DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft AZ-800 Practice Questions & Answers 2026 Part3

Are you preparing for the Microsoft AZ-800 certification exam? SPOTO offers the Microsoft AZ-800 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
Your company has a main office and a branch office. The two offices are connected by using a WAN link. Each office contains a firewall that filters WAN traffic. The network in the branch office contains 10 servers that run Windows Server. All servers are administered from the main office only. You plan to manage the servers in the branch office by using a Windows Admin Center gateway. On a server in the branch office, you install the Windows Admin Center gateway by using the defaults settings. You need to configure the firewall in the branch office to allow the required inbound connection to the Windows Admin Center gateway. Which inbound TCP port should you allow?
A. A443
B. B3389
C. C5985
D. D6516
View answer
Correct Answer: A

View The Updated AZ-800 Exam Questions

SPOTO Provides 100% Real AZ-800 Exam Questions for You to Pass Your AZ-800 Exam!

Question #2
You need to meet the technical requirements for Server3.Which users can perform the required tasks?
A. Admin3 only
B. Admin1 and Admin3 only
C. Admin1 only
D. Admin1, Admin2, and Admin3
E. Admin1 and Admin2 only
View answer
Correct Answer: C
Question #3
You need to ensure that access to storage1 for the Marketing OU users meets the technical requirements.What should you implement?
A. Active Directory Federation Services (AD FS)
B. Azure AD Connect in staging mode
C. Azure AD Connect cloud sync
D. Azure AD Connect in active mode
View answer
Correct Answer: C
Question #4
Your network contains an Active Directory Domain Services (AD DS) domain. You have a Group Policy Object (GPO) named GPO1 that contains Group Policy preferences. You plan to link GPO1 to the domain. You need to ensure that the preference in GPO1 apply only to domain member servers and NOT to domain controllers or client computers. All the other Group Policy settings in GPO1 must apply to all the computers. The solution must minimize administrative effort. Which type of item level targeting should you use?
A. Windows Server
B. Nano Server
C. Windows
D. Server Core
View answer
Correct Answer: B
Question #5
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
A. Yes
B. No
View answer
Correct Answer: B
Question #6
Your network contains an Active Directory Domain Services (AD DS) domain. The network also contains 20 domain controllers, 100 member servers, and 100 client computers.You have a Group Policy Object (GPO) named GPO1 that contains Group Policy preferences.You plan to link GPO1 to the domain.You need to ensure that the preference in GPO1 apply only to domain member servers and NOT to domain controllers or client computers. All the other GroupPolicy settings in GPO1 must apply to all the computers. The solution must minimize administrative effort.Which type of item level targeting should you use?
A. omain
B. perating System
C. ecurity Group
D. nvironment Variable
View answer
Correct Answer: B
Question #7
What should you implement for the deployment of DC3?
A. Azure Active Directory Domain Services (Azure AD DS)
B. an Azure virtual machine
C. an Azure AD administrative unit
D. Azure AD Application Proxy
View answer
Correct Answer: B
Question #8
You have a server named Server1 that runs Windows Server.You plan to host applications in Windows containers.You need to configure Server1 to run containers. What should you install?
A. he Windows Subsystem for Linux
B. octor
C. indows Admin Center
D. yper-V
View answer
Correct Answer: B
Question #9
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant.You have several Windows 10 devices that are Azure AD hybrid-joined.You need to ensure that when users sign in to the devices, they can use Windows Hello for Business.Which optional feature should you select in Azure AD Connect?
A. Device writeback
B. Group writebeack
C. Azure AD app and attribute filtering
D. Password writeback
E. Directory extension attribute sync
View answer
Correct Answer: A
Question #10
You have a server named Server1 that runs Windows Server 2019 and hosts a container named Contained.Contained uses a Windows Server 2019 base image that was built by using a Docker file.You upgrade Server1 to Windows Serve r 2022.You need to ensure that Contained will run on Server1. The solution must minimize administrative effort.What should you do?
A. tart Contained in process isolation mode
B. odify the Docker file
C. tart Contained in Hyper-V isolation mode
D. ebuild the base image for Contained
View answer
Correct Answer: C
Question #11
Your network contains a Active Directory Domain Service (AD DS) forest named contoso.com. The forest root domain contains a server named server1. contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?
A. Add fabrikam\Group1 to the local Users group on server1
B. Enable SID filtering for the trust
C. Enable Selective authentication for the trust
D. Change the trust to a one-way external trust
View answer
Correct Answer: C
Question #12
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.You need to identify which server is the PDC emulator for the domain.Solution: From Active Directory Domains and Trusts, you right-click Active Directory Domains and Trusts in the console tree, and then select OperationsMaster.Does this meet the goal?
A. es
B. o
View answer
Correct Answer: B
Question #13
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three domains. Each domain contains 10 domain controllers.You plan to store a DNS zone in a custom Active Directory partition.You need to create the Active Directory partition for the zone. The partition must replicate to only four of the domain controllers.What should you use?
A. NS Manager
B. ew-ADObjett
C. indows Admin Center
D. nscnd
View answer
Correct Answer: D
Question #14
You need to meet the technical requirements for the site links.Which users can perform the required tasks?
A. Admin1, Admin2, and Admin3
B. Admin1 and Admin3 only
C. Admin1 only
D. Admin1 and Admin2 only
E. Admin3 only
View answer
Correct Answer: C
Question #15
You have a server named Server1 that runs Windows Server and has the DHCP Server role installed. Server1 contains the following single scope:Scope: 192.168.16.0Address pool: 192.168.16.1-192.168.16.254Subnet mask: 255.255.255.0Lease duration: 8 daysYou have four testing devices that are configured with static IP addresses as shown in the following table.The test devices are turned on once a month.You need to prevent Server1 from assigning the IP addresses allocated to the test devices to other devices when the test devices are offline. The solution must minimize administrative effort.What should you do?
A. reate a policy
B. reate reservations
C. onfigure the Scope options
D. reate an exclusion range
View answer
Correct Answer: B
Question #16
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com and the servers shown in the following table.Contoso.com contains a user named User1.You add User1 to the built-in Backup Operators group in contoso.com.Which servers can User1 back up?
A. DC1 only
B. Server1 only
C. DC1 and DC2 only
D. DC1 and Server1 only
E. DC1, DC2, Server1, and Server2
View answer
Correct Answer: A
Question #17
You have an on premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant. The domain contains two servers named Server1 and Server2.
A. From the Azure portal, generate a new onboarding script
B. Assign Admin1 the Azure Connected Machine Onboarding role for RG1
C. Hybrid Microsoft Entra join Server1 and Server2
D. Create an Azure cloud-only account for Admin1
View answer
Correct Answer: B
Question #18
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.You need to identify which server is the PDC emulator for the domain.Solution: From a command prompt, you run netdom.exe query fsmo.Does this meet the goal?
A. es
B. o
View answer
Correct Answer: A
Question #19
Your network contains a Active Directory Domain Service (AD DS) forest named contoso.com. The forest root domain contains a server named server1. contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?
A. Add fabrikam\Group1 to the local Users group on server1
B. Enable SID filtering for the trust
C. Enable Selective authentication for the trust
D. Change the trust to a one-way external trust
View answer
Correct Answer: C
Question #20
Your network contains a multi-site Active Directory Domain Services (AD DS) forest. Each Active Directory site is connected by using manually configured site links and automatically generated connections.You need to minimize the convergence time for changes to Active Directory.What should you do?
A. For each site link, modify the replication schedule
B. For each site links, modify the site link costs
C. Create a site link bridge that contains all the site links
D. For each site link, modify the options attribute
View answer
Correct Answer: D
Question #21
You have an on premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant.You plan to implement self-service password reset (SSPR) in Azure AD.You need to ensure that users that reset their passwords by using SSPR can use the new password resources in the AD DS domain.What should you do?
A. eploy the Azure AD Password Protection proxy service to the on premises network
B. un the Microsoft Azure Active Directory Connect wizard and select Password writeback
C. rant the Change password permission for the domain to the Azure AD Connect service account
D. rant the impersonate a client after authentication user right to the Azure AD Connect service account
View answer
Correct Answer: B
Question #22
You have an Azure virtual machine named VM1 that contains the drives shown in the following table.On VM1, you plan to install an app named App1. The data for App1 must be stored on a persistent data disk assigned to drive D.You need assign the data disk to drive D.What should you do on VM1 first?
A. hange the drive letter of the Temporary Storage drive to F
B. ove pagefile
C. top (deallocate) VM1
D. xpand the Temporary Storage drive
View answer
Correct Answer: A
Question #23
You need to meet the technical requirements for the site links. Which users can perform the required tasks?
A. Admin1 only
B. Admin1 and Admin3 only
C. Admin1 and Admin2 only
D. Admin3 only
E. Admin1, Adrrun2
View answer
Correct Answer: C
Question #24
Your network contains a Active Directory Domain Service (AD DS) forest named contoso.com. The forest root domain contains a server named server1. contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?
A. Add fabrikam\Group1 to the local Users group on server1
B. Enable SID filtering for the trust
C. Enable Selective authentication for the trust
D. Change the trust to a one-way external trust
View answer
Correct Answer: C
Question #25
You need to meet the technical requirements for VM3 On which volumes can you enable Data Deduplication?
A. D and E only
B. C, D, E, and F
C. D only
D. C and D only
E. D, E, and F only
View answer
Correct Answer: C
Question #26
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the re view screen.Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSIT ELINK.You open a new branch office that contains only client computers.You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.Solution: You create a new site named Site4 and assoc iate Site4 to DEFAULTSITELINK.Does this meet the goal?
A. o
B. es
View answer
Correct Answer: A
Question #27
Your network contains a Active Directory Domain Service (AD DS) forest named contoso.com. The forest root domain contains a server named server1. contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?
A. Add fabrikam\Group1 to the local Users group on server1
B. Enable SID filtering for the trust
C. Enable Selective authentication for the trust
D. Change the trust to a one-way external trust
View answer
Correct Answer: C
Question #28
You need to meet the technical requirements for Server1.
A. Admin1 only
B. Admin3 only
C. Admin1 and Admin3 only
D. Admin1, Admin2 and Admin3
View answer
Correct Answer: C
Question #29
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains two servers named Server1 and Server2.Server1 contains a disk named Disk2. Disk2 contains a folder named UserData. UserData is shared to the Domain Users group. Disk2 is configured for deduplication. Server1 is protected by using Azure Backup.Server1 fails.You connect Disk2 to Server2.You need to ensure that you can access all the files on Disk2 as quickly as possible.What should you do?
A. Create a storage pool
B. Restore files from Azure Backup
C. Install the File Server Resource Manager server role
D. Install the Data Deduplication server role
View answer
Correct Answer: D
Question #30
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com and the servers shown in the following table.Contoso.com contains a user named User1.You add User1 to the built-in Backup Operators group in contoso.com.Which servers can User1 back up?
A. DC1 only
B. Server1 only
C. DC1 and DC2 only
D. DC1 and Server1 only
E. DC1, DC2, Server1, and Server2
View answer
Correct Answer: A
Question #31
You need to meet the technical requirements for User1. The solution must use the principle of least privilege. What should you do?
A. Add Users1 to the Server Operators group in contoso
B. Create a delegation on contoso
C. Add Users1 to the Account Operators group in contoso
D. Create a delegation on OU3
View answer
Correct Answer: D

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us