Complete list of current Q & A>> Download Administering Windows Server Hybrid Core Infrastructure (AZ-800) – Quiz 1 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 1. You have a server named Host1 that has the Hyper-V server role installed. Host1 hosts a virtual machine named VM1. You have a management server named Server1 that runs Windows Server. You remotely manage Host1 from Server1 by using Hyper-V Manager. You need to ensure that you can access a USB hard drive connected to Server1 when you connect to VM1 by using Virtual Machine Connection. Which two actions should you perform? A. From the Hyper-V Settings of Host1, select Allow enhanced session mode. B. From Virtual Machine Connection, select Show Options, and then select the USB hard drive. C. From Virtual Machine Connection, switch to a basic session. D. From Disk Management on Host1, select Rescan Disks. E. From Disk Management on Host1, attach a virtual hard disk. 2 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 2. You need to configure the Group Policy settings to ensure that the Azure Virtual Desktop session hosts meet the security requirements. What should you configure? A. loopback processing in GPO4 B. security filtering for the link of GPO1 C. loopback processing in GPO1 x D. the Enforced property for the link of GPO4 E. the Enforced property for the link of GPO1 F. security filtering for the link of GPO4 3 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 3. You have an on-premises server named Server1 that runs Windows Server. You have an Azure virtual network that contains an Azure virtual network gateway. You need to connect only Server1 to the Azure virtual network. What should you use? A. a Site-to-Site VPN B. Azure Network Adapter C. an ExpressRoute circuit D. Azure Extended Network 4 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 4. Your network contains an Active Directory Domain Services (AD DS) domain. You plan to use Active Directory Administrative Center to create a new user named User1. Which two attributes are required to create User1 A. Password B. Profile path C. User SamAccountName logon D. Full name E. First name F. User UPN logon 5 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 5. You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with Azure AD. You deploy an app that adds custom attributes to the domain. From Azure Cloud Shell, you discover that you cannot query the custom attributes of users. You need to ensure that the custom attributes are available in Azure AD. Which task should you perform from Microsoft Azure Active Directory Connect first? A. Configure device options B. Manage federation C. Customize synchronization options D. Refresh directory schema 6 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 6. Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three domains. Each domain contains 10 domain controllers. You plan to store a DNS zone in a custom Active Directory partition. You need to create the Active Directory partition for the zone. The partition must replicate to only four of the domain controllers. What should you use? A. Windows Admin Center B. Set-DnsServer C. New-ADObject D. ntdsutil.exe 7 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 7. You have an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with Azure AD by using Azure AD Connect. You enable password protection for contoso.com. You need to prevent users from including the word contoso as part of their password. What should you use? A. the Azure Active Directory admin center B. Active Directory Users and Computers C. Synchronization Service Manager D. Windows Admin Center 8 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 8. Your on-premises network contains an Active Directory domain named contoso.com. You have an Azure AD tenant. You plan to sync contoso.com with the Azure AD tenant by using Azure AD Connect cloud sync. You need to create an account that will be used by Azure AD Connect cloud sync. Which type of account should you create? A. system-assigned managed identity B. group managed service account (gMSA) C. user D. InetOrgPerson 9 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 9. Your network contains a multi-site Active Directory Domain Services (AD DS) forest. Each Active Directory site is connected by using manually configured site links and automatically generated connections. You need to minimize the latency for changes to Active Directory. What should you do? A. For each site links, modify the site link costs. B. Create a site link bridge that contains all the site links. C. For each site link, modify the options attribute. D. For each site link, modify the replication schedule. 10 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 10. Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three domains. Each domain contains 10 domain controllers. You plan to store a DNS zone in a custom Active Directory partition. You need to create the Active Directory partition for the zone. The partition must replicate to only four of the domain controllers. What should you use? A. Windows Admin Center B. DNS Manager C. Active Directory Sites and Services D. ntdsutil.exe 11 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 11. Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest root domain contains a server named server1.contoso.com. A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains. You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com. What should you do first? A. Add fabrikamGroup1 to the local Users group on server1.contoso.com. B. Enable SID filtering for the trust. C. Enable Selective authentication for the trust. D. Change the trust to a one-way external trust. 12 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 12. You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. You have several Windows 10 devices that are Azure AD hybrid-joined. You need to ensure that when users sign in to the devices, they can use Windows Hello for Business. Which optional feature should you select in Azure AD Connect? A. Device writeback B. Group writebeack C. Azure AD app and attribute filtering D. Password writeback E. Directory extension attribute sync 13 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 13. Your network contains a multi-site Active Directory Domain Services (AD DS) forest. Each Active Directory site is connected by using manually configured site links and automatically generated connections. You need to minimize the convergence time for changes to Active Directory. What should you do? A. For each site link, modify the replication schedule. B. For each site links, modify the site link costs. C. Create a site link bridge that contains all the site links. D. For each site link, modify the options attribute. 14 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 14. Your network contains an Active Directory Domain Services (AD DS) domain. The network also contains 20 domain controllers, 100 member servers, and 100 client computers. You have a Group Policy Object (GPO) named GPO1 that contains Group Policy preferences. You plan to link GPO1 to the domain. You need to ensure that the preference in GPO1 apply only to domain member servers and NOT to domain controllers or client computers. All the other Group Policy settings in GPO1 must apply to all the computers. The solution must minimize administrative effort. Which type of item level targeting should you use? A. Domain B. Operating System C. Security Group D. Environment Variable 15 / 15 Category: Administering Windows Server Hybrid Core Infrastructure (AZ-800) 15. You have an on premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. You plan to implement self-service password reset (SSPR) in Azure AD. You need to ensure that users that reset their passwords by using SSPR can use the new password resources in the AD DS domain. What should you do? A. Deploy the Azure AD Password Protection proxy service to the on premises network. B. Run the Microsoft Azure Active Directory Connect wizard and select Password writeback. C. Grant the Change password permission for the domain to the Azure AD Connect service account. D. Grant the impersonate a client after authentication user right to the Azure AD Connect service account Your score is 0% Restart quiz Send feedback