ExamGecko
Home Home / Microsoft / AZ-800

Microsoft AZ-800 Practice Test - Questions Answers, Page 6

Question list
Search
Search

List of questions

Search

Related questions











Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.

You open a new branch office that contains only client computers.

You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1. Solution: You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to Site1. Does this meet the goal?

A.
Yes
A.
Yes
Answers
B.
No
B.
No
Answers
Suggested answer: B

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.

You open a new branch office that contains only client computers.

You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1. Solution: You create a new subnet object that is associated to Site1.

Does this meet the goal?

A.
Yes
A.
Yes
Answers
B.
No
B.
No
Answers
Suggested answer: B

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.

You need to identify which server is the PDC emulator for the domain.

Solution: From a command prompt, you run netdom.exe query fsmo.

Does this meet the goal?

A.
Yes
A.
Yes
Answers
B.
No
B.
No
Answers
Suggested answer: A

Explanation:

Reference:

https://activedirectorypro.com/how-to-check-fsmo-roles/

Your network contains an Active Directory Domain Services (AD DS) domain named conioso.com.

You need to identify which server is the PDC emulator for the domain.

Solution: from Active Directory Users and Computers, you right-click contoso.com in the console tree, and then select Operations Master Does this meet the goal?

A.
Yes
A.
Yes
Answers
B.
No
B.
No
Answers
Suggested answer: A

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.

You need to identify which server is the PDC emulator for the domain.

Solution: From Active Directory Sites and Services, you right-click Default-First-Site-Name in the console tree, and then select Properties. Does this meet the goal?

A.
Yes
A.
Yes
Answers
B.
No
B.
No
Answers
Suggested answer: B

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.

You need to identify which server is the PDC emulator for the domain.

Solution: From Active Directory Domains and Trusts, you right-click Active Directory Domains and Trusts in the console tree, and then select Operations Master. Does this meet the goal?

A.
Yes
A.
Yes
Answers
B.
No
B.
No
Answers
Suggested answer: B

You have an on premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. You plan to implement self-service password reset (SSPR) in Azure AD.

You need to ensure that users that reset their passwords by using SSPR can use the new password resources in the AD DS domain. What should you do?

A.
Deploy the Azure AD Password Protection proxy service to the on premises network.
A.
Deploy the Azure AD Password Protection proxy service to the on premises network.
Answers
B.
Run the Microsoft Azure Active Directory Connect wizard and select Password writeback.
B.
Run the Microsoft Azure Active Directory Connect wizard and select Password writeback.
Answers
C.
Grant the Change password permission for the domain to the Azure AD Connect service account.
C.
Grant the Change password permission for the domain to the Azure AD Connect service account.
Answers
D.
Grant the impersonate a client after authentication user right to the Azure AD Connect service account.
D.
Grant the impersonate a client after authentication user right to the Azure AD Connect service account.
Answers
Suggested answer: B

Explanation:

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-ssprwriteback

You have an Azure Active Directory Domain Services (Azure AD DS) domain named contoso.com.

You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The solution must use the principle of least privilege. To which group should you add the administrator?

A.
AAD DC Administrators
A.
AAD DC Administrators
Answers
B.
Domain Admins
B.
Domain Admins
Answers
C.
Schema Admins
C.
Schema Admins
Answers
D.
Enterprise Admins
D.
Enterprise Admins
Answers
E.
Group Policy Creator Owners
E.
Group Policy Creator Owners
Answers
Suggested answer: B

Explanation:

Only the Domain Admins group and the Enterprise Admins group can fully manage GPOs. Members of the Group Policy Creator Owners group can create new GPOs but they can't link the GPOs to sites, the domain or OUs and they cannot manage existing GPOs.

Your network contains an Active Directory Domain Services (AD DS) domain.

You have a Group Policy Object (GPO) named GPO1 that contains Group Policy preferences.

You plan to link GPO1 to the domain.

You need to ensure that the preference in GPO1 apply only to domain member servers and NOT to domain controllers or client computers. All the other Group Policy settings in GPO1 must apply to all the computers. The solution must minimize administrative effort.

Which type of item level targeting should you use?

A.
Domain
A.
Domain
Answers
B.
Operating System
B.
Operating System
Answers
C.
Security Group
C.
Security Group
Answers
D.
Environment Variable
D.
Environment Variable
Answers
Suggested answer: B

Explanation:

Reference:

https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn789189(v=ws.11)#operating-system-targeting

Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The root domain contains the domain controllers shown in the following table.

A failure of which domain controller will prevent you from creating application partitions?

A.
DC1
A.
DC1
Answers
B.
DC2
B.
DC2
Answers
C.
DC3
C.
DC3
Answers
D.
DC4
D.
DC4
Answers
E.
DC5
E.
DC5
Answers
Suggested answer: A

Explanation:

Reference:

https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/fsmo-roles

Total 229 questions
Go to page: of 23