AZ-800: Administering Windows Server Hybrid Core InfrastructureDemo
By Microsoft · Browse Mode
//
AZ-800: Administering Windows Server Hybrid Core I… Practice Exam
QuestionQ1
Implementación y administración de Active Directory Domain Services (AD DS) en entornos locales y en la nube
Save question
Your network has an on-premises Active Directory Domain Services (AD DS) domain. The domain includes a user named User1 and the servers shown in the following table.
User1 belongs to the Protected Users security group.
User1 performs these actions:
From Server1, establishes a remote PowerShell session to Server2.
From the PowerShell session on Server2, tries to access a resource on Backup1.
The attempt to access the resource on Backup1 is denied.
You need to ensure that User1 can access the resources on Backup1 by using the PowerShell session on Server2. The solution must adhere to the principle of least privilege and minimize administrative effort.
What should you configure?
AKerberos delegation (unconstrained)
BCredSSP
CPSSessionConfiguration by using RunAs
Dresource-based Kerberos constrained delegation
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Implementación y administración de Active Directory Domain Services (AD DS) en entornos locales y en la nube
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Implementación y administración de Active Directory Domain Services (AD DS) en entornos locales y en la nube
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Administración de cargas de trabajo y servidores de Windows en un entorno híbrido
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Administración de máquinas virtuales y contenedores
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
Implementación y administración de Active Directory Domain Services (AD DS) en entornos locales y en la nubeAdministración de cargas de trabajo y servidores de Windows en un entorno híbridoAdministración de máquinas virtuales y contenedoresImplementación y administración de una infraestructura de red local e híbridaAdministración de servicios de archivos y almacenamiento
An Active Directory Domain Services (AD DS) domain contains a member server named Server1 that runs Windows Server.
You need to ensure that you can manage the domain password policies from Server1.
Which command should you run first on Server1?
AInstall-WindowsFeature RSAT-AD-Tools
BInstall-WindowsFeature RSAT-ADRMS
CInstall-WindowsFeature GPMC
DInstall-WindowsFeature RSAT-AD-PowerShell
Your on-premises network has a single-domain Active Directory Domain Services (AD DS) forest and an Azure AD tenant named contoso.com. The AD DS forest synchronizes with the Azure AD tenant by using Azure AD Connect.
You must ensure that forest users with a custom attribute of NoSync are excluded from synchronization.
How should you configure the Azure AD Connect cloudFiltered attribute, and which tool should you use?
Select
Attribute:
Tool:
You have an Azure subscription named Sub1 linked to a Microsoft Entra tenant named contoso.com. Contoso.com includes the users in the following table.
You deploy a virtual machine with these configurations:
Name: VM1
Resource group: RG1
Operating system: Windows Server
Login with Microsoft Entra ID: Enabled
The Azure role assignments are shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Yes or No
Yes
No
Statements
User1 can sign in to VM1 by using their Microsoft Entra credentials.
User2 can sign in to VM1 by using their Microsoft Entra credentials.
User3 can sign in to VM1 by using their Microsoft Entra credentials.
You have a Windows Server 2022 container host named Host1 with the Subsystem for Linux installed and the container images shown in the following table.
You need to deploy the images to Host1 while maximizing container isolation.
Which images can run using process isolation, and which can run using Hyper-V isolation?
Select
Process isolation:
Hyper-V isolation:
QuestionQ6
Administración de cargas de trabajo y servidores de Windows en un entorno híbrido
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Administración de servicios de archivos y almacenamiento
QuestionQ8
Implementación y administración de Active Directory Domain Services (AD DS) en entornos locales y en la nube
QuestionQ9
Implementación y administración de Active Directory Domain Services (AD DS) en entornos locales y en la nube
QuestionQ10
Implementación y administración de una infraestructura de red local e híbrida
QuestionQ11
Administración de servicios de archivos y almacenamiento
QuestionQ12
Administración de cargas de trabajo y servidores de Windows en un entorno híbrido
QuestionQ13
Implementación y administración de Active Directory Domain Services (AD DS) en entornos locales y en la nube
QuestionQ14
Implementación y administración de Active Directory Domain Services (AD DS) en entornos locales y en la nube
QuestionQ15
Implementación y administración de Active Directory Domain Services (AD DS) en entornos locales y en la nube
QuestionQ16
Implementación y administración de una infraestructura de red local e híbrida
QuestionQ17
Administración de servicios de archivos y almacenamiento
QuestionQ19
Administración de cargas de trabajo y servidores de Windows en un entorno híbrido
QuestionQ20
Implementación y administración de Active Directory Domain Services (AD DS) en entornos locales y en la nube
QuestionQ21
Administración de máquinas virtuales y contenedores
QuestionQ24
Implementación y administración de Active Directory Domain Services (AD DS) en entornos locales y en la nube
QuestionQ25
Implementación y administración de Active Directory Domain Services (AD DS) en entornos locales y en la nube
QuestionQ26
Administración de servicios de archivos y almacenamiento
QuestionQ27
Implementación y administración de Active Directory Domain Services (AD DS) en entornos locales y en la nube
QuestionQ29
Administración de servicios de archivos y almacenamiento
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
Overview
Your network includes an Active Directory Domain Services (AD DS) domain named contoso.com.
You implement a central store.
You create a new Group Policy Object (GPO) named GPO1.
When you try to edit GPO1, you see the settings shown in the exhibit. (Click the Exhibit tab.)
You need to make sure that all settings are available.
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
Your network includes an Active Directory Domain Services (AD DS) domain named contoso.com.
You implement a central store.
You create a new Group Policy Object (GPO) named GPO1.
When you try to edit GPO1, you see the settings shown in the exhibit. (Click the Exhibit tab.)
You need to make sure that all settings are available.
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
Overview
Your network includes an Active Directory Domain Services (AD DS) domain named contoso.com.
You implement a central store.
You create a new Group Policy Object (GPO) named GPO1.
When you try to edit GPO1, you see the settings shown in the exhibit. (Click the Exhibit tab.)
You need to make sure that all settings are available.
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Your on-premises network includes an Active Directory domain named contoso.com and 500 servers running Windows Server. All servers are Azure Arc-enabled and joined to contoso.com.
You need to implement PowerShell Desired State Configuration (DSC) on every server while minimizing administrative effort.
Where should the DSC scripts be stored, and what should be used to apply DSC to the servers?
Select
Store in:
Use:
You have a disaggregated cluster deployment containing a scale-out file server (SOFS) cluster that runs Windows Server and a compute cluster with the Hyper-V role enabled.
You need to implement Storage Quality of Service (QoS) so that bandwidth use between the SOFS cluster and the Hyper-V cluster can be controlled.
Which cmdlet should be run on each cluster? Each cmdlet can be used once, more than once, or not at all.
Drag & Drop
New-StorageQosPolicy
Set-VMHardDiskDrive
Set-VMSan
SOFS:
Hyper-V:
Your network includes an Active Directory Domain Services (AD DS) forest. The forest contains the sites and site links shown in the following exhibit.
The sites include the bridgehead domain controllers listed in the following table.
The IP intersite transport container is configured as shown in the following exhibit.
For each statement, select Yes when it is true. Otherwise, select No.
Yes or No
Yes
No
Statements
DC1 can replicate directly to DC3.
DC1 will load balance replication traffic to DC4 via SiteLink3 and SiteLink4.
To ensure that replication between DC4 and DC2 is routed via DC1, the configuration of the IP intersite transport container must be modified.
Which implementation should be used to deploy DC3?
AAzure Active Directory Domain Services (Azure AD DS)
Ban Azure virtual machine
Can Azure AD administrative unit
DAzure AD Application Proxy
You have servers running Windows Server 2022, as shown in the following table.
Server2 contains a .NET application named App1.
You need to establish a WebSocket connection from App1 to the SQL Server instance on Server1. The solution must meet the following requirements:
Minimize the number of network ports that must be opened on the on-premises network firewall.
Minimize administrative effort.
What should you create first?
Aan Azure Relay namespace
Ban Azure VPN gateway
Ca WFC relay connection
Da hybrid connection
You have an on-premises server running Windows Server that contains the folders shown in the following table.
You have an Azure subscription.
You plan to deploy Azure File Sync.
Which folders can be added as Azure File Sync server endpoints?
AFolder1 and Folder2 only
BFolder1, Folder2, and Folder3
CFolder1 only
DFolder2 and Folder3 only
EFolder3 only
FFolder2 only
You have an Azure subscription named sub1 and 500 on-premises virtual machines running Windows Server.
You plan to onboard the on-premises virtual machines to Azure Arc by running the Azure Arc deployment script.
You need to create an identity for the script to authenticate access to sub1. The solution must follow the principle of least privilege.
How should you complete the command?
Select
-DisplayName 'Arc-for-servers' -Role
Solution: Modify the properties of GPO1.
Does this achieve the goal?
AYes
BNo
Solution: Copy the contents of the C:\Windows\PolicyDefinitions folder to the Central Store.
Does this achieve the goal?
AYes
BNo
Solution: Delete the \\contoso.com\SYSVOL\contoso.com\Policies\PolicyDefinitions folder.
Does this accomplish the goal?
AYes
BNo
You have an on-premises DNS server named Server1 that runs Windows Server. Server1 hosts a DNS zone named fabnkam.com.
Your Azure subscription contains the resources shown in the following table.
You need to design a solution that automatically resolves the names of any PaaS resources for which you configure private endpoints in Vnet1.
How should you configure name resolution?
Select
On Vnet1
On the on-premises network
You have three on-premises Windows Server computers named SVR1, SVR2, and SVR3. SRV1 contains a direct-attached storage (DAS) array.
You plan to deploy a failover cluster named Cluster1 using SVR2 and SVR3.
You need to make sure that the DAS array on SRV1 can serve as shared storage for Cluster1. The solution must provide Cluster1 with block-level access to the storage.
What should you do first on SRV1?
ARun the start-service -name msiscsi cmdlet.
BInstall the iSCSI Target Server role service.
CInstall the File Server role service.
DRun the Enable-ClusterStorageSpacesDirect cmdlet.
You have 100 on-premises servers running Windows Server that are Azure Arc-enabled and an Azure subscription. You deploy a Custom Script Extension to the servers by using the following ARM template.
You regenerate the storage account key and update the template.
You must meet these requirements:
Ensure that the script runs again on the servers.
Minimize the risk that the key is compromised on the servers.
What should you do?
Select
To ensure that the script runs again:
To minimize the risk of a compromised key:
Your on-premises network includes an Active Directory domain named contoso.com. You have an Azure AD tenant.
You plan to synchronize contoso.com with the Azure AD tenant by using Azure AD Connect cloud sync.
You need to create an account for Azure AD Connect cloud sync to use.
Which type of account should you create?
Asystem-assigned managed identity
Bgroup managed service account (gMSA)
Cuser
DInetOrgPerson
You have a server named Server1 with the Hyper-V server role installed. Server1 hosts the virtual machines shown in the following exhibit.
Use the drop-down menus to complete each statement based on the information shown.
Select
can have production checkpoints.
can be hibernated.
Your network has one Active Directory Domain Services (AD DS) forest named contoso.com, containing a single Active Directory site.
You plan to deploy a read-only domain controller (RODC) to a new datacenter on Server1. User1 belongs to the local Administrators group on Server1.
Recommend a deployment plan that meets these requirements:
Allows User1 to perform the RODC installation on Server1
Lets you control the AD DS replication schedule to Server1
Places Server1 in a new site named RemoteSite1
Applies the principle of least privilege
Which three actions should be performed, in sequence?
Drag & Drop
Instruct User1 to run the Active Directory Domain Services installation Wizard on Server1.
Create a site and a subnet.
Create a site link.
Pre-create an RODC account.
Add User1 to the Contoso\Administrators group.
HOTSPOT
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com.
A partner company, ADatum Corporation, has an AD DS forest named adatum.com. You configure the trust relationship shown in the following exhibit.
The forests contain the groups shown in the following table.
The ADatum domains contain the member servers shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Yes or No
Yes
No
Statements
Group2 can be assigned permissions for the resources on Server2.
Group3 can be added as a member of Group1.
Group4 can be assigned permissions for the resources on Server1.
Your company has offices in Boston and Montreal connected by a 10-Mbps WAN link that is frequently saturated.
The Boston office contains:
An Active Directory Domain Services (AD DS) domain controller named DC1
A server named Server1 that runs Windows Server and has the File Server role installed
The Montreal office has 20 Windows 10 client computers and no servers.
The company plans to deploy a new line-of-business (LOB) application to every client computer. Its installation source files are located in \\Server1\Apps.
You need to make the installation source files available to the Montreal client computers while using the least possible WAN bandwidth. What should you do?
Select
On Server1
On the client computers
You have an on-premises Active Directory Domain Services (AD DS) domain that synchronizes with an Azure Active Directory (Azure AD) tenant. The domain includes two servers named Server1 and Server2.
A user named Admin1 belongs to the local Administrators group on Server1 and Server2.
You plan to manage Server1 and Server2 by using Azure Arc. Azure Arc objects will be added to a resource group named RG1.
You need to ensure that Admin1 can configure Server1 and Server2 to be managed by using Azure Arc.
What should you do first?
AFrom the Azure portal, generate a new onboarding script.
BAssign Admin1 the Azure Connected Machine Onboarding role for RG1.
CHybrid Azure AD join Server1 and Server2.
DCreate an Azure cloud-only account for Admin1.
You need to synchronize files from an on-premises server named Server1 to Azure by using Azure File Sync.
A cloud tiering policy is configured for 30 percent free space and 70 days. Volume E on Server1 is 500 GB. One year ago, you configured E:\Data on Server1 to synchronize by using Azure File Sync. The files visible in E:\Data are shown in the following table.
Community Discussion