Certification Provider: Microsoft
Exam Name: Administering Windows Server Hybrid Core Infrastructure
Exam Code: AZ-800
Official Exam Time: 120 mins
Number of questions in the Official Exam: 40-60 Q&As
Latest update time in our database: September 26,2023
AZ-800 Official Exam Topics:
  • Topic1 : Configure and manage AD DS replication
  • Topic2 : Manage users and groups in multi-domain and multi-forest scenarios / Join Windows Servers to AD DS, Azure AD DS, and Microsoft Azure Active Directory (Azure AD), part of Microsoft Entra
  • Topic3 : Implement Azure AD Connect cloud sync / Implement Group Policy in AD DS
  • Topic4 : Implement Group Policy Preferences in AD DS / Integrate Windows Servers with Log Analytics
  • Topic5 : Manage IaaS VMs in Azure that run Windows Server / Manage VM using PowerShell Remoting, PowerShell Direct and HVC.exe
  • Topic6 : Configure nested virtualization / Configure VM Memory
  • Topic7 : Configure Integration Services / Manage VM Checkpoints
  • Topic8 : Configure Hyper-V Network Adapter / Create Windows Server Container Images
  • Topic9 : Manage Windows Server Container Images / Configure Container Networking
  • Topic10 : Implement on-premises and hybrid name resolution / Implement Site to Site VPN
  • Topic11 : Configure and manage Azure File Sync / Configure Windows Server file share access
  • Topic12 : Configure BranchCache / Implement and configure Distributed File System (DFS)
  • Topic13 : Configure and manage Storage Spaces /

What should you do?

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains a DNS server named Server1. Server1 hosts a DNS zone named fabrikam.com that was signed by DNSSEC.

You need to ensure that all the member servers in the domain perform DNSSEC validation for the fabrikam.com namespace.

What should you do?
A . On Served, run the Add-DnsServerTrustAnchor cmdlet.
B . On each member server, run the Add-DnsServerTrustAnchor cmdlet.
C . From a Group Policy Object (GPO). add a rule to the Name Resolution Policy Table (NRPT).
D . From a Group Policy Object (GPO). modify the Network List Manager policies.

Answer: C

Which resources should you create in the subscription, and what should you install on Server1?

HOTSPOT

You have an on-premises server named Server1 that runs Windows Server and has internet connectivity.

You have an Azure subscription.

You need to monitor Server1 by using Azure Monitor.

Which resources should you create in the subscription, and what should you install on Server1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Table

Description automatically generated with medium confidence

What should you configure?

HOTSPOT

You need to configure network communication between the Seattle and New York offices.

The solution must meet the networking requirements.

What should you configure? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Table

Description automatically generated with medium confidence

Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com. The domain contains a file server named Server1 and three users named User1, User2, and User3

HOTSPOT

Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com. The domain contains a file server named Server1 and three users named User1, User2, and User3.

Server1 contains a shared folder named Share1 that has the following configurations:

The share permissions for Share1 are configured as shown in the Share Permissions exhibit.

Share1 contains a file named File1.bxt. The advanced security settings for File1.txt are configured as shown in the File Permissions exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Graphical user interface, text, application, email

Description automatically generated

What should you do?

You need to meet the technical requirements for User1. The solution must use the principle of least privilege.

What should you do?
A . Add Usersl to the Server Operators group in contoso.com.
B . Create a delegation on contoso.com.
C . Add Usersl to the Account Operators group in contoso.com.
D . Create a delegation on 0U3.

Answer: D

Explanation:

Reference: https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/delegating-administration-of-account-ous-and-resource-ous

Which type of network should you create?

You have a server named Server1 that hosts Windows containers. You plan to deploy an application that will have multiple containers. Each container will be You need to create a Docker network that supports the deployment of the application .

Which type of network should you create?
A . transparent
B . I2bridge
C . NAT
D . I2tunnel

Answer: B

Explanation:

Reference: https://docs.microsoft.com/en-us/virtualization/windowscontainers/container-networking/network-drivers-topologies

What should you use?

You have an on-premises server named Server1 that runs Windows Server. You have an Azure virtual network that contains an Azure virtual network gateway. You need to connect only Server1 to the Azure virtual network.

What should you use?
A . Azure Network Adapter
B . a Site-to-SiteVPN
C . an ExpressRoute circuit
D . Azure Extended Network

Answer: A