DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft AZ-800 Practice Questions & Answers 2026 Part1

Are you preparing for the Microsoft AZ-800 certification exam? SPOTO offers the Microsoft AZ-800 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
You plan to deploy a containerized application that requires .NET Core. You need to create a container image for the application. The image must be as small as possible. Which base image should you use?
A. Add the PowerShell Desired State Configuration (DSC) extension to VM1
B. Configure VM1 to use a user-assigned managed identity
C. Configure VM1 to use a system-assigned managed identity
D. Add the Custom Script Extension to VM1
View answer
Correct Answer: C

View The Updated AZ-800 Exam Questions

SPOTO Provides 100% Real AZ-800 Exam Questions for You to Pass Your AZ-800 Exam!

Question #2
You are planning the implementation Azure Arc to support the planned changes. You need to configure the environment to support configuration management policies. What should you do?
A. Hybrid Azure AD join all the servers
B. Create a hybrid runbook worker m Azure Automation
C. Deploy the Azure Connected Machine agent to all the servers
D. Deploy the Azure Monitor agent to all the servers
View answer
Correct Answer: C
Question #3
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that mightmeet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.You need to identify which server is the PDC emulator for the domain.Solution: From Active Directory Domains and Trusts, you right-click Active Directory Domains and Trusts in the console tree, and then select OperationsMaster.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #4
Case StudyThis is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.To start the case study To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.OverviewCompany Information ADatum Corporation is a manufacturing company that has a main office in Seattle and two branch offices in Los Angeles and Montreal.Fabrikam PartnershipADatum recently partnered with 2 company named Fabrikam, Inc.Fabrikam is a manufacturing company that has a main office in Boston and a branch office in Orlando.Both companies intend to collaborate on several joint projects.Existing EnvironmentADatum AD DS EnvironmentThe on-premises network of A. Datum contains an Active Directory Domain Services (AD DS) forest named adatum.com.The forest contains two domains named adatum.com and east.adatum.com and the domain controllers shown in the following table.Fabrikam AD DS EnvironmentThe on-premises network of Fabrikam contains an AD DS forest named fabrikam.com.The forest contains two domains named fabrikam.com and south.fabrikam.com.The fabrikam.com domain contains an organizational unit (OU) named Marketing.Server InfrastructureThe adatum.com domain contains the servers shown in the following table.HyperV1 contains the virtual machines shown in the following table.All the virtual machines on HyperV1 have only the default management tools installed.SSPace1 contains the Storage Spaces virtual disks shown in the following table.Azure ResourcesADatum has an Azure subscription that contains an Azure AD tenant. Azure AD Connect is configured to sync the adatum.com forest with Azure AD.The subscription contains the virtual networks shown in the following table.The subscription contains the Azure Private DNS zones shown in the following table.The subscription contains the virtual machines shown in the following table.All the servers are in a workgroup.The subscription contains a storage account named storage1 that has a file share named share1.RequirementsPlanned ChangesADatum plans to implement the following changes:Sync Data1 to share1.Configure an Azure runbook named Task1.Enable Azure AD users to sign in to Server1.Create an Azure DNS Private Resolver that has the following configurations:Name: Private1Region: West USVirtual network: VNet1Inbound endpoint: SubnetBEnable users in the adatum.com domain to access the resources in the south.fabrikam.com domain.Technical RequirementsADatum identifies the following technical requirements:The data on SSPace1 must be available always.DC2 must become the schema master if DC1 fails.VM3 must be configured to enable per-folder quotas.Trusts must allow access to only the required resources.The users in the Marketing OU must have access to storage1.Azure Automanage must be used on all supported Azure virtual machines.A direct SSH session must be used to manage all the supported virtual machines on HyperV1.You need to ensure that access to storage1 for the Marketing OU users meets the technical requirements.What should you implement?
A. ctive Directory Federation Services (AD FS)
B. zure AD Connect in staging mode
C. zure AD Connect cloud sync
D. zure AD Connect in active mode
View answer
Correct Answer: C
Question #5
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. You need to identify which server is the PDC emulator for the domain.Solution: From a command prompt, you run netdom.exe query fsmo. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #6
You are planning the implementation Azure Arc to support the planned changes. You need to configure the environment to support configuration management policies. What should you do?
A. Hybrid Azure AD join all the servers
B. Create a hybrid runbook worker m Azure Automation
C. Deploy the Azure Connected Machine agent to all the servers
D. Deploy the Azure Monitor agent to all the servers
View answer
Correct Answer: C
Question #7
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com and the servers shown in the following table.Contoso.com contains a user named User1.You add User1 to the built-in Backup Operators group in contoso.com.Which servers can User1 back up?
A. DC1 only
B. Server1 only
C. DC1 and DC2 only
D. DC1 and Server1 only
E. DC1, DC2, Server1, and Server2
View answer
Correct Answer: A
Question #8
Your network contains a Active Directory Domain Service (AD DS) forest named contoso.com. The forest root domain contains a server named server1. contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?
A. Add fabrikam\Group1 to the local Users group on server1
B. Enable SID filtering for the trust
C. Enable Selective authentication for the trust
D. Change the trust to a one-way external trust
View answer
Correct Answer: C
Question #9
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You are planning the deployment of DNS to a new network. You have three internal DNS servers as shown in the following table. The contoso.local zone contains zone delegations for east.conloso.local and west.contoso.local. All the DNS servers use root hints. You need to ensure that all the DNS servers can resolve the names of all the internal namespaces and internet hosts. Solution: On Server2 and Server3, you configure a conditional forwarder for contoso.local. Does this meet the goal? The DNS chapters in Administering Windows Server Hybrid Core Infrastructure describe conditional forwarders as a way to direct queries for specific namespaces to authoritative DNS servers. The text notes: ''A conditional forwarder forwards queries for a designated DNS domain to specified DNS servers,'' which is used to ''integrate split or private namespaces across sites or forests.'' In this design, Server1 hosts contoso.local and delegates east and west to Server2 and Server3. By configuring Server2 and Server3 with a conditional forwarder for contoso.local pointing to Server1, any query for contoso.local (including child names like east.contoso.local or west.contoso.local when not answered locally) is sent to Server1. Server1, being authoritative for the parent, uses the existing delegations to return referrals/answers from the proper child zones. For Internet hosts, all three servers already use root hints, which the course material confirms remains valid alongside conditional forwarding. The documentation also stresses that ''authoritative data is answered locally first; forwarding applies only to names the server is not authoritative for,'' so Server2 continues to answer east locally while leveraging Server1 to reach parent and sibling zones. This configuration ensures that all servers can resolve all internal namespaces and Internet hosts.
A. Yes
B. No
View answer
Correct Answer: A
Question #10
You have an Azure virtual machine named VM1 that has a private IP address only. You configure the Windows Admin Center extension on VM1. You have an on-premises computer that runs Windows 11. You use the computer for server management. You need to ensure that you can use Windows Admin Center from the Azure portal to manage VM1. What should you configure?
A. Aan Azure Bastion host on the virtual network that contains VM1
B. Ba VPN connection to the virtual network that contains VM1
C. Ca network security group 1NSG) rule that allows inbound traffic on port 443
D. Da private endpoint on the virtual network that contains VM1
View answer
Correct Answer: B
Question #11
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The root domain contains the domain controllers shown in the following table.A failure of which domain controller will prevent you from creating application partitions?
A. C1
B. C2
C. C3
D. C4
E. C5
View answer
Correct Answer: A
Question #12
Your network contains an Active Directory Domain Services (AD DS) domain. The network also contains 20 domain controllers, 100 member servers, and 100client computers.You have a Group Policy Object (GPO) named GPO1 that contains Group Policy preferences.You plan to link GPO1 to the domain.You need to ensure that the preference in GPO1 apply only to domain member servers and NOT to domain controllers or client computers. All the other GroupPolicy settings in GPO1 must apply to all the computers. The solution must minimize administrative effort.Which type of item level targeting should you use?
A. Domain
B. Operating System
C. Security Group
D. Environment Variable
View answer
Correct Answer: B
Question #13
You need to ensure that VM3 meets the technical requirements.What should you install first?
A. Enhanced Storage
B. the iSNS Server service
C. File Server Resource Manager (FSRM)
D. Windows Standards-Based Storage Management
View answer
Correct Answer: C
Question #14
Your network contains an Active Directory domain named contoso.com. The domain contains the computers shown in the following table. On Server3, you create a Group Policy Object (GPO) named GP01 and link GPOI to contoso.com. GP01 includes a shortcut preference named Shortcut1 that has item-level targeting configured as shown in the following exhibit. To which computer will Shortcut1 be applied? Group Policy Preferences support Item-Level Targeting (ILT), allowing a preference item to apply only when the target computer meets specified criteria, such as operating system family and version. The AZ-800 study content notes that when a GPO is linked at the domain level, scope is all domain computers, but ILT on a specific preference item restricts that item to clients that match the ILT filter; non-matching clients still process the GPO but skip the filtered item. In the Targeting Editor shown, the condition is ''the operating system is Windows Server 2022 Family.'' Among the listed machines: Computer1 (Windows 11), Server1 (Windows Server 2016), Server2 (Windows Server 2019), and Server3 (Windows Server 2022). Only Server3 satisfies the ILT. Therefore, the shortcut preference Shortcut1 is applied only to Server3.
A. Server3 only
B. Computer1 and Server3 only
C. Server2 and Server3 only
D. Server1, Server2, and Server3 only
View answer
Correct Answer: A
Question #15
You need to meet the technical requirements for Server1.Which users can currently perform the required tasks?
A. Admin3 only
B. Admin1 and Admin3 only
C. Admin1 only
D. Admin1, Admin2, and Admin3
View answer
Correct Answer: B
Question #16
Which two languages can you use for Task1? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point.
A. Java
B. Bicep
C. JavaScript
D. Python
E. PowerShell
View answer
Correct Answer: DE
Question #17
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The root domain contains the domain controllers shown in the following table. A failure of which domain controller will prevent you from creating application partitions?
A. ADC1
B. BDC2
C. CDC3
D. DDC4
E. EDC5
View answer
Correct Answer: A
Question #18
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com and the servers shown in the following table.Contoso.com contains a user named User1.You add User1 to the built-in Backup Operators group in contoso.com.Which servers can User1 back up?
A. DC1 only
B. Server1 only
C. DC1 and DC2 only
D. DC1 and Server1 only
E. DC1, DC2, Server1, and Server2
View answer
Correct Answer: A
Question #19
You need to implement the planned changes for Azure AD users to sign in to Server1.Which PowerShell cmdlet should you run?
A. New-ADComputer
B. Set-AzVM
C. Set-AzVMExtension
D. Add-ADComputerServiceAccount
View answer
Correct Answer: C
Question #20
Your network contains a single-domain Active Directory Domain Services (AD DS) forest named conto.com. The forest contains the servers shown in the following exhibit table.You plan to install a line-of-business (LOB) application on Server1. The application will install a custom windows services. A new corporate security policy states that all custom Windows services must run under the context of a group managed service account (gMSA). You deploy a root key. You need to create, configure, and install the gMSA that will be used by the new application. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
A. On Server1, run the setspn command
B. On DC1, run the New-ADServiceAccount cmdlet
C. On Server1, run the Install-ADServiceAccount cmdlet
D. On Server1, run the Get-ADServiceAccount cmdlet
E. On DC1, run the Set-ADComputer cmdlet
F. On DC1, run the Install-ADServiceAccount cmdlet
View answer
Correct Answer: BC
Question #21
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains 10 servers that run Windows Server. The servers have static IPv4 addresses.You plan to use DHCP to assign IPv4 addresses to the servers.You need to ensure that each server always receives the same IPv4 address.Which type of identifier should you use to create a DHCP reservation for each server?
A. ully qualified domain name (FQDN)
B. niversally unique identifier (UUID)
C. etBIOS name
D. AC address
View answer
Correct Answer: D
Question #22
You have an Azure virtual machine named VM1 that runs Windows Server.You have an Azure subscription that has Microsoft Defender for Cloud enabled.You need to ensure that you can use the Azure Policy guest configuration feature to manage VM1.What should you do?
A. dd the PowerShell Desired State Configuration (DSC) extension to VM1
B. onfigure VM1 to use a user-assigned managed identity
C. onfigure VM1 to use a system-assigned managed identity
D. dd the Custom Script Extension to VM1
View answer
Correct Answer: C
Question #23
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that mightmeet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.You need to identify which server is the PDC emulator for the domain.Solution: From a command prompt, you run netdom.exe query fsmo.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #24
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com and the servers shown in the following table.Contoso.com contains a user named User1.You add User1 to the built-in Backup Operators group in contoso.com.Which servers can User1 back up?
A. DC1 only
B. Server1 only
C. DC1 and DC2 only
D. DC1 and Server1 only
E. DC1, DC2, Server1, and Server2
View answer
Correct Answer: A
Question #25
You have an on-premises server that runs Windows Server and contains the folders shown in the following table.
A. Folder1 and Folder2 only
B. Folder1, FoWer
C. Folder1 only
D. Folder1 and Foldet3 only
E. Folder3 only
F. Folder2 only
View answer
Correct Answer: A
Question #26
You have a server named Server1 that runs Windows Server. The disks on Server1 are configured as shown in the following exhibit.You need to convert volume E to ReFS. The solution must meet the following requirements:* Preserve the existing data on volume E.* Minimize administrative effort.What should you do first?
A. Take Disk 2 offline
B. Back up the data on volume E
C. Convert Disk 2 to a dynamic disk
D. Runconvert
View answer
Correct Answer: B
Question #27
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. You need to identify which server is the PDC emulator for the domain.Solution: From Active Directory Domains and Trusts, you right-click Active Directory Domains and Trusts in the console tree, and then select Operations Master.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #28
You have a server named Server1 that hosts Windows containers. You plan to deploy an application that will have multiple containers. Each container will be You need to create a Docker network that supports the deployment of the application. Which type of network should you create? In the context of Windows Server Hybrid Core Infrastructure and container networking, choosing the correct network driver is critical for application deployment. According to official documentation, the l2bridge (Layer 2 Bridge) network mode is used when container hosts are connected to the same IP subnet. In this configuration, each container is assigned an IP address from the same prefix as the container host. All container traffic is bridged to the physical network through an external Hyper-V Virtual Switch. Because the containers share the same underlying network infrastructure as the host, they are visible to the rest of the physical network without requiring Network Address Translation (NAT). The documentation specifies that for multi-node clusters or deployments where containers must be directly reachable on the physical network via their own IP addresses, l2bridge is the standard choice. This differs from NAT, which uses a private internal IP range and translates traffic through the host's IP, and Transparent mode, which is often used for individual hosts where the container is directly connected to the physical network but can have complexities in virtualized environments. l2tunnel is specifically used for Microsoft Cloud Stack (Azure Stack HCI) and SDN scenarios, typically involving encapsulation, which is not the standard requirement for a general multi-container application deployment on a single server unless specified. Therefore, for a high-performance, direct-access network that bridges traffic at Layer 2, l2bridge is the verified architectural choice for Windows containers.
A. transparent
B. I2bridge
C. NAT
D. I2tunnel
View answer
Correct Answer: B
Question #29
You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server.
A. an Azure Automation account
B. an Azure workbook
C. a Log Analytics workspace
D. a Microsoft Power Automate flow
View answer
Correct Answer: A
Question #30
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a user named User1 and the servers shown in the following table.You need to ensure that User1 can manage only Scope1 and Scope3.What should you do?
A. dd User1 to the DHCP Administrators group on Server1 and Server2
B. mplement IP Address Management (IPAM)
C. dd User1 to the DHCP Administrators domain local group
D. mplement Windows Admin Center and add connections to Server1 and Server2
View answer
Correct Answer: B

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us