live chatMcAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams
Pass4Test 10%OFF Discount Code

Microsoft Administering Windows Server Hybrid Core Infrastructure - AZ-800 Exam Questions

QUESTION NO: 1
You have been hired as the networking administrator in the company. There is one user account that is required to be moved very often between the Sales & Marketing groups. But you notice that the changes aren't working. Which of the following Flexible Single Master Operation (FSMO) roles might be responsible?
Correct Answer: C
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 2
Drag and Drop Question
You have a server named Server1 that has Windows Admin Center installed. The certificate used by Windows Admin Center was obtained from a certification authority (CA).
The certificate expires.
You need to replace the certificate.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Correct Answer:

Explanation:
https://www.starwindsoftware.com/blog/change-the-windows-admin-center-certificate
QUESTION NO: 3
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
Your network contains an Active Directory Domains Services (AD DS) domain named contoso.com.
You implement a central store.
You create a new Group Policy Object (GPO) named GPO1.
When you attempt to edit GPO1, you see the settings shown in the exhibit. (Click the Exhibit tab.)

You need to ensure that all settings are available.
Solution: You modify the properties of GPO1.
Does this meet the goal?
Correct Answer: B
QUESTION NO: 4
SIMULATION
You need to ensure that you can manage DC1 by using Windows Admin Center on SRV1.
The required source files are located in a folder named \\dc1.contoso.com\install.
To connect to Windows Admin Center, open Microsoft Edge and enter the following URL:
https://localhost
Correct Answer:
To configure Windows Admin Center (WAC) to manage an Active Directory domain controller from your current environment, you must install the Active Directory extension and add the domain controller connection.
Follow these sequential steps to complete the scenario:
Action 1. Install the Active Directory Extension
Because you are accessing WAC locally via https://localhost, you need to download and install the management extension using the source files provided in your local network share:
Step 1: Open Microsoft Edge and navigate to https://localhost.
Step 2: Click the Settings (gear icon) in the top right corner of the Windows Admin Center interface.
Step 3: Select Extensions under the Gateway settings panel on the left.
Step 4: Click on the Feeds tab and click Add.
Step 5: Enter the path to your source folder: \\dc1.contoso.com\install and save it.
Step 6: Switch back to the Available Extensions tab.
Step 7: Locate and select Active Directory, then click Install.
The gateway service will automatically restart to apply the extension
Action 2. Connect to the Domain Controller
Once the toolset is updated, you must target the domain controller for management:
Step 8: Return to the Windows Admin Center All connections home dashboard.
Step 9: Click + Add. Under Servers, click Add
Step 10: Type the name or IP address of your domain controller (e.g., dc1.contoso.com).
Step 11: If prompted, select Use another account for this connection and enter valid Domain Admin credentials.
Step 12: Click Add with credentials or Add to add it to your list.
Reference:
https://www.youtube.com/watch?v=z1ticxlgjlk
QUESTION NO: 5
Hotspot Question
Your network contains two Active Directory Domain Services (AD DS) forests as shown in the following exhibit.

The forests contain the domain controllers shown in the following table.

You perform the following actions on DC1:
- Create a user named User1.
- Extend the schema with a new attribute named Attribute1.
To which domain controllers are User1 and Attribute1 replicated? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
User1:
This is a domain-level object.
Since DC1 and DC2 are in the same domain (adatum.com), User1 will be replicated to DC2.
DC3 is in a different domain (west.adatum.com), but it is in the same forest. Since it's a Global Catalog (GC) server, it will receive a partial replica of the adatum.com domain, including the newly created User1.
DC4 is in a completely different forest (contoso.com) and there is no direct trust relationship between contoso.com and west.adatum.com, so User1 will not be replicated to DC4.
Attribute1:
This is a schema-level object. The schema is a forest-wide object.
The schema master for the adatum.com forest is DC1, so any changes to the schema (such as adding a new attribute) are initially made on DC1.
These changes are then replicated to all other domain controllers in the adatum.com forest, which includes DC2 and DC3.
However, DC4 is in a different forest, so it will not receive the schema changes made in the adatum.com forest.
In summary, User1 and Attribute1 will be replicated to DC2 and DC3
QUESTION NO: 6
Drag and Drop Question
Your network contains a single domain Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains a single Active Directory site.
You plan to deploy a read only domain controller (RODC) to a new datacenter on a server named Server1. A user named User1 is a member of the local Administrators group on Server1.
You need to recommend a deployment plan that meets the following requirements:
* Ensures that a user named User1 can perform the RODC installation on Server1
* Ensures that you can control the AD DS replication schedule to the Server1
* Ensures that Server1 is in a new site named RemoteSite1
* Uses the principle of least privilege
Which three actions should you recommend performing in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Correct Answer:

Explanation:
Box 1.
We need to create a site and subnet for the remote site. The new site will be added to the Default IP Site Link so we don't need to create a new site link. You configure the replication schedule on the site link.
Box 2.
When we pre-create an RODC account, we can specify who is allowed to attach the server to the prestaged account. This means that the User1 does not need to be added to the Domain Admins group.
Box3.
User1 can connect the RODC to the prestaged account by running the AD DS installation wizard.
Reference:
https://mehic.se/2018/01/02/how-to-install-and-configure-read-only-domain-controller-rodc-2016/
QUESTION NO: 7
Hotspot Question
You have an Azure subscription named Sub1 that is linked to a Microsoft Entra tenant named contoso.com. Contoso.com contains the users shown in the following table.

You deploy a virtual machine that has the following configurations:
- Name: VM1
- Resource group: RG1
- Operating system: Windows Server
- Login with Microsoft Entra ID: Enabled
You have the Azure role assignments shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Box 1: No
User1 is a member.
User1 has the Virtual Machine Contributor role with scope RG1.
VM1 is in RG1 and has Entra login enabled.
A user with the Virtual Machine Contributor role in Azure AD (Entra ID) does not automatically have the ability to log in to a virtual machine with Entra ID login enabled. While the Contributor role provides significant management capabilities for the VM, it does not inherently grant the specific permissions needed for interactive login using Entra ID credentials.
Box 2: No
User2 is a guest.
User2 has the Virtual Machine User login role with scope RG1.
A guest user in an Entra ID (formerly Azure AD) tenant cannot log in to an Azure VM using Entra ID authentication, even if they have the Virtual Machine User Login role assigned. Entra guest accounts are not supported for Azure VM login via Entra ID authentication.
Box 3: Yes
User3 is a member.
User3 has the Virtual Machine Administrator login role with scope RG1.
A user who is a member of an Entra domain and has the "Virtual Machine Administrator Login" role assigned can log in to a virtual machine with Entra ID login enabled. This role grants users the necessary permissions to sign in to Azure virtual machines with administrator privileges Reference:
https://learn.microsoft.com/en-us/entra/identity/devices/howto-vm-sign-in-azure-ad-windows
QUESTION NO: 8
Hotspot Question
You have a Hyper-V host named Server1 that is connected to a managed switch. The switch is connected to multiple VLANs.
On Server1, you configure a new virtual machine named VM1.
You need to configure VM1 to communicate with all the VLANs. Any network traffic that is not tagged must be directed to VLAN 20.
How should you complete the PowerShell command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Box 1: Set-VMNetworkAdapterVlan
The Set-VMNetworkAdapterVlan cmdlet configures virtual LAN settings for the traffic through a virtual network adapter. Access, Trunk, Private VLAN (isolated, community, or promiscuous), and untagged are mutually exclusive.
Box 2: -Trunk -NativeVlanID 20
Specifies Trunk mode for the virtual machine network adapter. This parameter configures a tagged virtual port that passes all allowed VLANId tags to the VM adapter. Traffic with the NativeVLANId is passed untagged to the VM adapter. This parameter must be used in conjunction with parameters AllowedVlanIdList and NativeVlanId.
- NativeVlanId
Specifies the native virtual LAN identifier for a virtual machine network adapter. This parameter must be specified in conjunction with the switch parameter Trunk.
Reference:
https://learn.microsoft.com/en-us/powershell/module/hyper-v/set-vmnetworkadaptervlan
QUESTION NO: 9
Hotspot Question
You have a server named Host1 that runs Windows Server 2022 and is configured as a container host. Host1 stores a container image named image1 that is based on Windows Server 2019.
You need to start a container from image1 on Host1.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:
QUESTION NO: 10
You have an on-premises server named Server1 that runs Windows Server and is managed by using Windows Admin Center.
You have an Azure subscription that contains a virtual network named VNet1.
You need to connect Server1 to VNet1 by using an Azure Network Adapter.
What should you do first in Windows Admin Center?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 11
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a user named User1. User1 is a member of a group named Group1 and is in an organizational unit (OU) named OU1.
The domain has minimum password lengths configured as shown in the following table.

What is the minimum password length that User1 should use when changing to a new password?
Correct Answer: E
QUESTION NO: 12
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains two servers named Server1 and Server2.
Server1 contains a disk named Disk2. Disk2 contains a folder named UserData. UserData is shared to the Domain Users group. Disk2 is configured for deduplication. Server1 is protected by using Azure Backup.
Server1 fails.
You connect Disk2 to Server2.
You need to ensure that you can access all the files on Disk2 as quickly as possible.
What should you do?
Correct Answer: D
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).