πŸ”

AZ-801 β€” all questions

21 practice questions with answers and explanations.

Topic 1 Β· Question 1

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a server named Server1 that runs Windows Server. You need to ensure that only specific applications can modify the data in protected folders on Server1. Solution: From Virus & threat protection, you configure Controlled folder access. Does this meet the goal?

  • AYes (correct answer)
  • BNo
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Yes.

Topic 1 Β· Question 3

You have a Microsoft Sentinel deployment and 100 Azure Arc-enabled on-premises servers. All the Azure Arc-enabled resources are in the same resource group. You need to onboard the servers to Microsoft Sentinel. The solution must minimize administrative effort. What should you use to onboard the servers to Microsoft Sentinel?

  • AAzure Automation
  • BAzure Policy (correct answer)
  • CAzure virtual machine extensions
  • DMicrosoft Defender for Cloud
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Azure Policy

Explanation

Azure Policy enforces organizational rules and compliance across resources at scale.

Topic 1 Β· Question 4

You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant by using password hash synchronization. You have a Microsoft 365 subscription. All devices are hybrid Azure AD-joined. Users report that they must enter their password manually when accessing Microsoft 365 applications. You need to reduce the number of times the users are prompted for their password when they access Microsoft 365 and Azure services. What should you do?

  • AIn Azure AD, configure a Conditional Access policy for the Microsoft Office 365 applications.
  • BIn the DNS zone of the AD DS domain, create an autodiscover record.
  • CFrom Azure AD Connect, enable single sign-on (SSO). (correct answer)
  • DFrom Azure AD Connect, configure pass-through authentication.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: From Azure AD Connect, enable single sign-on (SSO).

Explanation

Azure Active Directory (Microsoft Entra ID) provides identity, single sign-on, and conditional access.

Topic 1 Β· Question 5

You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have 50 Azure virtual machines that run Windows Server. You need to ensure that any security exploits detected on the virtual machines are forwarded to Defender for Cloud. Which extension should you enable on the virtual machines?

  • AVulnerability assessment for machines (correct answer)
  • BMicrosoft Dependency agent
  • CLog Analytics agent for Azure VMs
  • DGuest Configuration agent
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Vulnerability assessment for machines.

Topic 1 Β· Question 7

You have 10 servers that run Windows Server in a workgroup. You need to configure the servers to encrypt all the network traffic between the servers. The solution must be as secure as possible. Which authentication method should you configure in a connection security rule?

  • ANTLMv2
  • Bpre-shared key
  • CKerberos V5
  • Dcomputer certificate (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: computer certificate.

Topic 1 Β· Question 8

You have an Azure virtual machine named VM1 that runs Windows Server. You need to encrypt the contents of the disks on VM1 by using Azure Disk Encryption. What is a prerequisite for implementing Azure Disk Encryption?

  • ACustomer Lockbox for Microsoft Azure
  • Ban Azure key vault (correct answer)
  • Ca BitLocker recovery key
  • Ddata-link layer encryption in Azure
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: an Azure key vault

Explanation

Azure Key Vault securely stores and manages secrets, keys, and certificates with access policies.

Topic 1 Β· Question 9 Β· Select all that apply

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains two servers named Server1 and Server2 that run Windows Server. You need to ensure that you can use the Computer Management console to manage Server2. The solution must use the principle of least privilege. Which two Windows Defender Firewall with Advanced Security rules should you enable on Server2? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • Athe COM+ Network Access (DCOM-In) rule (correct answer)
  • Ball the rules in the Remote Event Log Management group (correct answer)
  • Cthe Windows Management Instrumentation (WMI-In) rule
  • Dthe COM+ Remote Administration (DCOM-In) rule
  • Ethe Windows Management Instrumentation (DCOM-In) rule
Reveal answer & explanation
Correct answer: A, B

The correct answer is A, B. Option A: the COM+ Network Access (DCOM-In) rule Option B: all the rules in the Remote Event Log Management group

Explanation

Management Groups organize subscriptions into a hierarchy for unified governance and policy.

Topic 1 Β· Question 10

You have a server that runs Windows Server. The server is configured to encrypt all incoming traffic by using a connection security rule. You need to ensure that Server1 can respond to the unencrypted tracert commands initiated from computers on the same network. What should you do from Windows Defender Firewall with Advanced Security?

  • AFrom the IPsec Settings, configure IPsec defaults.
  • BCreate a new custom outbound rule that allows ICMPv4 protocol connections for all profiles.
  • CChange the Firewall state of the Private profile to Off.
  • DFrom the IPsec Settings, configure IPsec exemptions. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: From the IPsec Settings, configure IPsec exemptions.

Topic 1 Β· Question 11

You have an Azure virtual machine named VM1. You enable Microsoft Defender SmartScreen on VM1. You need to ensure that the SmartScreen messages displayed to users are logged. What should you do?

  • AFrom a command prompt, run WinRM quickconfig.
  • BFrom the local Group Policy, modify the Advanced Audit Policy Configuration settings.
  • CFrom Event Viewer, enable the Debug log. (correct answer)
  • DFrom the Windows Security app, configure the Virus & threat protection settings.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: From Event Viewer, enable the Debug log.

Topic 1 Β· Question 13

You have an on-premises server named Server1 that runs Windows Server. You have an Azure subscription. You need to onboard Server1 to Microsoft Defender for Cloud. What should you install on Server1?

  • Athe Azure File Sync agent
  • Bthe Microsoft Entra provisioning agent
  • Cthe Device Health Attestation role
  • Dthe Azure Connected Machine agent (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: the Azure Connected Machine agent.

Topic 1 Β· Question 14 Β· Select all that apply

You have a management group named MG1 that contains an Azure subscription named Sub1. Sub1 contains the resources shown in the following table. You need to enable Microsoft Defender for Servers. From the Azure portal, on which two resources can you enable Defender for Servers? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Exhibit 1 for question 14
  • ARG1
  • BWorkspace1 (correct answer)
  • CSub1 (correct answer)
  • DMG1
  • EVNet1
  • FVM1
Reveal answer & explanation
Correct answer: B, C

The correct answer is B, C. Option B: Workspace1 Option C: Sub1.

Topic 2 Β· Question 16

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a failover cluster named Cluster1 that hosts an application named App1. The General tab in App1 Properties is shown in the General exhibit. (Click the General tab.) The Failover tab in App1 Properties is shown in the Failover exhibit. (Click the Failover tab.) Server1 shuts down unexpectedly. You need to ensure that when you start Server1, App1 continues to run on Server2. Solution: From the Failover settings, you select Prevent failback. Does this meet the goal?

  • AYes (correct answer)
  • BNo
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Yes.

Topic 4 Β· Question 17

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You deploy Azure Migrate to an on-premises network. You have an on-premises physical server named Server1 that runs Windows Server and has the following configurations: β€’ Operating system disk: 600 GB β€’ Data disk: 3 TB β€’ NIC Teaming: Enabled β€’ Mobility service: Installed β€’ Windows Defender Firewall: Enabled β€’ Microsoft Defender Antivirus: Enabled You need to ensure that you can use Azure Migrate to migrate Server1. Solution: You shrink the data disk on Server1. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 4 Β· Question 18

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You deploy Azure Migrate to an on-premises network. You have an on-premises physical server named Server1 that runs Windows Server and has the following configurations: β€’ Operating system disk: 600 GB β€’ Data disk: 3 TB β€’ NIC Teaming: Enabled β€’ Mobility service: Installed β€’ Windows Defender Firewall: Enabled β€’ Microsoft Defender Antivirus: Enabled You need to ensure that you can use Azure Migrate to migrate Server1. Solution: You disable NIC Teaming on Server1. Does this meet the goal?

  • AYes (correct answer)
  • BNo
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Yes.

Topic 4 Β· Question 19

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You deploy Azure Migrate to an on-premises network. You have an on-premises physical server named Server1 that runs Windows Server and has the following configurations: β€’ Operating system disk: 600 GB β€’ Data disk: 3 TB β€’ NIC Teaming: Enabled β€’ Mobility service: Installed β€’ Windows Defender Firewall: Enabled β€’ Microsoft Defender Antivirus: Enabled You need to ensure that you can use Azure Migrate to migrate Server1. Solution: You disable Microsoft Defender Antivirus on Server1. Does this meet the goal?

  • AYes
  • BNo (correct answer)
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: No.

Topic 5 Β· Question 22

You have a Site-to-Site VPN between an on-premises network and an Azure VPN gateway. BGP is disabled for the Site-to-Site VPN. You have an Azure virtual network named Vnet1 that contains a subnet named Subnet1. Subnet1 contains a virtual machine named Server1. You can connect to Server1 from the on-premises network. You extend the address space of Vnet1. You add a subnet named Subnet2 to Vnet1. Subnet2 uses the extended address space. You deploy an Azure virtual machine named Server2 to Subnet2. You cannot connect to Server2 from the on-premises network. Server1 can connect to Server2. You need to ensure that you can connect to Subnet2 from the on-premises network. What should you do?

  • AAdd an additional Site-to-Site VPN between the on-premises network and Vnet1.
  • BAdd a private endpoint to Subnet2.
  • CTo Subnet2, add a route table that contains a user-defined route.
  • DUpdate the routing information on the on-premises routers. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Update the routing information on the on-premises routers.

Topic 5 Β· Question 25

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains three domain controllers named DC1, DC2, and DC3. You connect a Microsoft Defender for Identity instance to the domain. You need to onboard all the domain controllers to Defender for Identity. What should you run on the domain controllers?

  • AAzure ATP Sensor Setup.exe (correct answer)
  • BAzureConnectedMachineAgent.msi
  • CMARSAgentInstaller.exe
  • DMMASetup-AMD64.exe
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Azure ATP Sensor Setup.exe.

Topic 10 Β· Question 27

You need to meet technical requirements for Share1. What should you use?

  • AStorage Migration Service (correct answer)
  • BFile Server Resource Manager (FSRM)
  • CServer Manager
  • DStorage Replica
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Storage Migration Service.

Topic 11 Β· Question 30

You are planning the data share migration to support the on-premises migration plan. What should you use to perform the migration?

  • AStorage Migration Service (correct answer)
  • BMicrosoft File Server Migration Toolkit
  • CFile Server Resource Manager (FSRM)
  • DWindows Server Migration Tools
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Storage Migration Service.

Topic 13 Β· Question 34

You need to meet the technical requirements for User1. To which group in contoso.com should you add User1?

  • ADomain Admins (correct answer)
  • BAccount Operators
  • CSchema Admins
  • DBackup Operators
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Domain Admins.

Showing questions 1–20 of 21 Β· Page 1 of 2