Latest [Oct 26, 2024] Real Microsoft AZ-800 Exam Dumps Questions [Q66-Q89]

Share

Latest [Oct 26, 2024] Real Microsoft AZ-800 Exam Dumps Questions

AZ-800 Dumps To Pass Windows Server Exam in One Day (Updated 232 Questions)


One of the key benefits of earning the Microsoft AZ-800 certification is that it demonstrates your expertise in hybrid infrastructure management. Administering Windows Server Hybrid Core Infrastructure certification is recognized by employers around the world, and it can lead to new career opportunities and higher salaries. Additionally, the skills and knowledge you gain while preparing for the exam can help you become a more valuable asset to your current employer, as you will be able to contribute more effectively to hybrid cloud projects.


Microsoft AZ-800 certification exam is designed for IT professionals with experience in managing Windows Server infrastructures. Candidates should have a solid understanding of Windows Server administration, including Active Directory, networking, and security. Additionally, candidates should have experience working with cloud-based solutions, including Microsoft Azure and Microsoft 365.


Microsoft AZ-800 certification exam is a great way to validate your skills and knowledge in administering Windows Server Hybrid Core Infrastructure. Administering Windows Server Hybrid Core Infrastructure certification is recognized globally and can help you stand out in a competitive job market. By passing AZ-800 exam, you can demonstrate to your employers that you have the skills and knowledge needed to manage and secure hybrid cloud solutions.

 

NEW QUESTION # 66
Task 8
You need to create an Active Directory Domain Services (AD DS) site named Site2 that is associated to an IP address range of 192.168.2.0 to 192.168.2.255.

Answer:

Explanation:
See the solution of this Task below
Explanation:
To create an AD DS site named Site2 that is associated to an IP address range of 192.168.2.0 to 192.168.2.255, you can follow these steps:
On a domain controller or a computer that has the Remote Server Administration Tools (RSAT) installed, open Active Directory Sites and Services from the Administrative Tools menu or by typing dssite.msc in the Run box.
In the left pane, right-click on Sites and select New Site.
In the New Object - Site dialog box, enter Site2 as the Name of the new site. Select a site link to associate the new site with, such as DEFAULTIPSITELINK, and click OK. You can also create a new site link if you want to customize the replication frequency and schedule between the sites. For more information on how to create a site link, see Create a Site Link.
In the left pane, right-click on Subnets and select New Subnet.
In the New Object - Subnet dialog box, enter 192.168.2.0/24 as the Prefix of the subnet. This notation represents the IP address range of 192.168.2.0 to 192.168.2.255 with a subnet mask of 255.255.255.0. Select Site2 as the Site object to associate the subnet with, and click OK.
Wait for the changes to replicate to other domain controllers. You can verify the site and subnet creation by checking the Sites and Subnets containers in Active Directory Sites and Services.
Now, you have created an AD DS site named Site2 that is associated to an IP address range of 192.168.2.0 to 192.168.2.255. You can add domain controllers to the new site and configure the site links and site link bridges to optimize the replication topology.


NEW QUESTION # 67
You have a file server named Server1 that runs Windows Server and contains the volumes shown in the following table.

On which volumes can you use BitLocker Drive Encryption (BitLocker) and disk quotas? To answer select the appropriate options in the answer are a. NOTE Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/windows-server/storage/refs/refs-overview


NEW QUESTION # 68
Task 8
You need to deploy a new primary DNS zone named fabrikam.com to DC1. The zone must be signed.

Answer:

Explanation:
See the solution of this Task below.
Explanation:
To deploy a new primary DNS zone named fabrikam.com to DC1 and sign the zone, you can follow these steps:
Step 1: Create the Primary DNS Zone Use the Add-DnsServerPrimaryZone PowerShell command to create the primary zone:
Add-DnsServerPrimaryZone -Name "fabrikam.com" -ZoneFile "fabrikam.com.dns" -DynamicUpdate Secure This command creates a primary zone for fabrikam.com with a DNS file named fabrikam.com.dns and allows secure dynamic updates.
Step 2: Sign the Zone To sign the zone, you can use the DNS Manager or Windows PowerShell. Here's how to sign the zone using PowerShell:
Add-DnsServerSigningKey -ZoneName "fabrikam.com" -Type KeySigningKey -CryptoAlgorithm RsaSha256 Set-DnsServerDnsSecZoneSetting -ZoneName "fabrikam.com" -DenialOfExistence NSEC3
-NSEC3Parameters 1,0,10,""
These commands add a signing key to the zone and set DNSSEC settings with NSEC3 parameters.
Step 3: Publish the Signed Zone After signing the zone, ensure that it is published and available for DNS queries. You can verify the zone signing status using the following command:
Get-DnsServerZone -Name "fabrikam.com"
Note: Ensure that you have the appropriate permissions to perform these actions on DC1 and that the DNS Server role is installed and properly configured. Also, replace "fabrikam.com.dns" with the actual path to your DNS file if it's different12.
By following these steps, you should be able to deploy and sign the new primary DNS zone fabrikam.com on DC1.


NEW QUESTION # 69
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains two servers named Server1 and Server2.
Server1 contains a disk named Disk2. Disk2 contains a folder named UserDat a. UserData is shared to the Domain Users group. Disk2 is configured for deduplication. Server1 is protected by using Azure Backup.
Server1 fails.
You connect Disk2 to Server2.
You need to ensure that you can access all the files on Disk2 as quickly as possible.
What should you do?

  • A. Install the File Server Resource Manager server role.
  • B. Create a storage pool.
  • C. Install the Data Deduplication server role.
  • D. Restore files from Azure Backup.

Answer: C

Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/storage/data-deduplication/overview


NEW QUESTION # 70
Hotspot Question
Your on-premises network contains a server named Server1 and uses an IP address space of
192.168.10.0/24.
You have an Azure virtual network that contains a subnet named Subnet1. Subnet1 uses an IP address space of 192.168.10.0/24.
You need to migrate Server1 to Subnet1. You must use Azure Extended Network to maintain the existing IP address of Server1.
What is the minimum number of virtual machines that you should deploy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure- extended-network


NEW QUESTION # 71
You have a file server named Server1 that runs Windows Server and contains the volumes shown in the following table.

On which volumes can you use BitLocker Drive Encryption (BitLocker) and disk quotas? To answer select the appropriate options in the answer are a. NOTE Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/windows-server/storage/refs/refs-overview


NEW QUESTION # 72
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant
You have several Windows 10 devices that are Azure AD hybrid-joined.
You need to ensure that when users sign in to the devices, they can use Windows Hello for Business.
Which optional feature should you select in Azure AD Connect?

  • A. Directory extension attribute sync
  • B. Device writeback
  • C. Group writeback
  • D. Azure AD app and attribute filtering
  • E. Password writeback

Answer: E

Explanation:
Reference:
https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-trust-prereqs


NEW QUESTION # 73
You haw? a server named Host! that has the Hyper-V server role installed. Host! hosts a virtual machine named VM1.
You have a management server named Server! that runs Windows Server. You remotely manage Host1 from Server1 by using Hyper-V Manager.
You need to ensure that you can access a USB hard drive connected to Server1 when you connect to VM1 by using Virtual Machine Connection.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. From Virtual Machine Connection, switch to a basic session.
  • B. From Disk Management on Host1, select Rescan Disks
  • C. From Virtual Machine Connection select Show Options and then select the USB hard drive.
  • D. From the Hyper-V Settings of Host1, select Allow enhanced session mode
  • E. From Disk Management on Host1. attach a virtual hard disk.

Answer: C,D

Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/virtualization/hyper-v/learn-more/use-local-resources-on-hyper-v-virtual-machine-with-vmconnect


NEW QUESTION # 74
You have a server named Server1 that runs Windows Server Server1 has a just-a-bunch-of-disks (JBOD) enclosure attached.
You plan to create a storage pool on Server1 and a virtual disk that will use a mirror layout.
You are considering whether to use a two-way or a three-way mirror layout.
What is the minimum number of disks required for each type of minor layout? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation


NEW QUESTION # 75
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are planning the deployment of DNS to a new network.
You have three internal DNS servers as shown in the following table.

The contoso.local zone contains zone delegations for east.contoso.local and west.contoso.local. All the DNS servers use root hints.
You need to ensure that all the DNS servers can resolve the names of all the internal namespaces and internet hosts.
Solution: You configure Server2 and Server3 to forward DNS requests to 10.0.1.10.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: A


NEW QUESTION # 76
Your network contains an on -premises Active Directory Domain Services (AD DS) domain named contoso.com The domain contains the objects shown in the following table.

You plan to sync contoso.com with an Azure Active Directory (Azure AD) tenant by using Azure AD Connect You need to ensure that all the objects can be used in Conditional Access policies What should you do?

  • A. Change the scope of Group2 to Universal
  • B. Clear the Configure device writeback option.
  • C. Change the scope o' Group1 and Group2 to Global
  • D. Select the Configure Hybrid A2urc AD join option.

Answer: B


NEW QUESTION # 77
Hotspot Question
Your company has a main office and 10 branch offices that are connected by using WAN links.
The network contains an Active Directory domain.
All users have laptops and regularly travel between offices.
You plan to implement BranchCache in the branch offices.
In each branch office, you install a server that runs Windows Server and the BranchCache feature. You register the servers in Active Directory.
You need to configure the laptops to use the local BranchCache server automatically. The solution must minimize administrative effort.
Which two Group Policy settings should you configure? To answer, select the settings in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Set the "Turn on BranchCache" policy to "Enabled". This will enable the BranchCache feature on the laptops.
Set the "Configure BranchCache" policy to "Hosted Cache mode". This will configure the laptops to use the local BranchCache server automatically, without requiring any manual configuration.
https://learn.microsoft.com/en-us/windows-
server/networking/branchcache/branchcache#BKMK_2


NEW QUESTION # 78
Case Study 1 - Fabrikam, Inc
Overview
Fabrikam, Inc is a manufacturing company that has a main office in New York and a branch office in Seattle.
Existing Environment
On-premises Servers
The on-premises network contains servers that run Windows Server as shown in the following table.

DC1 hosts all the operation master roles.
WEB1 and WEB2 run an Internet Information Services (IIS) web app named Webapp1.
On-premises Network
The New York and Seattle offices are connected by using redundant WAN links.
The client computers in each office get IP addresses from their local DHCP server.
DHCP1 contains a scope named Scope1 that has addresses for the New York office, DHCP2 contains a scope named Scope2 that has addresses for the Seattle office.
Identity Infrastructure
The network contains a single on-premises Active Directory Domain Services (AD DS) domain named corp.falbrikam.com. Currently, all the service accounts use individual domain user accounts.
All domain controllers have the DNS Server role installed and host a copy of the Active Directory integrated DNS zone of corp.fabrikam.com.
The corp.fabrikam.com AD DS domain syncs with an Azure Active Directory (Azure AD) tenant.
Group Policy Objects (GPOs)
The corp.fabrikam.com domain contains the organizational units (OUs) and custom Group Policy Objects (GPOs) shown in the following table.

Requirements
Planned Changes
Fabrikam identifies the following planned changes:
Create a single Azure subscription named Sub1 that will contain a single Azure virtual network named Vnet1.
Replace the WAN links between the Seattle and New York offices by using Azure Virtual WAN and FxpressRoute. Both on premises offices will be connected to Vnet1 by using ExpressRoute.
Create three Azure file shares named newyorkhiles, seattlefiles, and companyfiles.
Create a domain controller named dc3.corp.fabrikam.com in Vnet1.
Deploy an Azure Virtual Desktop host pool to Vnet1. The Azure Virtual Desktop session hosts will be hybrid Azure AD-joined.
License all servers for Microsoft Defender for servers.
Use Azure Policy to enforce configuration management policies on the servers in Azure and on- premises.
Networking Requirements
Fabrikam identifies the following networking requirements:
Implement Virtual WAN and ensure that all the network traffic between the sites uses Virtual WAN. All communications must occur over ExpressRoute.
If a DHCP server fails, ensure that the client computers can continue to receive their dynamic IP address and renew their existing lease.
Ensure that the resources in Vnet1 can resolve the names of the on-premises servers in the corp.fabrikam.com domain.
Security Requirements
Fabrikam identifies the following security requirements:
Apply GPO4 to the Azure Virtual Desktop session hosts. Ensure that Azure Virtual Desktop user sessions lock after being idle for 10 minutes. Users must be able to control the lockout time manually from their client computer.
Ensure that server administrators request approval before they can establish a Remote Desktop connection to an Azure virtual machine. If the request is approved, the connection must be established within two hours.
Prevent user passwords from containing all or part of words that are based on the company name, such as Fab, f@br1kAm or fabr!|.
Ensure that all instances of Webapp1 use the same service account. The password of the service account must change automatically every 30 days.
Prevent domain controllers from directly contacting hosts on the internet.
File Sharing Requirements
You need to configure the synchronization of Azure files to meet the following requirements:
Ensure that seattlefiles syncs to FS2.
Ensure that newyorkfiles syncs to FS1.
Ensure that companyfiles syncs to both FS1 and FS2.
Question
Hotspot Question
You need to configure network communication between the Seattle and New York offices. The solution must meet the networking requirements.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
The network requirements state: "All communications must occur over ExpressRoute." That means you need to create the conditions for that kind of connection: an ExpressRoute gateway and an ExpressRoute circuit connection.
https://docs.microsoft.com/en-us/learn/modules/implement-hybrid-network-infrastructure/5- implement-azure-expressroute


NEW QUESTION # 79
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a user named User1 and the servers shown in the following table.

You need to ensure that User1 can manage only Scope1 and Scope3. What should you do?

  • A. Add User1 to the DHCP Administrators group on Server1 and Server2.
  • B. Implement Windows Admin Center and add connections to Server1 and Server2.
  • C. Implement IP Address Management (IPAM).
  • D. Add User1 to the DHCP Administrators domain local group.

Answer: C


NEW QUESTION # 80
Task 1
You need to prevent domain users from saving executable files in a share named \\SRVl\Data. The users must be able to save other files to the share.

Answer:

Explanation:
See the solution of this Task below.
Explanation:
One possible solution to prevent domain users from saving executable files in a share named \SRVl\Data is to use file screening on the file server. File screening allows you to block certain files from being saved based on their file name extension. Here are the steps to configure file screening:
* On the file server, open File Server Resource Manager from the Administrative Tools menu.
* In the left pane, expand File Screening Management and click on File Groups.
* Right-click on File Groups and select Create File Group.
* In the File Group Properties dialog box, enter a name for the file group, such as Executable Files.
* In the Files to include box, enter the file name extensions that you want to block, such as .exe, .bat,
.cmd, .com, .msi, .scr. You can use wildcards to specify multiple extensions, such as *.exe.
* Click OK to create the file group.
* In the left pane, click on File Screen Templates.
* Right-click on File Screen Templates and select Create File Screen Template.
* In the File Screen Template Properties dialog box, enter a name for the template, such as Block Executable Files.
* On the Settings tab, select the option Active screening: Do not allow users to save unauthorized files.
* On the File Groups tab, check the box next to the file group that you created, such as Executable Files.
* On the Notification tab, you can configure how to notify users and administrators when a file screening event occurs, such as sending an email, logging an event, or running a command or script. You can also customize the message that users see when they try to save a blocked file.
* Click OK to create the file screen template.
* In the left pane, click on File Screens.
* Right-click on File Screens and select Create File Screen.
* In the Create File Screen dialog box, enter the path of the folder that you want to apply the file screening to, such as \SRVl\Data.
* Select the option Derive properties from this file screen template (recommended) and choose the template that you created, such as Block Executable Files.
* Click Create to create the file screen.
Now, domain users will not be able to save executable files in the share named \SRVl\Data. They will be able to save other files to the share.


NEW QUESTION # 81
You need to configure Azure File Sync to meet the file sharing requirements. What should you do? To answer, select the appropriate options in the answer are a. NOTE Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/storage/file-sync/file-sync-planning


NEW QUESTION # 82
You have an Azure Active Directory Domain Services (Azure AD DS) domain.
You create a new user named Admin1.
You need Admin1 to deploy custom Group Policy settings to all the computers in the domain. The solution must use the principle of least privilege.
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/active-directory-domain-services/manage-group-policy


NEW QUESTION # 83
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.
The network contains the servers shown in the following table.

You plan to implement IP Address Management (IPAM).
You need to use the Group Policy based provisioning method for managed servers. The solution must support server discovery.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 84
You have two on-premises servers named Server1 and Servet2 that run Windows Server.
You have an Azure Storage account named storage1 that contains a file share named share'. Server1 syncs with share1 by using Azure File Sync You need to configure Server2 to sync with share1.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

1 - Add a Storage Sync Service to the Azure subscription.
2 - On Server2, install the Azure File Sync agent.
3 - Register Server2 with the Storage Sync Service.


NEW QUESTION # 85
Your network contains two Active Directory Domain Services (AD DS) forests as shown in the following exhibit.

The forests contain the domain controllers shown in the following table.

You perform the following actions on DO:
* Create a user named User1.
* Extend the schema with a new attribute named Attributed
To which domain controllers are User1 and Attribute1 replicated? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 86
SIMULATION
Task 7
You need to collect the recommended Windows Performance Counters from SRV1 in a Log Analytics workspace.
The required tiles are stored in a shared folder named \dc\install.

Answer:

Explanation:
See the solution of this Task below
Explanation:
To collect the recommended Windows Performance Counters from SRV1 in a Log Analytics workspace, you can follow these steps:
Step 1: Access the Log Analytics Workspace Log in to the Azure portal and navigate to your Log Analytics workspace.
Step 2: Configure Performance Counters In the Log Analytics workspace, select Advanced settings and then choose Data > Windows Performance Counters1. You can add the recommended performance counters by selecting the + button. If you're using legacy agent management, you can add counters from the Legacy agents management menu2.
Step 3: Add Performance Counters Select the counters you want to collect. You can add common counters quickly by checking the boxes next to them. For specific counters, enter the name of the counter in the format object(instance)\counter. For example, to collect the Processor Time counter for all instances of the Processor object, specify Processor(_Total)\% Processor Time.
Step 4: Set Sample Interval When adding a counter, you can set the sample interval, which is the frequency at which data is collected. The default is 10 seconds, but you can change this to a higher value if needed.
Step 5: Apply Configuration After adding the desired performance counters, select Apply at the top of the screen to save the configuration.
Step 6: Install and Configure the Agent Ensure that the Microsoft Monitoring Agent (MMA) is installed on SRV1. Configure the agent to report to your Log Analytics workspace by specifying the workspace ID and key during setup.
Step 7: Verify Data Collection After the agent is configured, it will start collecting the specified performance counters. You can verify the data collection in the Log Analytics workspace by running queries against the collected data.
Note: The legacy Log Analytics agent will be deprecated by August 2024. Migrate to the Azure Monitor agent before this date to continue ingesting data3.
By following these steps, you should be able to collect the recommended Windows Performance Counters from SRV1 in your Log Analytics workspace. Ensure that you have the necessary permissions and that SRV1 has network connectivity to Azure services.


NEW QUESTION # 87
SIMULATION
You need to create a user named Admin1 in contoso.com. Admin1 must be able to back up and restore files on SRV1. The solution must use principle of the least privilege.
To complete this task, sign in the required computer or computers.

Answer:

Explanation:


NEW QUESTION # 88
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the VPN servers shown in the following table.

You have a server named NPS1 that has Network Policy Server (NPS) installed. NPS1 has the following RADIUS clients:

VPN1, VPN2, and VPN3 use NPS1 for RADIUS authentication. All the users in contoso.com are allowed to establish VPN connections. For each of the following statements, select Yes If the statement is true.
Otherwise, select No. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Text, letter Description automatically generated


NEW QUESTION # 89
......

AZ-800 Exam Brain Dumps - Study Notes and Theory: https://skillsoft.braindumpquiz.com/AZ-800-exam-material.html