DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft AZ-801 Practice Questions & Answers 2026 Part1

Are you preparing for the Microsoft AZ-801 certification exam? SPOTO offers the Microsoft AZ-801 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
You are planning the deployment of Microsoft Sentinel. Which type of Microsoft Sentinel data connector should you use to meet the security requirements?
A. Threat Intelligence - TAXII
B. Azure Active Directory
C. Microsoft Defender for Cloud
D. Microsoft Defender for Identity
View answer
Correct Answer: D

View The Updated AZ-801 Exam Questions

SPOTO Provides 100% Real AZ-801 Exam Questions for You to Pass Your AZ-801 Exam!

Question #2
You have 100 Azure virtual machines that run Windows Server. The virtual machines are onboarded to Microsoft Defender for Cloud.You need to shut down a virtual machine automatically if Microsoft Defender for Cloud generates the "Antimalware disabled in the virtual machine" alert for the virtual machine.What should you use in Microsoft Defender for Cloud?
A. a logic app
B. a workbook
C. a security policy
D. adaptive network hardening
View answer
Correct Answer: A
Question #3
You are remediating the firewall security risks to meet the security requirements. What should you configure to reduce the risks?
A. a Group Policy Object (GPO)
B. adaptive network hardening in Microsoft Defender for Cloud
C. a network security group (NSG) in Sub1
D. an Azure Firewall policy
View answer
Correct Answer: A
Question #4
You have a Microsoft Sentinel deployment and 100 Azure Arc-enabled on-premises servers. All the Azure Arc- enabled resources are in the same resource group.You need to onboard the servers to Microsoft Sentinel. The solution must minimize administrative effort.What should you use to onboard the servers to Microsoft Sentinel?
A. Azure Automation
B. Azure Policy
C. Azure virtual machine extensions
D. Microsoft Defender for Cloud
View answer
Correct Answer: B
Question #5
You have an Azure virtual machine named VM1 that runs Windows Server.You plan to deploy a new line-of-business (LOB) application to VM1.You need to ensure that the application can create child processes.What should you configure on VM1?
A. icrosoft Defender Credential Guard
B. icrosoft Defender Application Control
C. icrosoft Defender SmartScreen
D. xploit protection
View answer
Correct Answer: D
Question #6
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant by using password hash synchronization.You have a Microsoft 365 subscription.All devices are hybrid Azure AD-joined.Users report that they must enter their password manually when accessing Microsoft 365 applications.You need to reduce the number of times the users are prompted for their password when they access Microsoft 365 and Azure services.What should you do?
A. In Microsoft Entra ID, configure a Conditional Access policy for the Microsoft Office 365 applications
B. In the DNS zone of the AD DS domain, create an autodiscover record
C. From Microsoft Entra Connect, enable single sign-on (SSO)
D. From Microsoft Entra Connect, configure pass-through authentication
View answer
Correct Answer: C
Question #7
You have 100 Azure virtual machines that run Windows Server. The virtual machines are onboarded to Microsoft Defender for Cloud.You need to shut down a virtual machine automatically if Microsoft Defender for Cloud generates the "Antimalware disabled in the virtual machine" alert for thevirtual machine.What should you use in Microsoft Defender for Cloud?
A. a logic app
B. a workbook
C. a security policy
D. adaptive network hardening
View answer
Correct Answer: A
Question #8
You have a server named Server1 that runs Windows Server.You install a custom app named App1 that is accessed by using TCP port 52310.Users report that they cannot access App1.You confirm that App1 is running on Server1.You need to ensure that the users can access App1. The solution must only provide access to App1 on Server1.What should you do in Windows Defender Firewall with Advanced Security?
A. Create an isolation connection security rule
B. Create an outbound rule
C. Create an inbound rule
D. For the current profile, allow all inbound connections
View answer
Correct Answer: C
Question #9
You have an Azure virtual machine named VM1 that runs Windows Server.You plan to deploy a new line-of-business (LOB) application to VM1.You need to ensure that the application can create child processes.What should you configure on VM1?
A. icrosoft Defender Credential Guard
B. icrosoft Defender Application Control
C. icrosoft Defender SmartScreen
D. xploit protection
View answer
Correct Answer: D
Question #10
You have 100 Azure virtual machines that run Windows Server. The virtual machines are onboarded to Microsoft Defender for Cloud.You need to shut down a virtual machine automatically if Microsoft Defender for Cloud generates the "Antimalware disabled in the virtual machine" alert for the virtual machine.What should you use in Microsoft Defender for Cloud?
A. logic app
B. workbook
C. security policy
D. daptive network hardening
View answer
Correct Answer: A
Question #11
You are planning the deployment of Microsoft Sentinel.Which type of Microsoft Sentinel data connector should you use to meet the security requirements?
A. Threat Intelligence - TAXII
B. Azure Active Directory
C. Microsoft Defender for Cloud
D. Microsoft Defender for Identity
View answer
Correct Answer: D
Question #12
Your network contains an Active Directory Domain Services (AD DS) forest. The forest functional level is Windows Server 2012 R2. The forest contains the domains shown in the following table.You create a user named Admin1.You need to ensure that Admin1 can add a new domain controller that runs Windows Server 2022 to the east.contoso.com domain. The solution must follow the principle of least privilege.To which groups should you add Admin1?
A. EAST\Domain Admins only
B. CONTOSO\Enterprise Admins only
C. CONTOSO\Schema Admins and EAST\Domain Admins
D. CONTOSO\Enterprise Admins and CONTOSO\Schema Admins
View answer
Correct Answer: A
Question #13
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that hosts an app named App1. App1 uses Active Directory authentication.You have a Microsoft Entra tenant that contains a user named User1.You deploy Microsoft Entra Connect sync and configure password synchronization.User1 fails to authenticate to App1.You need to ensure that User1can authenticate to App1.What should you do?
A. For Microsoft Entra Connect sync, enable the BlockCloudObjectTakeoverThroughHardMatch feature
B. For Microsoft Entra Connect sync, enable password writeback
C. From the AD DS domain, create a new user account named User1
D. For Microsoft Entra Connect sync, disable soft match
View answer
Correct Answer: B
Question #14
You need to meet the technical requirements for User1. To which group in contoso.com should you add User1?
A. ADomain Admins
B. BAccount Operators
C. CSchema Admins
D. DBackup Operators
View answer
Correct Answer: A
Question #15
Your company uses Storage Spaces Direct. You need to view the available storage in a Storage Space Direct storage pool. What should you use?
A. AFile Server Resource Manager (FSRM)
B. Bthe Get-StorageSubsystem cmdlet
C. CDisk Management
D. DWindows Admin Center
View answer
Correct Answer: D
Question #16
You have an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.You need to prevent the registration of specific COM objects on Server1.What should you use?
A. Windows Defender Application Control (WDAC)
B. exploit protection
C. Smart App Control
View answer
Correct Answer: A
Question #17
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1.You deploy a read-only domain controller (RODC) named RODC1.You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege.What should you use?
A. System Configuration
B. dsmgmt
C. Computer Management
D. Active Directory Sites and Services
View answer
Correct Answer: C
Question #18
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1.You deploy a read-only domain controller (RODC) named RODC1.You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege.What should you use?
A. System Configuration
B. dsmgmt
C. Computer Management
D. Active Directory Sites and Services
View answer
Correct Answer: C
Question #19
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that hosts an app named App1. App1 uses Active Directory authentication.You have a Microsoft Entra tenant that contains a user named User1.You deploy Microsoft Entra Connect sync and configure password synchronization.User1 fails to authenticate to App1.You need to ensure that User1can authenticate to App1.What should you do?
A. For Microsoft Entra Connect sync, enable the BlockCloudObjectTakeoverThroughHardMatch feature
B. For Microsoft Entra Connect sync, enable password writeback
C. From the AD DS domain, create a new user account named User1
D. For Microsoft Entra Connect sync, disable soft match
View answer
Correct Answer: B
Question #20
You have an on-premises server that runs Windows Server and has the Web Server (IIS) server role installed. The server hosts a web app that connects to an on-premises Microsoft SQL Server database.You plan to migrate the web app to an Azure App Services web app. The database will remain on-premises.You need to ensure that the migrated web app can access the database.What should you configure in Azure?
A. zure Extended Network
B. n Azure SQL managed instance
C. Hybrid Connection
D. n on-premises data gateway
View answer
Correct Answer: C
Question #21
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1.You deploy a read-only domain controller (RODC) named RODC1.You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege.What should you use?
A. System Configuration
B. dsmgmt
C. Computer Management
D. Active Directory Sites and Services
View answer
Correct Answer: C
Question #22
You have an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.You need to prevent the registration of specific COM objects on Server1.What should you use?
A. Windows Defender Application Control (WDAC)
B. exploit protection
C. Smart App Control
View answer
Correct Answer: A
Question #23
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1.You deploy a read-only domain controller (RODC) named RODC1.You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege.What should you use?
A. System Configuration
B. dsmgmt
C. Computer Management
D. Active Directory Sites and Services
View answer
Correct Answer: C
Question #24
You have an Azure subscription named Sub1 that contains a resource group named RG1. RG1 contains the resources shown in the following table.Sub1 has Microsoft Defender for Servers enabled. You are assigned the Contributor role for Sub1.You need to implement just-in-time (JIT) VM access for VM1.What should you do first?
A. Create a network security group (NSG)
B. Enable enhanced security in Microsoft Defender for Cloud
C. Request the Owner role for Sub1
D. Create an application security group
View answer
Correct Answer: A
Question #25
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server.You need to ensure that only specific applications can modify the data in protected folders on Server1.Solution: From App & browser control, you configure the Exploit protection settings.Does this meet the goal?
A. es
B. o
View answer
Correct Answer: B
Question #26
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that hosts an app named App1. App1 uses Active Directory authentication.You have a Microsoft Entra tenant that contains a user named User1.You deploy Microsoft Entra Connect sync and configure password synchronization.User1 fails to authenticate to App1.You need to ensure that User1can authenticate to App1.What should you do?
A. For Microsoft Entra Connect sync, enable the BlockCloudObjectTakeoverThroughHardMatch feature
B. For Microsoft Entra Connect sync, enable password writeback
C. From the AD DS domain, create a new user account named User1
D. For Microsoft Entra Connect sync, disable soft match
View answer
Correct Answer: B
Question #27
You have two servers named Host1 and Host2 that run Windows Server and have the Hyper-V server role installed. Host2 is configured as a replica server.Host1 contains a virtual machine named VM1.You plan to use Hyper-V Replica to replicate VM1 to Host2.You need to ensure that you can restore a replica of VM1 to a specific state from the past eight hours.What should you do?
A. From the Enable Replication wizard, configure recovery points
B. From the Properties of VM1, enable automatic checkpoints
C. From the Hyper-V Settings of Host2
D. From the Enable Replication wizard, modify the replication frequency
View answer
Correct Answer: A
Question #28
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1.You deploy a read-only domain controller (RODC) named RODC1.You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege.What should you use?
A. System Configuration
B. dsmgmt
C. Computer Management
D. Active Directory Sites and Services
View answer
Correct Answer: C
Question #29
You have a server named Server1 that runs Windows Server.You install a custom app named App1 that is accessed by using TCP port 52310.Users report that they cannot access App1.You confirm that App1 is running on Server1.You need to ensure that the users can access App1. The solution must only provide access to App1 on Server1.What should you do in Windows Defender Firewall with Advanced Security?
A. Create an isolation connection security rule
B. Create an outbound rule
C. Create an inbound rule
D. For the current profile, allow all inbound connections
View answer
Correct Answer: C
Question #30
You have a server named Server1 that runs Windows Server.You install a custom app named App1 that is accessed by using TCP port 52310.Users report that they cannot access App1.You confirm that App1 is running on Server1.You need to ensure that the users can access App1. The solution must only provide access to App1 on Server1.What should you do in Windows Defender Firewall with Advanced Security?
A. Create an isolation connection security rule
B. Create an outbound rule
C. Create an inbound rule
D. For the current profile, allow all inbound connections
View answer
Correct Answer: C
Question #31
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains two servers named Server1 and Server2 that run Windows Server.
A. the COM+ Network Access (DCOM-ln) rule
B. all the rules in the Remote Event Log Management group
C. the Windows Management Instrumentation (WMI-ln) rule
D. the COM+ Remote Administration (DCOM-ln) rule
E. the Windows Management Instrumentation (DCOM-ln) rule
View answer
Correct Answer: AB
Question #32
You have 200 Azure virtual machines. You create a recovery plan in Azure Site Recovery to fail over all the virtual machines to an Azure region. The plan has three manual actions. You need to replace one of the manual actions with an automated process. What should you use?
A. Azure Automation
B. Azure Policy
C. Azure virtual machine extensions
D. Microsoft Defender for Cloud
View answer
Correct Answer: B
Question #33
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that mightmeet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server.You need to ensure that only specific applications can modify the data in protected folders on Server1.Solution: From Virus & threat protection, you configure Tamper ProtectionDoes this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #34
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an on-premises server named Server1 that runs Windows Server.You have a Microsoft Sentinel instance.You add the Windows Firewall data connector in Microsoft Sentinel.You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1.Solution: You install the Microsoft Integration Runtime on Server1.Does this meet the goal?
A. es
B. o
View answer
Correct Answer: B
Question #35
You have an Azure subscription that contains a user named User1 and the resources shown in the following table.User1 has a computer named Computer1 that runs Windows 11. User1 works from home and establishes a Point-to-Site (P2S) connection to GW1 to access AppSvr1.You deploy the resources shown in the following table.User1 cannot access AppSvr2.You need to ensure that User1 can access AppSvr2.What should you do?
A. On Computer1, download and reinstall the VPN client
B. Create a route table and associate the table with GatewaySubnet on VNet1
C. On Computer1, modify the Windows Defender Firewall settings
D. Add a service endpoint to VNet2
View answer
Correct Answer: A
Question #36
You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have 50 Azure virtual machines that run Windows Server. You need to ensure that any security exploits detected on the virtual machines are forwarded to Defender for Cloud. Which extension should you enable on the virtual machines?
A. AVulnerability assessment for machines
B. BMicrosoft Dependency agent
C. CLog Analytics agent for Azure VMs
D. DGuest Configuration agent
View answer
Correct Answer: A
Question #37
You have an Azure virtual machine named VM1 that runs Windows Server. You need to encrypt the contents of the disks on VM1 by using Azure Disk Encryption. What is a prerequisite for implementing Azure Disk Encryption?
A. Vulnerability assessment for machines
B. Microsoft Dependency agent
C. Log Analytics agent for Azure VMs
D. Guest Configuration agent
View answer
Correct Answer: A
Question #38
Which of the following security policies would you configure from the Security Settings extension of the Local Group Policy Editor to control Encrypting File System, Data Protection, and BitLocker Drive Encryption?
A. ccount Policies
B. pplication Control Policies
C. ublic Key Policies
D. etwork List Manager Policies
E. ocal Policies
View answer
Correct Answer: C
Question #39
You have a server that runs Windows Server 2025 Standard and has the Hyper-V role installed. You need to upgrade the server to Windows Server 2025 Datacenter. The solution must minimize downtime. What should you run?
A. dism
B. setup
C. slagr
D. conwert
View answer
Correct Answer: C
Question #40
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that hosts an app named App1. App1 uses Active Directory authentication.You have a Microsoft Entra tenant that contains a user named User1.You deploy Microsoft Entra Connect sync and configure password synchronization.User1 fails to authenticate to App1.You need to ensure that User1can authenticate to App1.What should you do?
A. For Microsoft Entra Connect sync, enable the BlockCloudObjectTakeoverThroughHardMatch feature
B. For Microsoft Entra Connect sync, enable password writeback
C. From the AD DS domain, create a new user account named User1
D. For Microsoft Entra Connect sync, disable soft match
View answer
Correct Answer: B
Question #41
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains a single-domain Active Directory Domain Services (AD DS) forest named contoso.com. The functional level of the forest is Windows Server 2012 R2. All domain controllers run Windows Server 2012 R2.Sysvol replicates by using the File Replication Service (FRS).You plan to replace the existing domain controllers with new domain controllers that will run Windows Server 2022.You need to ensure that you can add the first domain controller that runs Windows Server 2022.Solution: You run the Active Directory Migration Tool (ADMT).Does this meet the goal?
A. o
B. es
View answer
Correct Answer: A

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us