Updated PDF (New 2024) Actual Microsoft AZ-800 Exam Questions
Verified AZ-800 Exam Dumps PDF [2024] Access using FreeCram
Microsoft AZ-800 exam is designed to test the skills and knowledge of IT professionals who are responsible for administering Windows Server hybrid core infrastructure. It is an advanced level certification exam that validates the candidate's ability to manage and maintain a hybrid environment that combines on-premises and cloud-based solutions. AZ-800 exam is targeted towards IT professionals who have experience with Microsoft Azure and Windows Server technologies and are looking to enhance their skills in managing hybrid infrastructure.
Microsoft AZ-800 certification exam is designed to test the knowledge and skills of IT professionals who work with Windows Server Hybrid Core Infrastructure. Administering Windows Server Hybrid Core Infrastructure certification is ideal for those who want to demonstrate their expertise in managing and administering hybrid environments that involve both on-premises and cloud-based infrastructure.
NEW QUESTION # 46
You have a server named Server1 that runs Windows Server and contains three volumes named C, D, and E. Files are stored on Server1 as shown in the following table.
For volume D, Data Deduplication is enabled and set to General purpose file server.
You perform the following actions:
* Move File1 to volume D.
* Copy File2 to volume D and name the copy File4.
* Move File3 to volume E
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 47
You have a Windows Server container host named Server1 and an Azure subscription.
You deploy an Azure container registry named Registry1 to the subscription.
On Server1, you create a container image named image1.
You need to store imager in Registry1.
Which command should you run on Server1 ? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/container-registry/container-registry-get-started-docker-cli?tabs=azure-cli#push-the-image-to-your-registry
NEW QUESTION # 48
You are planning the implementation Azure Arc to support the planned changes. You need to configure the environment to support configuration management policies. What should you do?
- A. Hybrid Azure AD join all the servers.
- B. Create a hybrid runbook worker m Azure Automation.
- C. Deploy the Azure Connected Machine agent to all the servers.
- D. Deploy the Azure Monitor agent to all the servers.
Answer: C
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/azure-arc/servers/plan-at-scale-deployment
NEW QUESTION # 49
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com.
The forest root domain contains a server named server1.contoso.com.
A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains.
You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com.
What should you do first?
- A. Change the trust to a one-way external trust.
- B. Enable SID filtering for the trust.
- C. Add fabrikam\Group1 to the local Users group on server1.contoso.com.
- D. Enable Selective authentication for the trust.
Answer: D
Explanation:
Selective authentication restricts access over an external or forest trust to only those users in a trusted domain or forest who have been explicitly given authentication permissions to computer objects (resource computers) residing in the trusting domain or forest. This authentication setting must be manually enabled.
Note: When a two way Forest Trust is created between Forest A and Forest B, all domains in Forest A will trust all domains in Forest B and vice versa.
NEW QUESTION # 50
Your network contains an Active Directory domain named contoso.com. The domain contains group managed service accounts (gMSAs). You have a server named Server1 that runs Windows Server and is in a workgroup. Server! hosts Windows containers.
You need to ensure that the Windows containers can authenticate to contoso.com.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
1 - In contoso.com, generate Key Distribution...
2 - In contoso.com, create a gMSA...
3 - From a domain-joined computer,...
NEW QUESTION # 51
Your network contains two Active Directory Domain Services (AD DS) forests named contoso.com and fabrikam.com. A two-way forest trust exists between the forests. Each forest contains a single domain. The domains contain the servers shown in the following table.
You need to configure resources based constrained delegation so that the users In contoso.com can use Windows Admin Center on Server) to connect to Server? How should you complete the command? To answer, select the appropriate options in the answer are a. NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/security/kerberos/kerberos-constrained-delegation-overview
https://docs.microsoft.com/en-us/powershell/module/activedirectory/set-adcomputer?view=windowsserver2022-ps
NEW QUESTION # 52
You have an on-premises server named Server1 that runs Windows Server and has internet connectivity.
You have an Azure subscription.
You need to monitor Server1 by using Azure Monitor.
Which resources should you create in the subscription, and what should you install on Server1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/azure-monitor/agents/gateway
https://docs.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure-monitor
NEW QUESTION # 53
You need to meet the technical requirements for Server4.
Which cmdlets should you run on Server1 and Server4? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://4sysops.com/wiki/enable-powershell-remoting/
NEW QUESTION # 54
You have an Azure subscription that contains the following resources:
- An Azure Log Analytics workspace
- An Azure Automation account
- Azure Arc
You have an on-premises server named Served that is onboaraed to Azure Arc.
You need to manage Microsoft updates on Server1 by using Azure Arc.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point
- A. On Server1, install the Azure Monitor agent
- B. From the Automation account, enable Update Management for Server1.
- C. Add Microsoft Sentinel to the Log Analytics workspace
- D. From the Virtual machines data source of the Log Analytics workspace, connect Server1.
Answer: A,B
Explanation:
https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/manage/hybrid/server/best- practices/arc-update-management
NEW QUESTION # 55
You have a server named Server1 that has Windows Admin Center installed. The certificate used by Windows Admin Center was obtained from a certification authority (CA).
The certificate expires.
You need to replace the certificate.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
1 - From Internet Information Services (IIS) Manager, bind a certificate.
2 - Copy the certificate thumbprint.
3 - Rerun Windows Admin Center Setup and select Change.
Reference:
https://www.starwindsoftware.com/blog/change-the-windows-admin-center-certificate
NEW QUESTION # 56
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant Group writeback is enabled in Azure AD Connect.
The AD DS domain contains a server named Server1 Server 1 contains a shared folder named share1.
You have an Azure Storage account named storage2 that uses Azure AD-based access control. The storage2 account contains a share named shared You need to create a security group that meets the following requirements:
* Can contain users from the AD DS domain
* Can be used to authorize user access to share 1 and share2
What should you do?
- A. in the Azure AD tenant create a security group that has assigned membership
- B. in the Azure AD Tenant create a security group that has dynamic membership.
- C. in the AD DS domain, create a universal security group
- D. in the Azure AD tenant create a Microsoft 365 group
Answer: A
NEW QUESTION # 57
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. Group writeback is enabled in Azure AD Connect.
The AD DS domain contains a server named Server1. Server1 contains a shared folder named share1.
You have an Azure Storage account named storage2 that uses Azure AD-based access control.
The storage2 account contains a share named share2.
You need to create a security group that meets the following requirements:
- Can contain users from the AD DS domain
- Can be used to authorize user access to share1 and share2
What should you do?
- A. in the Azure AD tenant create a security group that has assigned membership
- B. in the Azure AD Tenant create a security group that has dynamic membership.
- C. in the AD DS domain, create a universal security group
- D. in the Azure AD tenant create a Microsoft 365 group
Answer: A
Explanation:
Group Writeback is enabled so it can access Azure File Share and on-prem share with Azure AD group.
NEW QUESTION # 58
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. You plan deploy 100 new Azure virtual machines that will run Windows Server. You need to ensure that each new virtual machine is joined to the AD DS domain. What should you use?
- A. Azure AD Connect
- B. a Group Policy Object (GPO)
- C. an Azure management group
- D. an Azure Resource Manager (ARM) template
Answer: D
Explanation:
Reference:
https://www.ludovicmedard.com/create-an-arm-template-of-a-virtual-machine-automatically-joined-to-a-domain/
NEW QUESTION # 59
You create a new Azure subscription.
You plan to deploy Azure Active Directory Domain Services (Azure AD DS) and Azure virtual machines.
You need to ensure that the virtual machines can join Azure AD DS.
Which three actions should perform in sequence? To answer, move the appropriate actions from the list of action of the answer area and arrange them in the correct order.
Answer:
Explanation:
1 - Create an Azure virtual network.
2 - Create an Azure AD dS instance.
3 - Modify the settings of the Azure virtual network.
NEW QUESTION # 60
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains a child domain named east.contoso.com and the servers shown in the following table.
You need to create a folder for the Central Store to manage Group Policy template files for the entire forest.
What should you name the folder, and on which server should you create the folder? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 61
You need to configure the Group Policy settings to ensure that the Azure Virtual Desktop session hosts meet the security requirements. What should you configure?
- A. the Enforced property for the link of GP01
- B. loopback processing in 0PO4
- C. the Enforced property for the link of GP04
- D. security filtering for the link of GP04
- E. loopback processing in GPOl
- F. security filtering for the link of GPOl
Answer: A
NEW QUESTION # 62
You have an Azure Active Directory Domain Services (Azure AD DS) domain named contoso.com.
You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The solution must use the principle of least privilege.
To which group should you add the administrator?
- A. Domain Admins
- B. Schema Admins
- C. Group Policy Creator Owners
- D. AAD DC Administrators
- E. Enterprise Admins
Answer: E
Explanation:
Reference:
https://social.technet.microsoft.com/wiki/contents/articles/20579.delegation-of-group-policy-full-administration.aspx
NEW QUESTION # 63
You have on-premises file servers that run Windows Server as shown in the following table.
You have the Azure file shares shown in the following table.
You add a Storage Sync Service named Sync1 and an Azure File Sync sync group named Group1. Group1 uses share1 as a cloud endpoint.
You register Server1 and Server2 with Sync1. You add D:\Folder1 from Server1 as a server endpoint in Group1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/storage/file-sync/file-sync-planning
NEW QUESTION # 64
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains 10 servers that run Windows Server. The servers have static IP addresses.
You plan to use DHCP to assign IP addresses to the servers. You need to ensure that each server always receives the same IP address.
Which type of identifier should you use to create a DHCP reservation for each server?
- A. universally unique identifier (UUID)
- B. MAC address
- C. fully qualified domain name (FQDN)
- D. NetBIOS name
Answer: B
NEW QUESTION # 65
Your network contains an Azure AD Domain Services domain named contoso.com.
You need to configure a password policy for the local user accounts on the Azure virtual machines joined to contoso.com.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
NEW QUESTION # 66
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.
You open a new branch office that contains only client computers.
You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.
Solution: You create an organizational unit (OU) that contains the client computers in the new branch office. You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to the new OU.
Does this meet the goal?
- A. No
- B. Yes
Answer: A
Explanation:
https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/enabling-clients-to-locate- the-next-closest-domain-controller
NEW QUESTION # 67
You have a file server named Server1 that runs Windows Server and contains the volumes shown in the following table.
On which volumes can you use BitLocker Drive Encryption (BitLocker) and disk quotas? To answer select the appropriate options in the answer are a. NOTE Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 68
You deploy a single-domain Active Directory Domain Services (AD DS) forest named contoso.com.
You deploy a server to the domain and configure the server to run a service.
You need to ensure that the service can use a group managed service account (gMSA) to authenticate.
Which three PowerShell cmdlets should you run in sequence? To answer, move the appropriate cmdlets from the list of cmdlets to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation
NEW QUESTION # 69
Your network contains two Active Directory Domain Services (AD DS) forests named contoso.com and fabrikam.com. Contoso.com contains three child domains named amer.contoso.com, apac.contoso.com, and emea.contoso.com. Fabrikam.com contains a child domain named apac.fabrikam.com. A bidirectional forest trust exists between contoso.com and fabrikam.com.
You need to provide users in the contoso.com forest with access to the resources in the fabrikam.com forest.
The solution must meet the following requirements:
* Users in contoso.com must only be added directly to groups in the contoso.com forest.
* Permissions to access the resources in fabrikam.com must only be granted directly to groups in the fabrikam.com forest.
* The number of groups must be minimized.
Which type of groups should you use to organize the users and to assign permissions? To answer, drag the appropriate group types to the correct requirements. Each group type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
NEW QUESTION # 70
You have a server named Server 1 that runs Windows Server and has the Hyper-V server role installed.
Server1 hosts a virtual machine named VM1. Server1 has an NV Me storage device that is assigned to VM1 by using Discrete Device Assignment.
You need to make the device available to the host.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation
NEW QUESTION # 71
......
Microsoft AZ-800 exam, also known as Administering Windows Server Hybrid Core Infrastructure, is a certification exam that validates the skills and knowledge required to design and implement hybrid server environments. AZ-800 exam is designed for IT professionals who work with Windows Server and Azure services and are responsible for managing and monitoring hybrid infrastructures. Administering Windows Server Hybrid Core Infrastructure certification exam demonstrates that an individual has the expertise to manage and operate on-premises and cloud-based Windows Server environments seamlessly.
Try Best AZ-800 Exam Questions from Training Expert FreeCram: https://www.freecram.com/Microsoft-certification/AZ-800-exam-dumps.html
Practice Examples and Dumps & Tips for 2024 Latest AZ-800 Valid Tests Dumps: https://drive.google.com/open?id=17Z3vX-cxrn2pHAz_USg1gX3-Yp-TaQBj