..
Why this is the answer
The correct answer leverages Azure Policy Guest Configuration, which is designed for auditing and enforcing settings within virtual machines, including Arc-enabled servers. Assigning a Guest Configuration policy definition that audits and applies the LAPS configuration ensures continuous compliance. A managed identity is crucial for the policy to have the necessary permissions to make changes on the Arc-enabled servers. Creating a remediation task automatically fixes non-compliant servers at scale. Incorrect options: Azure Automation Update Management is for managing updates, not for configuring LAPS policies, and a PowerShell Runbook would require manual scheduling and lack continuous auditing. Deploying the Custom Script Extension would only apply the LAPS settings once, not continuously audit or remediate drift. Azure AD Conditional Access is for controlling access to resources based on conditions, not for configuring server-level settings like LAPS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed