Microsoft Administering Windows Server Hybrid Core Infrastructure - AZ-800 FREE EXAM DUMPS QUESTIONS & ANSWERS
Hotspot Question
You have a file server named Server1 that runs Windows Server and contains the volumes shown in the following table.

On which volumes can you use BitLocker Drive Encryption (BitLocker) and disk quotas? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a file server named Server1 that runs Windows Server and contains the volumes shown in the following table.

On which volumes can you use BitLocker Drive Encryption (BitLocker) and disk quotas? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
https://docs.microsoft.com/en-us/windows-server/storage/refs/refs-overview
Hotspot Question
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains the groups shown in the following table.

You need to implement a group nesting strategy.
Which groups can be added as members of Group12, and which groups can be added as members of Group21? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains the groups shown in the following table.

You need to implement a group nesting strategy.
Which groups can be added as members of Group12, and which groups can be added as members of Group21? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Box 1: Group13 only.
Group12 is Global in contoso.com.
A global group can contain users, computers and global groups from the same domain.
Only Group13 is also a Global group in contoso.com.
Box 2: Group12, Group13, and Group14 only.
Group21 is Universal group in east.contoso.com.
A universal group can contain users, global groups, and other universal groups from any domain in the forest.
Group21 can contain all groups except Group11 as it is domain local.
Reference:
https://blog.netwrix.com/2023/04/26/active-directory-nested-groups/
You have three on-premises servers named SVR1, SVR2, and SVR3 that run Windows Server.
SRV1 has a direct-attached storage (DAS) array.
You plan to deploy a failover cluster named Cluster1 by using SVR2 and SVR3.
You need to ensure that the DAS array on SRV1 can be used as shared storage for Cluster1.
The solution must ensure that Cluster1 has block-level access to the storage.
What should you do first on SRV1?
SRV1 has a direct-attached storage (DAS) array.
You plan to deploy a failover cluster named Cluster1 by using SVR2 and SVR3.
You need to ensure that the DAS array on SRV1 can be used as shared storage for Cluster1.
The solution must ensure that Cluster1 has block-level access to the storage.
What should you do first on SRV1?
Correct Answer: D
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Hotspot Question
Your network contains the domains shown in the following exhibit.

You need to establish trust relationships as shown in the following exhibit.

Which type of trust can you use for Trust1 and Trust2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Your network contains the domains shown in the following exhibit.

You need to establish trust relationships as shown in the following exhibit.

Which type of trust can you use for Trust1 and Trust2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Hotspot Question
You plan to deploy an Azure virtual machine that will run Windows Server. The virtual machine will host an Active Directory Domain Services (AD DS) domain controller and a drive named F: on a new virtual disk.
You need to configure storage for the virtual machine. The solution must meet the following requirements:
- Maximize resiliency for AD DS.
- Prevent accidental data loss.
How should you configure the storage? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You plan to deploy an Azure virtual machine that will run Windows Server. The virtual machine will host an Active Directory Domain Services (AD DS) domain controller and a drive named F: on a new virtual disk.
You need to configure storage for the virtual machine. The solution must meet the following requirements:
- Maximize resiliency for AD DS.
- Prevent accidental data loss.
How should you configure the storage? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Box 1: F
Create a separate virtual data disk for storing the database, logs, and sysvol folder for Active Directory. Do not store these items on the same disk as the operating system.
Box 2: None
By default, data disks that are attached to a VM use write-through caching. However, this form of caching can conflict with the requirements of AD DS. For this reason, set the Host Cache Preference setting on the data disk to None.
Reference:
https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/identity/adds-extend-domain
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with Azure AD.
You deploy an app that adds custom attributes to the domain.
From Azure Cloud Shell, you discover that you cannot query the custom attributes of users.
You need to ensure that the custom attributes are available in Azure AD.
Which task should you perform from Microsoft Azure Active Directory Connect first?
You deploy an app that adds custom attributes to the domain.
From Azure Cloud Shell, you discover that you cannot query the custom attributes of users.
You need to ensure that the custom attributes are available in Azure AD.
Which task should you perform from Microsoft Azure Active Directory Connect first?
Correct Answer: A
Vote an answer
Hotspot Question
You have a server named Server1 that runs Windows Server, has the File Server Resource Manager role service installed, and hosts a file share named Share02.
You need to configure Server1 to meet the following requirements:
- Notify administrators when a user uses more than 50 GB of space on
Share02.
- Send administrators a weekly email that lists duplicate files on
Server1.
The solution must minimize administrative effort.
What should you create for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a server named Server1 that runs Windows Server, has the File Server Resource Manager role service installed, and hosts a file share named Share02.
You need to configure Server1 to meet the following requirements:
- Notify administrators when a user uses more than 50 GB of space on
Share02.
- Send administrators a weekly email that lists duplicate files on
Server1.
The solution must minimize administrative effort.
What should you create for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Box 1: A soft quota for Share2
A soft quota does not enforce the quota limit, but it generates all configured notifications Box 2: A report task Set maximum values for storage reports On the Storage Reports tab when you configure File Server Resource Manager options, you can now specify the maximum number of files per report. When you configure default parameters for a report, you can also configure the following maximum values:
* For the *Duplicate Files report*, you can specify the maximum number of files in a duplicate group per report, and the maximum number of groups of duplicate files per report.
Reference:
https://learn.microsoft.com/en-us/iis/web-hosting/configuring-servers-in-the-windows-web-platform/enabling-directory-quotas
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn383587(v=ws.11)
Hotspot Question
Your network contains two Active Directory Domain Services (AD DS) forests named contoso.com and adatum.com. A two-way external trust exists between contoso.com and adatum.com. The forests contain the servers shown in the following table.

You need to ensure that users from contoso.com can access only shared resources hosted on SRV1. The solution must meet the following requirements:
- Ensure that users from adatum.com can access the resources hosted in
contoso.com.
- Prevent the contoso.com users from accessing any other resources in
adatum.com.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Your network contains two Active Directory Domain Services (AD DS) forests named contoso.com and adatum.com. A two-way external trust exists between contoso.com and adatum.com. The forests contain the servers shown in the following table.

You need to ensure that users from contoso.com can access only shared resources hosted on SRV1. The solution must meet the following requirements:
- Ensure that users from adatum.com can access the resources hosted in
contoso.com.
- Prevent the contoso.com users from accessing any other resources in
adatum.com.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Box 1: DC1
Modify the trust on:
Prevent the contoso.com users from accessing any other resources in adatum.com.
To prevent users in domain contoso.com from accessing resources in domain adatum.com you must break the existing two-way external trust by removing the outgoing trust from domain contoso.com using the Active Directory Domains and Trusts snap-in on a domain controller that hosts all FSMO roles in domain contoso.com, this is DC1. This will cut the connection from contoso.com's perspective, while the two-way trust still allows users in fabrik adatum.com to access resources in contoso.com.
Box 2: File shares on SRV1
Modify the permissions for the:
Prevent the contoso.com users from accessing any other resources in adatum.com.
Configure both share and NTFS permissions on the specific file server resource in domain adatum.com to grant access to users from domain contoso.com while denying access to all others. This can be achieved by creating a group in domain contoso.com that contains the users, and then adding that group to a local group on the domain adatum.com server, which is then granted permissions to the file share.
Reference:
https://learn.microsoft.com/en-us/entra/identity/domain-services/concepts-forest-trust
https://learn.microsoft.com/sv-se/azure/storage/files/storage-files-identity-multiple-forests
Hotspot Question
You have an Azure subscription and a computer named Computer1 that runs Windows 11.
From the Azure portal, you deploy a virtual machine named VM1 that runs Windows Server. You configure VM1 to use the default settings.
You need to ensure that you can connect to VM1 by using PowerShell remoting.
Which cmdlet should you run, and what should you use to run the cmdlet? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have an Azure subscription and a computer named Computer1 that runs Windows 11.
From the Azure portal, you deploy a virtual machine named VM1 that runs Windows Server. You configure VM1 to use the default settings.
You need to ensure that you can connect to VM1 by using PowerShell remoting.
Which cmdlet should you run, and what should you use to run the cmdlet? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

You have an Azure virtual machine named VM1 that contains the drives shown in the following table.

On VM1, you plan to install an app named App1. The data for App1 must be stored on a persistent data disk assigned to drive D.
You need assign the data disk to drive D.
What should you do on VM1 first?

On VM1, you plan to install an app named App1. The data for App1 must be stored on a persistent data disk assigned to drive D.
You need assign the data disk to drive D.
What should you do on VM1 first?
Correct Answer: B
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the servers shown in the following table.

You need to create a Distributed File System (DFS) namespace that will contain the following:
- A domain-based namespace named \\contoso.com\Public
- A folder named Finance
Which servers can you configure as folder targets for the Finance folder?

You need to create a Distributed File System (DFS) namespace that will contain the following:
- A domain-based namespace named \\contoso.com\Public
- A folder named Finance
Which servers can you configure as folder targets for the Finance folder?
Correct Answer: E
Vote an answer
Drag and Drop Question
You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server. VM1 contains a 128-GB operating system disk.
You need to increase the size of volume C on VM1 to 250 GB.
Which four actions should you perform in sequence.
To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server. VM1 contains a 128-GB operating system disk.
You need to increase the size of volume C on VM1 to 250 GB.
Which four actions should you perform in sequence.
To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Correct Answer:

Explanation:
https://learn.microsoft.com/en-us/azure/virtual-machines/windows/expand-os-disk
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.
You open a new branch office that contains only client computers.
You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.
Solution: You create an organizational unit (OU) that contains the client computers in the new branch office. You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to the new OU.
Does this meet the goal?
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.
You open a new branch office that contains only client computers.
You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.
Solution: You create an organizational unit (OU) that contains the client computers in the new branch office. You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to the new OU.
Does this meet the goal?
Correct Answer: A
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
SIMULATION
You need to monitor the security configuration of DC1 by using Microsoft Defender for Cloud.
The required source files are located in a folder named \\dc1.contoso.com\install.
To complete this task, sign in the required computer or computers.
You need to monitor the security configuration of DC1 by using Microsoft Defender for Cloud.
The required source files are located in a folder named \\dc1.contoso.com\install.
To complete this task, sign in the required computer or computers.
Correct Answer:
You can connect your non-Azure computers in any of the following ways:
* Onboarding with Azure Arc:
- By using Azure Arc-enabled servers (recommended)
-->By using the Azure portal
* Onboarding directly with Microsoft Defender for Endpoint
Connect on-premises machines by using the Azure portal
After you connect Defender for Cloud to your Azure subscription, you can start connecting your on-premises machines from the Getting started page in Defender for Cloud.
Step 1: Sign in to the Azure portal.
Step 2: Search for and select Microsoft Defender for Cloud.
Step 3: On the Defender for Cloud menu, select Getting started.
Step 4: Select the Get started tab.
Step 5: Find Add non-Azure servers and select Configure.

A list of your Log Analytics workspaces appears.
Step 6: (Optional) If you don't already have a Log Analytics workspace in which to store the data, select Create new workspace, and follow the on-screen guidance.
Step 7: From the list of workspaces, select Upgrade for the relevant workspace to turn on Defender for Cloud paid plans for 30 free days.
Step 8: From the list of workspaces, select Add Servers for the relevant workspace.
On the Agents management page, choose one of the following procedures, depending on the type of machines you're onboarding (Either Windows or Linux) Onboard your Windows server When you add a Windows server, you need to get the information on the Agents management page and download the appropriate agent file (32 bit or 64 bit).
To onboard a Windows server:
Step 1: Select Windows servers.

Step 2: Select the Download Windows Agent link that's applicable to your computer processor type to download the setup file.
Step 3: From the Agents management page, copy the Workspace ID and Primary Key values into Notepad.
Step 4: Copy the downloaded setup file to the target computer and run it.
Step 5: Follow the installation wizard (select Next > I Agree > Next > Next).
Step 6: On the Azure Log Analytics page, paste the Workspace ID and Primary Key values that you copied into Notepad.
Step 7: If the computer should report to a Log Analytics workspace in the Azure Government cloud, select Azure US Government from the Azure Cloud dropdown list.
Step 8: If the computer needs to communicate through a proxy server to the Log Analytics service, select Advanced. Then provide the URL and port number of the proxy server.
Step 9: When you finish entering all of the configuration settings, select Next.
Step 10: On the Ready to Install page, review the settings to be applied and select Install.
Step 11: On the Configuration completed successfully page, select Finish.
When the process is complete, Microsoft Monitoring agent appears in Control Panel. You can review your configuration there and verify that the agent is connected.
Reference:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-machines
* Onboarding with Azure Arc:
- By using Azure Arc-enabled servers (recommended)
-->By using the Azure portal
* Onboarding directly with Microsoft Defender for Endpoint
Connect on-premises machines by using the Azure portal
After you connect Defender for Cloud to your Azure subscription, you can start connecting your on-premises machines from the Getting started page in Defender for Cloud.
Step 1: Sign in to the Azure portal.
Step 2: Search for and select Microsoft Defender for Cloud.
Step 3: On the Defender for Cloud menu, select Getting started.
Step 4: Select the Get started tab.
Step 5: Find Add non-Azure servers and select Configure.

A list of your Log Analytics workspaces appears.
Step 6: (Optional) If you don't already have a Log Analytics workspace in which to store the data, select Create new workspace, and follow the on-screen guidance.
Step 7: From the list of workspaces, select Upgrade for the relevant workspace to turn on Defender for Cloud paid plans for 30 free days.
Step 8: From the list of workspaces, select Add Servers for the relevant workspace.
On the Agents management page, choose one of the following procedures, depending on the type of machines you're onboarding (Either Windows or Linux) Onboard your Windows server When you add a Windows server, you need to get the information on the Agents management page and download the appropriate agent file (32 bit or 64 bit).
To onboard a Windows server:
Step 1: Select Windows servers.

Step 2: Select the Download Windows Agent link that's applicable to your computer processor type to download the setup file.
Step 3: From the Agents management page, copy the Workspace ID and Primary Key values into Notepad.
Step 4: Copy the downloaded setup file to the target computer and run it.
Step 5: Follow the installation wizard (select Next > I Agree > Next > Next).
Step 6: On the Azure Log Analytics page, paste the Workspace ID and Primary Key values that you copied into Notepad.
Step 7: If the computer should report to a Log Analytics workspace in the Azure Government cloud, select Azure US Government from the Azure Cloud dropdown list.
Step 8: If the computer needs to communicate through a proxy server to the Log Analytics service, select Advanced. Then provide the URL and port number of the proxy server.
Step 9: When you finish entering all of the configuration settings, select Next.
Step 10: On the Ready to Install page, review the settings to be applied and select Install.
Step 11: On the Configuration completed successfully page, select Finish.
When the process is complete, Microsoft Monitoring agent appears in Control Panel. You can review your configuration there and verify that the agent is connected.
Reference:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-machines