Provide Valid AZ-800 Dumps To Help You Prepare For Administering Windows Server Hybrid Core Infrastructure Exam Mar 30, 2023 [Q10-Q31]

Share

Provide Valid AZ-800 Dumps To Help You Prepare For Administering Windows Server Hybrid Core Infrastructure Exam Mar 30, 2023

Microsoft AZ-800 Dumps Questions [2023] Pass for AZ-800 Exam


Following is the info about the Passing Score, Duration & Questions for the Microsoft AZ-800 Exam

Information about the Passing Score, Duration & Questions for the Microsoft AZ-800 Exam given in the AZ-800 exam dumps is as follows:

  • The passing score: 70%
  • Time Duration: 60 minutes
  • Languages: English
  • Number of Questions: 45-60

Microsoft AZ-800 Exam Syllabus Topics:

TopicDetails

Deploy and manage Active Directory Domain Services (AD DS) in onpremises and cloud environments (30-35%)

Deploy and manage AD DS domain controllers- deploy and manage domain controllers on-premises
- deploy and manage domain controllers in Azure
- deploy Read-Only Domain Controllers (RODCs)
- troubleshoot flexible single master operations (FSMO) roles
Configure and manage multi-site, multi-domain, and multi-forest environments- configure and manage forest and domain trusts
- configure and manage AD DS sites
- configure and manage AD DS replication
Create and manage AD DS security principals- create and manage AD DS users and groups
- manage users and groups in multi-domain and multi-forest scenarios
- implement group managed service accounts (gMSAs)
- join Windows Servers to AD DS, Azure AD DS, and Azure AD
Implement and manage hybrid identities- implement Azure AD Connect
- manage Azure AD Connect Synchronization
- implement Azure AD Connect cloud sync
- integrate Azure AD, AD DS, and Azure AD DS
- manage Azure AD DS
- manage Azure AD Connect Health
- manage authentication in on-premises and hybrid environments
- configure and manage AD DS passwords
Manage Windows Server by using domain-based Group Policies- implement Group Policy in AD DS
- implement Group Policy Preferences in AD DS
- implement Group Policy in Azure AD DS

Manage Windows Servers and workloads in a hybrid environment (10-15%)

Manage Windows Servers in a hybrid environment- deploy a Windows Admin Center gateway server
- configure a target machine for Windows Admin Center
- configure PowerShell Remoting
- configure CredSSP or Kerberos delegation for second hop remoting
- configure JEA for PowerShell Remoting
Manage Windows Servers and workloads by using Azure services- manage Windows Servers by using Azure Arc
- assign Azure Policy Guest Configuration
- deploy Azure services using Azure Virtual Machine extensions on non-Azure machines
- manage updates for Windows machines
- integrate Windows Servers with Log Analytics
- integrate Windows Servers with Azure Security Center
- manage IaaS virtual machines (VMs) in Azure that run Windows Server
- implement Azure Automation for hybrid workloads
- create runbooks to automate tasks on target VMs
- implement DSC to prevent configuration drift in IaaS machines

Manage virtual machines and containers (15-20%)

Manage Hyper-V and guest virtual machines- enable VM enhanced session mode
- manage VM using PowerShell Remoting, PowerShell Direct, and HVC.exe
- configure nested virtualization
- configure VM memory
- configure Integration Services
- configure Discrete Device Assignment
- configure VM Resource Groups
- configure VM CPU Groups
- configure hypervisor scheduling types
- manage VM Checkpoints
- implement high availability for virtual machines
- manage VHD and VHDX files
- configure Hyper-V network adapter
- configure NIC teaming
- configure Hyper-V switch
Create and manage containers- create Windows Server container images
- manage Windows Server container images
- configure Container networking
- manage container instances
Manage Azure Virtual Machines that run Windows Server- manage data disks
- resize Azure Virtual Machines
- configure continuous delivery for Azure Virtual Machines
- configure connections to VMs
- manage Azure Virtual Machines network configuration

Implement and manage an on-premises and hybrid networking infrastructure (15-20%)


 

NEW QUESTION 10
Your network contains an Active Directory Domain Services (AD DS) domain.
You have a Group Policy Object (GPO) named GPO1 that contains Group Policy preferences.
You plan to link GPO1 to the domain.
You need to ensure that the preference in GPO1 apply only to domain member servers and NOT to domain controllers or client computers. All the other Group Policy settings in GPO1 must apply to all the computers. The solution must minimize administrative effort.
Which type of item level targeting should you use?

  • A. Operating System
  • B. Security Group
  • C. Environment Variable
  • D. Domain

Answer: A

Explanation:
Reference:
https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn789189(v=ws.11)#operating-system-targeting

 

NEW QUESTION 11
Hotspot Question
You have a file server named Server1 that runs Windows Server and contains the volumes shown in the following table.

On which volumes can you use BitLocker Drive Encryption (BitLocker) and disk quotas? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
https://docs.microsoft.com/en-us/windows-server/storage/refs/refs-overview

 

NEW QUESTION 12
Case Study 2 - Contoso, Ltd
Overview
Contoso, Ltd. is a company that has a main office in Seattle and two branch offices in Los Angeles and Montreal.
Existing Environment
AD DS Environment
The network contains an on premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com.
The forest contains the domain controllers shown in the following table.

All the domain controllers are global catalog servers.
Server infrastructure
The network contains the servers shown in the following table.

A server named Server4 runs Windows Server and is in a workgroup. Windows Firewall on Server4 uses the private profile.
Server2 hosts three virtual machines named VM1, VM2, and VM3.
VM3 is a file server that stores data in the volumes shown in the following table.

Group Policies
The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table.

Existing Identities
The forest contains the users shown in the following table.

The forest contains the groups shown in the following table.

Current Problems
When an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out, another administrator can connect to the console session as the currently signed in user.
Requirements
Technical Requirements
Contoso identifies the following technical requirements:
Change the replication schedule for all site links to 30 minutes.
Promote Server1 to a domain controller in canada.contoso.com.
Install and authorize Server3 as a DHCP server.
Ensure that User1 can manage the membership of all the groups in Contoso\OU3.
Ensure that you can manage Server4 from Server1 by using PowerShell remoting.
Ensure that you can run virtual machines on VM1.
Force users to provide credentials when they connect to VM2.
On VM3, ensure that Data Deduplication on all volumes is possible.
Question
Hotspot Question
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box1: No
Admin1 is a domain user, thus only password settings which are applied on DCs will work in this case. From given GPOs only Default Domain Policy are applied on DCs, so minimum passwords length = 10 -> Admin1 does not have to use longer password.
Box2: Yes
User1 is a domain user too so we have same situation as above: minimum passwords length =
10 -> User1 must use a password that has at least 10 characters.
Box3: No
Password settings for local users on Server1 are comming from GPO which is applied to Server1.
Server1 is in OU=Member Servers. OU is linked with GPO2 thus local users on Server1 must use a password that has at least 8 characters.

 

NEW QUESTION 13
You need to configure Azure File Sync to meet the file sharing requirements. What should you do? To answer, select the appropriate options in the answer are a. NOTE Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/storage/file-sync/file-sync-planning

 

NEW QUESTION 14
Your organization uses a hybrid identity model for accessing both Azure-based and on-premises services. The Azure Active Directory Connect (Azure AD Connect) sync service is running on a dedicated server in your on-premises network; however, it has been decided that Active Directory (AD) passwords should not be stored in any form in the cloud.
You need to enable this using the Azure AD Connect application.
What should you do?

  • A. Enable password hash synchronization.
  • B. Enable Pass-through authentication.
  • C. Select Do not configure in the User sign-in options.
  • D. Delete user identities in Azure AD for your organization.

Answer: B

Explanation:
You should enable Pass-through authentication. This will allow your organization's users to use single sign-on (SSO) in order to securely access resources both in your on-premises network as well as in Azure AD. When users try to access Azure AD from the on-premises network, they will never need to enter their passwords. An additional feature of Pass-through authentication is that these passwords are never stored in the cloud, thus meeting the security requirement of the scenario. When configuring Pass-through authentication using the Azure AD Connect application an additional step is to ensure that the Enable single sign-on box has been checked.

 

NEW QUESTION 15
Case Study 2 - Contoso, Ltd
Overview
Contoso, Ltd. is a company that has a main office in Seattle and two branch offices in Los Angeles and Montreal.
Existing Environment
AD DS Environment
The network contains an on premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com.
The forest contains the domain controllers shown in the following table.

All the domain controllers are global catalog servers.
Server infrastructure
The network contains the servers shown in the following table.

A server named Server4 runs Windows Server and is in a workgroup. Windows Firewall on Server4 uses the private profile.
Server2 hosts three virtual machines named VM1, VM2, and VM3.
VM3 is a file server that stores data in the volumes shown in the following table.

Group Policies
The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table.

Existing Identities
The forest contains the users shown in the following table.

The forest contains the groups shown in the following table.

Current Problems
When an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out, another administrator can connect to the console session as the currently signed in user.
Requirements
Technical Requirements
Contoso identifies the following technical requirements:
Change the replication schedule for all site links to 30 minutes.
Promote Server1 to a domain controller in canada.contoso.com.
Install and authorize Server3 as a DHCP server.
Ensure that User1 can manage the membership of all the groups in Contoso\OU3.
Ensure that you can manage Server4 from Server1 by using PowerShell remoting.
Ensure that you can run virtual machines on VM1.
Force users to provide credentials when they connect to VM2.
On VM3, ensure that Data Deduplication on all volumes is possible.
Question
Hotspot Question
Which groups can you add to Group3 and Group5? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Group 3 = Group 1, 2 4 and 5 only. Domain-Local groups can contain members from the "forest".
Group 5 = Group 4 only. Global groups can only contain Users, Computers and Global groups from the "same" domain.
https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/active- directory-security-groups

 

NEW QUESTION 16
Your network contains a single domain Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains a single Active Directory site.
You plan to deploy a read only domain controller (RODC) to a new datacenter on a server named Server1. A user named User1 is a member of the local Administrators group on Server1.
You need to recommend a deployment plan that meets the following requirements:
Ensures that a user named User1 can perform the RODC installation on Server1 Ensures that you can control the AD DS replication schedule to the Server1 Ensures that Server1 is in a new site named RemoteSite1 Uses the principle of least privilege Which three actions should you recommend performing in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

1 - Add User1 to the Contoso\Adminisitrator group.
2 - Pre-create an RODC account.
3 - Instruct User1 to run the Active Directory Domain Services installation Wizard on Server1.

 

NEW QUESTION 17
You have servers that have the DNS Server role installed. The servers are configured as shown in the following table.

All the client computers in the New York office use Server2 as the DNS server.
You need to configure name resolution in the New York office to meet the following requirements:
Ensure that the client computers in New York can resolve names from contoso.com.
Ensure that Server2 forwards all DNS queries for internet hosts to 131. 107.100.200.
The solution must NOT require modifications to Server1.
Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. a forwarder
  • B. a conditional forwarder
  • C. a delegation
  • D. a reverse lookup zone
  • E. a secondary zone

Answer: A,B

Explanation:
A conditional forwarder is required for contoso.com.
A forwarder is required for all other domains.
When you have a conditional forwarder and a forwarder configured, the conditional forwarder will be used for the specified domain.
You could use a secondary zone for contoso.com but that would require a configuration change on Server1.

 

NEW QUESTION 18
You need to allow a user to change the settings like email notifications within Azure AD Connect Health.
Which of the following Roles would you provide to the user? (Choose the role with minimum privileges that suits the best and is sufficient for the given scenario)

  • A. Owner
  • B. Writer
  • C. Reader
  • D. Contributor

Answer: D

 

NEW QUESTION 19
You need to meet the technical requirements for VM3
On which volumes can you enable Data Deduplication?

  • A. D only
  • B. C, D, E, and F
  • C. C and D only
  • D. D and E only
  • E. D, E, and F only

Answer: D

Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/storage/data-deduplication/interop

 

NEW QUESTION 20
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains a child domain named east.contoso.com.
in the contoso.com domain, you create two users named Admin1 and Admin2.
You need to ensure that the users can perform the following tasks:
* Admin1 can create and manage Active Directory sites.
* Admin2 can deploy domain controller to the easl.conloso.com domain.
The solution must use the principle of least privilege.
To which group should you add each user? To answer, select the appropriate options in the answer area.
NOTE Each correct selection is worth one point.

Answer:

Explanation:

 

NEW QUESTION 21
Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com. The domain contains a server named Server1 and the users shown in the following table.

Server1 contains a folder named D:\Folder1. The advanced security settings for Folder1 are configured as shown in the Permissions exhibit. (Click the Permissions tab.)

Folder1 is shared by using the following configurations:

The share permissions for Share1 are shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

 

NEW QUESTION 22
Your network contains an Active Directory Domain Services (AD DS) domain- The domain contains 10 servers that run Windows Server. The servers have static IP addresses.
You plan to use DHCP to assign IP addresses to the servers.
You need to ensure that each server always receives the same IP address.
Which type of identifier should you use to create a DHCP reservation for each server?

  • A. fully qualified domain name (FQDN)
  • B. NetBIOS name
  • C. MAC address
  • D. universally unique identifier (UUID)

Answer: C

 

NEW QUESTION 23
Your network contains an Active Directory Domain Services (AD DS) domain.
You have a Group Policy Object (GPO) named GPO1 that contains Group Policy preferences.
You plan to link GPO1 to the domain.
You need to ensure that the preference in GPO1 apply only to domain member servers and NOT to domain controllers or client computers. All the other Group Policy settings in GPO1 must apply to all the computers. The solution must minimize administrative effort.
Which type of item level targeting should you use?

  • A. Operating System
  • B. Security Group
  • C. Environment Variable
  • D. Domain

Answer: A

Explanation:
https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-
2012/dn789189(v=ws.11)#operating-system-targeting

 

NEW QUESTION 24
You have 10 on-premises servers that run Windows Server.
You plan to use Azure Network Adapter to connect the servers to the resources in Azure.
Which prerequisites do you require on-premises and in Azure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/use-azure-network-adapter

 

NEW QUESTION 25
You have an Azure virtual machine named VM1 that runs Windows Server.
You need to configure the management of VM1 to meet the following requirements:
Require administrators to request access to VM1 before establishing a Remote Desktop connection.
Limit access to VM1 from specific source IP addresses.
Limit access to VM1 to a specific management port.
What should you configure?

  • A. Microsoft Defender for Cloud
  • B. Azure Active Directory (Azure AD) Privileged Identity Management (PIM)
  • C. Azure Front Door
  • D. a network security group (NSG)

Answer: A

Explanation:
https://docs.microsoft.com/en-us/azure/defender-fo

 

NEW QUESTION 26
Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com. The domain contains a file server named Server1 and three users named User1, User2, and User3.
Server1 contains a shared folder named Share1 that has the following configurations:

The share permissions for Share1 are configured as shown in the Share Permissions exhibit.

Share1 contains a file named File1.bxt. The advanced security settings for File1.txt are configured as shown in the File Permissions exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

 

NEW QUESTION 27
You need to meet the technical requirements for the site links. Which users can perform the required tasks?

  • A. Admin1 and Admin3 only
  • B. Admin1, Adrrun2. and Admin3
  • C. Admin1 and Admin2 only
  • D. Admin3 only
  • E. Admin1 only

Answer: C

Explanation:
Membership in the Enterprise Admins group or the Domain Admins group in the forest root domain is required.
Topic 1, Contoso Ltd
AD DS Environment
The network contains an on-premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com. The forest contains the domain controllers shown in the following table.

All the domain controllers are global catalog servers.
Server Infrastructure
The network contains the servers shown in the following table.

A server named Server4 runs Windows Server and is in a workgroup. Windows Firewall on Servei4 uses the private profile.
Server2 hosts three virtual machines named VM1. VM2, and VM3.
VM3 is a file server that stores data in the volumes shown in the following table.

Group Policies
The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table.

Existing Identities
The forest contains the users shown in the following table.

The forest contains the groups shown in the following table.

Current Problems
When an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out another administrator can connect to the console session as the currently signed-in user.
Requirements
Contoso identifies the following technical requirements:
* Change the replication schedule for all site links to 30 minutes.
* Promote Server1 to a domain controller in canada.contoso.com.
* Install and authorize Server3 as a DHCP server.
* Ensure that User! can manage the membership of all the groups in Contoso\OU3.
* Ensure that you can manage Server4 from Server1 by using PowerShell removing.
* Ensure that you can run virtual machines on VM1.
* Force users to provide credentials when they connect to VM2.
* On VM3, ensure that Data Deduplication on all volumes is possible.

 

NEW QUESTION 28
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are planning the deployment of DNS to a new network.
You have three internal DNS servers as shown in the following table.

The contoso.local zone contains zone delegations for east.contoso.local and west.contoso.local.
All the DNS servers use root hints.
You need to ensure that all the DNS servers can resolve the names of all the internal namespaces and internet hosts.
Solution: You configure Server2 and Server3 to forward DNS requests to 10.0.1.10.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: A

 

NEW QUESTION 29
You create a new Azure subscription.
You plan to deploy Azure Active Directory Domain Services (Azure AD DS) and Azure virtual machines. The virtual machines will be joined to Azure AD DS.
You need to deploy Active Directory Domain Services (AD DS) to ensure that the virtual machines can be deployed and joined to Azure AD DS.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

1 - Create an Azure ADDS intance.
2 - Create an Azure virual network.
3 - Run the Active Directory Domain Service installation Wizard.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory-domain-services/tutorial-create-instance

 

NEW QUESTION 30
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.
You open a new branch office that contains only client computers.
You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.
Solution: You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to Site1.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: A

 

NEW QUESTION 31
......

Achieve Success in Actual AZ-800 Exam AZ-800 Exam Dumps: https://www.exam4tests.com/AZ-800-valid-braindumps.html

Updated Microsoft Study Guide AZ-800 Dumps Questions: https://drive.google.com/open?id=12vGuLf0B68UkHygol7egm873YqUUYWkJ