Microsoft Configuring Windows Server Hybrid Advanced Services - AZ-801 FREE EXAM DUMPS QUESTIONS & ANSWERS
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1. You deploy a read-only domain controller (RODQ named RODC1.
You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege. What should you use?
You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege. What should you use?
Correct Answer: D
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
You need to meet the technical requirements for User1.
To which group in contoso.com should you add User1?
To which group in contoso.com should you add User1?
Correct Answer: D
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
You have an on-premises server named Server1 that runs Windows Server. Server1 has the Web Server (IIS) server role installed and hosts an ASP.NET web app named App1.
You have an Azure subscription.
You plan to migrate App1 to a container in Azure.
You need to export App1 to a ZIP file.
What should you install on Server1?
You have an Azure subscription.
You plan to migrate App1 to a container in Azure.
You need to export App1 to a ZIP file.
What should you install on Server1?
Correct Answer: B
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
You have an on-premises server named Server1 that runs Windows Server. Server1 contains multiple file shares and has an IP address of 192.168.10.12.
You have an Azure subscription.
You need to migrate the Server1 file shares to an Azure virtual machine by using Storage Migration Service.
The solution must ensure that on-premises users can access the migrated file shares by using the
192.168.10.12 IP address.
What should you include in the solution?
You have an Azure subscription.
You need to migrate the Server1 file shares to an Azure virtual machine by using Storage Migration Service.
The solution must ensure that on-premises users can access the migrated file shares by using the
192.168.10.12 IP address.
What should you include in the solution?
Correct Answer: B
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
You have an Azure subscription.
Your on-premises network connects to Azure by using an Azure VPN gateway named VPN1.
You need to monitor the Azure gateway health probe for VPN1.
Which TCP port should you use?
Your on-premises network connects to Azure by using an Azure VPN gateway named VPN1.
You need to monitor the Azure gateway health probe for VPN1.
Which TCP port should you use?
Correct Answer: E
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Your network contains an Active Directory Domain Services (AD DS) domain. You plan to protect high- privilege domain credentials by specifying the following:
* The lifetime of the Kerberos Ticket Granting Ticket (TGT)
* The conditions required for devices to request a TGT
What should you use, and what should you create? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
* The lifetime of the Kerberos Ticket Granting Ticket (TGT)
* The conditions required for devices to request a TGT
What should you use, and what should you create? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Correct Answer:

Explanation:
Detailed Explanation
Authentication policies, created and managed from the Active Directory Administrative Center ' s Authentication node, let an administrator set a maximum Kerberos ticket-granting-ticket lifetime for user, computer, or service accounts and define access-control conditions (device group membership or device claims) that a client must satisfy before a TGT is issued to it. This is distinct from an authentication policy silo, which groups accounts together to apply a shared policy rather than defining the TGT lifetime and device conditions itself. Because the requirement is specifically to set a TGT lifetime and device request conditions for high-privilege accounts, an authentication policy authored in ADAC is the object that implements both settings.
Official Reference
Authentication Policies and Authentication Policy Silos - https://learn.microsoft.com/en-us/windows-server
/security/credentials-protection-and-management/authentication-policies-and-authentication-policy-silos

Your network contains two Active Directory Domain Services (AD DS) forests named contoso.com and fabtikam.com. Contoso.com includes the groups shown in the following table.
You need to migrate the groups to fabrikam.com by using ADMT.
Which groups can be migrated and which groups can have the sIDHistory attribute populated after the migration?

Exhibit

You need to migrate the groups to fabrikam.com by using ADMT.
Which groups can be migrated and which groups can have the sIDHistory attribute populated after the migration?

Exhibit

Correct Answer:

Explanation:
CORRECTED ANSWER: Can be migrated: Group1, Group2, Group3, and Group4 (all four groups). Can have sIDHistory populated: Group1, Group2, and Group3 only.
Detailed Explanation
ADMT ' s Group Account Migration Wizard migrates group objects as part of its normal object migration regardless of whether a group is security-enabled or a distribution group, so all four groups shown, including Group4, can be migrated into fabrikam.com as directory objects. Populating the sIDHistory attribute, however, is performed through the DsAddSidHistory mechanism ADMT relies on, which only accepts security principals as source and destination objects, specifically users and security-enabled local, global, domain local, or universal groups; distribution groups are not security principals and are rejected. Because Group1, Group2, and Group3 are all security groups, they alone are eligible to have sIDHistory populated after migration, while Group4, a distribution group, is migrated as an object but cannot carry sIDHistory.
Official Reference
Using DsAddSidHistory - https://learn.microsoft.com/en-us/windows/win32/ad/using-dsaddsidhistory
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an on-premises server named Server1 that runs Windows Server.
You have a Microsoft Sentinel instance.
You add the Windows Firewall data connector in Microsoft Sentinel.
You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1.
Solution; You enable event subscription on Server1.
Does this meet the goal?
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an on-premises server named Server1 that runs Windows Server.
You have a Microsoft Sentinel instance.
You add the Windows Firewall data connector in Microsoft Sentinel.
You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1.
Solution; You enable event subscription on Server1.
Does this meet the goal?
Correct Answer: A
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
You have 20 on-premises servers, including a server named Server1, that run Windows Server. Server1 has Windows Admin Center deployed and is connected to the internet.
You have an Azure subscription.
You need to integrate Windows Admin Center with Azure so that you can use Azure services to manage and monitor the on-premises servers.
What should you do first?
You have an Azure subscription.
You need to integrate Windows Admin Center with Azure so that you can use Azure services to manage and monitor the on-premises servers.
What should you do first?
Correct Answer: A
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).