Microsoft Configuring Windows Server Hybrid Advanced Services - AZ-801 Exam Practice Test
You need to meet technical requirements for Share1.
What should you use?
What should you use?
Correct Answer: D
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
You have a server named Server1 that runs Windows Server.
For Server1, you enable the default App Control for Business policies in audit mode.
You need to ensure that specific third-party applications installed on Server1 are allowed to run by using App Control for Business.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

For Server1, you enable the default App Control for Business policies in audit mode.
You need to ensure that specific third-party applications installed on Server1 are allowed to run by using App Control for Business.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Correct Answer:

Explanation:
Detailed Explanation
On Windows Server, App Control for Business policies are now managed through OsConfig: you build the rule set for the specific third-party applications with New-CIPolicy and New-CIPolicyRule, use the App Control Policy Wizard to assemble and export those rules into a supplemental policy XML file, finish preparing that file for deployment by setting its version and policy identifier with Set-CIPolicyVersion and Set-CIPolicyIdInfo (including marking it as a supplement to the running audit-mode base policy), and finally push it into effect with Set-OSConfigDesiredConfiguration -Scenario AppControl. This lets the previously audited third-party applications run under the enforced policy without having to author an entirely new base policy.
Official Reference
Configure App Control for Business policies in Windows Server - https://learn.microsoft.com/en-us
/windows-server/security/osconfig/osconfig-how-to-configure-app-control-for-business

Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains the servers shown in the following table.
You have an Azure subscription.
You plan to migrate the data on FS1 to Azure by using Azure Data Box Gateway.
You need to configure a Data Box Gateway virtual device.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Exhibit

You have an Azure subscription.
You plan to migrate the data on FS1 to Azure by using Azure Data Box Gateway.
You need to configure a Data Box Gateway virtual device.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Exhibit

Correct Answer:

Explanation:
Detailed Explanation
Deploying an Azure Data Box Gateway virtual device follows a fixed sequence: you first create the Data Box Gateway resource in the Azure portal, which generates the virtual device image and an activation key; you then download that virtual device image; next you use the downloaded image to create a virtual machine on the on-premises Hyper-V host (HV1); and finally you power on that VM and activate it against the Azure resource using the activation key, which brings the Data Box Gateway share online so FS1 ' s data can start being copied to it. Creating a Storage Sync Service, installing the Azure File Sync agent, or configuring Hyper-V Replica are unrelated Azure File Sync/replication actions that do not belong in this Data Box Gateway deployment.
Official Reference
Deploy Data Box Gateway in Azure portal - https://learn.microsoft.com/en-us/azure/databox-gateway/data- box-gateway-deploy-provision-compute-device

Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains five servers that run Windows Server. The network also contains two workgroup servers that run Windows Server.
You need to implement a connection security rule between the member servers and the workgroup servers.
Which authentication method should you use?
You need to implement a connection security rule between the member servers and the workgroup servers.
Which authentication method should you use?
Correct Answer: D
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
You have two onpremises Hyper-V hosts named Served and Server2, Server1 contains two virtual machines named VM1 and VM2. Server2 contains three virtual machines named VM21. VM22, and VM23.
You have an Azure subscription.
You plan to use Azure Site Recovery to replicate all the virtual machines to Azure.
You need to deploy the Microsoft Azure Site Recovery Provider to the on-premises infrastructure.
What is the minimum number of providers you should install?
You have an Azure subscription.
You plan to use Azure Site Recovery to replicate all the virtual machines to Azure.
You need to deploy the Microsoft Azure Site Recovery Provider to the on-premises infrastructure.
What is the minimum number of providers you should install?
Correct Answer: A
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
You have 50 on-premises servers that run Windows Server.
You have an Azure subscription that contains a Recovery Services vault named Vaultl.
You plan to back up the on-premises servers to Vault1 by using Microsoft Azure Backup Server (MABS).
You need to configure prerequisites to support MABS. The solution must minimize costs.
What should you do for Vault1, and what should you deploy on-premises? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Exhibit
You have an Azure subscription that contains a Recovery Services vault named Vaultl.
You plan to back up the on-premises servers to Vault1 by using Microsoft Azure Backup Server (MABS).
You need to configure prerequisites to support MABS. The solution must minimize costs.
What should you do for Vault1, and what should you deploy on-premises? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Exhibit
Correct Answer:

Explanation:
Detailed Explanation
Microsoft Azure Backup Server (MABS) is the on-premises component you deploy to protect workloads such as file servers to a Recovery Services vault, so it must be installed on-premises before it can back up the 50 servers. To minimize cost for Vault1, you set the vault ' s storage replication type to locally redundant storage rather than the costlier geo-redundant default, since a single redundant copy is sufficient once MABS itself is managing the backup data. Configuring Azure Site Recovery, creating a private endpoint, or modifying the DefaultPolicy backup policy do not address the cost-minimization or MABS-prerequisite requirements described in this scenario.
Official Reference
About Microsoft Azure Backup Server - https://learn.microsoft.com/en-us/azure/backup/backup-azure- microsoft-azure-backup

Your network contains an on-premises Active Directory Domain Services (AD DS) domain.
The domain contains the servers shown in the following table.
Server1 has the connection security rule as shown in the Server1 exhibit. (Click the Server1 tab.) Server2 has the connection security rule as shown in the Server2 exhibit. (Click the Server2 tab.) Server1 has the inbound firewall rules as shown in the Server1 inbound rules exhibit. (Click the Server1 inbound rules tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Exhibit

Exhibit

Exhibit

Exhibit

Exhibit
The domain contains the servers shown in the following table.
Server1 has the connection security rule as shown in the Server1 exhibit. (Click the Server1 tab.) Server2 has the connection security rule as shown in the Server2 exhibit. (Click the Server2 tab.) Server1 has the inbound firewall rules as shown in the Server1 inbound rules exhibit. (Click the Server1 inbound rules tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Exhibit

Exhibit

Exhibit

Exhibit

Exhibit
Correct Answer:

Explanation:
Detailed Explanation
Server1 ' s connection security rule requires inbound and outbound authentication using Computer (Kerberos V5) for the Domain profile, and its inbound firewall rules for File and Printer Sharing, including ICMPv4
/ICMPv6 Echo Request and SMB-In, are all enabled and set to allow. Because Server2 has an identical connection security rule using the same Computer (Kerberos V5) authentication, both servers can successfully negotiate the required IPsec security association, so Server2 can both ping Server1 and reach its file shares over SMB. Server3, which has no matching connection security rule in this scenario, cannot complete the mandatory IPsec authentication that Server1 ' s rule demands for all inbound and outbound traffic, so it is unable to connect to a file share on Server1 even though the underlying firewall rules would otherwise allow SMB traffic.
Official Reference
Create an authentication request rule (connection security rules) - https://learn.microsoft.com/en-us
/windows-server/security/windows-firewall/create-an-authentication-request-rule

You are planning the migration of APP3 and APP4 to support the Azure migration plan.
What should you do on Cluster1 and in Azure before you perform the migration? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Exhibit
What should you do on Cluster1 and in Azure before you perform the migration? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Exhibit
Correct Answer:

Explanation:
Detailed Explanation
Migrating APP3 and APP4, which run as virtual machines on the on-premises Cluster1 Hyper-V failover cluster, to Azure uses the Azure Migrate: Server Migration workflow for Hyper-V. That workflow requires an Azure Migrate project to be created in Azure first to serve as the container for the migration effort and its discovered assets, and then the Azure Migrate appliance -- a purpose-built VM/OVA image supplied by Azure Migrate -- to be imported onto (deployed to) the Hyper-V host or cluster so it can discover the VMs and orchestrate replication into Azure. A P2S VPN, a Configure Azure Network Adapter action, the Azure File Sync agent, and the Windows Server Migration Tools do not perform Hyper-V VM discovery or replication, and a premium block blob storage account, private endpoint, or VPN gateway are not the Azure- side resource that Azure Migrate itself requires to begin a migration project.
Official Reference
Migrate Hyper-V VMs to Azure with Azure Migrate - https://learn.microsoft.com/en-us/azure/migrate
/tutorial-migrate-hyper-v

You have a Windows Server failover cluster named Cluster1 that has a cloud witness and the nodes shown in the following table.
Cluster1 has the roles shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Cluster1 has the roles shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Exhibit

Exhibit

Correct Answer:

Explanation:
Detailed Explanation
FS1 (File Server for general use) can run on any node that has the File Server role installed; Node4 has that role, so even though its cluster vote has been administratively set to 0 for quorum purposes, it remains a valid failover target and FS1 moves to it automatically when Node3 fails. DFS1 (DFS Namespace Server) in this deployment is hosted within the Site1 fault domain (Node1 and Node2), so when it is running on Node2 and Node2 fails, it does not automatically extend its ownership across the fault domain boundary to Node3 in Site2. Because Site1 remains intact and, together with the cloud witness, continues to hold cluster quorum, DFS1 stays available on Site1 even if the entire Site2 fault domain (Node3 and Node4) goes offline.
Official Reference
Configure cluster fault domain awareness (sites) - https://learn.microsoft.com/en-us/windows-server
/failover-clustering/manage-affinity-fault-domains

You have a Windows Server Failover Cluster (WSFQ that contains five nodes.
You need to ensure that if a network link fails on one of the nodes, the workloads are distributed across the remaining nodes during a failover. The solution must ensure that the workloads are distributed across all the nodes as evenly as possible.
Which command should you run?
You need to ensure that if a network link fails on one of the nodes, the workloads are distributed across the remaining nodes during a failover. The solution must ensure that the workloads are distributed across all the nodes as evenly as possible.
Which command should you run?
Correct Answer: A
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Your network contains an Active Directory Domain Services (AD DS) domain. The functional level of the domain is Windows Server 2016. All domain controllers run Windows Server 2025.
You need to prevent cached credentials and older authentication protocols, such as NTLM, from being used by highly privileged user accounts.
What should you do?
You need to prevent cached credentials and older authentication protocols, such as NTLM, from being used by highly privileged user accounts.
What should you do?
Correct Answer: A
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
You have two Azure virtual networks named Vnet1 and Vnet2.
You have a Windows 10 device named Client1 that connects to Vnet1 by using a Point-to-Site (P2S) IKEv2 VPN.
You implement virtual network peering between Vnet1 and Vnet2. Vnet1 allows gateway transit Vnet2 can use the remote gateway.
You discover that Client1 cannot communicate with Vnet2.
You need to ensure that Client1 can communicate with Vnet2.
Solution: You enable BGP on the gateway of Vnet1.
Does this meet the goal?
You have a Windows 10 device named Client1 that connects to Vnet1 by using a Point-to-Site (P2S) IKEv2 VPN.
You implement virtual network peering between Vnet1 and Vnet2. Vnet1 allows gateway transit Vnet2 can use the remote gateway.
You discover that Client1 cannot communicate with Vnet2.
You need to ensure that Client1 can communicate with Vnet2.
Solution: You enable BGP on the gateway of Vnet1.
Does this meet the goal?
Correct Answer: A
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
You have two file servers named Server1 and Server2 that run Windows Server. Server1 contains a shared folder named Data. Data contains 10 TB of data.
You plan to decommission Server1.
You need to migrate the files from Data to a new shared folder on Server2. The solution must meet the following requirements:
* Ensure that share, file, and folder permissions are copied.
* After the initial copy occurs, ensure that changes in \\Server1\Data can be synced to the destination without initiating a full copy.
* Minimize administrative effort.
What should you use?
You plan to decommission Server1.
You need to migrate the files from Data to a new shared folder on Server2. The solution must meet the following requirements:
* Ensure that share, file, and folder permissions are copied.
* After the initial copy occurs, ensure that changes in \\Server1\Data can be synced to the destination without initiating a full copy.
* Minimize administrative effort.
What should you use?
Correct Answer: D
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
You have two servers named Host1 and Host2 that run Windows Server and have the Hyper-V server role installed. Host2 is configured as a replica server.
Host1 contains a virtual machine named VM1.
You plan to use Hyper-V Replica to replicate VM1 to Host2.
You need to ensure that you can restore a replica of VM1 to a specific state from the past eight hours.
What should you do?
Host1 contains a virtual machine named VM1.
You plan to use Hyper-V Replica to replicate VM1 to Host2.
You need to ensure that you can restore a replica of VM1 to a specific state from the past eight hours.
What should you do?
Correct Answer: B
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server and uses Azure Disk Encryption.
You need to identify which Azure key vault stores the encryption keys for VM1. The solution must minimize administrative effort.
Which PowerShell cmdlet should you run?
You need to identify which Azure key vault stores the encryption keys for VM1. The solution must minimize administrative effort.
Which PowerShell cmdlet should you run?
Correct Answer: C
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).