Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

AZ-800 Administering Windows Server Hybrid Core Infrastructure Questions and Answers

Questions 4

You need to configure the Group Policy settings to ensure that the Azure Virtual Desktop session hosts meet the security requirements. What should you configure?

Options:

A.

security filtering for the link of GP04

B.

security filtering for the link of GPO1

C.

loopback processing in GPO4

D.

the Enforced property for the link of GP01

E.

loopback processing in GPO1

F.

the Enforced property for the link of GP04

Buy Now
Questions 5

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.

You open a new branch office that contains only client computers.

You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.

Solution: You create an organization unit (OU) that contains the client computers in the branch office. You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to the new OU.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 6

What should you implement for the deployment of DC3?

Options:

A.

Azure Active Directory Domain Services (Azure AD DS}

B.

Azure AD Application Proxy

C.

an Azure virtual machine

D.

an Azure AD administrative unit

Buy Now
Questions 7

Your network contains a single-domain Active Directory Domain Services (AD DS) forest named conto.com. The forest contains the servers shown in the following exhibit table.

You plan to install a line-of-business (LOB) application on Server1. The application will install a custom windows services.

A new corporate security policy states that all custom Windows services must run under the context of a group managed service account (gMSA). You deploy a root key.

You need to create, configure, and install the gMSA that will be used by the new application.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

On Server1, run the install-ADServiceAccount cmdlet.

B.

On DC1, run the New-ADServiceAccount cmdlet.

C.

On DC1, run the Set_ADComputer cmdlet.

D.

ON DC1, run the Install-ADServiceAccount cmdlet.

E.

On Server1, run the Get-ADServiceAccount cmdlet.

Buy Now
Questions 8

You need to meet the security requirements for passwords.

Where should you configure the components for Azure AD Password Protection? lo answer, drag the appropriate components to the correct locations. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE Each correct selection is worth one point.

Options:

Buy Now
Questions 9

You have a server named Server1 that runs Windows Server and has the Hyper V server role installed. Server1 hosts a virtual machine named VM1.

Server1 has an NVMe storage device. The device is currently assigned to VM1 by using Discrete Device Assignment.

You need to make the device available to Server1.

Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Buy Now
Questions 10

Your company has a main office and 10 branch offices that are connected by using WAN links. The network contains an Active Directory domain.

All users have laptops and regularly travel between offices.

You plan to implement BranchCache in the branch offices.

In each branch office, you install a server that runs Windows Server and the BranchCache feature. You register the servers in Active Directory.

You need to configure the laptops to use the local BranchCache server automatically. The solution must minimize administrative effort.

Which two Group Policy settings should you configure? To answer, select the settings in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 11

Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com The domain contains a server named Server1 and the users shown In the following table.

Server1 contains a folder named D:\Folder1. The advanced security settings for Folder 1 are configured as shown in the Permissions exhibit. (Click the Permissions lab.)

Folder1 is shared by using the following configurations

Options:

Buy Now
Questions 12

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the servers shown in the following table.

You need to create a Distributed File System (DFS) namespace that will contain the following:

• A domain-based namespace named \\contoso.com\Public

• A folder named Finance

Which servers can you configure as folder targets for the Finance folder?

Options:

A.

Setver3 only

B.

Server2 and Servers only

C.

Server1 and Server3 only

D.

Server1, Server2, and Server 3 only

E.

Server1, Server2, Server3, and Server4

Buy Now
Questions 13

Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com. The domain contains a file server named Server1 and three users named User1, User2, and User3.

Server1 contains a shared folder named Share1 that has the following configurations:

The share permissions for Share1 are configured as shown in the Share Permissions exhibit.

Share1 contains a file named File1.bxt. The share settings for File1.txt are configured as shown in the File Permissions exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 14

Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains the servers shown in the following table.

Server 1 hosts the DNS zone tor contoso.com. The General tab of the eontoso.com properties is configured as shown in the following exhibit.

Server3 hosts the DNS zone for east.contoso.com and is configured as shown in the following exhibit.

for each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 15

Your network contains an Active Directory Domain Services (AD DS) domain.

You have a Group Policy Object (GPO) named GPO1 that contains Group Policy preferences.

You plan to link GPO1 to the domain.

You need to ensure that the preference in GPO1 apply only to domain member servers and NOT to domain controllers or client computers. All the other Group Policy settings in GPO1 must apply to all the computers. The solution must minimize administrative effort.

Which type of item level targeting should you use?

Options:

A.

Domain

B.

Operating System

C.

Security Group

D.

Environment Variable

Buy Now
Questions 16

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.

You need to identify which server is the PDC emulator for the domain.

Solution: From Active Directory Domains and Trusts, you right-click Active Directory Domains and Trusts in the console tree, and then select Operations Master.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 17

You have a server named Server1 that runs Windows Server and has the Active Directory Federation Services role installed.

You plan to deploy Web Application Proxy to a server named Server2.

You export the Active Directory Federation Services (AD FS) certificate from Server1.

Which actions should you perform on Server2 in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTF: Each correct selection is worth one point.

Options:

Buy Now
Questions 18

You have an Active Directory Domain Services (AD DS) domain that contains the domain controllers shown in the following table.

The domain contains an app named App1 that uses a custom application partition to store configuration data.

You decommission App1.

When you attempt to remove the custom application partition, the process fails.

Which domain controller is unavailable?

Options:

A.

DC1

B.

DC2

C.

DC3

D.

DC4

Buy Now
Questions 19

Task 9

You plan to create group managed service accounts (gMSAs).

You need to configure the domain to support the creation of gMSAs.

Options:

Buy Now
Questions 20

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You are planning the deployment of DNS to a new network.

You have three internal DNS servers as shown in the following table.

The contoso.local zone contains zone delegations for east.contoso.local and west.contoso.local. All the DNS servers use root hints.

You need to ensure that all the DNS servers can resolve the names of all the internal namespaces and internet hosts.

Solution: You configure Server2 and Server3 to forward DNS requests to 10.0.1.10.

Does this meet the goal?

Options:

A.

Yes

B.

No

Buy Now
Questions 21

Task 10

You use a Group Policy preference to map \\dd.contoso.com\instal1 as drive H for all users. If a user already has an existing drive mapping for H. the new drive mapping must take precedence.

Options:

Buy Now
Questions 22

Task 3

You need to run a container that uses the mcr.microsoft.com/windows/servercore/iis image on SRV1. Pott 60 on the container must be published to port 5001 on SRV1 and the container must run in the background.

Options:

Buy Now
Questions 23

Task 1

You need to create a group-managed service account (gMSA) named gMSA1 and make gMSA1 available on SRV1.

Options:

Buy Now
Questions 24

Task 6

You need to ensure that you can manage DC1 by using Windows Admin Center on SRV1.

The required source files are located in a folder named \\dc1.contoso.com\install.

Options:

Buy Now
Questions 25

Task 5

You have an application that is copied to a folder named C:\app on SRV1. C:\app also contains also a Dockerfile for the app.

On SRV1. you need to create a container image for the application by using the Dockerfile. The container image mutt be named app1.

Options:

Buy Now
Questions 26

Task2

You need to ensure that the Azure file share named share1 can sync to on-premises servers.

The required source files are located in a folder named \\dc1.contoso.com\install.

You do NOT need to specify the on-premises servers at this time.

Options:

Buy Now
Questions 27

Task 2

You need to ensure that you can manage SRV1 remotely by using PowerShell

Options:

Buy Now
Questions 28

Task 10

You need to configure Hyper-V to ensure that running virtual machines can be moved between SRV1 and SRV2 without downtime.

You do NOT need to move any virtual machines at this time.

Options:

Buy Now
Questions 29

Task 1

You need to prevent domain users from saving executable files in a share named \\SRVl\Data. The users must be able to save other files to the share.

Options:

Buy Now
Questions 30

Task 6

You need to use Azure File Sync 10 replicate the contents of C:\app on SRV1 to an Azure file share named sharel1.

The required source files are located in a folder named \\dc1.contoso.com\install.

Options:

Buy Now
Questions 31

Task 12

You need to create a Group Policy Object (GPO) named GPO1 that only applies to a group named MemberServers.

Options:

Buy Now
Questions 32

Task 8

You need to create an Active Directory Domain Services (AD DS) site named Site2 that is associated to an IP address range of 192.168.2.0 to 192.168.2.255.

Options:

Buy Now
Questions 33

You need to ensure that data availability on SSPace1 meets the technical requirements.

What is the maximum number of physical disks that can fail on each disk? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 34

DC1 fails.

You need to meet the technical requirements for the schema master.

Yourunntdsutil.exe.

Which five commands should you run in sequence? To answer, move the appropriate commands from the list of commands to the answer area and arrange them in the correct order?

Options:

Buy Now
Questions 35

Task 5

You need to ensure that a DHCP scope named scope! on SRV1 can service client requests.

Options:

Buy Now
Questions 36

You need to meet the technical requirements for the site links. Which users can perform the required tasks?

Options:

A.

Admin1 only

B.

Admin1 and Admin3 only

C.

Admin1 and Admin2 only

D.

Admin3 only

E.

Admin1, Adrrun2. and Admin3

Buy Now
Questions 37

You need to meet the technical requirements for VM1.

Which cmdlet should you run first? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 38

You need to implement the planned changes for the Azure DNS Private Resolver.

Which private DNS zones can you use for name resolution?

Options:

A.

Zone1.com only

B.

Zone2.com only

C.

Zone1.com and Zone2.com only

D.

Zone2.com and Zone3.com only

E.

Zone1.com, Zone2.com, and Zone3.com

Buy Now
Questions 39

Which groups can you add lo Group3 and Groups? To answer, select the appropriate options in the answer area. NOTE Each correct selection is worth one point.

Options:

Buy Now
Questions 40

You need to ensure that access to storage1 for the Marketing OU users meets the technical requirements.

What should you implement?

Options:

A.

Microsoft Entra Connect cloud sync

B.

Active Directory Federation Services (AD FS)

C.

Microsoft Entra Connect in staging mode

D.

Microsoft Entra Connect in active mode

Buy Now
Questions 41

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 42

You need to configure remote administration to meet the security requirements. What should you use?

Options:

A.

just in time (JIT) VM access

B.

Azure AD Privileged Identity Management (PIM)

C.

the Remote Desktop extension for Azure Cloud Services

D.

an Azure Bastion host

Buy Now
Questions 43

You need to meet the technical requirements for VM3

On which volumes can you enable Data Deduplication?

Options:

A.

D and E only

B.

C, D, E, and F

C.

D only

D.

D and E only

E.

D, E, and F only

Buy Now
Questions 44

You need to meet the technical requirements for Server1. Which users can currently perform the required tasks?

Options:

A.

Admin1 only

B.

Admin3 only

C.

Admin1 and Admin3 only

D.

Admin1 Admin2. and Admm3

Buy Now
Questions 45

You need to meet the technical requirements for VM2.

What should you do?

Options:

A.

Implement shielded virtual machines.

B.

Enable the Guest services integration service.

C.

Implement Credential Guard.

D.

Enable enhanced session mode.

Buy Now
Questions 46

You need to meet the technical requirements for User1. The solution must use the principle of least privilege.

What should you do?

Options:

A.

Add Users1 to the Server Operators group in contoso.com.

B.

Create a delegation on contoso.com.

C.

Add Users1 to the Account Operators group in contoso.com.

D.

Create a delegation on OU3.

Buy Now
Questions 47

Which groups can you add to Group3 and Group5? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 48

You need to meet the technical requirements for Server4.

Which cmdlets should you run on Server1 and Server4? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Buy Now
Questions 49

You are planning the implementation Azure Arc to support the planned changes. You need to configure the environment to support configuration management policies. What should you do?

Options:

A.

Hybrid Azure AD join all the servers.

B.

Create a hybrid runbook worker m Azure Automation.

C.

Deploy the Azure Connected Machine agent to all the servers.

D.

Deploy the Azure Monitor agent to all the servers.

Buy Now
Questions 50

Which three actions should you perform in sequence to meet the security requirements for Webapp1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Buy Now
Questions 51

You need to configure Azure File Sync to meet the file sharing requirements. What should you do? To answer, select the appropriate options in the answer area. NOTE Each correct selection is worth one point.

Options:

Buy Now
Questions 52

You need to implement a name resolution solution that meets the networking requirements. Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point

Options:

A.

Create an Azure private DNS zone named corp.fabhkam.com.

B.

Create a virtual network link in the coip.fabnkam.c om Azure private DNS zone.

C.

Create an Azure DNS zone named corp.fabrikam.com.

D.

Configure the DNS Servers settings for Vnet1.

E.

Enable autoregistration in the corp.fabnkam.com Azure private DNS zone.

F.

On DC3, install the DNS Server role.

G.

Configure a conditional forwarder on DC3.

Buy Now
Exam Code: AZ-800
Exam Name: Administering Windows Server Hybrid Core Infrastructure
Last Update: Nov 24, 2024
Questions: 235
AZ-800 pdf

AZ-800 PDF

$28.5  $94.99
AZ-800 Engine

AZ-800 Testing Engine

$33  $109.99
AZ-800 PDF + Engine

AZ-800 PDF + Testing Engine

$43.5  $144.99