DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft AZ-801 Practice Questions & Answers 2026 Part2

Are you preparing for the Microsoft AZ-801 certification exam? SPOTO offers the Microsoft AZ-801 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
You have a server named Server1 that runs Windows Server.You install a custom app named App1 that is accessed by using TCP port 52310.Users report that they cannot access App1.You confirm that App1 is running on Server1.You need to ensure that the users can access App1. The solution must only provide access to App1 on Server1.What should you do in Windows Defender Firewall with Advanced Security?
A. Create an isolation connection security rule
B. Create an outbound rule
C. Create an inbound rule
D. For the current profile, allow all inbound connections
View answer
Correct Answer: C

View The Updated AZ-801 Exam Questions

SPOTO Provides 100% Real AZ-801 Exam Questions for You to Pass Your AZ-801 Exam!

Question #2
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1.You deploy a read-only domain controller (RODC) named RODC1.You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege.What should you use?
A. System Configuration
B. dsmgmt
C. Computer Management
D. Active Directory Sites and Services
View answer
Correct Answer: C
Question #3
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server.You need to ensure that only specific applications can modify the data in protected folders on Server1.Solution: From Virus & threat protection, you configure Controlled folder access.Does this meet the goal?
A. es
B. o
View answer
Correct Answer: A
Question #4
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains two servers named Server1 and Server2 that run Windows Server.You need to ensure that you can manage Server2 by using the Computer Management console from Server1.The solution must use the principle of least privilege.Which two Windows Defender Firewall with Advanced Security rules should you enable on Server2? Each correct answer presents part of the solution.Note: Each correct selection is worth one point.
A. the COM+ Network Access (DCOM-In) rule
B. all the rules in the Remote Event Log Management group
C. the Windows Management Instrumentation (WMI-In) rule
D. the COM+ Remote Administration (DCOM-In) rule
E. the Windows Management Instrumentation (DCOM-In) rule
View answer
Correct Answer: AB
Question #5
You have 50 on-premises servers that run Windows Server. You have an Azure subscription that contains 50 virtual machines that run Windows Server.
A. Create an Alert Rule
B. Install the Azure Monitor agent on each server
C. Enable System Insights on each server
D. Create a Log Analytics workspace and configure the Agent management settings
View answer
Correct Answer: A
Question #6
You have a server named Server1 that runs Windows Server.You install a custom app named App1 that is accessed by using TCP port 52310.Users report that they cannot access App1.You confirm that App1 is running on Server1.You need to ensure that the users can access App1. The solution must only provide access to App1 on Server1.What should you do in Windows Defender Firewall with Advanced Security?
A. Create an isolation connection security rule
B. Create an outbound rule
C. Create an inbound rule
D. For the current profile, allow all inbound connections
View answer
Correct Answer: C
Question #7
Your company uses Storage Spaces Direct.You need to view the available storage in a Storage Space Direct storage pool.What should you use?
A. ystem Configuration
B. esource Monitor
C. he Get-StorageFileServer cmdlet
D. indows Admin Center
View answer
Correct Answer: D
Question #8
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that hosts an app named App1. App1 uses Active Directory authentication.You have a Microsoft Entra tenant that contains a user named User1.You deploy Microsoft Entra Connect sync and configure password synchronization.User1 fails to authenticate to App1.You need to ensure that User1can authenticate to App1.What should you do?
A. For Microsoft Entra Connect sync, enable the BlockCloudObjectTakeoverThroughHardMatch feature
B. For Microsoft Entra Connect sync, enable password writeback
C. From the AD DS domain, create a new user account named User1
D. For Microsoft Entra Connect sync, disable soft match
View answer
Correct Answer: B
Question #9
You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server. The subscription contains the storage accounts shown in the following table.You plan to enable boot diagnostics for VM1.You need to configure storage for the boot diagnostics logs and snapshots.Which storage account should you use?
A. torage1
B. torage2
C. torage3
D. torage4
View answer
Correct Answer: C
Question #10
You have 100 Azure virtual machines that run Windows Server. The virtual machines are onboarded to Microsoft Defender for Cloud. You need to shut down a virtual machine automatically if Microsoft Defender for Cloud generates the "Antimalware disabled in the virtual machine" alert for the virtual machine. What should you use in Microsoft Defender for Cloud?
A. an Azure Desired State Configuration (DSC) virtual machine extension
B. an Azure Automation runbook
C. an Azure PowerShell function
D. a Custom Script Extension on the virtual machines
View answer
Correct Answer: B
Question #11
You have an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.You need to prevent the registration of specific COM objects on Server1.What should you use?
A. Windows Defender Application Control (WDAC)
B. exploit protection
C. Smart App Control
View answer
Correct Answer: A
Question #12
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that hosts an app named App1. App1 uses Active Directory authentication.You have a Microsoft Entra tenant that contains a user named User1.You deploy Microsoft Entra Connect sync and configure password synchronization.User1 fails to authenticate to App1.You need to ensure that User1can authenticate to App1.What should you do?
A. For Microsoft Entra Connect sync, enable the BlockCloudObjectTakeoverThroughHardMatch feature
B. For Microsoft Entra Connect sync, enable password writeback
C. From the AD DS domain, create a new user account named User1
D. For Microsoft Entra Connect sync, disable soft match
View answer
Correct Answer: B
Question #13
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server.You need to ensure that only specific applications can modify the data in protected folders on Server1.Solution: From App & browser control, you configure the Exploit protection settings.Does this meet the goal?
A. es
B. o
View answer
Correct Answer: B
Question #14
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a failover cluster named Cluster1 that hosts an application named App1.The General tab in App1 Properties is shown in the General exhibit. (Click the General tab.)The Failover tab in App1 Properties is shown in the Failover exhibit. (Click the Failover tab.)Server1 shuts down unexpectedly.You need to ensure that when you start Server1, App1 continues to run on Server2.Solution: You pause the Server1 node in Cluster1 and then start Server1.Does this meet the goal?
A. o
B. es
View answer
Correct Answer: A
Question #15
You have an on-premises IIS web server that hosts several .NET applications.You plan to migrate the applications to Azure App Service. The applications will NOT be containerized.What should you use to perform the migration?
A. pp Service Migration Assistant
B. eb Deploy
C. IS Manager
D. ata Migration Assistant (DMA)
E. indows Admin Center
View answer
Correct Answer: A
Question #16
You have a server named Server1 that runs the Remote Desktop Session Host role service. Server1 has five custom applications installed.
A. Processor information
B. Processor
C. Process
D. Processor performance
View answer
Correct Answer: C
Question #17
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1.You deploy a read-only domain controller (RODC) named RODC1.You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege.What should you use?
A. System Configuration
B. dsmgmt
C. Computer Management
D. Active Directory Sites and Services
View answer
Correct Answer: C
Question #18
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that mightmeet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server.You need to ensure that only specific applications can modify the data in protected folders on Server1.Solution: From Virus & threat protection, you configure Controlled folder access.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #19
You have an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.You need to prevent the registration of specific COM objects on Server1.What should you use?
A. Windows Defender Application Control (WDAC)
B. exploit protection
C. Smart App Control
View answer
Correct Answer: A
Question #20
You have an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.You need to prevent the registration of specific COM objects on Server1.What should you use?
A. Windows Defender Application Control (WDAC)
B. exploit protection
C. Smart App Control
View answer
Correct Answer: A
Question #21
You have an Azure subscription that has Microsoft Defender for Cloud enabled.You have 50 Azure virtual machines that run Windows Server.You need to ensure that any security exploits detected on the virtual machines are forwarded to Defender for Cloud.Which extension should you enable on the virtual machines?
A. Vulnerability assessment for machines
B. Microsoft Dependency agent
C. Log Analytics agent for Azure VMs
D. Guest Configuration agent
View answer
Correct Answer: A
Question #22
You have an Azure virtual machine named VM1.You enable Microsoft Defender SmartScreen on VM1.You need to ensure that the SmartScreen messages displayed to users are logged.What should you do?
A. From a command prompt, run WinRM quickconfig
B. From the local Group Policy, modify the Advanced Audit Policy Configuration settings
C. From Event Viewer, enable the Debug log
D. From the Windows Security app, configure the Virus & threat protection settings
View answer
Correct Answer: C
Question #23
You have a management group named MG1 that contains an Azure subscription named Sub1. Sub1 contains the resources shown in the following table.You need to enable Microsoft Defender for Servers.From the Azure portal, on which two resources can you enable Defender for Servers? Each correct answer presents a complete solution.Note: Each correct selection is worth one point.
A. RG1
B. Workspace1
C. Sub1
D. MG1
E. VNet1
F. VM1
View answer
Correct Answer: BC
Question #24
You have a server named Server1 that runs Windows Server.You install a custom app named App1 that is accessed by using TCP port 52310.Users report that they cannot access App1.You confirm that App1 is running on Server1.You need to ensure that the users can access App1. The solution must only provide access to App1 on Server1.What should you do in Windows Defender Firewall with Advanced Security?
A. Create an isolation connection security rule
B. Create an outbound rule
C. Create an inbound rule
D. For the current profile, allow all inbound connections
View answer
Correct Answer: C
Question #25
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server.You need to ensure that only specific applications can modify the data in protected folders on Server1.Solution: From Virus & threat protection, you configure Tamper ProtectionDoes this meet the goal?
A. es
B. o
View answer
Correct Answer: B
Question #26
You have a Microsoft Sentinel deployment and 100 Azure Arc-enabled on-premises servers. All the Azure Arc-enabled resources are in the same resource group.You need to onboard the servers to Microsoft Sentinel. The solution must minimize administrative effort.What should you use to onboard the servers to Microsoft Sentinel?
A. zure Automation
B. zure Policy
C. zure virtual machine extensions
D. icrosoft Defender for Cloud
View answer
Correct Answer: B
Question #27
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1.You deploy a read-only domain controller (RODC) named RODC1.You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege.What should you use?
A. System Configuration
B. dsmgmt
C. Computer Management
D. Active Directory Sites and Services
View answer
Correct Answer: C
Question #28
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains a single-domain Active Directory Domain Services (AD DS) forest named contoso.com. The functional level of the forest is Windows Server 2012 R2. All domain controllers run Windows Server 2012 R2.Sysvol replicates by using the File Replication Service (FRS).You plan to replace the existing domain controllers with new domain controllers that will run Windows Server 2022.You need to ensure that you can add the first domain controller that runs Windows Server 2022.Solution: You migrate sysvol from FRS to Distributed File System (DFS) Replication.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #29
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server.You need to ensure that only specific applications can modify the data in protected folders on Server1.Solution: From Virus & threat protection, you configure Controlled folder access.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #30
You have two Azure Virtual machines that run Windows Server. You plan to create a failover cluster that will host the virtual machines. You need to configure an Azure Storage account that will be used by the cluster as a cloud witness. The solution must maximize resiliency. Which type of redundancy should you configure for the storage account?
A. AGeo-zone-redundant storage (GZRS)
B. BGeo-redundant storage (GRS)
C. CZone-redundant storage (ZRS)
D. DLocally-redundant storage (LRS)
View answer
Correct Answer: C
Question #31
You have a server named Server1 that runs Windows Server.You install a custom app named App1 that is accessed by using TCP port 52310.Users report that they cannot access App1.You confirm that App1 is running on Server1.You need to ensure that the users can access App1. The solution must only provide access to App1 on Server1.What should you do in Windows Defender Firewall with Advanced Security?
A. Create an isolation connection security rule
B. Create an outbound rule
C. Create an inbound rule
D. For the current profile, allow all inbound connections
View answer
Correct Answer: C
Question #32
You have two Azure virtual networks named Vnet1 and Vnet2.You have a Windows 10 device named Client1 that connects to Vnet1 by using a Point-to-Site (P2S) IKEv2 VPN.You implement virtual network peering between Vnet1 and Vnet2. Vnet1 allows gateway transit Vnet2 can use the remote gateway.You discover that Client1 cannot communicate with Vnet2.You need to ensure that Client1 can communicate with Vnet2.Solution: You download and reinstall the VPN client configuration.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #33
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that mightmeet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server.You need to ensure that only specific applications can modify the data in protected folders on Server1.Solution: From App & browser control, you configure the Exploit protection settings.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #34
You are remediating the firewall security risks to meet the security requirements.What should you configure to reduce the risks?
A. a Group Policy Object (GPO)
B. adaptive network hardening in Microsoft Defender for Cloud
C. a network security group (NSG) in Sub1
D. an Azure Firewall policy
View answer
Correct Answer: A
Question #35
You have a Microsoft Sentinel deployment and 100 Azure Arc-enabled on-premises servers. All the Azure Arc-enabled resources are in the same resource group.You need to onboard the servers to Microsoft Sentinel. The solution must minimize administrative effort.What should you use to onboard the servers to Microsoft Sentinel?
A. Azure Automation
B. Azure Policy
C. Azure virtual machine extensions
D. Microsoft Defender for Cloud
View answer
Correct Answer: B
Question #36
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that hosts an app named App1. App1 uses Active Directory authentication.You have a Microsoft Entra tenant that contains a user named User1.You deploy Microsoft Entra Connect sync and configure password synchronization.User1 fails to authenticate to App1.You need to ensure that User1can authenticate to App1.What should you do?
A. For Microsoft Entra Connect sync, enable the BlockCloudObjectTakeoverThroughHardMatch feature
B. For Microsoft Entra Connect sync, enable password writeback
C. From the AD DS domain, create a new user account named User1
D. For Microsoft Entra Connect sync, disable soft match
View answer
Correct Answer: B
Question #37
You have a failover cluster named Cluster1 that has the following configurations: Number of nodes: 6 Quorum: Dynamic quorum Witness: File share, Dynamic witness What is the maximum number of nodes that can fail simultaneously while maintaining quorum? Note this question is asking about nodes failing 'simultaneously', not nodes failing one after the other. With six nodes and one witness, there are seven votes. To maintain quorum there needs to be four votes available (four votes is the majority of seven). This means that a minimum of three nodes plus the witness need to remain online for the cluster to function. Therefore, the maximum number of simultaneous failures is three. https://docs.microsoft.com/en-us/windows-server/storage/storage-spaces/understand-quorum
A. 1
B. 2
C. 3
D. 4
E. 5
View answer
Correct Answer: C
Question #38
You have an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.You need to prevent the registration of specific COM objects on Server1.What should you use?
A. Windows Defender Application Control (WDAC)
B. exploit protection
C. Smart App Control
View answer
Correct Answer: A
Question #39
You have two Azure virtual networks named Vnet1 and Vnet2. You have a Windows 10 device named Client1 that connects to Vnet1 by using a Point-to-Site (P2S) IKEv2 VPN. You implement virtual network peering between Vnet1 and Vnet2. Vnet1 allows gateway transit Vnet2 can use the remote gateway. You discover that Client1 cannot communicate with Vnet2. You need to ensure that Client1 can communicate with Vnet2. Solution: You download and reinstall the VPN client configuration. Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us