Microsoft AZ-800 Real Exam Questions
The questions for AZ-800 were last updated at Nov 21,2024.
- Exam Code: AZ-800
- Exam Name: Administering Windows Server Hybrid Core Infrastructure
- Certification Provider: Microsoft
- Latest update: Nov 21,2024
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant The on-premises network is connected to Azure by using a Site-to-Site VPN.
You have the DNS zones shown in the following table.
You need to ensure that names from (aDiifcam.com can be resolved from the on-premises network.
Which two actions should you perform? Each correct answer presents part of the solution, NOTE: Each correct selection Is worth one point
- A . Create a conditional forwarder for fabrikam.com on DC1.
- B . Create a stub zone for fabrikam.com on DC1.
- C . Create a secondary zone for fabnlcam.com on DO.
- D . Deploy an Azure virtual machine that runs Windows Server. Modify the DNS Servers settings for the virtual network.
- E . Deploy an Azure virtual machine that runs Windows Server. Configure the virtual machine &s a DNS forwarder.
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.
You open a new branch office that contains only client computers.
You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.
Solution: You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to Site1.
Does this meet the goal?
- A . Yes
- B . No
You need to meet the technical requirements for VM2.
What should you do?
- A . Implement shielded virtual machines.
- B . Enable the Guest services integration service.
- C . Implement Credential Guard.
- D . Enable enhanced session mode.
You need to implement a name resolution solution that meets the networking requirements.
Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point
- A . Create an Azure private DNS zone named corp.fabhkam.com.
- B . Create a virtual network link in the coip.fabnkam.c om Azure private DNS zone.
- C . Create an Azure DNS zone named corp.fabrikam.com.
- D . Configure the DNS Servers settings for Vnet1.
- E . Enable autoregistration in the corp.fabnkam.com Azure private DNS zone.
- F . On DC3, install the DNS Server role.
- G . Configure a conditional forwarder on DC3.
HOTSPOT
You need to meet the technical requirements for VM1.
Which cmdlet should you run first? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.
You open a new branch office that contains only client computers.
You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.
Solution: You create a new subnet object that is associated to Site1.
Does this meet the goal?
- A . Yes
- B . No
You need to ensure that access to storage1 for the Marketing OU users meets the technical requirements.
What should you implement?
- A . Microsoft Entra Connect cloud sync
- B . Active Directory Federation Services (AD FS)
- C . Microsoft Entra Connect in staging mode
- D . Microsoft Entra Connect in active mode
You have an Azure virtual machine named VM1 that has a private IP address only.
You configure the Windows Admin Center extension on VM1.
You have an on-premises computer that runs Windows 11. You use the computer for server management.
You need to ensure that you can use Windows Admin Center from the Azure portal to manage VM1.
What should you configure?
- A . an Azure Bastion host on the virtual network that contains VM1.
- B . a VPN connection to the virtual network that contains VM1.
- C . a network security group 1NSG) rule that allows inbound traffic on port 443.
- D . a private endpoint on the virtual network that contains VM1.
You need to meet the technical requirements for the site links.
Which users can perform the required tasks?
- A . Admin1 only
- B . Admin1 and Admin3 only
- C . Admin1 and Admin2 only
- D . Admin3 only
- E . Admin1, Adrrun2. and Admin3
Your network contains an Active Directory Domain Services (AD DS) domain named conioso.com.
You need to identify which server is the PDC emulator for the domain.
Solution: from Active Directory Users and Computers, you right-click contoso.com in the console tree, and then select Operations Master
Does this meet the goal?
- A . Yes
- B . No