Labour Day Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Microsoft AZ-801 Configuring Windows Server Hybrid Advanced Services Exam Practice Test

Page: 1 / 14
Total 143 questions

Configuring Windows Server Hybrid Advanced Services Questions and Answers

Question 1

You need to implement a security policy solution to authorize the applications. The solution must meet the security requirements.

Which service should you use to enforce the security policy, and what should you use to manage the policy settings? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 1

Options:

Question 2

You are planning the DHCP1 migration to support the DHCP migration plan.

Which two PowerShell cmdlets should you run on DHCP1, and which two PowerShell cmdlets should you run on DHCP2? To answer, drag the appropriate cmdlets to the correct servers. Each cmdlet may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Question # 2

Options:

Question 3

You are planning the data share migration to support the on-premises migration plan.

What should you use to perform the migration?

Options:

A.

Storage Migration Service

B.

Microsoft File Server Migration Toolkit

C.

File Server Resource Manager (FSRM)

D.

Windows Server Migration Tools

Question 4

You are remediating the firewall security risks to meet the security requirements.

What should you configure to reduce the risks?

Options:

A.

a Group Policy Object (GPO)

B.

adaptive network hardening in Microsoft Defender for Cloud

C.

a network security group (NSG) in Sub1

D.

an Azure Firewall policy

Question 5

You are planning the implementation of Cluster2 to support the on-premises migration plan.

You need to ensure that the disks on Cluster2 meet the security requirements.

In which order should you perform the actions? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order.

Question # 5

Options:

Question 6

You are planning the europe.fabrikam.com migration to support the on-premises migration plan-Where should you install the Password Export Server (PES) service, where should you generate the encryption key? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 6

Options:

Question 7

You are planning the migration of Archive1 to support the on-premises migration plan.

What is the minimum number of IP addresses required for the node and cluster roles on Cluster3?

Options:

A.

2

B.

3

C.

4

D.

5

Question 8

You are planning the deployment of Microsoft Sentinel.

Which type of Microsoft Sentinel data connector should you use to meet the security requirements?

Options:

A.

Threat Intelligence - TAXII

B.

Azure Active Directory

C.

Microsoft Defender for Cloud

D.

Microsoft Defender for Identity

Question 9

You are planning the migration of APP3 and APP4 to support the Azure migration plan.

What should you do on Cluster1 and in Azure before you perform the migration? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 9

Options:

Question 10

You are planning the www.fabrikam.com website migration to support the Azure migration plan.

How should you configure WebApp1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 10

Options:

Question 11

Which domain controller should be online to meet the technical requirements for DC4?

Options:

A.

DC1

B.

DC2

C.

DC3

Question 12

What is the effective minimum password length for User1 and Admin1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 12

Options:

Question 13

You need to meet the technical requirements for Cluster3.

What should you include in the solution?

Options:

A.

Enable integration services on all the virtual machines.

B.

Add a Windows Server server role.

C.

Configure a fault domain doe the cluster.

D.

Add a failover cluster role.

Question 14

You need to meet technical requirements for Share1.

What should you use?

Options:

A.

Storage Migration Service

B.

File Server Resource Manager (FSRM)

C.

Server Manager

D.

Storage Replica

Question 15

You have an Azure virtual machine named VM1 that runs Windows Server.

The operating system on VM1 fails to start due to a disk error.

You need to resolve the error.

Which four commands should you run in sequence in Azure Cloud Shell? To answer, move the appropriate commands from the list of commands to the answer area and arrange them in the correct order.

Question # 15

Options:

Question 16

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a server named Server1 that runs Windows Server.

You need to ensure that only specific applications can modify the data in protected folders on Server1.

Solution: From App & browser control, you configure the Exploit protection settings.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 17

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains servers that run Windows Server as shown in the following table.

Question # 17

Server1 has the connection security rules shown in the following table.

Question # 17

Server2 has the connection security rules shown in the following table.

.

Question # 17

Options:

Question 18

Your network contains an Active Directory Domain Services (AD DS) domain.

You need to implement a solution that meets the following requirements:

  • Ensures that the members of the Domain Admins group are allowed to sign in only to domain controllers
  • Ensures that the lifetime of Kerberos Ticket Granting Ticket (TGT) for the members of the Domain Admins group is limited to one hour

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Question # 18

Options:

Question 19

You have a server named Server1 that runs Windows Server and has the Hyper-V server role installed. You have a Hyper-V failover cluster named Cluster1. All servers are members of the same domain.

You need to ensure that you use Hyper-V Replica with Kerberos authentication on the default port to replicate virtual machines from Cluster1 to Server1.

What should you do on Server1?

Options:

A.

Add primary servers to the Hyper-V Replica Broker configuration.

B.

From Hyper-V Settings, select Enable incoming and outgoing live migrations

C.

From Windows Defender Firewall with Advanced Security, enable the Hyper-V Replica HTTPS Listener (TCP-ln) rule.

D.

From Windows Defender Firewall with Advanced Security, enable the Hyper-V Replica HTTP Listener (TCP-ln) rule.

Question 20

You have a Site-to-Site VPN between an on-premises network and an Azure VPN gateway. BGP is disabled for the Site-to-Site VPN.

You have an Azure virtual network named Vnet1 that contains a subnet named Subnet1. Subnet1 contains a virtual machine named Server1.

You can connect to Server1 from the on-premises network.

You extend the address space of Vnet1. You add a subnet named Subnet2 to Vnet1. Subnet2 uses the extended address space. You deploy an Azure virtual machine named Server2 to Subnet2.

You cannot connect to Server2 from the on-premises network. Server1 can connect to Server2.

You need to ensure that you can connect to Subnet2 from the on-premises network.

What should you do?

Options:

A.

Add an additional Site-to-Site VPN between the on-premises network and Vnetl.

B.

Add a private endpoint to Subnet2.

C.

To Subnet2. add a route table that contains a user-defined route.

D.

Update the routing information on the on-premises routers.

Question 21

Your network contains a single-domain Active Directory Domain Services (AD DS) forest named contoso.com. The functional level of the forest is Windows Server 2012 R2. All domain controllers run Windows Server 2012 R2.

Sysvol replicates by using the File Replication Service (FRS).

You plan to replace the existing domain controllers with new domain controllers that will run Windows Server 2022.

You need to ensure that you can add the first domain controller that runs Windows Server 2022.

Solution; You raise the domain and forest functional levels.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 22

Your network contains an Active Directory Domain Services (AD DS) domain All domain members have Microsoft Defender Credential Guard with UEFI tock configured in the domain you deploy a server named Server1 that runs Windows Server. You disable Credential Guard on Server1. You need to ensure that Server1 is MOST subject to Credential Guard restrictions. What should you do next?

Options:

A.

Run the Device Guard and Credential Guard hardware readiness tool

B.

Disable the Turn on Virtual nation Based Security group policy setting

C.

Run dism and specify the /Disable-Feature and /FeatureName:IsolatedUserMode parameters

Question 23

You have a server that runs Windows Server and has the Web Server (IIS) server role installed. Server1 hosts a single website that has the following configurations:

  • Is accessible by using a URL of https://www.contoso.com:8443 and has an SSL certificate that was issued by a third-party certification authority (CA) in the Microsoft Trusted Root Program
  • Uses anonymous authentication
  • Was developed by using PHP

You plan to use APP Service Migration Assistant to migrate the website to Azure App Service.

You need to migrate the website. The solution must minimize the number of changes made to the existing website.

What should you do manually to ensure that the website migration is successful? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 23

Options:

Question 24

You have three Azure virtual machines named VM1, VM2, and VM3 that host a multitier application.

You plan to implement Azure Site Recovery.

You need to ensure that VM1, VM2, and VM3 fail over as a group.

What should you configure?

Options:

A.

an availability zone

B.

a recovery plan

C.

an availability set

Question 25

You have a three-node failover cluster.

You need to run pre-scripts and post-scripts when Cluster-Aware Updating (CAU) runs. The solution must minimize administrative effort.

What should you use?

Options:

A.

Scheduled tasks

B.

Run profiles

C.

Azure Functions

D.

Windows Server Update Serveries (WSUS)

Question 26

You have a Microsoft Sentinel deployment and 100 Azure Arc-enabled on-premises servers. All the Azure Arc-enabled resources are in the same resource group.

You need to onboard the servers to Microsoft Sentinel. The solution must minimize administrative effort.

What should you use to onboard the servers to Microsoft Sentinel?

Options:

A.

Azure Automation

B.

Azure Policy

C.

Azure virtual machine extensions

D.

Microsoft Defender for Cloud

Question 27

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an on-premises server named Server1 that runs Windows Server.

You have a Microsoft Sentinel instance.

You add the Windows Firewall data connector in Microsoft Sentinel.

You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1.

Solution: You install the Log Analytics agent on Server1

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 28

You have an Azure Active Directory Domain Services (Azure AD DS) domain named aadds.contoso.com.

You have an Azure virtual network named Vnet1. Vnet1 contains two virtual machines named VM1 and VM2 that run Windows Server. VMI and VM2 are joined to aadds.contoso.com.

You create a new Azure virtual network named Vnet2. You add a new server named VM3 to Vnet2.

When you attempt to join VM3 to aadds.contoso.com, you get an error message that the domain cannot be found.

You need to ensure that you can join VM3 toaadds.contoso.com.

Question # 28

Options:

Page: 1 / 14
Total 143 questions