AZ-800 Administering Windows Server Hybrid Core Infrastructure Dumps

If you are looking for free AZ-800 dumps than here we have some sample question answers available. You can prepare from our Microsoft AZ-800 exam questions notes and prepare exam with this practice test. Check below our updated AZ-800 exam dumps.

DumpsGroup are top class study material providers and our inclusive range of AZ-800 Real exam questions would be your key to success in Microsoft Microsoft Certified: Windows Server Hybrid Administrator Associate Certification Exam in just first attempt. We have an excellent material covering almost all the topics of Microsoft AZ-800 exam. You can get this material in Microsoft AZ-800 PDF and AZ-800 practice test engine formats designed similar to the Real Exam Questions. Free AZ-800 questions answers and free Microsoft AZ-800 study material is available here to get an idea about the quality and accuracy of our study material.


discount banner

Sample Question 4

You have an Azure virtual machine named VM1 that runs Windows Server. You perform the following actions on VM1: • Create a folder named Folder1 on volume C • Create a folder named Folder2 on volume D. • Add a new data disk to VM1 and create a new volume that is assigned drive letter E. • Install an app named App1 on volume E. You plan to resize VM1. Which objects will present after you resize VM1?

A. Folded and Folder2 only 
B. Folder1, volume 
E, and App1 only 
C. Folder1 only
 D. Folded. Folder2. App1, and volume E


Sample Question 5

Your network contains a Active Directory Domain Service (AD DS) forest named contoso.com. The forest root domain contains a server named server1. contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?

A. Change the trust to a one-way external trust. 
B. Add fabrikam\Group1 to the local Users group on server1.contoso.com. 
C. Enable SID filtering for the trust.
 D. Enable Selective authentication for the trust. 


Sample Question 6

Your network contains an Active Domain Services (AD DS) forest. The forest contains three domains. Each domain contains 10 domain controllers. You plan to store a DNS zone in a custom active Directory partition. You need to create the Active Directory partition for the zone. The partition replicate to only four of the domain controllers. What should you use?

A. Active Directory Sites and Services 
B. Active Directory Administrator Center 
C. dnscmd.exe 
D. DNS Manager 


Sample Question 7

You have an Azure virtual machine named Server1 that runs a network management application. Server1 has the following network configuration. * Network interface.Nic1 * IP address 10.1.1.1/24 * Connected to: Vnet1/Subnet1 You need connect Server1 to an additional subnet named Vnet1/Subnet2. What should you do?

A. Create a private endpoint on Subnet2
 B. Add a network interface to server1. 
C. Modify the IP configurations of Nic1. 
D. Add an IP configuration to Nic1. 


Sample Question 8

You have a server named Server1 that runs Windows Server. You plan to host applications in Windows containers. You need to configure Server1 to run containers. What should you install?

A. Windows Admin Center 
B. the Windows Subsystem for Linux 
C. Doctor
 D. Hyper-V


Sample Question 9

You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant Group writeback is enabled in Azure AD Connect. The AD DS domain contains a server named Server1 Server 1 contains a shared folder named share1. You have an Azure Storage account named storage2 that uses Azure AD-based access control. The storage2 account contains a share named shared You need to create a security group that meets the following requirements: • Can contain users from the AD DS domain • Can be used to authorize user access to share 1 and share2 What should you do?

A. in the AD DS domain, create a universal security group 
B. in the Azure AD tenant create a security group that has assigned membership 
C. in the Azure AD Tenant create a security group that has dynamic membership. 
D. in the Azure AD tenant create a Microsoft 365 group 


Sample Question 10

You haw an Azure virtual machine named VM1 that runs Windows Server You need to configure the management of VM1 to meet the following requirements: • Require administrators to request access to VM1 before establishing a Remote Desktop connection. • Limit access to VM1 from specific source IP addresses. • Limit access to VMI to a specific management portWhat should you configure?

A. a network security group (NSG) 
B. Azure Active Directory (Azure AD) Privileged identity Management (PIM) 
C. Azure Front Door 
D. Microsoft Defender for Cloud 


Sample Question 11

You haw an Azure virtual machine named VM1 that runs Windows Server You need to configure the management of VM1 to meet the following requirements: • Require administrators to request access to VM1 before establishing a Remote Desktopconnection.• Limit access to VM1 from specific source IP addresses.• Limit access to VMI to a specific management portWhat should you configure?

A. a network security group (NSG) 
B. Azure Active Directory (Azure AD) Privileged identity Management (PIM) 
C. Azure Front Door 
D. Microsoft Defender for Cloud 


Sample Question 12

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK. You open a new branch office that contains only client computers. You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1. Solution: You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to Site1.Does this meet the goal?

A. Yes 
B. No 


Sample Question 13

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains a DNS server named Server1. Server1 hosts a DNS zone named fabrikam.com that was signed by DNSSEC. You need to ensure that all the member servers in the domain perform DNSSEC validation for the fabrikam.com namespace. What should you do?

A. On Served, run the Add-DnsServerTrustAnchor cmdlet. 
B. On each member server, run the Add-DnsServerTrustAnchor cmdlet. 
C. From a Group Policy Object (GPO). add a rule to the Name Resolution Policy Table (NRPT). 
D. From a Group Policy Object (GPO). modify the Network List Manager policies. 


Sample Question 14

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. You need to identify which server is the PDC emulator for the domain. Solution: From Active Directory Sites and Services, you right-click Default-First-Site-Name in the console tree, and then select Properties.  Does this meet the goal?

A. Yes 
B. No 


Sample Question 15

You have an Azure Active Directory Domain Services (Azure AD DS) domain named contoso.com. You need to provide an administrator with the ability to manage Group Policy Objects(GPOs). The solution must use the principle of least privilege. To which group should you add the administrator?

A. AAD DC Administrators 
B. Domain Admins 
C. Schema Admins 
D. Enterprise Admins 
E. Group Policy Creator Owners 


Sample Question 16

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK. You open a new branch office that contains only client computers. You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1. Solution: You create a new site named Site4 and associate Site4 to DEFAULTSITELINK. Does this meet the goal?

A. Yes 
B. No 


Sample Question 17

You have an on premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. You plan to implement self-service password reset (SSPR) in Azure AD. You need to ensure that users that reset their passwords by using SSPR can use the new password resources in the AD DS domain. What should you do?

A. Deploy the Azure AD Password Protection proxy service to the on premises network. 
B. Run the Microsoft Azure Active Directory Connect wizard and select Password writeback. 
C. Grant the Change password permission for the domain to the Azure AD Connect service account. 
D. Grant the impersonate a client after authentication user right to the Azure AD Connect service account. 


Sample Question 18

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com You need to identify which server is the PDC emulator for the domain. Solution: From Active Directory Domains and Trusts, you right-click Active Directory Domains and Trusts in the console tree, and then select Operations Master.Does this meet the goal?

A. Yes 
B. No 


Sample Question 19

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains two servers named Server1 and Server2. Server1 contains a disk named Disk2. Disk2 contains a folder named UserData. UserData is shared to the Domain Users group. Disk2 is configured for deduplication. Server1 is protected by using Azure Backup.Server1 fails. You connect Disk2 to Server2. You need to ensure that you can access all the files on Disk2 as quickly as possible. What should you do?

A. Create a storage pool. 
B. Restore files from Azure Backup. 
C. Install the File Server Resource Manager server role. 
D. Install the Data Deduplication server role. 


Sample Question 20

Your network contains an Active Directory Domain Services (AD DS) domain namedcontoso.com.You need to identify which server is the PDC emulator for the domain.Solution: From a command prompt, you run netdom.exe query fsmo.Does this meet the goal?

A. Yes 
B. No 


Sample Question 21

You have an on premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. The domain contains two servers namedServer1 and Server2. A user named Admin1 is a member of the local Administrators group on Server1 and Server2. You plan to manage Server1 and Server2 by using Azure Arc. Azure Arc objects will be added to a resource group named RG1. You need to ensure that Admin1 can configure Server1 and Server2 to be managed by using Azure Arc. What should you do first? 

A. From the Azure portal, generate a new onboarding script. 
B. Assign Admin1 the Azure Connected Machine Onboarding role for RG1. 
C. Hybrid Azure AD join Server1 and Server2. 
D. Create an Azure cloud-only account for Admin1. 


Sample Question 22

You have an on-premises network that is connected to an Azure virtual network by using a Site-to-Site VPN. Each network contains a subnet that has the same IP address space.The on-premises subnet contains a virtual machine. You plan to migrate the virtual machine to the Azure subnet. You need to migrate the on premises virtual machine to Azure without modifying the IP address. The solution must minim administrative effort. What should you implement before you perform the migration?

A. Azure Extended Network 
B. Azure Virtual Network NAT 
C. Azure Application Gateway 
D. Azure virtual network peering 


Sample Question 23

You have an Azure virtual machine named VM1 that has a private IP address only.You configure the Windows Admin Center extension on VM1.You have an on-premises computer that runs Windows 11. You use the computer forserver management.You need to ensure that you can use Windows Admin Center from the Azure portal tomanage VM1.What should you configure?

A. an Azure Bastion host on the virtual network that contains VM1. 
B. a VPN connection to the virtual network that contains VM1. 
C. a network security group 1NSG) rule that allows inbound traffic on port 443. 
D. a private endpoint on the virtual network that contains VM1.


Sample Question 24

You have a Windows Server container host named Server 1 and a container image named Image1. You need to start a container from image1. The solution must run the container on a HyperV virtual machine. Which parameter should you specify when you run the docker run command?

A. --expose 
B. --privileged 
C. --runtime 
D. --entrypoint 
E. --isolation 


Sample Question 25

You plan to deploy a containerized application that requires .NET Core. You need to create a container image for the application. the image must be as small as possible.Which base image should you use?

A. Nano Server 
B. Server Cote 
C. Windows Server 
D. Windows 


Sample Question 26

Your network contains an Active Directory Domain Services (AD DS) domain- The domain contains 10 servers that run Windows Server. The servers have static IP addresses.You plan to use DHCP to assign IP addresses to the servers. You need to ensure that each server always receives the same IP address. Which type of identifier should you use to create a DHCP reservation for each server?

A. universally unique identifier (UUID) 
B. fully qualified domain name (FQDN) 
C. NetBIOS name 
D. MAC address 


Sample Question 27

Your network contains an Active Directory Domain Services (AD DS) domain named conioso.com. You need to identify which server is the PDC emulator for the domain. Solution: from Active Directory Users and Computers, you right-click contoso.com in the console tree, and then select Operations Master Does this meet the goal?

A. Yes 
B. No 


Sample Question 28

You have five tile servers that run Windows Server.You need to block users from uploading video files that have the .mov extension to sharedfolders on the file servers. All other types of files must be allowed. The solution mustminimize administrative effort.What should you create?

A. a Dynamic Access Control central access policy 
B. a file screen 
C. a Dynamic Access Control central access rule 
D. a data loss prevention (DLP) policy 


Sample Question 29

You have an on-premises server named Server1 that runs Windows Server. You have an Azure virtual network that contains an Azure virtual network gateway. You need to connectonly Server1 to the Azure virtual network What should you use?

A. Azure Network Adapter 
B. a Site-to-SiteVPN 
C. an ExpressRoute circuit 
D. Azure Extended Network 


Sample Question 30

You have an Azure virtual machine named VM1 that runs Windows Server and has the following configurations: Size: D2s_v4 Operating system disk: 127-GiB standard SSD Data disk 128-GiB standard SSD Virtual machine generation: Gen 2 You plan to perform the following changes to VM1: Change the virtual machine size to D4s_v4. Detach the data disk. Add a new standard SSD. Which changes require downtime for VM1?

A. Detaching the data disk only and adding a new standard SSD. 
B. Detaching the data disk only. 
C. Changing the virtual machine size only. 
D. Adding a new standard SSD only. 


Sample Question 31

You haw? a server named Host! that has the Hyper-V server role installed. Host! hosts a virtual machine named VM1. You have a management server named Server! that runs Windows Server. You remotely manage Host1 from Server1 by using Hyper-V Manager. You need to ensure that you can access a USB hard drive connected to Server1 when you connect to VM1 by using Virtual Machine Connection. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A. From the Hyper-V Settings of Host1, select Allow enhanced session mode 
B. From Disk Management on Host1. attach a virtual hard disk. 
C. From Virtual Machine Connection, switch to a basic session. 
D. From Virtual Machine Connection select Show Options and then select the USB hard drive. 
E. From Disk Management on Host1, select Rescan Disks 


Sample Question 32

You have an Azure subscription that contains the following resources: • An Azure Log Analytics workspace • An Azure Automation account • Azure Arc. You have an on-premises server named Server1 that is onboaraed to Azure Arc You need to manage Microsoft updates on Server! by using Azure Arc Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point

A. Add Microsoft Sentinel to the Log Analytics workspace 
B. On Server1, install the Azure Monitor agent 
C. From the Automation account, enable Update Management for Server1. 
D. From the Virtual machines data source of the Log Analytics workspace, connectServer1. 


Sample Question 33

You have a server that runs Windows Server and contains a shared folder named UserData. You need to limit the amount of storage space that each user can consume in UserData.What should you use?

A. Storage Spaces 
B. Work Folders 
C. Distributed File System (DFS) Namespaces 
D. File Server Resource Manager (FSRM) 


Sample Question 34

You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. You plan deploy 100 new Azure virtualmachines that will run Windows Server. You need to ensure that each new virtual machine is joined to the AD DS domain. What should you use?

A. Azure AD Connect 
B. a Group Policy Object (GPO) 
C. an Azure Resource Manager (ARM) template 
D. an Azure management group 


Sample Question 35

You have a server named Server1 that hosts Windows containers. You plan to deploy an application that will have multiple containers. Each container will be You need to create a Docker network that supports the deployment of the application. Which type of network should you create?

A. transparent 
B. I2bridge 
C. NAT 
D. I2tunnel 


Sample Question 36

Your network contains an Active Directory Domain Services (AD DS) domain. You have a Group Policy Object (GPO) named GPO1 that contains Group Policy preferences. You plan to link GPO1 to the domain. You need to ensure that the preference in GPO1 apply only to domain member servers and NOT to domain controllers or client computers. All the other Group Policy settings in GPO1 must apply to all the computers. The solution must minimize administrative effort. Which type of item level targeting should you use?

A. Domain 
B. Operating System 
C. Security Group 
D. Environment Variable 



Exam Code: AZ-800
Exam Name: Administering Windows Server Hybrid Core Infrastructure
Last Update: May 13, 2024
Questions: 218