Big Halloween Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Microsoft AZ-801 Dumps Questions Answers

Page: 1 / 12
Total 255 questions

Configuring Windows Server Hybrid Advanced Services Questions and Answers

Question 1

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1 that has following attributes:

• whenCreated: 8/16/2023 8:04:55 AM

• distinguishedName: CN=Userl,DC=contoso,DC=com

• objectGUID: ef91eeG0-d371-4ee4-9c35-7da64c432a67

• objectSID: S-l-5-21-2106002304-3506747707-1284373444-1610

You need to use the Active Directory Migration Tool (ADMT) to migrate User1 to an AD DS forest named fabrikam.com. Which attributes will change after you migrate User1 to fabrikam.com?

Options:

A.

distinguishedName only

B.

distinguishedNane and objectSID only

C.

distinguishedHame, objectSID, and whenCreated only

D.

distinguishedName. objectGUID, and objectSID only

E.

distinguishedName, objectGUID, objectSID, and whenCreated

Buy Now
Question 2

You have a Hyper-V host named Server1 that runs Windows Server 2019. Server1 hosts a virtual machine named VM1 that has the following configurations:

• Static IP address: 192.168.10.15

• Configuration version: 8.0

• Virtual network: VNet1

• Generation: 1

You deploy a Hyper-V host named Server2 that runs Windows Server 2025. You plan to export VM1 from Served and import VM1 to Server2 by using Hyper-V Manager. Which VM1 configurations will be preserved when VM1 is imported to Server2?

Options:

A.

the virtual network and IP address only

B.

the virtual network and generation only

C.

the IP address and configuration version only

D.

the IP address, configuration version, and generation only

E.

the virtual network, IP address, configuration version, and generation

Question 3

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the organizational units (OUs) shown in the following table.

In the domain, you create the Group Policy Objects (GPOs) shown in the following table.

You need to implement IPsec authentication to ensure that only authenticated computer accounts can connect to the members in the domain. The solution must minimize administrative effort.

Which GPOs should you apply to the Domain Controllers OU and the Domain Servers OU? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 4

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains two servers named Server1 and Server2 that run Windows Server.

On Server1, you create an event subscription named Subscription! that retrieves events from Server2. The Query Filter settings (or Subscription! are configured as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Question 5

You have an Azure subscription that has Microsoft Defender for Cloud enabled.

You have 50 Azure virtual machines that run Windows Server.

You need to ensure that any security exploits detected on the virtual machines are forwarded to Defender for Cloud.

Which extension should you enable on the virtual machines?

Options:

A.

Vulnerability assessment for machines

B.

Microsoft Dependency agent

C.

Log Analytics agent for Azure VMs

D.

Guest Configuration agent

Question 6

You have two on-premises Hyper-V hosts named Server1and Served Server 1 hosts a virtual machine named VM1 that uses a static IP address. VM1 replicates to Server2 by using Hyper-V Replica.

You plan to perform a failover test for VM1.

You need to configure the Failover TCP/IP settings and the virtual switch for the failover.

Where should you configure the Failover TCP/IP settings, and where should you configure the virtual switch? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 7

Your network contains an Active Directory Domain Services (AD DS) domain. You plan to protect high-privilege domain credentials by specifying the following:

• The lifetime of the Kerberos Ticket Granting Ticket (TGT)

• The conditions required for devices to request a TGT

What should you use, and what should you create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 8

You have an on-premises server named Server1 that runs Windows Server. You need to perform an on-demand backup of the files on Server 1 by using Azure Backup.

Which five actions should you perform in sequence? To answer, move the appropriate actions actions from the list of actions to the answer are and arrange them in the correct order.

Options:

Question 9

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a failover cluster named Cluster1 that hosts an application named App1.

The General tab in App1 Properties is shown in the General exhibit. (Click the General tab.)

The Failover tab in App1 Properties is shown in the Failover exhibit. (Click the Failover tab.)

Server1 shuts down unexpectedly.

You need to ensure that when you start Server1, App1 continues to run on Server2.

Solution: You increase Maximum failures in the specified period for the App1 cluster role.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 10

Your network contains an Active Directory Domain Services (AD DS) domain.

You need to implement a solution that meets the following requirements:

    Ensures that the members of the Domain Admins group are allowed to sign in only to domain controllers

    Ensures that the lifetime of Kerberos Ticket Granting Ticket (TGT) for the members of the Domain Admins group is limited to one hour

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Question 11

You have two Azure virtual networks named Vnet1 and Vnet2.

You have a Windows 10 device named Client1 that connects to Vnet1 by using a Point-to-Site (P2S) IKEv2 VPN.

You implement virtual network peering between Vnet1 and Vnet2. Vnet1 allows gateway transit Vnet2 can use the remote gateway.

You discover that Client1 cannot communicate with Vnet2.

You need to ensure that Client1 can communicate with Vnet2.

Solution: You resize the gateway of Vnet1 to a larger SKU.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 12

You have an Azure subscription that contains an Azure Recovery Services vault.

You have an on-premises physical server that runs Windows Server.

You need to back up the server daily to Azure.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Question 13

You have two physical servers named AppSrv1 and AppSrv2 and an unconfigured server named Server1. All the servers run Windows Server. Only Server1 can access the internet.

You plan to use Azure Site Recovery to replicate AppSrv1 and AppSrv2 to Azure.

You need to deploy the required components to AppSrv1, AppSrv2, and Server1.

Which components should you deploy? To answer, drag the appropriate components to the correct servers. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Question 14

You have an Azure virtual machine named VM1 that runs Windows Server.

The operating system on VM1 fails to fully initialize its network stack, and you cannot establish a network connection.

You need to establish an interactive shell session.

What should you use?

Options:

A.

Azure Bastion

B.

Serial console

C.

just-in-time (JIT) VM access

Question 15

You have a Site-to-Site VPN between an on-premises network and an Azure VPN gateway. BGP is disabled for the Site-to-Site VPN.

You have an Azure virtual network named Vnet1 that contains a subnet named Subnet1. Subnet1 contains a virtual machine named Server1.

You can connect to Server1 from the on-premises network.

You extend the address space of Vnet1. You add a subnet named Subnet2 to Vnet1. Subnet2 uses the extended address space. You deploy an Azure virtual machine named Server2 to Subnet2.

You cannot connect to Server2 from the on-premises network. Server1 can connect to Server2.

You need to ensure that you can connect to Subnet2 from the on-premises network.

What should you do?

Options:

A.

Add an additional Site-to-Site VPN between the on-premises network and Vnetl.

B.

Add a private endpoint to Subnet2.

C.

To Subnet2. add a route table that contains a user-defined route.

D.

Update the routing information on the on-premises routers.

Question 16

You have an Azure virtual machine named VM1.

You install an application on VM1, and then restart the virtual machine.

After the restart, you get the following error message: “Boot failure. Reboot and Select proper Boot Device or Insert Boot Media in selected Boot Device.”

You need to mount the operating system disk offline from VM1 to a temporary virtual machine to troubleshoot the issue.

Which command should you run in Azure CLI?

Options:

A.

az vm repair create

B.

az vm boot-diagnostics enable

C.

az vm capture

D.

az vm disk attach

Question 17

You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant.

The AD DS domain contains a domain controller named DC1. DC1 does NOT have internet access.

You need to configure password security for on-premises users. The solution must meet the following requirements:

    Prevent the users from using known weak passwords.

    Prevent the users from using the company name in passwords.

What should you do? To answer, drag the appropriate configurations to the correct targets. Each configuration may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Question 18

You have three Hyper-V hosts named Server 1, Server2, and Server 3 that run Windows Server Server1 hosts a virtual machine named VM1.

You enable Hyper-V Replica to replicate VM1 to Server2 and set the replication frequency to 30 seconds.

You need to extend the replication and create a second replica of VM1.

On which Hyper-V hosts can you configure the replication, and what is the minimum replication frequency you can use? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 19

You have two file servers named Server1 and Server2 that run Windows Server. Server1 contains a shared folder named Data. Data contains 10 TB of data.

You plan to decommission Server1.

You need to migrate the files from Data to a new shared folder on Server2. The solution must meet the following requirements:

    Ensure that share, file, and folder permissions are copied.

    After the initial copy occurs, ensure that changes in \\Server1\Data can be synced to the destination without initiating a full copy.

    Minimize administrative effort.

What should you use?

Options:

A.

xcopy

B.

Storage Replica

C.

Storage Migration Service

D.

azcopy

Question 20

Your network contains an Active Directory Domain Services (AD DS) forest. The forest functional level is Windows Server 2012 R2. The forest contains the domains shown in the following table.

You create a user named Admin1.

You need to ensure that Admin1 can add a new domain controller that runs Windows Server 2022 to the east.contoso.com domain. The solution must follow the principle of least privilege.

To which groups should you add Admin1?

Options:

A.

EAST\Domain Admins only

B.

CONTOSO\Enterprise Admins only

C.

CONTOSO/Schema Admins and EAST\Domain Admins

D.

CONTOSO\Enterprise Admins and CONTOSO/Schema Admins

Question 21

You have a Windows Server Failover Cluster (WSFQ that contains five nodes.

You need to ensure that if a network link fails on one of the nodes, the workloads are distributed across the remaining nodes during a failover. The solution must ensure that the workloads are distributed across all the nodes as evenly as possible.

Which command should you run?

Options:

A.

(Get-Cluster). Name | % { (Get-Cluster J_).HodeWeight - 0 }

B.

(Get-Cluster). Name | % { (Get-Cluster _).NodeHeight - 1 >

C.

(Get-ClusterNode). Name | % { (Get-ClusterNode $_) .HodeWeight - 1 }

D.

(Get-ClusterHode). Name | % { (Get-ClusterNode J_).NodeWeight - 0 }

Question 22

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a server named Server1 that runs Windows Server.

You need to ensure that only specific applications can modify the data in protected folders on Server1.

Solution: From App & browser control, you configure Reputation-based protection.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 23

You have 500 on-premises servers that run Windows Server.

You have an Azure subscription that contains a Log Analytics workspace named Workspace1.

You plan to use VM insights in Azure Monitor to monitor the on-premises servers.

You need to onboard the servers to Azure Arc by using the template script. The solution must meet the following requirements:

• Follow the principle of least privilege.

• Minimize administrative effort.

What should you do first?

Options:

A.

Create a group managed service account (gMSA).

B.

Download the Log Analytics workspace ID.

C.

Generate a Log Analytics key.

D.

Create a Microsoft Entra service principal.

Question 24

You have a management group named MG1 that contains an Azure subscription named Sub1. Sub1 contains the resources shown in the following table.

You need to enable Microsoft Defender for Servers.

From the Azure portal, on which two resources can you enable Defender for Servers? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

Options:

A.

VM1

B.

Workspace1

C.

RG1

D.

VNet1

E.

Sub1

F.

MG1

Question 25

Your network contains a single-domain Active Directory Domain Services (AD DS) forest named contoso.com. The functional level of the forest is Windows Server 2012 R2. All domain controllers run Windows Server 2012 R2.

Sysvol replicates by using the File Replication Service (FRS).

You plan to replace the existing domain controllers with new domain controllers that will run Windows Server 2022.

You need to ensure that you can add the first domain controller that runs Windows Server 2022.

Solution; You raise the domain and forest functional levels.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 26

You have a Storage Spaces Direct cluster named Cluster1 that contains multiple nodes.

You have a firmware update for the hard disks attached to each node.

You create a configuration file named FileLxm1 for the update.

You need to automate the rollout of the firmware update to the nodes of Cluster1. The solution must minimize downtime of the workloads hosted in Cluster1.

How should you complete the PowerShell commands? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 27

You need to implement a security policy solution to authorize the applications. The solution must meet the security requirements.

Which service should you use to enforce the security policy, and what should you use to manage the policy settings? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 28

You are planning the deployment of Microsoft Sentinel.

Which type of Microsoft Sentinel data connector should you use to meet the security requirements?

Options:

A.

Threat Intelligence - TAXII

B.

Azure Active Directory

C.

Microsoft Defender for Cloud

D.

Microsoft Defender for Identity

Question 29

You are planning the data share migration to support the on-premises migration plan.

What should you use to perform the migration?

Options:

A.

Storage Migration Service

B.

Microsoft File Server Migration Toolkit

C.

File Server Resource Manager (FSRM)

D.

Windows Server Migration Tools

Question 30

You are remediating the firewall security risks to meet the security requirements.

What should you configure to reduce the risks?

Options:

A.

a Group Policy Object (GPO)

B.

adaptive network hardening in Microsoft Defender for Cloud

C.

a network security group (NSG) in Sub1

D.

an Azure Firewall policy

Question 31

You are planning the DHCP1 migration to support the DHCP migration plan.

Which two PowerShell cmdlets should you run on DHCP1, and which two PowerShell cmdlets should you run on DHCP2? To answer, drag the appropriate cmdlets to the correct servers. Each cmdlet may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Question 32

You are planning the website migration to support the Azure migration plan.

How should you configure WebApp1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 33

You are planning the migration of APP3 and APP4 to support the Azure migration plan.

What should you do on Cluster1 and in Azure before you perform the migration? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 34

You are planning the migration of Archive1 to support the on-premises migration plan.

What is the minimum number of IP addresses required for the node and cluster roles on Cluster3?

Options:

A.

2

B.

3

C.

4

D.

5

Question 35

You are planning the implementation of Cluster2 to support the on-premises migration plan.

You need to ensure that the disks on Cluster2 meet the security requirements.

In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Question 36

You are planning the europe.fabrikam.com migration to support the on-premises migration plan-Where should you install the Password Export Server (PES) service, where should you generate the encryption key? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 37

With which servers can Server1 and Server3 communicate? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 38

You need to meet the technical requirements for Cluster3.

What should you include in the solution?

Options:

A.

Enable integration services on all the virtual machines.

B.

Add a Windows Server server role.

C.

Configure a fault domain doe the cluster.

D.

Add a failover cluster role.

Question 39

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Question 40

You need to meet the technical requirements for Cluster2.

Which four actions should you perform in sequence before you can enable replication? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Question 41

You need to meet technical requirements for Share1.

What should you use?

Options:

A.

Storage Migration Service

B.

File Server Resource Manager (FSRM)

C.

Server Manager

D.

Storage Replica

Question 42

What is the effective minimum password length for User1 and Admin1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 43

You need to implement alerts for the domain controllers. The solution must meet the technical requirements.

What should you do on the domain controllers, and what should you create on Azure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 44

You need to meet the technical requirements for User1.

To which group in contoso.com should you add User1?

Options:

A.

Domain Admins

B.

Account Operators

C.

Schema Admins

D.

Backup Operators

Question 45

You need to configure BitLocker on Server4.

On which volumes can you turn on BitLocker, and on which volumes can you turn on auto-unlock? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 46

You are evaluating the technical requirements tor Cluster2.

What is the minimum number of Azure Site Recovery Providers that you should install?

Options:

A.

1

B.

4

C.

12

D.

16

Question 47

You need to back up Server 4 to meet the technical requirements.

What should you do first?

Options:

A.

Deploy Microsoft Azure Backup Server (MABS).

B.

Configure Windows Server Backup.

C.

Install the Microsoft Azure Recovery Services (MARS) agent.

D.

Configure Storage Replica.

Question 48

Which domain controller should be online to meet the technical requirements for DC4?

Options:

A.

DC1

B.

DC2

C.

DC3

Page: 1 / 12
Total 255 questions