ExamMini
πŸ”

AZ-800 β€” all questions

124 practice questions with answers and explanations.

Topic 1 Β· Question 1

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. You need to identify which server is the PDC emulator for the domain. Solution: From Active Directory Domains and Trusts, you right-click Active Directory Domains and Trusts in the console tree, and then select Operations Master. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 1 Β· Question 2

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. You need to identify which server is the PDC emulator for the domain. Solution: From a command prompt, you run netdom.exe query fsmo. Does this meet the goal?

  • AYes (correct answer)
  • BNo
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Yes.

Topic 1 Β· Question 3

You have an on premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. You plan to implement self-service password reset (SSPR) in Azure AD. You need to ensure that users that reset their passwords by using SSPR can use the new password resources in the AD DS domain. What should you do?

  • ADeploy the Azure AD Password Protection proxy service to the on premises network.
  • BRun the Microsoft Azure Active Directory Connect wizard and select Password writeback. (correct answer)
  • CGrant the Change password permission for the domain to the Azure AD Connect service account.
  • DGrant the impersonate a client after authentication user right to the Azure AD Connect service account.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Run the Microsoft Azure Active Directory Connect wizard and select Password writeback.

Topic 1 Β· Question 7

Your network contains an Active Directory Domain Services (AD DS) domain. The network also contains 20 domain controllers, 100 member servers, and 100 client computers. You have a Group Policy Object (GPO) named GPO1 that contains Group Policy preferences. You plan to link GPO1 to the domain. You need to ensure that the preference in GPO1 apply only to domain member servers and NOT to domain controllers or client computers. All the other Group Policy settings in GPO1 must apply to all the computers. The solution must minimize administrative effort. Which type of item level targeting should you use?

  • ADomain
  • BOperating System (correct answer)
  • CSecurity Group
  • DEnvironment Variable
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Operating System.

Topic 1 Β· Question 9

Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The root domain contains the domain controllers shown in the following table. A failure of which domain controller will prevent you from creating application partitions?

  • ADC1 (correct answer)
  • BDC2
  • CDC3
  • DDC4
  • EDC5
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: DC1.

Topic 1 Β· Question 10

Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the objects shown in the following table. You plan to sync contoso.com with an Azure Active Directory (Azure AD) tenant by using Azure AD Connect. You need to ensure that all the objects can be used in Conditional Access policies. What should you do?

  • ASelect the Configure Hybrid Azure AD join option. (correct answer)
  • BChange the scope of Group1 and Group2 to Global.
  • CClear the Configure device writeback option.
  • DChange the scope of Group2 to Universal.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Select the Configure Hybrid Azure AD join option.

Explanation

Azure Active Directory (Microsoft Entra ID) provides identity, single sign-on, and conditional access.

Topic 1 Β· Question 11

Your network contains a multi-site Active Directory Domain Services (AD DS) forest. Each Active Directory site is connected by using manually configured site links and automatically generated connections. You need to minimize the convergence time for changes to Active Directory. What should you do?

  • AFor each site link, modify the replication schedule.
  • BFor each site links, modify the site link costs.
  • CCreate a site link bridge that contains all the site links.
  • DFor each site link, modify the options attribute. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: For each site link, modify the options attribute.

Topic 1 Β· Question 13

You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. You have several Windows 10 devices that are Azure AD hybrid-joined. You need to ensure that when users sign in to the devices, they can use Windows Hello for Business. Which optional feature should you select in Azure AD Connect?

  • ADevice writeback (correct answer)
  • BGroup writebeack
  • CAzure AD app and attribute filtering
  • DPassword writeback
  • EDirectory extension attribute sync
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Device writeback.

Topic 1 Β· Question 15

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK. You open a new branch office that contains only client computers. You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1. Solution: You create an organization unit (OU) that contains the client computers in the branch office. You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to the new OU. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 1 Β· Question 16

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK. You open a new branch office that contains only client computers. You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1. Solution: You create a new site named Site4 and associate Site4 to DEFAULTSITELINK. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 1 Β· Question 17

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK. You open a new branch office that contains only client computers. You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1. Solution: You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to Site1. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 1 Β· Question 18

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. You need to identify which server is the PDC emulator for the domain. Solution: From Active Directory Sites and Services, you right-click Default-First-Site-Name in the console tree, and then select Properties. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 1 Β· Question 19 Β· Select all that apply

Your network contains a single-domain Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains the servers shown in the following exhibit table. You plan to install a line-of-business (LOB) application on Server1. The application will install a custom Windows service. A new corporate security policy states that all custom Windows services must run under the context of a group managed service account (gMSA). You deploy a root key. You need to create, configure, and install the gMSA that will be used by the new application. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point

  • AOn Server1, run the setspn command.
  • BOn DC1, run the New-ADServiceAccount cmdlet. (correct answer)
  • COn Server1, run the Install-ADServiceAccount cmdlet. (correct answer)
  • DOn Server1, run the Get-ADServiceAccount cmdlet.
  • EOn DC1, run the Set-ADComputer cmdlet.
  • FOn DC1, run the Install-ADServiceAccount cmdlet.
Reveal answer & explanation
Correct answer: B, C

The correct answer is B, C. Option B: On DC1, run the New-ADServiceAccount cmdlet. Option C: On Server1, run the Install-ADServiceAccount cmdlet.

Topic 1 Β· Question 21

Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest root domain contains a server named server1.contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?

  • AAdd fabrikam\Group1 to the local Users group on server1.contoso.com.
  • BEnable SID filtering for the trust.
  • CEnable Selective authentication for the trust. (correct answer)
  • DChange the trust to a one-way external trust.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Enable Selective authentication for the trust.

Topic 1 Β· Question 22

Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com and the servers shown in the following table. Contoso.com contains a user named User1. You add User1 to the built-in Backup Operators group in contoso.com. Which servers can User1 back up?

Exhibit 1 for question 22
  • ADC1 only (correct answer)
  • BServer1 only
  • CDC1 and DC2 only
  • DDC1 and Server1 only
  • EDC1, DC2, Server1, and Server2
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: DC1 only.

Topic 1 Β· Question 29

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three domains. Each domain contains 10 domain controllers. You plan to store a DNS zone in a custom Active Directory partition. You need to create the Active Directory partition for the zone. The partition must replicate to only four of the domain controllers. What should you use?

  • AWindows Admin Center
  • BDNS Manager
  • CActive Directory Sites and Services
  • Dntdsutil.exe (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: ntdsutil.exe.

Topic 1 Β· Question 31

Your network contains an Active Directory domain named contoso.com. The domain contains the computers shown in the following table. On Server3, you create a Group Policy Object (GPO) named GPO1 and link GPO1 to contoso.com. GPO1 includes a shortcut preference named Shortcut1 that has item-level targeting configured as shown in the following exhibit. To which computer will Shortcut1 be applied?

Exhibit 1 for question 31Exhibit 2 for question 31
  • AServer3 only (correct answer)
  • BComputer1 and Server3 only
  • CServer2 and Server3 only
  • DServer1, Server2, and Server3 only
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Server3 only.

Topic 1 Β· Question 32

Your network contains a multi-site Active Directory Domain Services (AD DS) forest. Each Active Directory site is connected by using manually configured site links and automatically generated connections. You need to minimize the latency for changes to Active Directory. What should you do?

  • AFor each site links, modify the site link costs.
  • BCreate a site link bridge that contains all the site links.
  • CFor each site link, modify the options attribute. (correct answer)
  • DFor each site link, modify the replication schedule.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: For each site link, modify the options attribute.

Topic 1 Β· Question 38

Your on-premises network contains an Active Directory domain named contoso.com. You have an Azure AD tenant. You plan to sync contoso.com with the Azure AD tenant by using Azure AD Connect cloud sync. You need to create an account that will be used by Azure AD Connect cloud sync. Which type of account should you create?

  • Asystem-assigned managed identity
  • Bgroup managed service account (gMSA) (correct answer)
  • Cuser
  • DInetOrgPerson
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: group managed service account (gMSA).

Topic 1 Β· Question 39

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains the domain controllers shown in the following table. You need to ensure that if an attacker compromises the computer account of RODC1, the attacker cannot view the Employee-Number AD DS attribute. Which partition should you modify?

Exhibit 1 for question 39
  • Aconfiguration
  • Bglobal catalog
  • Cdomain
  • Dschema (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: schema.

Showing questions 1–20 of 124 Β· Page 1 of 7