All Obstacles During AZ-800 Exam Preparation with AZ-800 Real Test Questions
Fully Updated Free Actual Microsoft AZ-800 Exam Questions
Schedule exam
Languages: English, Japanese, Chinese (Simplified), Korean, German, French, Spanish, Portuguese (Brazil), Arabic (Saudi Arabia), Russian, Chinese (Traditional), Italian, Indonesian (Indonesia)
Retirement date: none
This exam measures your ability to accomplish the following technical tasks: deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments; manage Windows Servers and workloads in a hybrid environment; manage virtual machines and containers; implement and manage an on-premises and hybrid networking infrastructure; and manage storage and file services.
NEW QUESTION # 69
You have a server named Server1 that runs Windows Server and has the Hyper V server role installed. Server1 hosts a virtual machine named VM1.
Server1 has an NVMe storage device. The device is currently assigned to VM1 by using Discrete Device Assignment.
You need to make the device available to Server1.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
1 - From Server1, stop VM1.
2 - From Server1, run the Remove-VMAssignableDevice cmdlet.
3 - From Server1, run the Mount-VMHost AssignableDevice cmdlet.
4 - From Server1, enable the device by using Device Manager.
Reference:
https://docs.microsoft.com/en-us/windows-server/virtualization/hyper-v/deploy/deploying-storage-devices-using-dda
NEW QUESTION # 70
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com.
The root domain contains the domain controllers shown in the following table.
A failure of which domain controller will prevent you from creating application partitions?
- A. DC1
- B. DC4
- C. DC2
- D. DC5
- E. DC3
Answer: A
Explanation:
Initial replication and connectivity requirements
This FSMO role holder is only active when the role owner has inbound replicated the configuration NC successfully since the Directory Service started.
Domain members of the forest only contact the FSMO role holder when they update the cross- references. DCs contact the FSMO role holder when:
Domains are added or removed in the forest.
New instances of application directory partitions on DCs are added. For example, a DNS server has been enlisted for the default DNS application directory partitions.
https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/fsmo- roles#domain%20naming
NEW QUESTION # 71
You have been tasked to decommission the member hosts from an existing server farm. As a part of the procedure, you have removed the member host from group Managed Service Account (gMSA) and now you need to remove gMSA.
Which of the following cmdlet would you use in PowerShell?
- A. Remove-ADServiceAccount
- B. Uninstall-gMSAAccount
- C. Uninstall-ADServiceAccount
- D. Remove -gMSAAccount
Answer: C
Explanation:
The cached gMSA credentials can be removed from the member host using Uninstall- ADServiceAccount cmdlet or the NetRemoveServiceAccount API on the host system.
Syntax:
Uninstall-ADServiceAccount <ADServiceAccount>
Reference:
https://docs.microsoft.com/en-us/windows-server/security/group-managed-service- accounts/getting-started-with-group-managed-service-accounts
NEW QUESTION # 72
Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com.

The domain contains a 'He server named Server1 and three users named User1. User2 and User), Server1 contains a shared folder named Share1 tha1 has the following configurations:
The share permissions for Share1 are configured as shown in the Share Permissions exhibit. (Click the Share Permissions tab.) Share! contains a file named Filel.txt. The advanced security settings for Filel.txt are configured as shown in the File Permissions exhibit. (Click the File Permissions tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: f ach correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 73
Your company needs to deploy a Kerberos authentication-based application, having no requirements related to on-premises directory services. Choose the deployment model that will suit best in this case.
- A. Deploy a separate AD forest that's trusted by domains in their on-premises AD forest
- B. Deploy AD DS only on an Azure VMright
- C. Deploy AD DS in on-premises infrastructure and on an Azure VM
- D. You can choose any deployment model. All will have equal performance.
Answer: B
Explanation:
Deploying AD DS only on an Azure VM is best suitable for the:
- Applications based upon Kerberos authentication but having no requirements related to on- premises directory services.
- Greenfield deployments with no existing on-premises AD DS environment.
Reference:
https://docs.microsoft.com/en-us/learn/modules/deploy-manage-azure-iaas-active-directory- domain-controllers-azure/02-select-option-implement-directory-identity-services
NEW QUESTION # 74
You need to meet the technical requirements for VM2.
What should you do?
- A. Implement shielded virtual machines.
- B. Enable enhanced session mode.
- C. Enable the Guest services integration service.
- D. Implement Credential Guard.
Answer: C
NEW QUESTION # 75
You have an Azure virtual machine named VM1 that runs Windows Server and has the following configurations:
Size: D2s_v4
Operating system disk: 127-GiB standard SSD
Data disk 128-GiB standard SSD
Virtual machine generation: Gen 2
You plan to perform the following changes to VM1:
Change the virtual machine size to D4s_v4.
Detach the data disk.
Add a new standard SSD.
Which changes require downtime for VM1?
- A. Changing the virtual machine size only.
- B. Adding a new standard SSD only.
- C. Detaching the data disk only.
- D. Detaching the data disk only and adding a new standard SSD.
Answer: A
Explanation:
Data disks can be added and detached without requiring downtime. Changing the VM size requires the VM to be restarted.
NEW QUESTION # 76
Drag and Drop Question
You have two on-premises servers named Server1 and Server2 that run Windows Server.
You have an Azure Storage account named storage1 that contains a file share named share1.
Server1 syncs with share1 by using Azure File Sync.
You need to configure Server2 to sync with share1.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation:
https://docs.microsoft.com/en-us/azure/storage/file-sync/file-sync-server-registration
https://docs.microsoft.com/en-us/azure/storage/file-sync/file-sync-server-endpoint- create?tabs=azure-portal
NEW QUESTION # 77
You have an on-premises server named Server 1 that runs Windows Server. You have an Azure subscription that contains a virtual network named VNetl. You need to connect Server! to VNetl by using Azure Network Adapter. What should you use?
- A. Windows Admin Center
- B. the Azure portal
- C. Device Manager
- D. Azure AD Connect
Answer: D
NEW QUESTION # 78
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains a server named Server1 that has the DFS Namespaces role service installed. Server! hosts a domain-based Distributed File System (DFS) Namespace named Files.
The domain contains a tile server named Server2. Seiver2 contains a shared folder named Share1. Share1 contains a subfolder named Folder 1.
In the Files namespace, you create a folder named Folder! that has a target of \\Server2.contoso.com\Share1\Folder1.
You need to configure a logon script that will map drive letter M to Folder1. The solution must use the path of the DFS Namespace.
How should you complete the command to map the drive letter? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 79
Your company has a main office and a branch office. The two offices are connected by using a WAN link. Each office contains a firewall that filters WAN traffic.
The network in the branch office contains 10 servers that run Windows Server. All servers are administered from the main office only.
You plan to manage the servers in the branch office by using a Windows Admin Center gateway.
On a server in the branch office, you install the Windows Admin Center gateway by using the defaults settings.
You need to configure the firewall in the branch office to allow the required inbound connection to the Windows Admin Center gateway.
Which inbound TCP port should you allow?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
The default port for the Windows Admin Center Gateway Installation is Port 443 - it is recommended to use this default port.
https://www.manfredhelber.de/installing-and-configuring-windows-admin-center-for-windows- server-2022-management/
NEW QUESTION # 80
You need to meet the security requirements for passwords.
Where should you configure the components for Azure AD Password Protection? lo answer, drag the appropriate components to the correct locations. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad-on-premises
NEW QUESTION # 81
You have a file server named Server1 that runs Windows Server and contains the volumes shown in the following table.
On which volumes can you use BitLocker Drive Encryption (BitLocker) and disk quotas? To answer select the appropriate options in the answer are a. NOTE Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/storage/refs/refs-overview
NEW QUESTION # 82
You have a server named Server1 that has Windows Admin Center installed. The certificate used by Windows Admin Center was obtained from a certification authority (CA).
The certificate expires.
You need to replace the certificate.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
1 - From Internet Information Services (IIS) Mnager,bind a certificate.
2 - Copy the certificate thumbprint.
3 - Rerun Windows Admin Center Setup and select Change.
Reference:
https://www.starwindsoftware.com/blog/change-the-windows-admin-center-certificate
NEW QUESTION # 83
You have an on-premises server named Server1 that runs Windows Server and has internet connectivity.
You have an Azure subscription.
You need to monitor Server1 by using Azure Monitor.
Which resources should you create in the subscription, and what should you install on Server1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure-monitor
NEW QUESTION # 84
......
Validate your AZ-800 Exam Preparation with AZ-800 Practice Test: https://freedumps.validvce.com/AZ-800-exam-collection.html
