Microsoft Configuring Windows Server Hybrid Advanced Services - AZ-801 Exam Practice Test

Question 1
You have the on-premises servers shown in the following table.
You have an Azure subscription.
You plan to migrate the servers to Azure generation 2 virtual machines. Which servers can be migrated to Azure by using Azure Migrate?

Exhibit

Correct Answer: B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 2
You have an on-premises Active Directory Domain Services (AD DS) domain that contains the resources shown in the following table.
The domain contains the domain controllers shown in the following table.
You configure a site link between Site1 and Site2 and set the replication interval to 20 minutes.
At 10:00 AM, connectivity between Site1 and Site2 fails.
Administrators perform the actions shown in the following table.
At 10:30 AM, connectivity between Site1 and Site2 is restored.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth dim point

Exhibit

Exhibit

Exhibit
Correct Answer:

Explanation:
CORRECTED ANSWER: Statement 1 (At 11:30 AM, User1 and User2 are members of Group1): No.
Statement 2 (At 11:30 AM, the phone number of User2 is 333-333): Yes. Statement 3 (At 11:30 AM, User3 is deleted): No.
Detailed Explanation
Group membership is stored as a linked, multivalued attribute, so DC2 ' s removal of User1 from Group1 and DC1 ' s addition of User2 to Group1 apply to two different values and merge without conflict once the 10:00-
10:30 partition heals; by 11:30 AM (well past the 20-minute replication interval), Group1 has converged to contain only User2, so the claim that both User1 and User2 are members is false. For the single-valued telephone-number attribute, Active Directory resolves a genuine conflict by comparing each domain controller ' s local originating-write version number for that attribute, using timestamp only as a tiebreaker when versions are equal; because DC1 wrote the attribute twice during the outage (222-222, then 333-333) while DC2 wrote it only once (444-444), DC1 ' s value carries the higher version and wins the conflict regardless of DC2 ' s later wall-clock time, so User2 ' s phone number converges to 333-333. For User3, DC1 moved it into OU1 while DC2, still seeing OU1 as empty, deleted OU1; when the two changes replicate together, Active Directory detects the now-orphaned User3 object and relocates it into the domain ' s LostAndFound container rather than deleting it, so User3 still exists at 11:30 AM.
Official Reference
How the Active Directory replication model works - https://learn.microsoft.com/en-us/previous-versions
/windows/it-pro/windows-server-2003/cc772726(v=ws.10)
Question 3
The servers run Windows Server and have the network configurations shown in the following table.
Server3 is configured as a NAT gateway. All the servers allow ICMP requests.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Exhibit
Exhibit
Correct Answer:

Explanation:
Detailed Explanation
Server1 ' s only interface, NIC1 (172.16.0.1/24), sits on the same subnet as Server2 ' s NIC2 (172.16.0.100
/24) - its configured default gateway - so Server1 can reach itself and NIC2 directly, but Server2 has no IP routing/RRAS enabled to forward packets between its two NICs, so traffic aimed at the 192.168.15.0/24 or
131.107.0.0/24 subnets never gets relayed and those pings fail. Server2 can likewise reach its own two directly connected subnets - NIC1/NIC2 on 172.16.0.0/24 and NIC3/NIC4 on 192.168.15.0/24 - but NIC3 has no gateway configured pointing at Server3 ' s NAT interface, so Server2 has no route to the 131.107.0.0
/24 network and cannot reach NIC5. Because Server3 ' s role as a NAT gateway only translates outbound traffic that is actually routed to it, and neither Server1 nor Server2 has the routing/gateway configuration needed to send traffic that far, connectivity in both cases is limited to each server ' s directly attached subnets.
Official Reference
Configure NAT network address translation on Windows Server - https://learn.microsoft.com/en-us
/windows-server/networking/technologies/nat/nat-overview
Question 4
You have an Azure subscription that has Microsoft Defender for Cloud enabled.
You have 50 Azure virtual machines that run Windows Server.
You need to ensure that any security exploits detected on the virtual machines are forwarded to Defender for Cloud.
Which extension should you enable on the virtual machines?

Correct Answer: D
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 5
You have an on-premises server named Server 1 that runs Windows Server.
You have an Azure subscription.
You migrate Server1 to an Azure virtual machine named VM1.
You need to configure a backup solution for VM1. The solution must provide recovery points.
What should you do on VM1, and in which type of vault should you store the backups? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Correct Answer:

Explanation:
Detailed Explanation
Azure VM backup is delivered through an extension that the Azure Backup service pushes to the virtual machine, and that extension depends on the Azure VM Agent already being present on the guest OS, so installing the Windows Azure VM Agent on VM1 is the prerequisite step to enable backup. Recovery points for a full Azure IaaS VM (application-consistent or crash-consistent snapshots) are stored in a Recovery Services vault, which remains the vault type used for whole-VM backup and restore, as opposed to the newer Backup vault type used for workloads like Azure Disks or blob operational backup. Backup vault and Azure Key Vault do not provide the VM-level recovery point functionality this scenario calls for.
Official Reference
Prepare to back up Azure VMs - https://learn.microsoft.com/en-us/azure/backup/backup-azure-arm-vms- prepare
Question 6
Your network contains an Active Directory Domain Services (AD DS) domain that has a Windows Server
2012 R2 forest and domain functional level. The domain contains the domain controllers shown in the following table.
You need to ensure that you can deploy a new domain controller that runs Windows Server 2025. The solution must minimize administrative effort.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

Exhibit

Correct Answer: B,D
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 7
Your network contains an Active Directory Domain Services (AD DS) domain. The functional level of the domain is Windows Server 2012 R2.
You need to create and link an authentication policy silo.
What should you do first?

Correct Answer: D
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 8
Your company uses Storage Spaces Direct.
You need to view the available storage in a Storage Space Direct storage pool.
What should you use?

Correct Answer: B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 9
You have 50 on-premises servers that run Windows Server.
You have an Azure subscription that contains a Microsoft Sentinel workspace.
You plan to monitor the servers by using Microsoft Sentinel.
You need to perform the following actions in Microsoft Sentinel;
* Add the Windows Forwarded Events data connector.
* Create a playbook that has an incident trigger.
Which two settings should you use? To answer, select the appropriate settings in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Correct Answer:

Explanation:
Detailed Explanation
In the Microsoft Sentinel navigation pane under Configuration, data connectors such as Windows Forwarded Events are added and configured from the Data connectors page, which is where the underlying Log Analytics data connection for forwarded Windows events is enabled. Automation rules and playbooks, including a Logic App playbook that starts with a Microsoft Sentinel incident trigger, are created and managed from the Automation page in the same Configuration section. These are the two purpose-built areas of the Sentinel workspace for connecting server-generated event data and for building automated incident-response playbooks, matching the two actions described in the scenario.
Official Reference
Connect data sources in Microsoft Sentinel - https://learn.microsoft.com/en-us/azure/sentinel/connect-data- sources