Seven areas carry the exam, and their published shares tell you where to spend the evening. Directory work is the largest at a fifth to a quarter: domain controllers on both sides of the hybrid line, read-only replicas and the account security around them, the single-master roles, trusts across sites, domains and forests, replication topologies, principals and service accounts, and everything Group Policy delivers.
Storage plus file services and the monitoring-and-troubleshooting area come next, each around a sixth. Storage runs from Azure file shares and file synchronisation, including the migrations off DFS and off classic shares, through resource management and namespaces on the server itself, down to disks, resilient storage pools, block-level replication, deduplication, RDMA transfers, quality of service, ReFS versus NTFS, iSCSI targets and volume encryption. Monitoring and troubleshooting pairs the observation tools — performance counters, collector sets, insights, event logs, cloud collection rules and alerting — with the repair work: names that do not resolve, updates that will not install, clocks that drift, extensions that fail, encrypted volumes that will not unlock, and a directory that needs its recycle bin, a restore-mode boot, a rebuilt system volume, or a fix for Kerberos and machine-account trust.
The remaining four areas share the last third roughly evenly. Hybrid instance management is remote administration done properly — the browser-based console run locally and from inside the Azure portal, remoting with the double-hop problem solved and constrained endpoints, secure shell, remote desktop — plus the Azure services that reach onto physical machines: Arc onboarding, Arc configuration, extensions pushed onto machines that do not run in Azure, patching, and runbooks. Virtual machines cover the hypervisor host and its guests (session mode, direct consoles, nesting, memory, integration components, hardware pass-through, GPU sharing, checkpoints, virtual disks, switches, adapter teaming, replication, guest clustering) and the same fleet once it lives in Azure. Networking is name resolution and addressing: directory-integrated zones and records, forwarders, resolution across the hybrid boundary, resolution policies, signed zones, and the address-lease service with its scopes, reservations and failover. Security hardens two layers — the operating system through exploit mitigation, application allow-listing, credential isolation, reputation checks, policy-delivered settings, a baseline tool, managed local administrator passwords, server protection and the firewall; and the directory through password policy, cloud-backed password protection, protected accounts, hardened and access-restricted controllers, account and administrative-group options, delegation, and the authentication protocols themselves.