Microsoft AZ-800 Certification Exam Dumps with 232 Practice Test Questions
New AZ-800 Exam Dumps with High Passing Rate
Microsoft AZ-800 certification exam is designed to test the skills and knowledge of IT professionals who are responsible for administering and managing Windows Server Hybrid Core Infrastructure. AZ-800 exam covers a wide range of topics related to the planning, deployment, configuration, and maintenance of hybrid cloud environments that incorporate both on-premises and cloud-based resources.
The AZ-800 exam covers a wide range of topics, including Azure Arc-enabled servers, Azure Stack HCI, Azure Stack Hub, Azure hybrid networking, Azure hybrid identity, and Azure security. AZ-800 exam also assesses a candidate's ability to implement and manage hybrid server environments, configure and manage storage solutions, and implement disaster recovery and high availability solutions. To pass the exam, candidates must have a deep understanding of Microsoft technologies and be able to apply them to real-world scenarios.
NEW QUESTION # 45
You have a Windows Server container host named Server1 that has a single disk.
On Server1, you plan to start the containers shown in the following table.
Which isolation mode can you use for each container? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/virtualization/windowscontainers/manage-containers/hyperv-container
NEW QUESTION # 46
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the VPN servers shown in the following table.
You have a server named NPS1 that has Network Policy Server (NPS) installed. NPS1 has the following RADIUS clients:
VPN1, VPN2, and VPN3 use NPS1 for RADIUS authentication. All the users in contoso.com are allowed to establish VPN connections. For each of the following statements, select Yes If the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 47
Your network contains a single domain Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains a single Active Directory site.
You plan to deploy a read only domain controller (RODC) to a new datacenter on a server named Server1. A user named User1 is a member of the local Administrators group on Server1.
You need to recommend a deployment plan that meets the following requirements:
Ensures that a user named User1 can perform the RODC installation on Server1 Ensures that you can control the AD DS replication schedule to the Server1 Ensures that Server1 is in a new site named RemoteSite1 Uses the principle of least privilege Which three actions should you recommend performing in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
1 - Create a site and a subnet.
2 - Pre-create an RODC account.
3 - Instruct User1 to run the Active Directory Domain Services installation Wizard on Server1.
Reference:
https://mehic.se/2018/01/02/how-to-install-and-configure-read-only-domain-controller-rodc-2016/
NEW QUESTION # 48
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant The on-premises network is connected to Azure by using a Site-to-Site VPN. You have the DNS zones shown in the following table.
You need to ensure that names from (aDiifcam.com can be resolved from the on-premises network Which two actions should you perform? Each correct answer presents part of the solution, NOTE: Each correct selection Is worth one point
- A. Create a stub zone for fabrikam.comonDC1.
- B. Deploy an Azure virtual machine that runs Windows Server. Modify the DNS Servers settings for the virtual network.
- C. Create a secondary zone for fabnlcam.com on DO.
- D. Create a conditional forwarder for fabrikam.com on DC1.
- E. Deploy an Azure virtual machine the runs Windows Server. Configure the virtual machine &s a DNS forwarder.
Answer: A,B
NEW QUESTION # 49
You deploy a single-domain Active Directory Domain Services (AD DS) forest named contoso.com.
You deploy a server to the domain and configure the server to run a service.
You need to ensure that the service can use a group managed service account (gMSA) to authenticate.
Which three PowerShell cmdlets should you run in sequence? To answer, move the appropriate cmdlets from the list of cmdlets to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation
NEW QUESTION # 50
You have on-premises servers that run Windows Server as shown in the following table.
You have an Azure subscription that contains a virtual machine named VMV You need to ensure that you can manage all the servers by using Azure Arc. The solution must minimize administrative effort.
On which servers should you install the Azure Connected Machine agent?
- A. VM1 and VM2 only
- B. Server1, VM1, and VM2
- C. Server1 only
- D. VM2only
- E. VM1 only
- F. Server1 and VM2 only
Answer: F
NEW QUESTION # 51
You have two on-premises servers named Server1 and Servet2 that run Windows Server.
You have an Azure Storage account named storage1 that contains a file share named share'. Server1 syncs with share1 by using Azure File Sync You need to configure Server2 to sync with share1.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
1 - Add a Storage Sync Service to the Azure subscription.
2 - On Server2, install the Azure File Sunc agent.
3 - Register Server2 with the Storage Sync Service.
NEW QUESTION # 52
You need to meet technical requirements for HyperV1.
Which command should you run? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 53
Your network contains two VLANs for client computers and one VLAN for a datacenter Each VLAN is assigned an IPv4 subnet Currently, all the client computers use static IP addresses.
You plan to deploy a DHCP server to the VLAN in the datacenter.
You need to use the DHCP server to provide IP configurations to all the client computers.
What is the minimum number of scopes and DHCP relays you should create? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 54
You plan to deploy an Azure virtual machine that will run Windows Server.
You need to ensure that an Azure Active Directory (Azure AD) user [email protected] can connect 10 the virtual machine by using the Azure Serial Console.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/troubleshoot/azure/virtual-machines/serial-console-overview
NEW QUESTION # 55
Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com The domain contains a server named Server1 and the users shown In the following table.
Server1 contains a folder named D:\Folder1. The advanced security settings for Folder 1 are configured as shown in the Permissions exhibit. (Click the Permissions lab.)
Folder1 is shared by using the following configurations


Answer:
Explanation:
Explanation:
NEW QUESTION # 56
You have a server that runs Windows Server and has the DHCP Server role installed. The server has a scope named Scope! that has the following configurations:
* Address range: 192.168.0.2 to 192.16B.1.2M . Mask 255.255.254.0
* Router: 192.168.0.1
* Lease duration: 3 days
* DNS server 172.16.0.254
You have 50 Microsoft Teams Phone devices from the same vendor. All the devices have MAC addresses within the same range.
You need to ensure that all the Teams Phone devices that receive a lease from Scope1 have IP addresses in the range of 192.168.1.100 to 192.168.1.200. The solution must NOT affect other DHCP clients that receive IP configurations from Scope1.
What should you create?
- A. a fitter
- B. a policy
- C. scope options
- D. a scope
Answer: B
Explanation:
Reference:
https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/dn425040(v=ws.11)
NEW QUESTION # 57
Hotspot Question
Your network contains two Active Directory Domain Services (AD DS) forests named contoso.com and fabrikam.com. A two-way forest trust exists between the forests. Each forest contains a single domain.
The domains contain the servers shown in the following table.
You need to configure resource based constrained delegation so that the users in contoso.com can use Windows Admin Center on Server1 to connect to Server2.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
https://docs.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/user- access-control#:~:text=To%20configure%20Resource,Get%2DADComputer%20wac)
NEW QUESTION # 58
You have a server named Server 1 that runs Windows Server and has the Hyper-V server role installed.
Server1 hosts a virtual machine named VM1. Server1 has an NV Me storage device that is assigned to VM1 by using Discrete Device Assignment.
You need to make the device available to the host.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
1 - From Server1, stop VM1.
2 - From Server1, run the Remove-VMAssignableDevice cmdlet.
3 - From Sever1, run the Mount-VMHostAssignableDevice cmdlet.
4 - From Server1, enable the device by using Device Manager.
NEW QUESTION # 59
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant The on-premises network is connected to Azure by using a Site-to-Site VPN. You have the DNS zones shown in the following table.
You need to ensure that names from (aDiifcam.com can be resolved from the on-premises network Which two actions should you perform? Each correct answer presents part of the solution, NOTE: Each correct selection Is worth one point
- A. Create a conditional forwarder for fabrikam.com on DC1.
- B. Create a stub zone for fabrikam.com on DC1.
- C. Create a secondary zone for fabnlcam.com on DO.
- D. Deploy an Azure virtual machine that runs Windows Server. Modify the DNS Servers settings for the virtual network.
- E. Deploy an Azure virtual machine that runs Windows Server. Configure the virtual machine &s a DNS forwarder.
Answer: A,E
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/private-link/private-endpoint-dns#on-premises-workloads-using-a-dns-forwarder
NEW QUESTION # 60
Drag and Drop Question
You have a server named Server1 that runs Windows Server and has the Hyper-V server role installed. Server1 hosts a virtual machine named VM1.
Server1 has an NVMe storage device that is assigned to VM1 by using Discrete Device Assignment.
You need to make the device available to the host.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation:
https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/deploy/deploying-storage- devices-using-dda
NEW QUESTION # 61
Your company has a main office and 10 branch offices that are connected by using WAN links. The network contains an Active Directory domain.
All users have laptops and regularly travel between offices.
You plan to implement BranchCache in the branch offices.
In each branch office, you install a server that runs Windows Server and the BranchCache feature. You register the servers in Active Directory.
You need to configure the laptops to use the local BranchCache server automatically. The solution must minimize administrative effort.
Which two Group Policy settings should you configure? To answer, select the settings in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 62
Hotspot Question
You have a server named Server1 that runs Windows Server and has the Hyper-V server role installed. Server1 contains a virtual machine named VM1 that runs Windows Server.
You need to install the Hyper-V server role on VM1.
Which PowerShell command should you run first? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 63
You have two servers that have the Hyper-V server role installed.
The servers are joined to a failover cluster both servers can connect to the same disk on an iSCSi storage device.
You plan to use the iSCSI storage to store highly available Hyper-V virtual machines that will support live migration functionality.
You need to configure a storage resource in the failover cluster to store the virtual machines.
What should you configure?
- A. a storage pool
- B. a mirrored volume
- C. Cluster Shared volumes (CSV)
- D. attributed File System (DFS) Replication
Answer: C
NEW QUESTION # 64
You need to meet the technical requirements for User1. The solution must use the principle of least privilege.
What should you do?
- A. Create a delegation on contoso.com.
- B. Add Users1 to the Server Operators group in contoso.com.
- C. Create a delegation on OU3.
- D. Add Users1 to the Account Operators group in contoso.com.
Answer: C
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/delegating-administration-of-account-ous-and-resource-ous
Topic 2, Fabrikam inc.
On-premises Servers
The on-premises network contains servers that run Windows Server as shown in the following table.
DC1 hosts all the operation master roles.
WEB1 and WEB2 run an Internet Information Services (IIS) web app named Webapp1.
On-premises Network
The New York and Seattle offices are connected by using redundant WAN links.
The client computers in each office get IP addresses from their local DHCP server.
DHCP! contains a scope named Scope1 that has addresses for the New York office. DHCP2 contains a scope named Scope2 that has addresses for the Seattle office.
Group Policy Object (GPOs)
The cwp.fabrikam.com domain contains the organizational units (OUs) and custom Group Policy Objects (GPOs) shown in the following table.
Requirements:
Fabrikam Identifies the following planned changes:
* Create a single Azure subscription named Sub1 that will contain a single Azure virtual network named Vnet1.
* Replace the WAN links between the Seattle and New York offices by using Azure Virtual WAN and ExpressRoute. Both on-premises offices will be connected to Vnet1 by using ExpressRoute.
* Create three Azure file shares named newyorkfiles, seattfefiles, and companyfiles.
* Create a domain controller named dc3.corp.fabrikam,com in Vnet1.
* Deploy an Azure Virtual Desktop host pool lo Vnet1. The Azure Virtual Desktop session hosts will be hybrid Azure AD joined.
* License all servers for Microsoft Defender for servers.
* Use Azure Policy to enforce configuration management policies on the servers in Azure and on-premises.
Networking Requirements
Fabrikam identifies the following security requirements:
* Apply GP04 to the Azure Virtual Desktop session hosts. Ensure that Azure Virtual Desktop user sessions lock after being idle for 10 minutes. Users must be able to control the lockout lime manually from their client computer.
* Ensure that server administrators request approval before they can establish a Remote Desktop connection to an Azure virtual machine. If the request is approved, the connection must be established within two hours.
* Prevent user passwords from containing all or part of words that are based on the company name, such as Fab. fabrikam or fsbr! |.
* Ensure that all instances of Webapp1 use the same service account. The password of the service account must change automatically every 30 days.
* Prevent domain controllers from directly contacting hosts on the internet.
File Sharing Requirements
You need to configure the synchronization of Azure files to meet the following requirements:
* Ensure that seattlefiles syncs to FS2.
* Ensure that newyorkfiles syncs to FS1.
* Ensure that companyfiles syncs to both FS1 and FS2.
NEW QUESTION # 65
Hotspot Question
Your network contains three Active Directory Domain Services (AD DS) forest as shown in the following exhibit.
The network contains the users shown in the following table.
The network contains the security groups shown in the following table.
For each of the following statements, select Yes if the statement is true, Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Box 1: Yes
User1 is in east.contoso.com. Group1 is Domain Local group in west.adutm.com.
Accounts from any domain or any trusted domain Global groups from any domain or any trusted domain can be members of Domain Local groups.
Accounts, Global groups, and Universal groups from other forests and from external domains can also be members of Domain Local groups.
Box 2: No
User2 is in the fabrikam.com domain.
Group3 is a Universal group in east.contso.com.
Only accounts from any domain in the same forest can be added as members.
Box 3: Yes
Group2 is a Universal group in contoso.com.
Group2 can grant permissions On any domain in the same forest or trusting forests.
Active Directory Domain Services add to Domain Local group.
Reference:
https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/active- directory-security-groups
NEW QUESTION # 66
You need to meet the security requirements for passwords.
Where should you configure the components for Azure AD Password Protection? lo answer, drag the appropriate components to the correct locations. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad-on-premises
NEW QUESTION # 67
You need to meet the technical requirements for Server4.
Which cmdlets should you run on Server1 and Server4? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://4sysops.com/wiki/enable-powershell-remoting/
NEW QUESTION # 68
......
Get AZ-800 Braindumps & AZ-800 Real Exam Questions: https://lead2pass.guidetorrent.com/AZ-800-dumps-questions.html