
Explanation:

In a cloud-sync deployment , Microsoft's hybrid identity guidance for Administering Windows Server Hybrid Core Infrastructure specifies that you do not install the full Microsoft Entra (Azure AD) Connect server .
Instead, cloud sync " uses a lightweight agent-called the Microsoft Entr a Connect provisioning agent- installed on one or more Windows Server computers that can reach your AD DS domain controllers ." The agent handles directory read operations and securely communicates with the cloud provisioning service.
The study material further states that all configuration-including creating sync configurations, scoping filters, and enabling features such as Password Hash Synchronization (PHS)-is performed in the Microsoft Entra admin experience : " Cloud sync is configured in the Azure po rtal; you create a cloud sync configuration, select the on-premises AD forest, and enable password hash synchronization so password hashes are synchronized to Microsoft Entra ID. " Because you are using Microsoft Entra Connect cloud sync , the correct softwa re to install on-premises is the Microsoft Entra Connect provisioning agent (not the full Microsoft Entra Connect server or ADFS tools). And to enable PHS for cloud sync, you use the Azure portal (Microsoft Entra admin center) to turn on Password hash sync hronization within the cloud sync configuration. This meets both requirements:
installing the proper agent for cloud sync and enabling PHS centrally in the portal.