microsoft AZ-800 Exam Questions

Questions for the AZ-800 were updated on : Jul 20 ,2024

Page 1 out of 6. Viewing questions 1-15 out of 88

Question 1 Topic 1, Case Study 1Case Study Question View Case

You need to configure the Group Policy settings to ensure that the Azure Virtual Desktop session hosts meet the security
requirements.
What should you configure?

  • A. loopback processing in GPO4
  • B. security filtering for the link of GPO1
  • C. loopback processing in GPO1
  • D. the Enforced property for the link of GPO4
  • E. the Enforced property for the link of GPO1
  • F. security filtering for the link of GPO4
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%
F
50%
Discussions
vote your answer:
A
B
C
D
E
F
0 / 1000

Question 2 Topic 1, Case Study 1Case Study Question View Case

What should you implement for the deployment of DC3?

  • A. Azure Active Directory Domain Services (Azure AD DS)
  • B. an Azure virtual machine
  • C. an Azure AD administrative unit
  • D. Azure AD Application Proxy
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
Create a domain controller named dc3.corp.fabrikam.com in Vnet1.
In a hybrid network, you can configure Azure virtual machines as domain controllers. The domain controllers in Azure
communicate with the on-premises domain controllers in the same way that onpremises domain controllers communicate
with each other.

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 3 Topic 1, Case Study 1Case Study Question View Case

DRAG DROP
Which three actions should you perform in sequence to meet the security requirements for Webapp1? To answer, move the
appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:

Answer:


Explanation:
Reference: https://docs.microsoft.com/en-us/windows-server/security/group-managed-service-accounts/group-managed-
service-accounts-overview

Discussions
0 / 1000

Question 4 Topic 1, Case Study 1Case Study Question View Case

DRAG DROP
You need to meet the security requirements for passwords.
Where should you configure the components for Azure AD Password Protection? To answer, drag the appropriate
components to the correct locations. Each component may be used once, more than once, or not at all. You may need to
drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Select and Place:

Answer:


Explanation:
Reference: https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad-on-premises

Discussions
0 / 1000

Question 5 Topic 2, Case Study 2Case Study Question View Case

You need to meet the technical requirements for Server1.
Which users can currently perform the required tasks?

  • A. Admin3 only
  • B. Admin1 and Admin3 only
  • C. Admin1 only
  • D. Admin1, Admin2, and Admin3
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 6 Topic 2, Case Study 2Case Study Question View Case

You need to meet the technical requirements for the site links.
Which users can perform the required tasks?

  • A. Admin1, Admin2, and Admin3
  • B. Admin1 and Admin3 only
  • C. Admin1 only
  • D. Admin1 and Admin2 only
  • E. Admin3 only
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%

Explanation:
Membership in the Enterprise Admins group or the Domain Admins group in the forest root domain is required.

Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 7 Topic 2, Case Study 2Case Study Question View Case

You need to meet the technical requirements for User1. The solution must use the principle of least privilege.
What should you do?

  • A. Add Users1 to the Server Operators group in contoso.com.
  • B. Create a delegation on contoso.com.
  • C. Add Users1 to the Account Operators group in contoso.com.
  • D. Create a delegation on OU3.
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
Reference: https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/delegating-administration-of-account-ous-
and-resource-ous

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 8 Topic 2, Case Study 2Case Study Question View Case

HOTSPOT
Which groups can you add to Group3 and Group5? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Answer:


Explanation:
Reference:
https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directory-security-groups

Discussions
0 / 1000

Question 9 Topic 3, Case Study 3Case Study Question View Case

HOTSPOT
You need to meet the technical requirements for VM1.
Which cmdlet should you run first? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Answer:


Explanation:
Reference: https://docs.microsoft.com/en-us/virtualization/hyper-v-on-windows/user-guide/nested-virtualization

Discussions
0 / 1000

Question 10 Topic 3, Case Study 3Case Study Question View Case

You need to meet the technical requirements for VM2.
What should you do?

  • A. Implement shielded virtual machines.
  • B. Enable the Guest services integration service.
  • C. Implement Credential Guard.
  • D. Enable enhanced session mode.
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 11 Topic 4, Case Study 4Case Study Question View Case

You need to implement a name resolution solution that meets the networking requirements.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. Configure the DNS Servers settings for Vnet1.
  • B. On DC3, install the DNS Server role.
  • C. Create a virtual network link in the corp.fabrikam.com Azure private DNS zone.
  • D. Configure a conditional forwarder on DC3.
  • E. Enable autoregistration in the corp.fabrikam.com Azure private DNS zone.
  • F. Create an Azure private DNZ zone named corp.fabrikam.com.
  • G. Create an Azure DNZ zone named corp.fabrikam.com.
Answer:

A B

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%
F
50%
G
50%

Explanation:
Virtual machines in an Azure virtual network receive their DNS configuration from the DNS settings configured on the virtual
network. You need to configure the Azure virtual network to use DC3 as the DNS server. Then all virtual machines in the
virtual network will use DC3 and their DNS server.

Discussions
vote your answer:
A
B
C
D
E
F
G
0 / 1000

Question 12 Topic 4, Case Study 4Case Study Question View Case

HOTSPOT
You need to configure network communication between the Seattle and New York offices. The solution must meet the
networking requirements.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Answer:


Explanation:
Reference: https://docs.microsoft.com/en-us/azure/virtual-wan/virtual-wan-expressroute-portal

Discussions
0 / 1000

Question 13 Topic 4, Case Study 4Case Study Question View Case

You need to configure remote administration to meet the security requirements.
What should you use?

  • A. an Azure Bastion host
  • B. Azure AD Privileged Identity Management (PIM)
  • C. the Remote Desktop extension for Azure Cloud Services
  • D. just in time (JIT) VM access
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
Reference: https://docs.microsoft.com/en-us/azure/defender-for-cloud/just-in-time-access-usage?tabs=jit-config-asc%2Cjit-
request-asc

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 14 Topic 4, Case Study 4Case Study Question View Case

You need to implement an availability solution for DHCP that meets the networking requirements.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. On DHCP1, create a scope that contains 25 percent of the IP addresses from Scope2.
  • B. On the router in each office, configure a DHCP relay.
  • C. DHCP2, configure a scope that contains 25 percent of the IP addresses from Scope1.
  • D. On each DHCP server, install the Failover Clustering feature and add the DHCP cluster role.
  • E. On each DHCP scope, configure DHCP failover.
Answer:

B E

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%

Explanation:
Reference: https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-
2012/hh831385(v=ws.11)

Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 15 Topic 5, Mixed Questions

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a
unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in
the review screen.
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.
You need to identify which server is the PDC emulator for the domain.
Solution: From Active Directory Sites and Services, you right-click Default-First-Site-Name in the console tree, and then
select Properties.
Does this meet the goal?

  • A. Yes
  • B. No
Answer:

B

User Votes:
A
50%
B
50%
Discussions
vote your answer:
A
B
0 / 1000
To page 2