Pre-Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Microsoft AZ-800 Practice Exam with Questions & Answers | Set: 4

Questions 31

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains the servers shown in the following table.

AZ-800 Question 31

On Server1, you create a DNS zone named Zone1.com as shown in the following exhibit.

AZ-800 Question 31

To which DNS servers is Zone1.com replicated?

Options:
A.

Server2 only

B.

Server2 and Server3 only

C.

Setver2 and Sen/er4 only

D.

Server2. Server3, and Server4 only

E.

Server2, Server3, Server4, and Server5

Microsoft AZ-800 Premium Access
Questions 32

You have a server named Server1 that runs Windows Server.

You plan to host applications in Windows containers.

You need to configure Server1 to run containers. What should you install?

Options:
A.

Windows Admin Center

B.

the Windows Subsystem for Linux

C.

Doctor

D.

Hyper-V

Questions 33

You have a Windows Server container host named Server1.

You start the containers on Server1 as shown in the following table.

AZ-800 Question 33

You need to validate the status of ProcessA and ProcessC.

Where can you verify that ProcessA and ProcessC are in a running state? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

AZ-800 Question 33

Options:
Questions 34

You have an on premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant.

Yo u plan to implement self-service password reset (SSPR) in Azure AD.

You need to ensure that users that reset their passwords by using SSPR can use the new password resources in the AD DS domain.

What should you do?

Options:
A.

Deploy the Azure AD Password Protec tion proxy service to the on premises network.

B.

Run the Microsoft Azure Active Directory Connect wizard and select Password writeback.

C.

Grant the Change password permission for the domain to the Azure AD Connect service account.

D.

Grant the impersonat e a client after authentication user right to the Azure AD Connect service account.

Questions 35

Your on-premises network contains an Active Directory domain named contoso.com. You have an Azure AD tenant. You plan to sync contoso.com with the Azure AD tenant by using Azure AD Connect cloud sync. You need to create an account that will be used by Azure AD Connect cloud sync. Which type of account should you create?

Options:
A.

system-assigned managed identity

B.

group managed service account (gMSA)

C.

user

D.

InetOrgPerson

Questions 36

You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD ) tenant

You have several Windows 10 devices that are Azure AD hybrid-joined.

You need to ensure that when users sign in to the devices, they can use Windows Hello for Business.

Which optional feature should you select in Azure AD Connect?

Options:
A.

Device writeb ack

B.

Group writeback

C.

Password writeback

D.

Directory extension attribute sync

E.

Azure AD app and attribute filtering

Questions 37

You have an on-premises Active Directory Domain Servic es (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant Group writeback is enabled in Azure AD Connect.

The AD DS domain contains a server named Server1 Server 1 contains a shared folder named share1.

You have an Azure Storage account named storage2 that uses Azure AD-based access control. The storage2 account contains a share named shared

You need to create a security group that meets the following requirements:

• Can contain users from the AD DS domain

• Can be used to authorize user access to share 1 and share2

What should you do?

Options:
A.

in the AD DS domain, create a universal security group

B.

in the Azure AD tenant create a security group that has assigned membership

C.

in the Azure AD Tenant create a security group that has dynamic me mbership.

D.

in the Azure AD tenant create a Microsoft 365 group

Questions 38

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains the servers shown in the following table.

AZ-800 Question 38

You need to ensure that from Server1, you can use Windows Admin Center to manage the DHCP Server role on Server2. What should you do first?

Options:
A.

Install the DHCP Server Tools feature on Server1.

B.

Install a Windows Admin Center extension.

C.

Install the DHCP Server Tools feature on Server2.

D.

Modify the PowerShell remoting settings for Se rver2.

Questions 39

You have an on-premises server named Server1 that runs Windows Server. Server1 contains an app named App1 and a firewall named Firewall1.

You have an Azure subscription.

Internal users connect to App1 by using WebSockets.

You need to make App1 available to users on the internet. The solution must minimize the number of inbound ports open on Firewall 1.

What should you include in the solution?

Options:
A.

Microsoft Application Request Routing (ARR) Version 2

B.

Web Application Proxy

C.

Azure Relay

D.

Azure Application Gateway

Questions 40

Your network contains two Active Directory forests and a domain trust as shown in the following exhibit.

AZ-800 Question 40

The domain trust has the following configurations:

• Name: adatum.com

• Type: External

• Dire ction: One-way. outgoing

• Outgoing trust authentication level: Domain-wide authentication

AZ-800 Question 40

The forests contain the network shares shown in the following table.

AZ-800 Question 40

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

AZ-800 Question 40

Options:
Exam Code: AZ-800
Certification Provider: Microsoft
Exam Name: Administering Windows Server Hybrid Core Infrastructure
Last Update: May 22, 2026
Questions: 266