we provide Breathing Microsoft AZ-800 download which are the best for clearing AZ-800 test, and to get certified by Microsoft Administering Windows Server Hybrid Core Infrastructure. The AZ-800 Questions & Answers covers all the knowledge points of the real AZ-800 exam. Crack your Microsoft AZ-800 Exam with latest dumps, guaranteed!
Online AZ-800 free questions and answers of New Version:
NEW QUESTION 1
HOTSPOT
You have an onpremises DNS server named Server1 that runs Windows Server. Server 1 hosts a DNS zone named fabrikam.com
You have an Azure subscription that contains the resources shown in the following table.
Solution:

Does this meet the goal?
- A. Yes
- B. Not Mastered
Answer: A
NEW QUESTION 2
DRAG DROP
You deploy a single-domain Active Directory Domain Services (AD DS) forest named contoso.com.
You deploy a server to the domain and configure the server to run a service.
You need to ensure that the service can use a group managed service account (gMSA) to authenticate.
Which three PowerShell cmdlets should you run in sequence? To answer, move the appropriate cmdlets from the list of cmdlets to the answer area and arrange them in the correct order.
Solution:

Does this meet the goal?
- A. Yes
- B. Not Mastered
Answer: A
NEW QUESTION 3
SIMULATION
Task 11
You need to ensure that all DHCP clients that get an IP address from SRV1 will be configured to use DC1 as a DNS server.
Solution:
One possible solution to ensure that all DHCP clients that get an IP address from SRV1 will be configured to use DC1 as a DNS server is to use the DHCP scope options. DHCP scope options are settings that apply to all DHCP clients that obtain an IP address from a specific scope. You can use the DHCP scope options to specify the DNS server IP address, as well as other parameters such as the default gateway, the domain name, and the DNS suffix. Here are the steps to configure the DHCP scope options on SRV1:
✑ On SRV1, open DNS Manager from the Administrative Tools menu or by
typing dnsmgmt.msc in the Run box.
✑ In the left pane, expand your DHCP server and click on IPv4.
✑ In the right pane, right-click on the scope that you want to configure and select Properties.
✑ In the Scope Properties dialog box, click on the DNS tab.
✑ Check the box Enable DNS dynamic updates according to the settings below. This option allows the DHCP server to register and update the DNS records for the DHCP clients.
✑ Select the option Always dynamically update DNS records. This option ensures that the DHCP server updates both the A and PTR records for the DHCP clients, regardless of whether they request or support dynamic updates.
✑ Check the box Discard A and PTR records when lease is deleted. This option

✑ Check the box Dynamically update DNS records for DHCP clients that do not
request updates. This option allows the DHCP server to update the DNS records for the DHCP clients that do not support dynamic updates, such as legacy or non- Windows clients.
✑ In the DNS servers section, click on the Add button to add a new DNS server IP address.
✑ In the Add Server dialog box, enter the IP address of DC1, which is the DNS server that you want to use for the DHCP clients, and click Add.
✑ Click OK to close the Add Server dialog box and return to the Scope Properties dialog box.
✑ Click OK to apply the changes and close the Scope Properties dialog box.
Now, all DHCP clients that get an IP address from SRV1 will be configured to use DC1 as a DNS server. You can verify the DNS configuration by using the ipconfig /all command on a DHCP client computer and checking the DNS Servers entry. You can also check the DNS records for the DHCP clients by using the DNS Manager console on DC1.
Does this meet the goal?
- A. Yes
- B. Not Mastered
Answer: A
NEW QUESTION 4
HOTSPOT
Your network contains a two-domain on-premises Active Directory Domain Services (AD DS) forest named Contoso.com. The forest contains the domain controllers shown in the
following table.
You create an Active Directory site named Site3. Site1, Site2 and Site3 each has a dedicated site link to the Hub site.
In Site3, you install a new server named Server1.
You need to promote Server1 to an ROOC in child.contoso.com by using the install from Media (IFM) option. The solution must minimize network traffic.
What should you do? To answer select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Solution:

Does this meet the goal?
- A. Yes
- B. Not Mastered
Answer: A
NEW QUESTION 5
SIMULATION
Task 8
You need to create an Active Directory Domain Services (AD DS) site named Site2 that is associated to an IP address range of 192.168.2.0 to 192.168.2.255.
Solution:
To create an AD DS site named Site2 that is associated to an IP address range of 192.168.2.0 to 192.168.2.255, you can follow these steps:
✑ On a domain controller or a computer that has the Remote Server Administration
Tools (RSAT) installed, open Active Directory Sites and Services from the Administrative Tools menu or by typing dssite.msc in the Run box.
✑ In the left pane, right-click on Sites and select New Site.
✑ In the New Object - Site dialog box, enter Site2 as the Name of the new site.
Select a site link to associate the new site with, such as DEFAULTIPSITELINK, and click OK. You can also create a new site link if you want to customize the

✑ In the left pane, right-click on Subnets and select New Subnet.
✑ In the New Object - Subnet dialog box, enter 192.168.2.0/24 as the Prefix of the subnet. This notation represents the IP address range of 192.168.2.0 to 192.168.2.255 with a subnet mask of 255.255.255.0. Select Site2 as the Site object to associate the subnet with, and click OK.
✑ Wait for the changes to replicate to other domain controllers. You can verify the
site and subnet creation by checking the Sites and Subnets containers in Active Directory Sites and Services.
Now, you have created an AD DS site named Site2 that is associated to an IP address range of 192.168.2.0 to 192.168.2.255. You can add domain controllers to the new site and configure the site links and site link bridges to optimize the replication topology.
Does this meet the goal?
- A. Yes
- B. Not Mastered
Answer: A
NEW QUESTION 6
You have an on-premises network that is connected to an Azure virtual network by using a Site-to-Site VPN. Each network contains a subnet that has the same IP address space. The on-premises subnet contains a virtual machine.
You plan to migrate the virtual machine to the Azure subnet.
You need to migrate the on premises virtual machine to Azure without modifying the IP address. The solution must minim administrative effort.
What should you implement before you perform the migration?
- A. Azure Extended Network
- B. Azure Virtual Network NAT
- C. Azure Application Gateway
- D. Azure virtual network peering
Answer: A
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure-extended-network
NEW QUESTION 7
HOTSPOT
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains a server named Server1 that has the DFS Namespaces role service installed. Server! hosts a domain-based Distributed File System (DFS) Namespace named Files.
The domain contains a tile server named Server2. Seiver2 contains a shared folder named Share1. Share1 contains a subfolder named Folder 1.
In the Files namespace, you create a folder named Folder! that has a target of
\\Server2.contoso.com\Share1\Folder1.
You need to configure a logon script that will map drive letter M to Folder1. The solution must use the path of the DFS Namespace.
How should you complete the command to map the drive letter? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Solution:

Does this meet the goal?
- A. Yes
- B. Not Mastered
Answer: A
NEW QUESTION 8
DRAG DROP
You have a server named Server1 that runs Windows Server and has the Hyper V server role installed. Server1 hosts a virtual machine named VM1.
Server1 has an NVMe storage device. The device is currently assigned to VM1 by using Discrete Device Assignment.
You need to make the device available to Server1.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Solution:

Does this meet the goal?
- A. Yes
- B. Not Mastered
Answer: A
NEW QUESTION 9
You need to meet the technical requirements for User1. The solution must use the principle of least privilege.
What should you do?
- A. Add Users1 to the Server Operators group in contoso.com.
- B. Create a delegation on contoso.com.
- C. Add Users1 to the Account Operators group in contoso.com.
- D. Create a delegation on OU3.
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/delegating-administration-of-account-ous-and-resource-ous
NEW QUESTION 10
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are planning the deployment of DNS to a new network.
You have three internal DNS servers as shown in the following table.
The contoso.local zone contains zone delegations for east.contoso.local and west.contoso.local. All the DNS servers use root hints.
You need to ensure that all the DNS servers can resolve the names of all the internal namespaces and internet hosts.
Solution: You configure Server2 and Server3 to forward DNS requests to 10.0.1.10. Does this meet the goal?
- A. Yes
- B.
No
Answer: B
NEW QUESTION 11
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.
You open a new branch office that contains only client computers.
You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.
Solution: You create a new site named Site4 and associate Site4 to DEFAULTSITELINK. Does this meet the goal?
- A. Yes
- B. No
Answer: B
NEW QUESTION 12
You have an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with Azure AD by using A2ure AD Connect.
You enable password protection for contoso.com.
You need to prevent users from including the word Contoso as part of their password. What should you use?
- A. the Azure Active Directory admin center
- B. Active Directory Users and Computers
- C. Synchronization Service Manager
- D. Windows Admin Center
Answer: D
NEW QUESTION 13
Your network contains a multi-site Active Directory Domain Services (AD DS) forest. Each Active Directory site is connected by using manually configured site links and automatically generated connections.
You need to minimize the convergence time for changes to Active Directory. What should you do?
- A. For each site link, modify the options attribute.
- B. For each site link, modify the site link costs.
- C. For each site link, modify the replication schedule.
- D. Create a site link bridge that contains all the site links.
Answer: C
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/determining-the- interval
NEW QUESTION 14
SIMULATION
Task 9
You plan to create group managed service accounts (gMSAs).
You need to configure the domain to support the creation of gMSAs.
Solution:
To configure the domain to support the creation of gMSAs, you need to perform the following steps:
✑ On a domain controller or a computer that has the Remote Server Administration
Tools (RSAT) installed, open PowerShell as an administrator and run the following command to install the Active Directory module:
Install-WindowsFeature -Name RSAT-AD-PowerShell
✑ Run the following command to create a Key Distribution Service (KDS) root key, which is required for generating passwords for gMSAs. You only need to do this once per domain:
Add-KdsRootKey -EffectiveImmediately
✑ Wait for at least 10 hours for the KDS root key to replicate to all domain controllers in the domain. Alternatively, you can use the -EffectiveTime parameter to specify a past date and time for the KDS root key, but this is not recommended for security reasons. For more information, see Add-KdsRootKey.
✑ After the KDS root key is replicated, you can create and configure gMSAs using
the New-ADServiceAccount and Set-ADServiceAccount cmdlets. For more information, see Create a gMSA and Configure a gMSA.
Does this meet the goal?
- A. Yes
- B. Not Mastered
Answer: A
NEW QUESTION 15
You have an Azure virtual machine named Server1 that runs a network management application. Server1 has the following network configuration.
* Network interface.Nic1
* IP address 10.1.1.1/24
* Connected to: Vnet1/Subnet1
You need connect Server1 to an additional subnet named Vnet1/Subnet2. What should you do?
- A. Create a private endpoint on Subnet2
- B. Add a network interface to server1.
- C. Modify the IP configurations of Nic1.
- D. Add an IP configuration to Nic1.
Answer: B
NEW QUESTION 16
......
Recommend!! Get the Full AZ-800 dumps in VCE and PDF From Certleader, Welcome to Download: https://www.certleader.com/AZ-800-dumps.html (New 140 Q&As Version)