Latest Verified & Correct Microsoft AZ-800 Questions & Answers Daily Updated [Q40-Q61]

Share

Latest Verified & Correct Microsoft AZ-800 Questions & Answers Daily Updated

100% Pass Guaranteed Download Windows Server Exam PDF Q&A

NEW QUESTION # 40
Your network contains an Active Directory Domain Services (AD DS) domain named conioso.com.
You need to identify which server is the PDC emulator for the domain.
Solution: from Active Directory Users and Computers, you right-click contoso.com in the console tree, and then select Operations Master
Does this meet the goal?

  • A. Yes
  • B. No

Answer: A


NEW QUESTION # 41
You plan to deploy an Azure virtual machine that will run Windows Server.
You need to ensure that an Azure Active Directory (Azure AD) user [email protected] can connect 10 the virtual machine by using the Azure Serial Console.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

Reference:
https://docs.microsoft.com/en-us/troubleshoot/azure/virtual-machines/serial-console-overview


NEW QUESTION # 42
Hotspot Question
You have an on-premises DNS server named Server1 that runs Windows Server. Server1 hosts a DNS zone named fabrikam.com.
You have an Azure subscription that contains the resources shown in the following table.

You need to design a solution that will automatically resolve the names of any PaaS resources for which you configure private endpoints in Vnet1.
How should you configure the name resolution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
https://learn.microsoft.com/en-us/azure/private-link/private-endpoint-dns#on-premises-workloads- using-a-dns-forwarder


NEW QUESTION # 43
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three domains. Each domain contains 10 domain controllers.
You plan to store a DNS zone in a custom Active Directory partition.
You need to create the Active Directory partition for the zone. The partition must replicate to only four of the domain controllers.
What should you use?

  • A. ntdsutil.exe
  • B. Active Directory Administrative Center
  • C. New-ADobject
  • D. Active Directory Sites and Services

Answer: A


NEW QUESTION # 44
You plan to deploy an Azure virtual machine that will run Windows Server.
You need to ensure that an Azure Active Directory (Azure AD) user [email protected] can connect 10 the virtual machine by using the Azure Serial Console.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/troubleshoot/azure/virtual-machines/serial-console-overview


NEW QUESTION # 45
Your network contains two Active Directory Domain Services (AD DS) forests named contoso.com and fabrikam.com. A two-way forest trust exists between the forests. Each forest contains a single domain. The domains contain the servers shown in the following table.

You need to configure resources based constrained delegation so that the users In contoso.com can use Windows Admin Center on Server) to connect to Server? How should you complete the command? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Text Description automatically generated

Reference:
https://docs.microsoft.com/en-us/windows-server/security/kerberos/kerberos-constrained-delegation-overview
https://docs.microsoft.com/en-us/powershell/module/activedirectory/set-adcomputer?view=windowsserver2022-


NEW QUESTION # 46
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains a child domain named east.contoso.com.
in the contoso.com domain, you create two users named Admin1 and Admin2.
You need to ensure that the users can perform the following tasks:
* Admin1 can create and manage Active Directory sites.
* Admin2 can deploy domain controller to the easl.conloso.com domain.
The solution must use the principle of least privilege.
To which group should you add each user? To answer, select the appropriate options in the answer area.
NOTE Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/windows-server/remote/remote-access/ras/multisite/configure/step-2-configure-the-multisite-infrastructure


NEW QUESTION # 47
Which three actions should you perform in sequence to meet the security requirements for Webapp1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

1 - Configure the IIS application pool to run as Network Service.
2 - Create a group managed service account (gMSA) in Active Directory.
3 - Create the Key Distribution Services (KDS) root key in AD DS.


NEW QUESTION # 48
You have an Active Directory Domain Services (AD DS) domain that contains the member servers shown in the following table.

Server3 contains a data disk named Disk1 that has Data Deduplication installed. Disk1 contains the files shown in the following table.

Server3 fails.
You need to recover the files on Disk1.
Which files can you recover if you attach Disk1 to Server 1, and which files can you recover if you attach Disk1 to Server2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 49
You need to meet the technical requirements for Server1. Which users can currently perform the required tasks?

  • A. Admin3 only
  • B. Admin1 only
  • C. Admin1 Admin2. and Admm3
  • D. Admin1 and Admin3 only

Answer: D

Explanation:
Topic 2, Fabrikam inc.
To start the case study
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements, if the case study has an All Information tab. note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview
Fabrikam, Inc. Is a manufacturing company that has a main office In New York and a branch office in Seattle.
On-premises Servers
The on-premises network contains servers that run Windows Server as shown in the following table.

DC1 hosts all the operation master roles.
WEB1 and WEB2 run an Internet Information Services (IIS) web app named Webapp1.
On-premises Network
The New York and Seattle offices are connected by using redundant WAN links.
The client computers in each office get IP addresses from their local DHCP server.
DHCP! contains a scope named Scope1 that has addresses for the New York office. DHCP2 contains a scope named Scope2 that has addresses for the Seattle office.
Group Policy Object (GPOs)
The cwp.fabrikam.com domain contains the organizational units (OUs) and custom Group Policy Objects (GPOs) shown in the following table.

Requirements:
Fabrikam Identifies the following planned changes:
* Create a single Azure subscription named Sub1 that will contain a single Azure virtual network named Vnet1.
* Replace the WAN links between the Seattle and New York offices by using Azure Virtual WAN and ExpressRoute. Both on-premises offices will be connected to Vnet1 by using ExpressRoute.
* Create three Azure file shares named newyorkfiles, seattfefiles, and companyfiles.
* Create a domain controller named dc3.corp.fabrikam,com in Vnet1.
* Deploy an Azure Virtual Desktop host pool lo Vnet1. The Azure Virtual Desktop session hosts will be hybrid Azure AD joined.
* License all servers for Microsoft Defender for servers.
* Use Azure Policy to enforce configuration management policies on the servers in Azure and on-premises.
Networking Requirements
Fabrikam identifies the following security requirements:
* Apply GP04 to the Azure Virtual Desktop session hosts. Ensure that Azure Virtual Desktop user sessions lock after being idle for 10 minutes. Users must be able to control the lockout lime manually from their client computer.
* Ensure that server administrators request approval before they can establish a Remote Desktop connection to an Azure virtual machine. If the request is approved, the connection must be established within two hours.
* Prevent user passwords from containing all or part of words that are based on the company name, such as Fab. fabrikam or fsbr! |.
* Ensure that all instances of Webapp1 use the same service account. The password of the service account must change automatically every 30 days.
* Prevent domain controllers from directly contacting hosts on the internet.
File Sharing Requirements
You need to configure the synchronization of Azure files to meet the following requirements:
* Ensure that seattlefiles syncs to FS2.
* Ensure that newyorkfiles syncs to FS1.
* Ensure that companyfiles syncs to both FS1 and FS2.


NEW QUESTION # 50
Your network contains an on -premises Active Directory Domain Services (AD DS) domain named contoso.com The domain contains the objects shown in the following table.

You plan to sync contoso.com with an Azure Active Directory (Azure AD) tenant by using Azure AD Connect You need to ensure that all the objects can be used in Conditional Access policies What should you do?

  • A. Change the scope o' Group1 and Group2 to Global
  • B. Clear the Configure device writeback option.
  • C. Select the Configure Hybrid Azure AD join option.
  • D. Change the scope of Group2 to Universal

Answer: C

Explanation:
Explanation
Hybrid Azure AD join needs to be configured to enable Computer1 to be used in Conditional Access Policies.
Synchronized users, universal groups and domain local groups can be used in Conditional Access Policies.


NEW QUESTION # 51
You deploy a new Active Directory Domain Services (AD DS) forest named contoso.com. The domain contains three domain controllers named DC1, DC2, and DC3.
You rename Default-First-Site-Name as Site1.
You plan to ship DC1, DC2, and DC3 to datacenters in different locations.
You need to configure replication between DC1, DC2, and DC3 to meet the following requirements:
Each domain controller must reside in its own Active Directory site.
The replication schedule between each site must be controlled independently.
Interruptions to replication must be minimized.
Which three actions should you perform in sequence in the Active Directory Sites and Services console? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

1 - Create two additional sites named Site2 and Site3. Move DC2 to Site2 and DC3 to Site3.
2 - Create a connection object between DC1 and DC2.
3 - Create a connection object between DC2 and DC3.


NEW QUESTION # 52
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com.
The root domain contains the domain controllers shown in the following table.

A failure of which domain controller will prevent you from creating application partitions?

  • A. DC3
  • B. DC5
  • C. DC2
  • D. DC4
  • E. DC1

Answer: E

Explanation:
Initial replication and connectivity requirements
This FSMO role holder is only active when the role owner has inbound replicated the configuration NC successfully since the Directory Service started.
Domain members of the forest only contact the FSMO role holder when they update the cross- references. DCs contact the FSMO role holder when:
Domains are added or removed in the forest.
New instances of application directory partitions on DCs are added. For example, a DNS server has been enlisted for the default DNS application directory partitions.
https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/fsmo- roles#domain%20naming


NEW QUESTION # 53
Your network contains an Active Domain Services (AD DS) forest. The forest contains three domains.
Each domain contains 10 domain controllers.
You plan to store a DNS zone in a custom active Directory partition.
You need to create the Active Directory partition for the zone. The partition replicate to only four of the domain controllers.
What should you use?

  • A. Active Directory Administrator Center
  • B. DNS Manager
  • C. Active Directory Sites and Services
  • D. dnscmd.exe

Answer: A


NEW QUESTION # 54
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant You have an on-premises web app named WebApp1 that only supports Kerberos authentication.
You need to ensure that users can access WebApp1 by using their Azure AD account. The solution must minimize administrative effort.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation

Reference:
https://docs.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy-add-on-premises-applicatio


NEW QUESTION # 55
Your network contains two Active Directory Domain Services (AD DS) forests named contoso.com and fabrikam.com. Contoso.com contains three child domains named amer.contoso.com, apac.contoso.com, and emea.contoso.com. Fabrikam.com contains a child domain named apac.fabrikam.com. A bidirectional forest trust exists between contoso.com and fabrikam.com.
You need to provide users in the contoso.com forest with access to the resources in the fabrikam.com forest.
The solution must meet the following requirements:
* Users in contoso.com must only be added directly to groups in the contoso.com forest.
* Permissions to access the resources in fabrikam.com must only be granted directly to groups in the fabrikam.com forest.
* The number of groups must be minimized.
Which type of groups should you use to organize the users and to assign permissions? To answer, drag the appropriate group types to the correct requirements. Each group type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation


NEW QUESTION # 56
You have an on-premises server named Server1 that runs Windows Server. You have an Azure virtual network that contains an Azure virtual network gateway. You need to connect only Server1 to the Azure virtual network. What should you use?

  • A. an ExpressRoute circuit
  • B. Azure Network Adapter
  • C. a Site-to-SiteVPN
  • D. Azure Extended Network

Answer: C

Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/use-azure-network-adap


NEW QUESTION # 57
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains a child domain named east.contoso.com.
in the contoso.com domain, you create two users named Admin1 and Admin2.
You need to ensure that the users can perform the following tasks:
* Admin1 can create and manage Active Directory sites.
* Admin2 can deploy domain controller to the easl.conloso.com domain.
The solution must use the principle of least privilege.
To which group should you add each user? To answer, select the appropriate options in the answer area.
NOTE Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 58
You have an Azure subscription named sub1 and 500 on-premises virtual machines that run Windows Server.
You plan to onboard the on-premises virtual machines to Azure Arc by running the Azure Arc deployment script You need to create an identity that mil be used by the script to authenticate access to sub1. The solution must use the principle of least privilege.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/azure-arc/servers/onboard-service-principal


NEW QUESTION # 59
Your on-premises network contains an Active Directory domain named contoso.com. You have an Azure AD tenant. You plan to sync contoso.com with the Azure AD tenant by using Azure AD Connect cloud sync. You need to create an account that will be used by Azure AD Connect cloud sync. Which type of account should you create?

  • A. system-assigned managed identity
  • B. user
  • C. InetOrgPerson
  • D. group managed service account (gMSA)

Answer: B


NEW QUESTION # 60
Your network contains two VLANs for client computers and one VLAN for a datacenter Each VLAN is assigned an IPv4 subnet Currently, all the client computers use static IP addresses.
You plan to deploy a DHCP server to the VLAN in the datacenter.
You need to use the DHCP server to provide IP configurations to all the client computers.
What is the minimum number of scopes and DHCP relays you should create? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation
Table Description automatically generated

Box 1: 3
You need a DHCP scope for each of the three subnets.
Box 2: 2
The two client VLANs need a DHCP Relay Agent to forward DHCP requests to the DHCP server. The datacenter VLAN that contains the DHCP server does not require a DHCP Relay Agent.


NEW QUESTION # 61
......

AZ-800 PDF Dumps Are Helpful To produce Your Dreams Correct QA's: https://www.prep4sureguide.com/AZ-800-prep4sure-exam-guide.html

AZ-800 Practice Test Dumps with 100% Passing Guarantee: https://drive.google.com/open?id=1DQfkZbto-iDFkxP_gVMXZIAZFIR4kOaS