Microsoft Configuring Windows Server Hybrid Advanced Services (AZ-801日本語版) - AZ-801日本語 Exam Practice Test

Question 1
ホットスポットに関する質問
お客様はAzureサブスクリプションをお持ちです。そのサブスクリプションには、Windows Serverを実行するVM1という名前の仮想マシンが含まれています。
VM1のネットワークインターフェースは、オペレーティングシステムで無効になっています。
Azureシリアルコンソールを使用して、ネットワークインターフェイスを有効にする必要があります。
このコマンドをどのように完了すればよいですか?回答するには、回答欄で適切なオプションを選択してください。
注:正解ごとに1ポイントが加算されます。
Correct Answer:

Explanation:
Box 1: netsh.exe
Enable the Adapter:
In the Command Prompt, type the following command: netsh interface set interface "Ethernet" admin=enable.
The Ethernet is the default name for the adapter in Windows; if your adapter has a different name, you will need to use that name.
Box 2: interface
Reference:
https://www.youtube.com/watch?v=q3IJ1k7FnyU
Question 2
オンプレミス環境には、Windows Server 2025 Standardが動作するServer1という名前のサーバーがあります。
お客様は、以下の表に示す仮想マシンを含む Azure サブスクリプションを所有しています。

このサブスクリプションには、米国中部AzureリージョンにあるSentinel1という名前のMicrosoft Sentinelインスタンスが含まれています。
WindowsファイアウォールイベントをAMAコネクタ経由で実装する必要があります。
どのサーバーがWindowsファイアウォールのイベントをSentinel1に送信できますか?

Correct Answer: E
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 3
注: この質問は、同じシナリオを提示する一連の質問の一部です。シリーズの各質問には、指定された目標を達成できる独自のソリューションが含まれています。問題セットには、複数の正解があるものもあれば、正解がないものもあります。
このセクションの質問に回答すると、その質問に戻ることはできなくなります。そのため、これらの質問はレビュー画面に表示されません。
Windows Server を実行する Server1 という名前のサーバーがあります。
特定のアプリケーションのみが Server1 の保護フォルダー内のデータを変更できるようにする必要があります。
解決策: アプリとブラウザー コントロールから、エクスプロイト保護設定を構成します。
これは目標を満たしていますか?

Correct Answer: B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 4
ホットスポットに関する質問
以下のような構成の Windows Server フェールオーバー クラスター (WSFQ) があります。
- 名前: App1
- 所有者ノード: Node3
- タイプ: 汎用アプリケーション
App1の一般設定は、「一般」の図に示されています。(「一般」タブをクリックしてください。)

App1のフェイルオーバー設定は、フェイルオーバーの図に示されています。(「フェイルオーバー」タブをクリックしてください。)

App1の高度なポリシー設定は、「高度なポリシー」の図に示されています。(「高度なポリシー」タブをクリックしてください。)

以下の各記述について、正しい場合は「はい」を選択してください。そうでない場合は「いいえ」を選択してください。
注:正解ごとに1ポイントが加算されます。
Correct Answer:

Explanation:
Box 1: No
In the General settings for App1 we see only Node1 and Node2 listed as Preferred Owners.
Note: Description
The Set-ClusterOwnerNode cmdlet specifies which nodes can own a resource in a failover cluster or specifies the order of preference among owner nodes for a clustered role, or resource group.
The settings that control the possible or preferred owners affect the way the cluster responds to the failure of a resource or a clustered role.
Box 2: No
In the Advanced Policies settings for App1 we the three Possible Owners: Node2, Node3, and Node4.
The cluster would fail over to Node4, the next node.
Box 3: No
The Preferred Owners are Node1 and Node2.
The failback will be to one of the Preferred Owners, not to Node3.
Reference:
https://learn.microsoft.com/en-us/troubleshoot/windows-server/high-availability/groups-fail-logic-three-more-cluster-node-members
Question 5
Windows Serverが動作するServer1とServer2という名前のサーバーが2台あります。
あなたは以下の操作を実行します。
- Server1で、Policy1という名前のアプリケーション制御ポリシーを作成します。
フォルダ内のすべての実行可能ファイルを許可するルールが含まれています。
D:\Folder1.
- Policy1に、\\Server2\Folder2という名前のフォルダを信頼するルールを追加します。
- Policy1をデプロイします。
ポリシー1がサーバー1に適用されていることを確認する必要があります。
どのイベントビューアーログを確認すべきですか?

Correct Answer: D
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 6
オンプレミス環境には、Windows Server 2022 Standardが動作するServer1という名前のサーバーがあります。
お客様は、以下の表に示す仮想マシンを含む Azure サブスクリプションを所有しています。

このサブスクリプションには、米国中部AzureリージョンにあるSentinel1という名前のMicrosoft Sentinelインスタンスが含まれています。
Windowsファイアウォールコネクタを実装する必要があります。
どのサーバーがWindowsファイアウォールのログをSentinel1に送信できますか?

Correct Answer: B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 7
注:この問題は、同じシナリオを提示する一連の問題の一部です。このシリーズの各問題には、提示された目標を満たす可能性のある独自の解答が含まれています。問題セットによっては、複数の正解がある場合もあれば、正解がない場合もあります。
このセクションの質問に回答すると、後から戻って回答することはできません。そのため、これらの質問は復習画面には表示されません。
Azure Migrate をオンプレミス ネットワークにデプロイします。
オンプレミスにServer1という名前の物理サーバーがあり、Windows Serverが稼働しており、以下の構成になっています。
* オペレーティングシステムディスク 600GB
* データディスク 3TB
* NICチーミング:有効
* モビリティサービス:インストール済み
* Windowsファイアウォール:有効
* Microsoft Defender ウイルス対策: 有効
Azure Migrateを使用してServer1を移行できることを確認する必要があります。
解決策:Server1でNICチーミングを無効にします。
これは目標を達成していると言えるでしょうか?

Correct Answer: A
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 8
ホットスポットに関する質問
Windows Serverを実行するAzure仮想マシンが100台あります。
Azure Monitorエージェントを使用して、各仮想マシンのアプリケーションログにおけるイベントID 1035の発生状況を追跡する予定です。
イベントがLog Analyticsで分析可能になることを確認する必要があります。また、Azureに保存されるイベントの総量を最小限に抑えるソリューションでなければなりません。
どうすればよいですか?回答するには、回答欄で適切な選択肢を選んでください。
注:正解ごとに1ポイントが加算されます。
Correct Answer:

Explanation:
Box 1: A Data Collection Rule (DCR)
Collect Windows events from virtual machine with Azure Monitor
Windows event logs are some of the most common sources for health of the client operating system and workloads of Windows machines. You can collect events from standard logs, such as System and Application, and any custom logs created by applications you need to monitor.
Collect Windows event logs from virtual machines using a data collection rule (DCR) with a Windows events data source.
Box 2: XPath query
Extract XPath queries from Windows Event Viewer
You can use Event Viewer in Windows to extract XPath queries as shown in the following screenshots.
Reference:
https://learn.microsoft.com/en-us/azure/azure-monitor/vm/data-collection-windows-events
Question 9
ドラッグアンドドロップ問題
お客様のネットワークには、contoso.com という名前の Active Directory ドメイン サービス (AD DS) ドメインが含まれています。フォレストおよびドメインの機能レベルは Windows Server 2012 R2 です。このドメインには、次の表に示すドメイン コントローラーが含まれています。

フォレストの機能レベルをWindows Server 2016に引き上げる必要があります。解決策は以下の要件を満たす必要があります。
- 起動後にドメインコントローラーが 3 つあることを確認してください
レベル。
FSMOの役割が利用できない時間を最小限に抑える。
どの3つの行動を順番に実行すべきでしょうか?回答するには、行動リストから適切な行動を回答欄に移動させ、正しい順序に並べ替えてください。
Correct Answer:

Explanation:
https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/upgrade-domain-controllers
Question 10
ドラッグアンドドロップ問題
お客様のネットワークには、Active Directoryドメインサービス(AD DS)ドメインが含まれています。このドメインには、Cluster1という名前のフェールオーバークラスターが含まれています。
Windows Admin Center (WAC) を使用して、クラスター上でクラスター対応更新 (CAU) を構成する必要があります。
どの3つの行動を順番に実行すべきでしょうか?回答するには、行動リストから適切な行動を回答欄に移動させ、正しい順序に並べ替えてください。
Correct Answer:

Explanation:
Step 1: Enable CredSSP
Some tasks that require CredSSP to be enabled include:
- Create Cluster wizard workflow
- Active Directory queries or updates
- SQL Server queries or updates
Locating accounts or computers on a different domain or non-domain joined environment The Credential Security Support Provider protocol (CredSSP) is a Security Support Provider that is implemented by using the Security Support Provider Interface (SSPI). CredSSP lets an application delegate the user's credentials from the client to the target server for remote authentication.
Step 2: Add Cluster1 to WAC
Add the failover cluster to Windows Admin Center
Step 3: Add the Cluster-Aware Updating role.
Enabling self-updating mode.
To enable the self-updating mode, you must add the Cluster-Aware Updating clustered role to the failover cluster.
Incorrect:
* Failover clusters do not support gMSAs. However, services that run on top of the Cluster service can use a gMSA or a sMSA if they are a Windows service, an App pool, a scheduled task, or natively support gMSA or sMSA.
* The Windows Admin Center gateway, when published to DNS and given access through corresponding corporate firewalls, lets you securely connect to, and manage, your servers from anywhere with Microsoft Edge or Google Chrome.
Reference:
https://docs.microsoft.com/en-us/azure-stack/hci/manage/troubleshoot-credssp
https://docs.microsoft.com/en-us/windows-server/manage/windows-admin-center/use/manage-failover-clusters
https://docs.microsoft.com/en-us/windows-server/failover-clustering/cluster-aware-updating
Question 11
御社はStorage Spaces Directを利用しています。
Storage Space Directストレージプールで使用可能なストレージ容量を確認する必要があります。
何を使うべきでしょうか?

Correct Answer: C
Question 12
あなたは Contoso の管理者で、OS ディスクとデータディスクをそれぞれ 1 つずつ持つ新しい VM を作成する必要があります。VM の作成時には、デフォルトのオプションを使用します。サブスクリプションにはキー ボールトが設定されていません。次のオプションのうち、これらのディスクの暗号化状態を最も正確に表しているのはどれですか?

Correct Answer: C
Question 13
お使いのネット​​ワークには、Active Directoryドメインサービス(AD DS)ドメインが含まれています。
特定のユーザーアカウントおよびコンピューターアカウントに対して、チケット発行チケット(TGT)の有効期間を設定する必要があります。ソリューションは以下の要件を満たす必要があります。
- 他のユーザーおよびコンピューター アカウントへの影響を最小限に抑える
ドメイン。
・管理業務の手間を最小限に抑える。
何を設定すればよいですか?

Correct Answer: B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 14
ホットスポットに関する質問
お客様のネットワークには、contoso.com という名前の Active Directory ドメイン サービス (AD DS) ドメインが含まれています。このドメインには、Windows Server 2016 を実行するドメイン コントローラーが含まれています。
nwtraders.com という名前の新しい AD DS フォレストを構築します。このフォレストには、Windows Server 2025 を実行するドメインコントローラーが含まれています。
あなたはcontoso.comからnwtraders.comへの段階的な移行を計画しています。
あなたは以下の操作を実行します。
- contoso.com のユーザーを nwtraders.com に移行し、有効化します
SIDの歴史。
- contoso.com と
nwtraders.com
- nwtraders.com に Active Directory 移行ツール (ADMT) をインストールします。
- contoso.com にパスワードエクスポートサーバー (PES) サービスをインストールします。
以下の各記述について、正しい場合は「はい」を選択してください。そうでない場合は「いいえ」を選択してください。
注:正解ごとに1ポイントが加算されます。
Correct Answer:

Explanation:
Box 1: No
SID History is an Active Directory (AD) attribute that stores previous SIDs of an object, such as a user or group, to maintain access to resources in a previous domain after migration. It allows users to retain access to old resources during a domain consolidation or forest restructuring without requiring permissions to be re-assigned. Storing old SIDs enables historical Access Control List (ACL) entries to continue working, ensuring a smoother, less disruptive transition.
Box 2: Yes
Note: The Password Export Server (PES) is a Microsoft tool, version 3.1, that works with the Active Directory Migration Tool (ADMT) to securely migrate user account passwords when moving users between different Active Directory Domain Services (AD DS) environments, such as when changing Active Directory forests. To perform password migration, a user must install PES on a domain controller in the source domain and create a special encryption key file that establishes a trusted connection with the ADMT, enabling the migration of passwords.
Box 3: No
you would not need to install a Windows Server 2025 in the original domain to migrate user profiles to a new domain. A user migration involves joining clients to the new domain, and then setting up user profiles within that domain. You will need a Windows Server 2025 or a machine with the necessary Remote Server Administration Tools (RSAT) installed in the target domain to perform the migration, not in the source domain..
Reference:
https://www.microsoft.com/en-us/download/details.aspx?id=1838
https://www.microsoft.com/en-us/download/details.aspx?id=1838