DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Efficient Microsoft AZ-800 Exam Preparation with Updated Practice Questions

Explore the advantages of SPOTO Microsoft AZ-800 exam questions for Microsoft Administering Windows Server Hybrid Core Infrastructure certification. The AZ-800 exam is designed for candidates proficient in managing fundamental Windows Server workloads across on-premises, hybrid, and cloud environments. Our exam questions and answers cover key areas such as identity management, computing, networking, storage, and administrative tools like Windows Admin Center, PowerShell, Azure Arc, and IaaS virtual machine administration. Prepare effectively with our comprehensive test questions that simulate real exam scenarios. Access expertly crafted study materials and exam resources to enhance your preparation strategy. Utilize our mock exams to assess readiness and build confidence for a successful exam outcome. Trust SPOTO for a reliable path to passing the Microsoft AZ-800 exam.
Take other online exams

Question #1
Case Study - This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided. To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other
A. Server1 only
B. Server2 only
C. Server1 and Server2 only
D. Server2 and Server3 only
E. Server1 and Server4 only
View answer
Correct Answer: D
Question #2
You need to ensure that VM3 meets the technical requirements.What should you install first?
A. nhanced Storage
B. he iSNS Server service
C. ile Server Resource Manager (FSRM)
D. indows Standards-Based Storage Management
View answer
Correct Answer: C
Question #3
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1.You implement Just Enough Administration (JEA) on Server1.You need to perform remote administration tasks on Server by using only JEA.What should you use?
A. PowerShell only
B. Remote Server Administration Tools (RSAT) only
C. PowerShell or Remote Desktop only
D. PowerShell or Remote Server Administration Tools (RSAT) only
E. Remote Server Administration Tools (RSAT) or Remote Desktop only
F. PowerShell, Remote Server Administration Tools (RSAT), or Remote Desktop
View answer
Correct Answer: A
Question #4
HOTSPOT (Drag and Drop is not supported)You have an Azure subscription named sub1 and 500 on-premises virtual machines that run Windows Server.You plan to onboard the on-premises virtual machines to Azure Arc by running the Azure Arc deployment script.You need to create an identity that will be used by the script to authenticate access to sub1. The solution must use the principle of least privilege.How should you complete the command? To answer, select the appropriate options in the answer area. NOTE: Each
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #5
HOTSPOT (Drag and Drop is not supported)Your on-premises network contains a single-domain Active Directory Domain Services (AD DS) forest. You have an Azure AD tenant named contoso.com. The AD DS forest syncs with the Azure AD tenant by using Azure AD Connect.You need to ensure that users in the forest that have a custom attribute of NoSync are excluded from synchronization.How should you configure the Azure AD Connect cloudFiltered attribute, and which tool should you use? To answer, select the appropriate
A. es
B. o
View answer
Correct Answer: A
Question #6
You have an Azure Active Directory Domain Services (Azure AD DS) domain named contoso.com.You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The solution must use the principle of least privilege.To which group should you add the administrator?
A. AD DC Administrators
B. omain Admins
C. chema Admins
D. nterprise Admins
E. roup Policy Creator Owners
View answer
Correct Answer: A
Question #7
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant.You have several Windows 10 devices that are Azure AD hybrid-joined.You need to ensure that when users sign in to the devices, they can use Windows Hello for Business.Which optional feature should you select in Azure AD Connect?
A. evice writeback
B. roup writebeack
C. zure AD app and attribute filtering
D. assword writeback
E. irectory extension attribute sync
View answer
Correct Answer: A
Question #8
You have an Azure virtual machine named VM1 that has a private IP address only.You configure the Windows Admin Center extension on VM1.You have an on-premises computer that runs Windows 11. You use the computer for server management.You need to ensure that you can use Windows Admin Center from the Azure portal to manage VM1.What should you configure?
A. an Azure Bastion host on the virtual network that contains VM1
B. a VPN connection to the virtual network that contains VM1
C. a private endpoint on the virtual network that contains VM1
D. a network security group (NSG) rule that allows inbound traffic on port 443
View answer
Correct Answer: B
Question #9
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with Azure AD.You deploy an app that adds custom attributes to the domain.From Azure Cloud Shell, you discover that you cannot query the custom attributes of users.You need to ensure that the custom attributes are available in Azure AD.Which task should you perform from Microsoft Azure Active Directory Connect first?
A. onfigure device options
B. anage federation
C. ustomize synchronization options
D. efresh directory schema
View answer
Correct Answer: C
Question #10
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory Domain Services (AD DS) domain named
A. es
B. o
View answer
Correct Answer: B
Question #11
HOTSPOT (Drag and Drop is not supported)Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with an Azure AD tenant. The tenant contains a group named Group1 and the users shown in the following table.Domain/OU filtering in Azure AD Connect is configured as shown in the Filtering exhibit. (Click the Filtering tab.)You review the Azure AD Connect configurations as shown in the Configure exhibit. (Click the Configure tab.)For each of the following
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #12
HOTSPOT (Drag and Drop is not supported)You need to meet technical requirements for HyperV1.Which command should you run? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point.
A. one1
B. one2
C. one1
D. one2
E. one1
View answer
Correct Answer: A
Question #13
Your network contains an Active Directory domain named contoso.com. The domain contains the computers shown in the following table.On Server3, you create a Group Policy Object (GPO) named GP01 and link GPOI to contoso.com. GP01 includes a shortcut preference named Shortcut1 that has item-level targeting configured as shown in the following exhibit.To which computer will Shortcut1 be applied?
A. erver3 only
B. omputer1 and Server3 only
C. erver2 and Server3 only
D. erver1, Server2, and Server3 only
View answer
Correct Answer: A
Question #14
Your network contains an Active Directory domain named contoso.com. The domain contains the computers shown in the following table.On Server3, you create a Group Policy Object (GPO) named GPO1 and link GPO1 to contoso.com. GPO1 includes a shortcut preference named Shortcut1 that has item-level targeting configured as shown in the following exhibit.To which computer will Shortcut1 be applied?
A. erver3 only
B. omputer1 and Server3 only
C. erver2 and Server3 only
D. erver1, Server2, and Server3 only
View answer
Correct Answer: A
Question #15
You need to meet the technical requirements for the site links.Which users can perform the required tasks?
A. dmin1, Admin2, and Admin3
B. dmin1 and Admin3 only
C. dmin1 only
D. dmin1 and Admin2 only
E. dmin3 only
View answer
Correct Answer: D
Question #16
You need to configure the Group Policy settings to ensure that the Azure Virtual Desktop session hosts meet the security requirements.What should you configure?
A. oopback processing in GPO4
B. ecurity filtering for the link of GPO1
C. oopback processing in GPO1
D. he Enforced property for the link of GPO4
E. he Enforced property for the link of GPO1
View answer
Correct Answer: A
Question #17
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The root domain contains the domain controllers shown in the following table.A failure of which domain controller will prevent you from creating application partitions?
A. C1
B. C2
C. C3
D. C4
E. C5
View answer
Correct Answer: A
Question #18
Your on-premises network contains an Active Directory domain named contoso.com. You have an Azure AD tenant.You plan to sync contoso.com with the Azure AD tenant by using Azure AD Connect cloud sync.You need to create an account that will be used by Azure AD Connect cloud sync.Which type of account should you create?
A. ystem-assigned managed identity
B. roup managed service account (gMSA)
C. ser
D. netOrgPerson
View answer
Correct Answer: B
Question #19
HOTSPOT (Drag and Drop is not supported)You have a Windows Server container host named Server1 and an Azure subscription.You deploy an Azure container registry named Registry1 to the subscription.On Server1, you create a container image named image1.You need to store image1 in Registry1.Which command should you run on Server1? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #20
You have an Active Directory Domain Services (AD DS) domain. The domain contains three servers named Server1, Server2, and Server3 that run Windows Server.You sign in to Server1 by using a domain account and start a remote PowerShell session to Server2. From the remote PowerShell session, you attempt to access a resource on Server3, but access to the resource is denied.You need to ensure that your credentials are passed from Server1 to Server3. The solution must minimize administrative effort.What should yo
A. onfigure Kerberos constrained delegation
B. onfigure Just Enough Administration (JEA)
C. onfigure selective authentication for the domain
D. isable the Enforce user logon restrictions policy setting for the domain
View answer
Correct Answer: B
Question #21
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory Domain Services (AD DS) forest. The fo
A. es
B. o
View answer
Correct Answer: B
Question #22
DRAG DROP (Drag and Drop is not supported)You create an Azure virtual machine named Server1 that runs Windows Server. Server1 has the disk configuration shown in the following exhibit. You need to create a new 100-GB volume on Server1.Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #23
HOTSPOT (Drag and Drop is not supported)Your network contains two Active Directory forests and a domain trust as shown in the following exhibit.The domain trust has the following configurations:•Name: adatum.com•Type: External•Direction: One-way, outgoing•Outgoing trust authentication level: Domain-wide authenticationThe forests contain the users shown in the following table.The forests contain the network shares shown in the following table.For each of the following statements, select Yes if the statement
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #24
DRAG DROP (Drag and Drop is not supported)DC1 fails.You need to meet the technical requirements for the schema master.You run ntdsutil.exe.Which five commands should you run in sequence? To answer, move the appropriate commands from the list of commands to the answer area and arrange them in the correct order?
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #25
HOTSPOT (Drag and Drop is not supported)Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains the servers shown in the following table.The domain controllers do NOT have internet connectivity.You plan to implement Azure AD Password Protection for the domain.You need to deploy Azure AD Password Protection agents. The solution must meet the following requirements:•All Azure AD Password Protection policies must be enforced.•Agent updates must be applied autom
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #26
You have an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with Azure AD by using Azure AD Connect.You enable password protection for contoso.com.You need to prevent users from including the word contoso as part of their password.What should you use?
A. he Azure Active Directory admin center
B. ctive Directory Users and Computers
C. ynchronization Service Manager
D. indows Admin Center
View answer
Correct Answer: A
Question #27
HOTSPOT (Drag and Drop is not supported)You plan w deploy an Azure virtual machine that win run Windows Server. The virtual machine will host an Active Directory Domain Services (AD DS) domain controller and a drive named f: on a new virtual disk. You need to configure storage foe the virtual machine. The solution must meet the following requirements:-Maximize resiliency for AD DS. -Prevent accidental data loss.How should you configure the storage? To answer, select the appropriate options in the answer are
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #28
You have an Azure subscription that contains the following resources.-An Azure Log Analytics workspace-An Azure Automation account-Azure ArcYou have an on-premises server named Server1 that is onboarded to Azure Arc.You need to manage Microsoft updates on Server1 by using Azure Arc.Which two actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: AC
Question #29
You have an Azure subscription that contains the virtual networks shown in the following table.You deploy a virtual machine named VM1 that runs Windows Server. VM1 is connected to Subnet11.You plan to add an additional network interface named NIC1 to VM1.To which subnets can NIC1 be attached?
A. ubnet11 only
B. ubnet12 only
C. ubnet11 and Subnet12only
D. ubnet12 and Subnet21 only
E. ubnet11, Subnet12, Subnet21f and Subnet31
View answer
Correct Answer: B
Question #30
You need to ensure that access to storage1 for the Marketing OU users meets the technical requirements.What should you implement?
A. ctive Directory Federation Services (AD FS)
B. zure AD Connect in staging mode
C. zure AD Connect cloud sync
D. zure AD Connect in active mode
View answer
Correct Answer: C
Question #31
You have a Windows Server container host named Server1 and a container image named image1.You need to start a container from image1. The solution must run the container on a Hyper-V virtual machine. Which parameter should you specify when you run the docker run command?
A. -expose
B. -privileged
C. -runtime
D. -isolation
E. -entrypoint
View answer
Correct Answer: D
Question #32
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains the resources shown in the following table.You plan to replicate a volume from Server1 to Server2 by using Storage Replica.You need to configure Storage Replica.Where should you install Windows Admin Center?
A. erver1
B. LIENT1
C. C1
D. erver2
View answer
Correct Answer: B
Question #33
DRAG DROP (Drag and Drop is not supported)You have a server named Server1 that runs Windows Server and has the Hyper V server role installed. Server1 hosts a virtual machine named VM1.Server1 has an NVMe storage device. The device is currently assigned to VM1 by using Discrete Device Assignment.You need to make the device available to Server1.Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #34
You have an Active Directory Domain Services (AD DS) domain that contains the domain controllers shown in the following table.The domain contains an app named App1 that uses a custom application partition to store configuration data.You decommission App1.When you attempt to remove the custom application partition, the process fails.Which domain controller is unavailable?
A. C1
B. C2
C. C3
D. C4
View answer
Correct Answer: C
Question #35
SIMULATIONYou need to ensure that the minimum password length for members of the BranchAdmins group is 12 characters. The solution must affect only the BranchAdmins group.To complete this task, sign in the required computer or computers.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #36
HOTSPOT (Drag and Drop is not supported)Your on-premises network contains an Active Directory Domain Services (AD DS) domain.You plan to sync the domain with an Azure AD tenant by using Azure AD Connect cloud sync.You need to meet the following requirements:•Install the software required to sync the domain and Azure AD.•Enable password hash synchronization.What should you install, and what should you use to enable password hash synchronization? To answer, select the appropriate options in the answer area.NO
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #37
DRAG DROP (Drag and Drop is not supported)Which three actions should you perform in sequence to meet the security requirements for Webapp1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.Select and Place:
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #38
You need to ensure that Automanage meets the technical requirements.On which Azure virtual machines should you enable Automanage?
A. ee Explanation section for answer
View answer
Correct Answer: D
Question #39
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant.You plan deploy 100 new Azure virtual machines that will run Windows Server.You need to ensure that each new virtual machine is joined to the AD DS domain.What should you use?
A. n Azure Resource Manager (ARM) template
B. Group Policy Object (GPO)
C. zure AD Connect
D. n Azure management group
View answer
Correct Answer: A
Question #40
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory Domain Services (AD DS) domain named c
A. es
B. o
View answer
Correct Answer: B
Question #41
You have an on premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant.You plan to implement self-service password reset (SSPR) in Azure AD.You need to ensure that users that reset their passwords by using SSPR can use the new password resources in the AD DS domain.What should you do?
A. eploy the Azure AD Password Protection proxy service to the on premises network
B. un the Microsoft Azure Active Directory Connect wizard and select Password writeback
C. rant the Change password permission for the domain to the Azure AD Connect service account
D. rant the impersonate a client after authentication user right to the Azure AD Connect service account
View answer
Correct Answer: B
Question #42
You have an Azure virtual machine named VM1 that has a private IP address only.You configure the Windows Admin Center extension on VM1.You have an on-premises computer that runs Windows 11. You use the computer for server management.You need to ensure that you can use Windows Admin Center from the Azure portal to manage VM1.What should you configure?
A. n Azure Bastion host on the virtual network that contains VM1
B. VPN connection to the virtual network that contains VM1
C. private endpoint on the virtual network that contains VM1
D. network security group (NSG) rule that allows inbound traffic on port 443
View answer
Correct Answer: B
Question #43
Your network contains an Active Directory Domain Services (AD DS) domain.You plan to use Active Directory Administrative Center to create a new user named User1.Which two attributes are required to create User1? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: CD
Question #44
HOTSPOT (Drag and Drop is not supported)You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant.You have an on-premises web app named WebApp1 that only supports Kerberos authentication.You need to ensure that users can access WebApp1 by using their Azure AD account. The solution must minimize administrative effort.What should you configure? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #45
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.Your network contains an Active Directory Domain Services (AD DS) forest. The fo
A. es
B. o
View answer
Correct Answer: B
Question #46
You have a server named Server1 that runs Windows Server and has the DHCP Server role installed. Server1 contains the following single scope:? Scope: 192.168.16.0? Address pool: 192.168.16.1-192.168.16.254? Subnet mask: 255.255.255.0? Lease duration: 8 daysYou have four testing devices that are configured with static IP addresses as shown in the following table.The test devices are turned on once a month.You need to prevent Server1 from assigning the IP addresses allocated to the test devices to other devic
A. Create a policy
B. Create reservations
C. Configure the Scope options
D. Create an exclusion range
View answer
Correct Answer: B
Question #47
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant.You deploy an app that adds custom attributes to the domain.From Azure Cloud Shell, you discover that you cannot query the custom attributes of users.You need to ensure that the custom attributes are available in Microsoft Entra ID.Which task should you perform from Microsoft Entra Connect first?
A. efresh directory schema
B. onfigure device options
C. ustomize synchronization options
D. anage federation
View answer
Correct Answer: C
Question #48
Your network contains a multi-site Active Directory Domain Services (AD DS) forest. Each Active Directory site is connected by using manually configured site links and automatically generated connections.You need to minimize the convergence time for changes to Active Directory.What should you do?
A. or each site link, modify the replication schedule
B. or each site links, modify the site link costs
C. reate a site link bridge that contains all the site links
D. or each site link, modify the options attribute
View answer
Correct Answer: D
Question #49
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three domains. Each domain contains 10 domain controllers.You plan to store a DNS zone in a custom Active Directory partition.You need to create the Active Directory partition for the zone. The partition must replicate to only four of the domain controllers.What should you use?
A. indows Admin Center
B. NS Manager
C. ctive Directory Sites and Services
D. tdsutil
View answer
Correct Answer: B
Question #50
You need to meet the technical requirements for VM2. What should you do?
A. mplement shielded virtual machines
B. nable the Guest services integration service
C. mplement Credential Guard
D. nable enhanced session mode
View answer
Correct Answer: D
Question #51
You need to meet the technical requirements for Server3.Which users can perform the required tasks?
A. dmin3 only
B. dmin1 and Admin3 only
C. dmin1 only
D. dmin1, Admin2, and Admin3
E. dmin1 and Admin2 only
View answer
Correct Answer: B
Question #52
HOTSPOT (Drag and Drop is not supported)For each of the following statements, select Yes if the statement is true. Otherwise. select No.NOTE: Each correct selection is worth one point.Hot Area:
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #53
You plan to deploy a containerized application that requires .NET Core.You need to create a container image for the application. The image must be as small as possible. Which base image should you use?
A. indows Server
B. ano Server
C. indows
D. erver Core
View answer
Correct Answer: B
Question #54
DRAG DROP (Drag and Drop is not supported)You need to implement the planned change for Data1.Which actions should you perform in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #55
You have an Azure virtual machine named Server1 that runs a network management application. Server1 has the following network configuration. -Network interface.Nic1 -IP address 10.1.1.1/24 -Connected to: Vnet1/Subnet1 You need connect Server1 to an additional subnet named Vnet1/Subnet2. What should you do?
A. odify the IP configurations of Nic1
B. dd an IP configuration to Nic1
C. dd a network interface to Server1
D. reate a private endpoint on Subnet2
View answer
Correct Answer: C
Question #56
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three domains. Each domain contains 10 domain controllers.You plan to store a DNS zone in a custom Active Directory partition.You need to create the Active Directory partition for the zone. The partition must replicate to only four of the domain controllers.What should you use?
A. indows Admin Center
B. et-DnsServer
C. ew-ADObject
D. tdsutil
View answer
Correct Answer: D
Question #57
HOTSPOT (Drag and Drop is not supported)Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains the domain controllers shown in the following table.You need to configure DC3 to be the authoritative time server for the domain.Which operations master role should you transfer to DC3, and which console should you use? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #58
Your network contains a multi-site Active Directory Domain Services (AD DS) forest. Each Active Directory site is connected by using manually configured site links and automatically generated connections.You need to minimize the latency for changes to Active Directory.What should you do?
A. or each site links, modify the site link costs
B. reate a site link bridge that contains all the site links
C. or each site link, modify the options attribute
D. or each site link, modify the replication schedule
View answer
Correct Answer: C
Question #59
You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server.You plan to manage VM1 by using a PowerShell runbook.You need to create the runbook.What should you create first?
A. n Azure Automation account
B. n Azure workbook
C. Log Analytics workspace
D. Microsoft Power Automate flow
View answer
Correct Answer: A
Question #60
You have an Azure virtual machine named VM1 that runs Windows Server. You have an Azure subscription that has Microsoft Defender for Cloud enabled.You need to ensure that you can use the Azure Policy guest configuration feature to manage VM1. What should you do?
A. dd the PowerShell Desired State Configuration (DSC) extension to VM1
B. onfigure VM1 to use a user-assigned managed identity
C. onfigure VM1 to use a system-assigned managed identity
D. dd the Custom Script Extension to VM1
View answer
Correct Answer: C
Question #61
Your network contains a single-domain Active Directory Domain Services (AD DS) forest named conto.com. The forest contains the servers shown in the following exhibit table. You plan to install a line-of-business (LOB) application on Server1. The application will install a custom windows services. A new corporate security policy states that all custom Windows services must run under the context of a group managed service account (gMSA). You deploy a root key. You need to create, configure, and install the gM
A. ee Explanation section for answer
View answer
Correct Answer: BE
Question #62
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains the domain controllers shown in the following table.You need to ensure that if an attacker compromises the computer account of RODC1, the attacker cannot view the Employee-Number AD DS attribute.Which partition should you modify?
A. onfiguration
B. lobal catalog
C. omain
D. chema
View answer
Correct Answer: D
Question #63
You have an on premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. The domain contains two servers named Server1 and Server2.A user named Admin1 is a member of the local Administrators group on Server1 and Server2.You plan to manage Server1 and Server2 by using Azure Arc. Azure Arc objects will be added to a resource group named RG1.You need to ensure that Admin1 can configure Server1 and Server2 to be managed by using Azure Arc. What should
A. rom the Azure portal, generate a new onboarding script
B. ssign Admin1 the Azure Connected Machine Onboarding role for RG1
C. ybrid Azure AD join Server1 and Server2
D. reate an Azure cloud-only account for Admin1
View answer
Correct Answer: B

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number: