DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft AZ-801 Practice Questions & Answers 2026 Part3

Are you preparing for the Microsoft AZ-801 certification exam? SPOTO offers the Microsoft AZ-801 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
You have an on-premises Hyper- V deployment that hosts multiple virtual machines. You have an Azure subscription that contains an Azure Migrate project named Project1. You plan to migrate the virtual machines to Azure by using Project1.You need to discover all the Hyper-V hosts and virtual machines running in your environment. The solution must minimize administrative effort. What should you do first?
A. Generate a project key
B. Create a private endpoint
C. Register an appliance
D. Deploy an Azure Network Adapter
View answer
Correct Answer: A

View The Updated AZ-801 Exam Questions

SPOTO Provides 100% Real AZ-801 Exam Questions for You to Pass Your AZ-801 Exam!

Question #2
You have an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.You need to prevent the registration of specific COM objects on Server1.What should you use?
A. Windows Defender Application Control (WDAC)
B. exploit protection
C. Smart App Control
View answer
Correct Answer: A
Question #3
You have an Azure virtual machine named VM1 that runs Windows Server. You plan to deploy a new line-of-business (LOB) application to VM1. You need to ensure that the application can create child processes. What should you configure on VM1?
A. NTLMv2
B. pre-shared key
C. Kerberos V5
D. computer certificate
View answer
Correct Answer: D
Question #4
You have a three-node failover cluster.
A. Scheduled tasks
B. Run profiles
C. Azure Functions
D. Windows Server Update Serveries (WSUS)
View answer
Correct Answer: B
Question #5
You have an Azure subscription that has Microsoft Defender for Cloud enabled.You have 50 Azure virtual machines that run Windows Server.You need to ensure that any security exploits detected on the virtual machines are forwarded to Defender for Cloud.Which extension should you enable on the virtual machines?
A. ulnerability assessment for machines
B. icrosoft Dependency agent
C. og Analytics agent for Azure VMs
D. uest Configuration agent
View answer
Correct Answer: A
Question #6
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server.You need to ensure that only specific applications can modify the data in protected folders on Server1.Solution: From Virus & threat protection, you configure Tamper Protection.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #7
You have 10 servers that run Windows Server in a workgroup.You need to configure the servers to encrypt all the network traffic between the servers. The solution must be as secure as possible.Which authentication method should you configure in a connection security rule?
A. NTLMv2
B. pre-shared key
C. Kerberos V5
D. computer certificate
View answer
Correct Answer: D
Question #8
You are planning the migration of Archive1 to support the on - premises migration plan. What is the minimum number of IP addresses required for the node and cluster roles on Cluster3?
A. 2
B. 3
C. 4
D. 5
View answer
Correct Answer: B
Question #9
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that hosts an app named App1. App1 uses Active Directory authentication.You have a Microsoft Entra tenant that contains a user named User1.You deploy Microsoft Entra Connect sync and configure password synchronization.User1 fails to authenticate to App1.You need to ensure that User1can authenticate to App1.What should you do?
A. For Microsoft Entra Connect sync, enable the BlockCloudObjectTakeoverThroughHardMatch feature
B. For Microsoft Entra Connect sync, enable password writeback
C. From the AD DS domain, create a new user account named User1
D. For Microsoft Entra Connect sync, disable soft match
View answer
Correct Answer: B
Question #10
You have an Azure virtual machine named VM1 that runs Windows Server.You need to encrypt the contents of the disks on VM1 by using Azure Disk Encryption.What is a prerequisite for implementing Azure Disk Encryption?
A. Customer Lockbox for Microsoft Azure
B. an Azure key vault
C. a BitLocker recovery key
D. data-link layer encryption in Azure
View answer
Correct Answer: B
Question #11
You have a Windows Server 2022 Remote Desktop Services deployment that includes the servers shown in the following table.You need to upgrade Remote Desktop Services deployment to Windows Server 2025.Which Server must you upgrade first?
A. erver3
B. erver2
C. erver5
D. erver1
E. erver4
View answer
Correct Answer: A
Question #12
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an on-premises server named Server1 that runs Windows Server.You have a Microsoft Sentinel instance.You add the Windows Firewall data connector in Microsoft Sentinel.You need to ensure that Microsoft Sentinel can collect Windows Firewall logs from Server1.Solution: You install the Log Analytics agent on Server1.Does this meet the goal?
A. es
B. o
View answer
Correct Answer: A
Question #13
You have a server named Server1 that runs Windows Server.You install a custom app named App1 that is accessed by using TCP port 52310.Users report that they cannot access App1.You confirm that App1 is running on Server1.You need to ensure that the users can access App1. The solution must only provide access to App1 on Server1.What should you do in Windows Defender Firewall with Advanced Security?
A. Create an isolation connection security rule
B. Create an outbound rule
C. Create an inbound rule
D. For the current profile, allow all inbound connections
View answer
Correct Answer: C
Question #14
You establish synchronization between an AD DS and Azure AD environments. Users whose accounts are synced were able to sign in, but none of them could access cloud resources. What could be the problem?
A. one of these
B. he users don't have licenses assigned for cloud apps
C. he users don't have licenses assigned for cloud apps
D. he users don't have licenses assigned for cloud apps
View answer
Correct Answer: D
Question #15
You have an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.You need to prevent the registration of specific COM objects on Server1.What should you use?
A. Windows Defender Application Control (WDAC)
B. exploit protection
C. Smart App Control
View answer
Correct Answer: A
Question #16
You have an on-premises server named Server1 that runs Windows Server.You have an Azure subscription.You need to onboard Server1 to Microsoft Defender for Cloud.What should you install on Server1?
A. the Azure File Sync agent
B. the Microsoft Entra provisioning agent
C. the Device Health Attestation role
D. the Azure Connected Machine agent
View answer
Correct Answer: D
Question #17
You have a server that runs Windows Server. The server is configured to encrypt all incoming traffic by using a connection security rule.You need to ensure that Server1 can respond to the unencrypted tracert commands initiated from computers on the same network.What should you do from Windows Defender Firewall with Advanced Security?
A. From the IPsec Settings, configure IPsec defaults
B. Create a new custom outbound rule that allows ICMPv4 protocol connections for all profiles
C. Change the Firewall state of the Private profile to Off
D. From the IPsec Settings, configure IPsec exemptions
View answer
Correct Answer: D
Question #18
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains two servers named Server1 and Server2 that run WindowsServer.You need to ensure that you can use the Computer Management console to manage Server2. The solution must use the principle of least privilege.Which two Windows Defender Firewall with Advanced Security rules should you enable on Server2? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. he COM+ Network Access (DCOM-In) rule
B. ll the rules in the Remote Event Log Management group
C. he Windows Management Instrumentation (WMI-In) rule
D. he COM+ Remote Administration (DCOM-In) rule
E. he Windows Management Instrumentation (DCOM-In) rule
View answer
Correct Answer: AB
Question #19
You have an on-premises server named Server1 that runs Windows Server 2022 Standard.You have an Azure subscription that contains the virtual machines shown in the following table.The subscription contains a Microsoft Sentinel instance named Sentinel1 in the Central US Azure region.You need to implement the Windows Firewall connector.Which servers can send Windows Firewall logs to Sentinel1?
A. VM1 only
B. VM2 only
C. VM1 and Server1 only
D. VM1, VM2, and VM3 only
E. VM1, VM2, and Server1 only
F. VM1, VM2, VM3, and Server1
View answer
Correct Answer: E
Question #20
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a file server named Server 1 that hosts multiple shared folders. You have an Azure subscription. You need to migrate the files stored on Server! to Azure by using an Azure Data Box gateway. To which storage services can you migrate the files?
A. Azure Files only
B. Azure files and Azure Storage page blobs only
C. Azure Files and Azure Storage block blobs only
D. Azure Files
View answer
Correct Answer: D
Question #21
You are planning the data share migration to support the on-premises migration plan.What should you use to perform the migration?
A. Storage Migration Service
B. Microsoft File Server Migration Toolkit
C. File Server Resource Manager (FSRM)
D. Windows Server Migration Tools
View answer
Correct Answer: A
Question #22
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server.You need to ensure that only specific applications can modify the data in protected folders on Server1.Solution: From App & browser control, you configure Reputation-based protection.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #23
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that hosts an app named App1. App1 uses Active Directory authentication.You have a Microsoft Entra tenant that contains a user named User1.You deploy Microsoft Entra Connect sync and configure password synchronization.User1 fails to authenticate to App1.You need to ensure that User1can authenticate to App1.What should you do?
A. For Microsoft Entra Connect sync, enable the BlockCloudObjectTakeoverThroughHardMatch feature
B. For Microsoft Entra Connect sync, enable password writeback
C. From the AD DS domain, create a new user account named User1
D. For Microsoft Entra Connect sync, disable soft match
View answer
Correct Answer: B
Question #24
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server.You need to ensure that only specific applications can modify the data in protected folders on Server1.Solution: From App & browser control, you configure the Exploit protection settings.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #25
You have an Azure virtual machine named VM1 that runs Windows Server.You plan to deploy a new line-of-business (LOB) application to VM1.You need to ensure that the application can create child processes.What should you configure on VM1?
A. Microsoft Defender Credential Guard
B. Microsoft Defender Application Control
C. Microsoft Defender SmartScreen
D. Exploit protection
View answer
Correct Answer: D
Question #26
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1.You deploy a read-only domain controller (RODC) named RODC1.You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege.What should you use?
A. System Configuration
B. dsmgmt
C. Computer Management
D. Active Directory Sites and Services
View answer
Correct Answer: C
Question #27
You have an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.You need to prevent the registration of specific COM objects on Server1.What should you use?
A. Windows Defender Application Control (WDAC)
B. exploit protection
C. Smart App Control
View answer
Correct Answer: A
Question #28
You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have 50 Azure virtual machines that run Windows Server. You need to ensure that any security exploits detected on the virtual machines are forwarded to Defender for Cloud. Which extension should you enable on the virtual machines?
A. 1
B. 2
C. 3
D. 4
E. 5
View answer
Correct Answer: E
Question #29
You have 500 on-premises servers that run Windows Server.You have an Azure subscription that contains a Log Analytics workspace named Workspace1.You plan to use VM insights in Azure Monitor to monitor the on-premises servers.You need to onboard the servers to Azure Arc by using the template script. The solution must meet the following requirements:Follow the principle of least privilege.Minimize administrative effort.What should you do first?
A. Create a group managed service account (gMSA)
B. Generate a Log Analytics key
C. Create a Microsoft Entra service principal
D. Download the Log Analytics workspace I
View answer
Correct Answer: C
Question #30
You have a server that runs Windows Server. The server is configured to encrypt all incoming traffic by using a connection security rule.You need to ensure that Server1 can respond to the unencrypted tracert commands initiated from computers on the same network.What should you do from Windows Defender Firewall with Advanced Security?
A. From the IPsec Settings, configure IPsec defaults
B. Create a new custom outbound rule that allows ICMPv4 protocol connections for all profiles
C. Change the Firewall state of the Private profile to Off
D. From the IPsec Settings, configure IPsec exemptions
View answer
Correct Answer: D
Question #31
You have an Azure virtual machine named VM1 that runs Windows Server.You plan to deploy a new line-of-business (LOB) application to VM1.You need to ensure that the application can create child processes.What should you configure on VM1?
A. Microsoft Defender Credential Guard
B. Microsoft Defender Application Control
C. Microsoft Defender SmartScreen
D. Exploit protection
View answer
Correct Answer: D
Question #32
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a failover cluster named Cluster1 that hosts an application named App1.The General tab in App1 Properties is shown in the General exhibit. (Click the General tab.)The Failover tab in App1 Properties is shown in the Failover exhibit. (Click the Failover tab.)Server1 shuts down unexpectedly.You need to ensure that when you start Server1, App1 continues to run on Server2.Solution: From the General settings, you move Server2 up.Does this meet the goal?
A. o
B. es
View answer
Correct Answer: A
Question #33
You have an Azure virtual machine named VM1 that runs Windows Server.The operating system on VM1 fails to fully initialize its network stack, and you cannot establish a network connection.You need to establish an interactive shell session.What should you use?
A. Azure Bastion
B. Serial console
C. just-in-time (JIT) VM access
View answer
Correct Answer: A
Question #34
You have a server that runs Windows Server 2025 Standard and has the Hyper-V role installed.
A. dism
B. setup
C. slmgc
D. convert
View answer
Correct Answer: A
Question #35
Your on-premises network is connected to Azure. You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server. You need to identify the latency between the on-premises network and VM1. Which Azure Network Watcher settings should you use?
A. AIP flow verify
B. BConnection monitor
C. CVPN troubleshoot
D. DConnection troubleshoot
View answer
Correct Answer: B
Question #36
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains a file Server named Server1 that hosts multiple shared folders.You have an Azure subscription.You need to migrate the files stored on Server1 to Azure by using an Azure Data Box gateway.To which storage services can you migrate the files?
A. zure Files and Azure Storage block blobs only
B. zure Files and Azure Storage page blobs only
C. zure Files, Azure Storage page blobs, and Azure Storage block blobs
D. zure Files only
View answer
Correct Answer: C
Question #37
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1. You deploy a read-only domain controller (RODC) named RODC1. You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege. What should you use?
A. dsmgmt
B. dsamain
C. net user
D. Active Directory Sites and Services
View answer
Correct Answer: D
Question #38
You have a failover cluster named Cluster1 that has the following configurations: - Number of nodes: 6 - Quorum: Dynamic quorum - Witness: File share, Dynamic witness What is the maximum number of nodes that can fail simultaneously while maintaining quorum?
A. adaptive network hardening
B. a workbook
C. a security policy
D. a logic app
View answer
Correct Answer: D
Question #39
You have a server named Server1 that runs Windows Server.You install a custom app named App1 that is accessed by using TCP port 52310.Users report that they cannot access App1.You confirm that App1 is running on Server1.You need to ensure that the users can access App1. The solution must only provide access to App1 on Server1.What should you do in Windows Defender Firewall with Advanced Security?
A. Create an isolation connection security rule
B. Create an outbound rule
C. Create an inbound rule
D. For the current profile, allow all inbound connections
View answer
Correct Answer: C

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us