ExamGecko
Home Home / Microsoft / AZ-800

Microsoft AZ-800 Practice Test - Questions Answers, Page 12

Question list
Search
Search

List of questions

Search

Related questions











HOTSPOT

You have a Group Policy Object (GPO) named GPO1 that contains user settings only.

You plan to apply GPO1 to a global security group named Group1.

You link GP01 to the domain, and you remove all the permissions granted to the Authenticated Users group. You need to configure permissions for GP01 to meet the following requirements.

• GPO1 must apply only to the users in Group 1.

• The solution must use the principle of least privilege


Question 111
Correct answer: Question 111

HOTSPOT

You have a server named Server1 that runs Windows Server Server1 has a just-a-bunch-of-disks

(JBOD) enclosure attached.

You plan to create a storage pool on Server1 and a virtual disk that will use a mirror layout.

You are considering whether to use a two-way or a three-way mirror layout.

What is the minimum number of disks required for each type of minor layout? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.


Question 112
Correct answer: Question 112

HOTSPOT

Your company has offices in Boston and Montreal. The offices are connected by using a 10-Mbps WAN link that is often saturated The office in Boston contains the following:

• An Active Directory Domain Services (AD DS) domain controller named DC1.

• A server named Server1 that runs Windows Server and has the File Server role installed The office in Montreal contains 20 client computers that run Windows 10 Montreal does NOT have any servers. The company plans to deploy a new line of business (LOB) application to all the client computers. The installation source files for the application are in \\Server\Apps.


Question 113
Correct answer: Question 113

Your network contains an Active Domain Services (AD DS) forest. The forest contains three domains.

Each domain contains 10 domain controllers.

You plan to store a DNS zone in a custom active Directory partition.

You need to create the Active Directory partition for the zone. The partition replicate to only four of the domain controllers. What should you use?

A.
DNS Manager
A.
DNS Manager
Answers
B.
New-ADObjett
B.
New-ADObjett
Answers
C.
dnscnd.exe
C.
dnscnd.exe
Answers
D.
Windows Admin Center
D.
Windows Admin Center
Answers
Suggested answer: D

Your network contains a Active Directory Domain Service (AD DS) forest named contoso.com. The forest root domain contains a server named server1. contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first?

A.
Change the trust to a one-way external trust.
A.
Change the trust to a one-way external trust.
Answers
B.
Add fabrikam\Group1 to the local Users group on server1.contoso.com.
B.
Add fabrikam\Group1 to the local Users group on server1.contoso.com.
Answers
C.
Enable SID filtering for the trust.
C.
Enable SID filtering for the trust.
Answers
D.
Enable Selective authentication for the trust.
D.
Enable Selective authentication for the trust.
Answers
Suggested answer: C

Your network contains a single-domain Active Directory Domain Services (AD DS) forest named conto.com. The forest contains the servers shown in the following exhibit table.

You plan to install a line-of-business (LOB) application on Server1. The application will install a custom windows services. A new corporate security policy states that all custom Windows services must run under the context of a group managed service account (gMSA). You deploy a root key. You need to create, configure, and install the gMSA that will be used by the new application.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

A.
On Server1, run the install-ADServiceAccount cmdlet.
A.
On Server1, run the install-ADServiceAccount cmdlet.
Answers
B.
On DC1, run the New-ADServiceAccount cmdlet.
B.
On DC1, run the New-ADServiceAccount cmdlet.
Answers
C.
On DC1, run the Set_ADComputer cmdlet.
C.
On DC1, run the Set_ADComputer cmdlet.
Answers
D.
ON DC1, run the Install-ADServiceAccount cmdlet.
D.
ON DC1, run the Install-ADServiceAccount cmdlet.
Answers
E.
On Server1, run the Get-ADServiceAccount cmdlet.
E.
On Server1, run the Get-ADServiceAccount cmdlet.
Answers
Suggested answer: A, B

You have an Azure virtual machine named Server1 that runs a network management application.

Server1 has the following network configuration.

* Network interface.Nic1

* IP address 10.1.1.1/24

* Connected to: Vnet1/Subnet1

You need connect Server1 to an additional subnet named Vnet1/Subnet2.

What should you do?

A.
Create a private endpoint on Subnet2
A.
Create a private endpoint on Subnet2
Answers
B.
Add a network interface to server1.
B.
Add a network interface to server1.
Answers
C.
Modify the IP configurations of Nic1.
C.
Modify the IP configurations of Nic1.
Answers
D.
Add an IP configuration to Nic1.
D.
Add an IP configuration to Nic1.
Answers
Suggested answer: B

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three domains. Each domain contains 10 domain controllers. You plan to store a DNS zone in a custom Active Directory partition.

You need to create the Active Directory partition for the zone. The partition must replicate to only four of the domain controllers. What should you use?

A.
ntdsutil.exe
A.
ntdsutil.exe
Answers
B.
Active Directory Sites and Services
B.
Active Directory Sites and Services
Answers
C.
New-ADobject
C.
New-ADobject
Answers
D.
Active Directory Administrative Center
D.
Active Directory Administrative Center
Answers
Suggested answer: A

You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant Group writeback is enabled in Azure AD Connect. The AD DS domain contains a server named Server1 Server 1 contains a shared folder named share1.

You have an Azure Storage account named storage2 that uses Azure AD-based access control. The storage2 account contains a share named shared You need to create a security group that meets the following requirements:

• Can contain users from the AD DS domain

• Can be used to authorize user access to share 1 and share2

What should you do?

A.
in the AD DS domain, create a universal security group
A.
in the AD DS domain, create a universal security group
Answers
B.
in the Azure AD tenant create a security group that has assigned membership
B.
in the Azure AD tenant create a security group that has assigned membership
Answers
C.
in the Azure AD Tenant create a security group that has dynamic membership.
C.
in the Azure AD Tenant create a security group that has dynamic membership.
Answers
D.
in the Azure AD tenant create a Microsoft 365 group
D.
in the Azure AD tenant create a Microsoft 365 group
Answers
Suggested answer: B

You have a server named Server1 that runs Windows Server.

You plan to host applications in Windows containers.

You need to configure Server1 to run containers. What should you install?

A.
Windows Admin Center
A.
Windows Admin Center
Answers
B.
the Windows Subsystem for Linux
B.
the Windows Subsystem for Linux
Answers
C.
Doctor
C.
Doctor
Answers
D.
Hyper-V
D.
Hyper-V
Answers
Suggested answer: C
Total 229 questions
Go to page: of 23