This page was exported from Top Exam Collection [ http://blog.topexamcollection.com ] Export date:Sun Apr 6 9:38:13 2025 / +0000 GMT ___________________________________________________ Title: [Sep 25, 2024] Latest Windows Server AZ-800 Actual Free Exam Questions [Q58-Q80] --------------------------------------------------- [Sep 25, 2024] Latest Windows Server AZ-800 Actual Free Exam Questions Windows Server AZ-800 Dumps Updated Practice Test and 232 unique questions Microsoft AZ-800 (Administering Windows Server Hybrid Core Infrastructure) Certification Exam is designed for IT professionals who specialize in managing and administering hybrid environments that use Windows Server and cloud services from Microsoft Azure. Administering Windows Server Hybrid Core Infrastructure certification exam measures the skills and knowledge required to manage and secure Windows Server workloads in a hybrid environment, including deploying and configuring Azure services, monitoring and troubleshooting hybrid environments, and implementing disaster recovery solutions. Microsoft AZ-800 certification exam is an excellent way for IT professionals to demonstrate their expertise in managing complex hybrid infrastructures. It is highly valued in the industry and can significantly enhance your career prospects. If you are interested in pursuing this certification, be sure to invest in appropriate training and study materials, and gain practical experience in administering hybrid environments.   NEW QUESTION 58Drag and Drop QuestionYou have a server named Server1 that runs Windows Server and has the Hyper-V server role installed. Server1 hosts a virtual machine named VM1.Server1 has an NVMe storage device that is assigned to VM1 by using Discrete Device Assignment.You need to make the device available to the host.Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. Explanation:https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/deploy/deploying-storage- devices-using-ddaNEW QUESTION 59Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server 2022 and has the DHCP Server role. Server1 contains a single DHCP scope named Scope1.You deploy five printers to the network.You need to ensure that the printers are always assigned the same IP address.Solution: You configure the DHCP scope options for Scope1.Does this meet the requirement?  Yes  No NEW QUESTION 60You have an Azure Active Directory Domain Services (Azure AD DS) domain.You create a new user named Admin1.You need Admin1 to deploy custom Group Policy settings to all the computers in the domain. The solution must use the principle of least privilege.What should you include in the solution? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point Explanation:Reference:https://docs.microsoft.com/en-us/azure/active-directory-domain-services/manage-group-policyNEW QUESTION 61Your company has a main office and a branch office. The two offices are connected by using a WAN link. Each office contains a firewall that filters WAN traffic.The network in the branch office contains 10 servers that run Windows Server. All servers are administered from the main office only.You plan to manage the servers in the branch office by using a Windows Admin Center gateway.On a server in the branch office, you install the Windows Admin Center gateway by using the defaults settings.You need to configure the firewall in the branch office to allow the required inbound connection to the Windows Admin Center gateway.Which inbound TCP port should you allow?  443  3389  5985  6516 NEW QUESTION 62You need to meet the technical requirements for User1. The solution must use the principle of least privilege.What should you do?  Add Usersl to the Server Operators group in contoso.com.  Create a delegation on contoso.com.  Add Usersl to the Account Operators group in contoso.com.  Create a delegation on 0U3. Reference:https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/delegating-administration-of-account-ous-and-resource-ousTopic 1, Contoso LtdAD DS EnvironmentThe network contains an on-premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com. The forest contains the domain controllers shown in the following table.All the domain controllers are global catalog servers.Server InfrastructureThe network contains the servers shown in the following table.A server named Server4 runs Windows Server and is in a workgroup. Windows Firewall on Servei4 uses the private profile.Server2 hosts three virtual machines named VM1. VM2, and VM3.VM3 is a file server that stores data in the volumes shown in the following table.Group PoliciesThe contoso.com domain has the Group Policies Objects (GPOs) shown in the following table.Existing IdentitiesThe forest contains the users shown in the following table.The forest contains the groups shown in the following table.Current ProblemsWhen an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out another administrator can connect to the console session as the currently signed-in user.RequirementsContoso identifies the following technical requirements:* Change the replication schedule for all site links to 30 minutes.* Promote Server1 to a domain controller in canada.contoso.com.* Install and authorize Server3 as a DHCP server.* Ensure that User! can manage the membership of all the groups in ContosoOU3.* Ensure that you can manage Server4 from Server1 by using PowerShell removing.* Ensure that you can run virtual machines on VM1.* Force users to provide credentials when they connect to VM2.* On VM3, ensure that Data Deduplication on all volumes is possible.NEW QUESTION 63Which groups can you add lo Group3 and Groups? To answer, select the appropriate options in the answer are a. NOTE Each correct selection is worth one point. NEW QUESTION 64Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains a server named Server1 that has the DFS Namespaces role service installed. Server! hosts a domain-based Distributed File System (DFS) Namespace named Files.The domain contains a tile server named Server2. Seiver2 contains a shared folder named Share1. Share1 contains a subfolder named Folder 1.In the Files namespace, you create a folder named Folder! that has a target of Server2.contoso.comShare1Folder1.You need to configure a logon script that will map drive letter M to Folder1. The solution must use the path of the DFS Namespace.How should you complete the command to map the drive letter? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point. NEW QUESTION 65You have a server named Server1 that runs Windows Server Server1 has a just-a-bunch-of-disks (JBOD) enclosure attached.You plan to create a storage pool on Server1 and a virtual disk that will use a mirror layout.You are considering whether to use a two-way or a three-way mirror layout.What is the minimum number of disks required for each type of minor layout? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point. NEW QUESTION 66You have an Azure virtual machine named VM1 that contains the drives shown in the following table.On VM1, you plan to install an app named App1. The data for App1 must be stored on a persistent data disk assigned to drive D.You need assign the data disk to drive D.What should you do on VM1 first?  Change the drive letter of the Temporary Storage drive to F.  Move pagefile.sys to the Operating System drive.  Stop (deallocate) VM1.  Expand the Temporary Storage drive. NEW QUESTION 67You deploy a single-domain Active Directory Domain Services (AD DS) forest named contoso.com.You deploy five servers to the domain. You add the servers to a group named iTFarmHosts.You plan to configure a Network Load Balancing (NIB) cluster named NLBCluster.contoso.com that will contain the five servers.You need to ensure that the NLB service on the nodes of the cluster can use a group managed service account (gMSA) to authenticate.Which three PowerShell cmdlets should you run in sequence? To answer, move the appropriate cmdiets from the list of cmdlets to the answer area and arrange them in the correct order. 1 – Add-KdsRootKey2 – New-ADServiceAccout3 – Install-ADServiceAccountReference:https://docs.microsoft.com/en-us/windows-server/security/group-managed-service-accounts/create-the-key-distribution-services-kds-root-keyhttps://docs.microsoft.com/en-us/windows-server/security/group-managed-service-accounts/getting-started-with-group-managed-service-accountsNEW QUESTION 68Your network contains an Active Directory domain named contoso.com. The domain contains the computers shown in the following table.On Server3, you create a Group Policy Object (GPO) named GP01 and link GPOI to contoso.com. GP01 includes a shortcut preference named Shortcut1 that has item-level targeting configured as shown in the following exhibit.To which computer will Shortcut1 be applied?  Server3 only  Computer1 and Server3 only  Server2 and Server3 only  Server1, Server2, and Server3 only NEW QUESTION 69You have a Group Policy Object (GPO) named GPO1 that contains user settings only.You plan to apply GPO1 to a global security group named Group1.You link GP01 to the domain, and you remove all the permissions granted to the Authenticated Users group.You need to configure permissions for GP01 to meet the following requirements.* GPO1 must apply only to the users in Group 1.* The solution must use the principle of least privilege NEW QUESTION 70You have a server named Server1 that runs Windows Server and has the Hyper-V server role installed.Server1 contains a virtual machine named VM1 that runs Windows Server.You need to install the Hyper-V server role on VM1.Which PowerShell command should you run first? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point. Explanation:NEW QUESTION 71You have an Azure Active Directory Domain Services (Azure AD DS) domain.You create a new user named Admin1.You need Admin1 to deploy custom Group Policy settings to all the computers in the domain. The solution must use the principle of least privilege.What should you include in the solution? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point Reference:https://docs.microsoft.com/en-us/azure/active-directory-domain-services/manage-group-policyNEW QUESTION 72You deploy a new Active Directory Domain Services (AD DS) forest named contoso.com. The domain contains three domain controllers named DC1, DC2, and DC3.You rename Default-First-Site-Name as Site1.You plan to ship DC1, DC2, and DC3 to datacenters in different locations.You need to configure replication between DC1, DC2, and DC3 to meet the following requirements:Each domain controller must reside in its own Active Directory site.The replication schedule between each site must be controlled independently.Interruptions to replication must be minimized.Which three actions should you perform in sequence in the Active Directory Sites and Services console? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. 1 – Create two additional sites named Site2 and Site3.Move DC2 to Site2 and DC3 to Site3.2 – Create a connection object between DC1 and DC2.3 – Create a connection object between DC2 and DC3.NEW QUESTION 73You have an Azure virtual machine named VM1 that runs Windows Server.You need to ensure that administrators request access to VM1 before establishing a Remote Desktop connection.What should you configure?  Azure Front Door  Microsoft Defender for Cloud  Azure AD Privileged Identity Management (PIM)  a network security group (NSG) NEW QUESTION 74You need to meet the technical requirements for VM2.What should you do?  Implement shielded virtual machines.  Enable the Guest services integration service.  Implement Credential Guard.  Enable enhanced session mode. Topic 1, Contoso LtdOverviewThis is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more Information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.To start the case studyTo display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements, if the case study has an All Information tab. note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.AD DS EnvironmentThe network contains an on-premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com. The forest contains the domain controllers shown in the following table.All the domain controllers are global catalog servers.Server InfrastructureThe network contains the servers shown in the following table.A server named Server4 runs Windows Server and is in a workgroup. Windows Firewall on Servei4 uses the private profile.Server2 hosts three virtual machines named VM1. VM2, and VM3.VM3 is a file server that stores data in the volumes shown in the following table.Group PoliciesThe contoso.com domain has the Group Policies Objects (GPOs) shown in the following table.Existing IdentitiesThe forest contains the users shown in the following table.The forest contains the groups shown in the following table.Current ProblemsWhen an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out another administrator can connect to the console session as the currently signed-in user.RequirementsContoso identifies the following technical requirements:* Change the replication schedule for all site links to 30 minutes.* Promote Server1 to a domain controller in canada.contoso.com.* Install and authorize Server3 as a DHCP server.* Ensure that User! can manage the membership of all the groups in ContosoOU3.* Ensure that you can manage Server4 from Server1 by using PowerShell removing.* Ensure that you can run virtual machines on VM1.* Force users to provide credentials when they connect to VM2.* On VM3, ensure that Data Deduplication on all volumes is possible.NEW QUESTION 75Your network contains an Azure AD Domain Services domain named contoso.com.You need to configure a password policy for the local user accounts on the Azure virtual machines joined to contoso.com.What should you do? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point. NEW QUESTION 76Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.You open a new branch office that contains only client computers.You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.Solution: You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to Site1.Does this meet the goal?  Yes  No NEW QUESTION 77Case Study 3 – ADatum CorporationOverviewCompany InformationADatum Corporation is a manufacturing company that has a main office in Seattle and two branch offices in Los Angeles and Montreal.Fabrikam PartnershipADatum recently partnered with 2 company named Fabrikam, Inc.Fabrikam is a manufacturing company that has a main office in Boston and a branch office in Orlando.Both companies intend to collaborate on several joint projects.Existing EnvironmentADatum AD DS EnvironmentThe on-premises network of ADatum contains an Active Directory Domain Services (AD DS) forest named adatum.com.The forest contains two domains named adatum.com and east.adatum.com and the domain controllers shown in the following table.Fabrikam AD DS EnvironmentThe on-premises network of Fabrikam contains an AD DS forest named fabrikam.com.The forest contains two domains named fabrikam.com and south.fabrikam.com.The fabrikam.com domain contains an organizational unit (OU) named Marketing.Server InfrastructureThe adatum.com domain contains the servers shown in the following table.HyperV1 contains the virtual machines shown in the following table.All the virtual machines on HyperV1 have only the default management tools installed.SSPace1 contains the Storage Spaces virtual disks shown in the following table.Azure ResourcesADatum has an Azure subscription that contains an Azure AD tenant. Azure AD Connect is configured to sync the adatum.com forest with Azure AD.The subscription contains the virtual networks shown in the following table.The subscription contains the Azure Private DNS zones shown in the following table.The subscription contains the virtual machines shown in the following table.All the servers are in a workgroup.The subscription contains a storage account named storage1 that has a file share named share1.RequirementsPlanned ChangesADatum plans to implement the following changes:– Sync Data1 to share1.– Configure an Azure runbook named Task1.– Enable Azure AD users to sign in to Server1.– Create an Azure DNS Private Resolver that has the following configurations:– Name: Private1– Region: West US– Virtual network: VNet1– Inbound endpoint: SubnetB– Enable users in the adatum.com domain to access the resources in the south.fabrikam.com domain.Technical RequirementsADatum identifies the following technical requirements:– The data on SSPace1 must be available always.– DC2 must become the schema master if DC1 fails.– VM3 must be configured to enable per-folder quotas.– Trusts must allow access to only the required resources.– The users in the Marketing OU must have access to storage1.– Azure Automanage must be used on all supported Azure virtual machines.– A direct SSH session must be used to manage all the supported virtual machines on HyperV1.Drag and Drop QuestionYou need to implement the planned change for Data1.Which actions should you perform in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.NOTE: Each correct selection is worth one point. NEW QUESTION 78You have servers that run Windows Server 2022 as shown in the following table.Server2 contains a .NET app named App1.You need to establish a WebSocket connection from App1 to the SQL Server instance on Server!. The solution must meet the following requirements:* Minimize the number of network ports that must be open on the on-premises network firewall.* Minimize administrative effort.What should you create first?  an Azure Relay namespace  an Azure VPN gateway  a WFC relay connection  a hybrid connection NEW QUESTION 79You have an on-premises server named Server1 that runs Windows Server and has internet connectivity.You have an Azure subscription.You need to monitor Server1 by using Azure Monitor.Which resources should you create in the subscription, and what should you install on Server1? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point. Reference:https://docs.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure-monitorNEW QUESTION 80You need to implement an availability solution for DHCP that meets the networking requirements.Which two actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.  On DHCP1. create a scope that contains 25 percent of the IP addresses from Scope2.  On the router in each office, configure a DHCP relay.  DHCP2. configure a scope that contains 25 percent of the IP addresses from Scope 1 .  On each DHCP server, install the Failover Clustering feature and add the DHCP cluster role.  On each DHCP scope, configure DHCP failover. Reference:https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/hh831385(v=ws.11)Topic 1, Fabrikam inc.OverviewThis is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more Information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.To start the case studyTo display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements, if the case study has an All Information tab. note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.OverviewFabrikam, Inc. Is a manufacturing company that has a main office In New York and a branch office in Seattle.On-premises ServersThe on-premises network contains servers that run Windows Server as shown in the following table.DC1 hosts all the operation master roles.WEB1 and WEB2 run an Internet Information Services (IIS) web app named Webapp1.On-premises NetworkThe New York and Seattle offices are connected by using redundant WAN links.The client computers in each office get IP addresses from their local DHCP server.DHCP! contains a scope named Scope1 that has addresses for the New York office. DHCP2 contains a scope named Scope2 that has addresses for the Seattle office.Group Policy Object (GPOs)The cwp.fabrikam.com domain contains the organizational units (OUs) and custom Group Policy Objects (GPOs) shown in the following table.Requirements:Fabrikam Identifies the following planned changes:* Create a single Azure subscription named Sub1 that will contain a single Azure virtual network named Vnet1.* Replace the WAN links between the Seattle and New York offices by using Azure Virtual WAN and ExpressRoute. Both on-premises offices will be connected to Vnet1 by using ExpressRoute.* Create three Azure file shares named newyorkfiles, seattfefiles, and companyfiles.* Create a domain controller named dc3.corp.fabrikam,com in Vnet1.* Deploy an Azure Virtual Desktop host pool lo Vnet1. The Azure Virtual Desktop session hosts will be hybrid Azure AD joined.* License all servers for Microsoft Defender for servers.* Use Azure Policy to enforce configuration management policies on the servers in Azure and on-premises.Networking RequirementsFabrikam identifies the following security requirements:* Apply GP04 to the Azure Virtual Desktop session hosts. Ensure that Azure Virtual Desktop user sessions lock after being idle for 10 minutes. Users must be able to control the lockout lime manually from their client computer.* Ensure that server administrators request approval before they can establish a Remote Desktop connection to an Azure virtual machine. If the request is approved, the connection must be established within two hours.* Prevent user passwords from containing all or part of words that are based on the company name, such as Fab. fabrikam or fsbr! |.* Ensure that all instances of Webapp1 use the same service account. The password of the service account must change automatically every 30 days.* Prevent domain controllers from directly contacting hosts on the internet.File Sharing RequirementsYou need to configure the synchronization of Azure files to meet the following requirements:* Ensure that seattlefiles syncs to FS2.* Ensure that newyorkfiles syncs to FS1.* Ensure that companyfiles syncs to both FS1 and FS2. Loading … Verified AZ-800 dumps Q&As - 100% Pass from TopExamCollection: https://www.topexamcollection.com/AZ-800-vce-collection.html --------------------------------------------------- Images: https://blog.topexamcollection.com/wp-content/plugins/watu/loading.gif https://blog.topexamcollection.com/wp-content/plugins/watu/loading.gif --------------------------------------------------- --------------------------------------------------- Post date: 2024-09-25 09:32:13 Post date GMT: 2024-09-25 09:32:13 Post modified date: 2024-09-25 09:32:13 Post modified date GMT: 2024-09-25 09:32:13