Microsoft Administering Windows Server Hybrid Core Infrastructure - AZ-800 Exam Practice Test

Hotspot Question
You have an Azure subscription named Sub1 that is linked to a Microsoft Entra tenant named contoso.com. Contoso.com contains the users shown in the following table.

You deploy a virtual machine that has the following configurations:
- Name: VM1
- Resource group: RG1
- Operating system: Windows Server
- Login with Microsoft Entra ID: Enabled
You have the Azure role assignments shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Box 1: No
User1 is a member.
User1 has the Virtual Machine Contributor role with scope RG1.
VM1 is in RG1 and has Entra login enabled.
A user with the Virtual Machine Contributor role in Azure AD (Entra ID) does not automatically have the ability to log in to a virtual machine with Entra ID login enabled. While the Contributor role provides significant management capabilities for the VM, it does not inherently grant the specific permissions needed for interactive login using Entra ID credentials.
Box 2: No
User2 is a guest.
User2 has the Virtual Machine User login role with scope RG1.
A guest user in an Entra ID (formerly Azure AD) tenant cannot log in to an Azure VM using Entra ID authentication, even if they have the Virtual Machine User Login role assigned. Entra guest accounts are not supported for Azure VM login via Entra ID authentication.
Box 3: Yes
User3 is a member.
User3 has the Virtual Machine Administrator login role with scope RG1.
A user who is a member of an Entra domain and has the "Virtual Machine Administrator Login" role assigned can log in to a virtual machine with Entra ID login enabled. This role grants users the necessary permissions to sign in to Azure virtual machines with administrator privileges Reference:
https://learn.microsoft.com/en-us/entra/identity/devices/howto-vm-sign-in-azure-ad-windows
You have a Windows Server container host named Server1.
You create a Dockerfile named df1.
You need to generate a container image by using df1.
Which command should you run?
Correct Answer: A Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
You plan to deploy a containerized application that requires .NET Core.
You need to create a container image for the application. The image must be as small as possible.
Which base image should you use?
Correct Answer: D Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
You have a server that runs Windows Server and has the DHCP Server role installed. The server has a scope named Scope1 that has the following configurations:
* Address range: 192.168.0.2 to 192. 168.1.254
* Mask: 255.255.254.0
* Router: 192.168.0.1
* Lease duration: 3 days
* DNS server: 172.16.0.254
You have 50 Microsoft Teams Phone devices from the same vendor. All the devices have MAC addresses within the same range.
You need to ensure that all the Teams Phone devices that receive a lease from Scope1 have IP addresses in the range of 192.168.1.100 to 192.168.1.200. The solution must NOT affect other DHCP clients that receive IP configurations from Scope1.
What should you create?
Correct Answer: A Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
SIMULATION
You need to make the shares named Marketing and Sales from SRV1 available on the network by using the following UNC paths:
- \\contoso.com\documents\marketing
- \\contoso.com\documents\sales
To complete this task, sign in to the required computer or computers.
Correct Answer:
How to Set Up Windows Server for File Sharing
Windows File Sharing Setup
Step 1: Open the Computer Management window, which you can access by going to Server Manager > Tools > Computer Management. Open SRV1.
Step 2: Select the directory that you want to share (or select a new directory).
We select: \\contoso.com\documents\marketing
Step 3: Right-click this directory (folder) and in the context menu, hit Properties.

Step 4: Specify name of the Share as Marketing

Step 5: Share \\contoso.com\documents\sales as Sales in the same manner.
Reference:
https://www.nakivo.com/blog/create-file-share-windows-server/
Case Study 3 - ADatum Corporation
Overview
Company Information
ADatum Corporation is a manufacturing company that has a main office in Seattle and two branch offices in Los Angeles and Montreal.
Fabrikam Partnership
ADatum recently partnered with 2 company named Fabrikam, Inc.
Fabrikam is a manufacturing company that has a main office in Boston and a branch office in Orlando.
Both companies intend to collaborate on several joint projects.
Existing Environment
ADatum AD DS Environment
The on-premises network of ADatum contains an Active Directory Domain Services (AD DS) forest named adatum.com.
The forest contains two domains named adatum.com and east.adatum.com and the domain controllers shown in the following table.

Fabrikam AD DS Environment
The on-premises network of Fabrikam contains an AD DS forest named fabrikam.com.
The forest contains two domains named fabrikam.com and south.fabrikam.com.
The fabrikam.com domain contains an organizational unit (OU) named Marketing.
Server Infrastructure
The adatum.com domain contains the servers shown in the following table.

HyperV1 contains the virtual machines shown in the following table.

All the virtual machines on HyperV1 have only the default management tools installed.
SSPace1 contains the Storage Spaces virtual disks shown in the following table.

Azure Resources
ADatum has an Azure subscription that contains an Azure AD tenant. Azure AD Connect is configured to sync the adatum.com forest with Azure AD.
The subscription contains the virtual networks shown in the following table.

The subscription contains the Azure Private DNS zones shown in the following table.

The subscription contains the virtual machines shown in the following table.

All the servers are in a workgroup.
The subscription contains a storage account named storage1 that has a file share named share1.
Requirements
Planned Changes
ADatum plans to implement the following changes:
- Sync Data1 to share1.
- Configure an Azure runbook named Task1.
- Enable Azure AD users to sign in to Server1.
- Create an Azure DNS Private Resolver that has the following configurations:
- Name: Private1
- Region: West US
- Virtual network: VNet1
- Inbound endpoint: SubnetB
- Enable users in the adatum.com domain to access the resources in the south.fabrikam.com domain.
Technical Requirements
ADatum identifies the following technical requirements:
- The data on SSPace1 must be available always.
- DC2 must become the schema master if DC1 fails.
- VM3 must be configured to enable per-folder quotas.
- Trusts must allow access to only the required resources.
- The users in the Marketing OU must have access to storage1.
- Azure Automanage must be used on all supported Azure virtual machines.
- A direct SSH session must be used to manage all the supported virtual machines on HyperV1.
Which two languages can you use for Task1? Each correct answer presents a complete solution.
Correct Answer: A,E Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
SIMULATION
You need to ensure that the minimum password length for members of the BranchAdmins group is 12 characters. The solution must affect only the BranchAdmins group.
To complete this task, sign in the required computer or computers.
Correct Answer:
Create a new fine-grained password policy.
In the following procedure you will create a new fine-grained password policy using the UI in ADAC.
To create a new fine grained password policy.
Step 1: Right click the Windows PowerShell icon, click Run as Administrator and type dsac.exe to open ADAC.
Step 2: Click Manage, click Add Navigation Nodes and select the appropriate target domain in the Add Navigation Nodes dialog box and then click OK.
Step 3: Click Manage, click Add Navigation Nodes and select the appropriate target domain in the Add Navigation Nodes dialog box and then click OK.
Step 4: In the Tasks pane, click New, and then click Password Settings.
Fill in or edit fields inside the property page to create a new Password Settings object. The Name and Precedence fields are required.
In our case:
Minimum password length: 12

Step 5: Under Directly Applies To, click Add, type BranchAdmin, and then click OK.
Reference:
https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/adac/introduction-to-active-directory-administrative-center-enhancements--level-100-#bkmk2_test_fgpp1
You have a server named Server1 that runs Windows Server.
You plan to host applications in Windows containers.
You need to configure Server1 to run containers.
What should you install?
Correct Answer: B Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Case Study 3 - ADatum Corporation
Overview
Company Information
ADatum Corporation is a manufacturing company that has a main office in Seattle and two branch offices in Los Angeles and Montreal.
Fabrikam Partnership
ADatum recently partnered with 2 company named Fabrikam, Inc.
Fabrikam is a manufacturing company that has a main office in Boston and a branch office in Orlando.
Both companies intend to collaborate on several joint projects.
Existing Environment
ADatum AD DS Environment
The on-premises network of ADatum contains an Active Directory Domain Services (AD DS) forest named adatum.com.
The forest contains two domains named adatum.com and east.adatum.com and the domain controllers shown in the following table.

Fabrikam AD DS Environment
The on-premises network of Fabrikam contains an AD DS forest named fabrikam.com.
The forest contains two domains named fabrikam.com and south.fabrikam.com.
The fabrikam.com domain contains an organizational unit (OU) named Marketing.
Server Infrastructure
The adatum.com domain contains the servers shown in the following table.

HyperV1 contains the virtual machines shown in the following table.

All the virtual machines on HyperV1 have only the default management tools installed.
SSPace1 contains the Storage Spaces virtual disks shown in the following table.

Azure Resources
ADatum has an Azure subscription that contains an Azure AD tenant. Azure AD Connect is configured to sync the adatum.com forest with Azure AD.
The subscription contains the virtual networks shown in the following table.

The subscription contains the Azure Private DNS zones shown in the following table.

The subscription contains the virtual machines shown in the following table.

All the servers are in a workgroup.
The subscription contains a storage account named storage1 that has a file share named share1.
Requirements
Planned Changes
ADatum plans to implement the following changes:
- Sync Data1 to share1.
- Configure an Azure runbook named Task1.
- Enable Azure AD users to sign in to Server1.
- Create an Azure DNS Private Resolver that has the following configurations:
- Name: Private1
- Region: West US
- Virtual network: VNet1
- Inbound endpoint: SubnetB
- Enable users in the adatum.com domain to access the resources in the south.fabrikam.com domain.
Technical Requirements
ADatum identifies the following technical requirements:
- The data on SSPace1 must be available always.
- DC2 must become the schema master if DC1 fails.
- VM3 must be configured to enable per-folder quotas.
- Trusts must allow access to only the required resources.
- The users in the Marketing OU must have access to storage1.
- Azure Automanage must be used on all supported Azure virtual machines.
- A direct SSH session must be used to manage all the supported virtual machines on HyperV1.
You need to implement the planned changes for Azure AD users to sign in to Server1.
Which PowerShell cmdlet should you run?
Correct Answer: A Vote an answer
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
Your network contains an Active Directory Domains Services (AD DS) domain named contoso.com.
You implement a central store.
You create a new Group Policy Object (GPO) named GPO1.
When you attempt to edit GPO1, you see the settings shown in the exhibit. (Click the Exhibit tab.)

You need to ensure that all settings are available.
Solution: You modify the WMI Filtering settings for GPO1.
Does this meet the goal?
Correct Answer: A Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).