DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft AZ-800 Practice Questions & Answers 2026 Part2

Are you preparing for the Microsoft AZ-800 certification exam? SPOTO offers the Microsoft AZ-800 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com and the servers shown in the following table.Contoso.com contains a user named User1.You add User1 to the built-in Backup Operators group in contoso.com.Which servers can User1 back up?
A. C1 and Server! only
B. erver1 only
C. C1 only
D. C! and DC2 only
E. C1
View answer
Correct Answer: C

View The Updated AZ-800 Exam Questions

SPOTO Provides 100% Real AZ-800 Exam Questions for You to Pass Your AZ-800 Exam!

Question #2
You need to meet the technical requirements for Server1. Which users can currently perform the required tasks?
A. Admin1 only
B. Admin3 only
C. Admin1 and Admin3 only
D. Admin1 Admin2
View answer
Correct Answer: A
Question #3
Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the objects shown in the following table.You plan to sync contoso.com with an Azure Active Directory (Azure AD) tenant by using Azure AD Connect.You need to ensure that all the objects can be used in Conditional Access policies.What should you do?
A. Select the Configure Hybrid Azure AD join option
B. Change the scope of Group1 and Group2 to Global
C. Clear the Configure device writeback option
D. Change the scope of Group2 to Universal
View answer
Correct Answer: A
Question #4
Your network contains a Active Directory Domain Service (AD DS) forest named contoso.com. The forest root domain contains a server named server1. contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?
A. Add fabrikam\Group1 to the local Users group on server1
B. Enable SID filtering for the trust
C. Enable Selective authentication for the trust
D. Change the trust to a one-way external trust
View answer
Correct Answer: C
Question #5
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com and the servers shown in the following table.Contoso.com contains a user named User1.You add User1 to the built-in Backup Operators group in contoso.com.Which servers can User1 back up?
A. DC1 only
B. Server1 only
C. DC1 and DC2 only
D. DC1 and Server1 only
E. DC1, DC2, Server1, and Server2
View answer
Correct Answer: A
Question #6
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.You open a new branch office that contains only client computers.You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.Solution: You create a new site named Site4 and associate Site4 to DEFAULTSITELINK.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #7
You have an Azure Active Directory Domain Services (Azure AD DS) domain named contoso.com.You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The solution must use the principle of least privilege.To which group should you add the administrator?
A. AAD DC Administrators
B. Domain Admins
C. Schema Admins
D. Enterprise Admins
E. Group Policy Creator Owners
View answer
Correct Answer: A
Question #8
Which two languages can you use for Task1? Each correct answer presents a complete solution.
A. Bicep
B. Python
C. Java
D. PowerShell
E. JavaScript
View answer
Correct Answer: BD
Question #9
What should you implement for the deployment of DC3?
A. Azure Active Directory Domain Services (Azure AD DS)
B. an Azure virtual machine
C. an Azure AD administrative unit
D. Azure AD Application Proxy
View answer
Correct Answer: B
Question #10
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. You need to identify which server is the PDC emulator for the domain. Solution: From a command prompt, you run netdom.exe query fsmo. Does this meet the goal? Within the Manage AD DS operations master roles (FSMO) section of the AZ-800 materials, Microsoft documents multiple supported methods to identify role holders. The guidance states that the command-line utility NETDOM can enumerate all FSMO roles with: netdom query fsmo. The output lists the Schema Master, Domain Naming Master, RID Master, PDC Emulator, and Infrastructure Master, each with the current role holder's FQDN. The course notes emphasize that this method is fast, non-interactive, and does not require specific MMC snap-ins, making it suitable for both Server Core and remote administration scenarios. Because the command returns the PDC Emulator holder explicitly in its results, running netdom.exe query fsmo does meet the goal of identifying which server is the PDC Emulator for the domain. This aligns with best practices for quick verification of FSMO placement during operations such as time service verification, password update convergence checks, or when planning FSMO transfers and seizures.
A. Yes
B. No
View answer
Correct Answer: A
Question #11
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com and the servers shown in the following table.Contoso.com contains a user named User1.You add User1 to the built-in Backup Operators group in contoso.com.Which servers can User1 back up?
A. DC1 only
B. Server1 only
C. DC1 and DC2 only
D. DC1 and Server1 only
E. DC1, DC2, Server1, and Server2
View answer
Correct Answer: A
Question #12
You need to implement the planned changes for Microsoft Entra users to sign in to Server1.Which PowerShell cmdlet should you run?
A. Add-ADComputerServiceAccount
B. Set-AzVM
C. Set-AzVMExtension
D. New-ADComputer
View answer
Correct Answer: C
Question #13
Your network contains a Active Directory Domain Service (AD DS) forest named contoso.com. The forest root domain contains a server named server1. contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?
A. Add fabrikam\Group1 to the local Users group on server1
B. Enable SID filtering for the trust
C. Enable Selective authentication for the trust
D. Change the trust to a one-way external trust
View answer
Correct Answer: C
Question #14
You need to configure the Group Policy settings to ensure that the Azure Virtual Desktop session hosts meet the security requirements.What should you configure?
A. loopback processing in GPO4
B. security filtering for the link of GPO1
C. loopback processing in GPO1
D. the Enforced property for the link of GPO4
E. the Enforced property for the link of GPO1
F. security filtering for the link of GPO4
View answer
Correct Answer: A
Question #15
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com and the servers shown in the following table.Contoso.com contains a user named User1.You add User1 to the built-in Backup Operators group in contoso.com.Which servers can User1 back up?
A. DC1 only
B. Server1 only
C. DC1 and DC2 only
D. DC1 and Server1 only
E. DC1, DC2, Server1, and Server2
View answer
Correct Answer: A
Question #16
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The root domain contains the domain controllers shown in thefollowing table.A failure of which domain controller will prevent you from creating application partitions?
A. DC1
B. DC2
C. DC3
D. DC4
E. DC5
View answer
Correct Answer: A
Question #17
You have an Azure virtual machine named VM1 that runs Windows Server. You have an Azure subscription that has Microsoft Defender for Cloud enabled. You need to ensure that you can use the Azure Policy guest configuration feature to manage VM1. What should you do?
A. --expose
B. --privileged
C. --runtime
D. --isolation
E. --entrypoint
View answer
Correct Answer: D
Question #18
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.You open a new branch office that contains only client computers.You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.Solution: You create an organization unit (OU) that contains the client computers in the branch office. You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to the new OU.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #19
You have a server named Server1 that hosts Windows containers. You plan to deploy an application that will have multiple containers. Each container will be on the same subnet. Each container requires a separate MAC address and IP address. Each container must be able to communicate by using its IP address. You need to create a Docker network that supports the deployment of the application. Which type of network should you create?
A. Domain
B. Environment Variable
C. Security Group
D. Operating System
View answer
Correct Answer: D
Question #20
Your network contains a multi-site Active Directory Domain Services (AD DS) forest. Each Active Directory site is connected by using manually configured site links and automatically generated connections. You need to minimize the convergence time for changes to Active Directory. What should you do?
A. For each site link, modify the replication schedule
B. For each site link, modify the site link costs
C. Create a site link bridge that contains all the site links
D. For each site link, modify the options attribute
View answer
Correct Answer: D
Question #21
You need to implement the planned changes for the Azure DNS Private Resolver.Which private DNS zones can you use for name resolution?
A. Zone1
B. Zone2
C. Zone1
D. Zone2
E. Zone1
View answer
Correct Answer: A
Question #22
You need to meet the technical requirements for Server1. Which users can currently perform the required tasks?
A. Admin1 only
B. Admin3 only
C. Admin1 and Admin3 only
D. Admin1 Admin2
View answer
Correct Answer: C
Question #23
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. You need to identify which server is the PDC emulator for the domain.Solution: From Active Directory Sites and Services, you right-click Default-First-Site-Name in the console tree, and then select Properties.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #24
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.You open a new branch office that contains only client computers.You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.Solution: You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to Site1.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #25
You have a Windows Server container host named Server1 and a container image named image1. You need to start a container from image1. The solution must run the container on a Hyper-V virtual machine. Which parameter should you specify when you run the docker run command?
A. Date policy
B. Cost policy
C. Volume free space policy
D. Disk space policy
E. Read policy
View answer
Correct Answer: AC
Question #26
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com and the servers shown in the following table.Contoso.com contains a user named User1.You add User1 to the built-in Backup Operators group in contoso.com.Which servers can User1 back up?
A. DC1 only
B. Server1 only
C. DC1 and DC2 only
D. DC1 and Server1 only
E. DC1, DC2, Server1, and Server2
View answer
Correct Answer: A
Question #27
Your network contains a Active Directory Domain Service (AD DS) forest named contoso.com. The forest root domain contains a server named server1. contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?
A. Add fabrikam\Group1 to the local Users group on server1
B. Enable SID filtering for the trust
C. Enable Selective authentication for the trust
D. Change the trust to a one-way external trust
View answer
Correct Answer: C
Question #28
Your network contains a Active Directory Domain Service (AD DS) forest named contoso.com. The forest root domain contains a server named server1. contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?
A. Add fabrikam\Group1 to the local Users group on server1
B. Enable SID filtering for the trust
C. Enable Selective authentication for the trust
D. Change the trust to a one-way external trust
View answer
Correct Answer: C
Question #29
You have an on premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant.You plan to implement self-service password reset (SSPR) in Azure AD.You need to ensure that users that reset their passwords by using SSPR can use the new password resources in the AD DS domain.What should you do?
A. Deploy the Azure AD Password Protection proxy service to the on premises network
B. Run the Microsoft Azure Active Directory Connect wizard and select Password writeback
C. Grant the Change password permission for the domain to the Azure AD Connect service account
D. Grant the impersonate a client after authentication user right to the Azure AD Connect service account
View answer
Correct Answer: B
Question #30
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com and the servers shown in the following table.Contoso.com contains a user named User1.You add User1 to the built-in Backup Operators group in contoso.com.Which servers can User1 back up?
A. DC1 only
B. Server1 only
C. DC1 and DC2 only
D. DC1 and Server1 only
E. DC1, DC2, Server1, and Server2
View answer
Correct Answer: A
Question #31
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The root domain contains the domain controllers shown in the following table.A failure of which domain controller will prevent you from creating application partitions?
A. DC1
B. DC2
C. DC3
D. DC4
E. DC5
View answer
Correct Answer: A
Question #32
You have an on premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. You plan to implement self-service password reset (SSPR) in Azure AD. You need to ensure that users that reset their passwords by using SSPR can use the new password resources in the AD DS domain. What should you do?
A. Deploy the Azure AD Password Protection proxy service to the on premises network
B. Run the Microsoft Azure Active Directory Connect wizard and select Password writeback
C. Grant the Change password permission for the domain to the Azure AD Connect service account
D. Grant the impersonate a client after authentication user right to the Azure AD Connect service account
View answer
Correct Answer: B
Question #33
Your network contains a Active Directory Domain Service (AD DS) forest named contoso.com. The forest root domain contains a server named server1. contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?
A. Add fabrikam\Group1 to the local Users group on server1
B. Enable SID filtering for the trust
C. Enable Selective authentication for the trust
D. Change the trust to a one-way external trust
View answer
Correct Answer: C
Question #34
Your network contains an Active Directory Domain Services (AD DS) domain.You have a Group Policy Object (GPO) named GPO1 that contains Group Policy preferences. You plan to link GPO1 to the domain.You need to ensure that the preference in GPO1 apply only to domain member servers and NOT to domain controllers or client computers. All the other Group Policy settings in GPO1 must apply to all the computers. The solution must minimize administrative effort.Which type of item level targeting should you use?
A. Domain
B. Operating System
C. Security Group
D. Environment Variable
View answer
Correct Answer: B
Question #35
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a server named Server1 that runs Windows Server 2022 and has the DHCP Server role. Server1 contains a single DHCP scope named Scope1. You deploy five printers to the network. You need to ensure that the printers are always assigned the same IP address. Solution: You create a DHCP address exclusion for each printer. Does this meet the requirement?
A. AYes
B. BNo
View answer
Correct Answer: B
Question #36
You have an on premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant.You plan to implement self-service password reset (SSPR) in Azure AD.You need to ensure that users that reset their passwords by using SSPR can use the new password resources in the AD DS domain.What should you do?
A. Deploy the Azure AD Password Protection proxy service to the on premises network
B. Run the Microsoft Azure Active Directory Connect wizard and select Password writeback
C. Grant the Change password permission for the domain to the Azure AD Connect service account
D. Grant the impersonate a client after authentication user right to the Azure AD Connect service account
View answer
Correct Answer: B
Question #37
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Som e question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You are planning the deployment of DNS to a new network.You have three internal DNS servers as shown in the following table.The contoso.local zone contains zone delegations for east.contoso.local and west.contoso.local. All the DNS servers use root hints.You need to ensure that all the DNS servers can resolve the names of all the internal namespaces and internet hosts.Solution: On Server2, you create a conditional forwarder for west.contoso.local. On Server3, you create a conditional for warder for east.contoso.local.Does this meet the goal?
A. o
B. es
View answer
Correct Answer: A
Question #38
You need to ensure that Automanage meets the technical requirements.On which Azure virtual machines should you enable Automanage?
A. Server1 only
B. Server2 only
C. Server1 and Server2 only
D. Server2 and Server3 only
E. Server1 and Server4 only
View answer
Correct Answer: D

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us