Pre-Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Microsoft AZ-800 - Administering Windows Server Hybrid Core Infrastructure

Page: 3 / 5
Total 266 questions

You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant The on-premises network is connected to Azure by using a Site-to-Site VPN. You have the DNS zones shown in the following tab le.

You need to ensure that names from fabrikam.com can be resolved from the on-premises network Which two actions should you perform? Each correct answer presents part of the solution, NOTE: Each correct selection Is worth one point

A.

Create a conditio nal forwarder for fabrikam.com on DC1.

B.

Create a stub zone for fabrikam.com on DC1.

C.

Create a secondary zone for fabnlcam.com on DO.

D.

Deploy an Azure virtual machine that runs Windows Server. Modify the DNS Servers settings for the virtual network.

E.

E . Deploy an Azure virtual machine that runs Windows Server. Configure the virtual machine & s a DNS forwarder.

You have an on-premise s Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant

You have an on-premises web app named WebApp1 that only supports Kerberos authentication.

You need to ensure that users can access WebApp1 by using their Azure AD account. The solution must minimize administrative effort.

What should you configure? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Your network contains an on-premises Active Directory Domain Services (AD DS) domain. The domain contains a user named User1 and the servers shown in the following table.

User1 is a member of the Protected Users security group.

User1 performs the following actions:

• From Se rver1, establishes a remote PowerShell session on Server2

• From the PowerShell session on Server2, attempts to access a resource on Backup1

The request to access the resource on 8ackup1 is denied.

You need to ensure that User1 can access the resources on Backup1 by using the PowerShell session on Server2. The solution must follow the principle of least privilege and minimize administrative effort.

What should you configure?

A.

Kerberos delegation (unconstrained)

B.

CredSSP

C.

PSSessionConfigu ration by usi ng RunAs

D.

resource-based Kerberos constrained delegation

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains the servers shown in the following table.

The domain contains the users shown in the following table.

On Server2. you run the Enable-PSRemoting cmdlet

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

You have a server that runs Windows Server.

You need to prevent the creation of SM8 Direct connections.

Which cmdlet should you run?

A.

Disable-WindowsOptionalFeature

B.

Remove-Windows Feature

C.

Set-NetAdapterAdvancedProperty

D.

Disable-NetAdapterBinding

You have an Active Directory Domain Services (AD DS) domain. The domain contains three servers named Server 1, Server2, and Server3 that run Windows Server.

You sign in to Server1 by using a domain account and start a remote PowerShell session to Server2. From the remote PowerShell session, you attempt to access a resource on Server3. but access to the resource is denied.

You need to ensure tha t your credentials are passed from Server1 to Server3. The solution must minimize administrative effort. What should you do?

A.

Configure Kerberos constrained delegation.

B.

Configure Just Enough Administration (JEA).

C.

Configure selective authentication for the domain.

D.

Disable the Enforce user logon restrictions policy setting for the domain.

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.

You need to identify which server is the PDC emulator fo r the domain.

Solution: From a command prompt, you run netdom.exe query fsmo.

Does this meet the goal?

A.

Yes

B.

No

Note: This question is part of a series of questions that present the same scenario. Each q uestion in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be ab le to return to it. As a result, these questions will not appear in the review screen.

You have a server named Server1 that runs Windows Server 2022 and has the DHCP Server role. Server1 contains a single DHCP scope named Scope1.

You deploy five printers t o the network.

You need to ensure that the printers are always assigned the same IP address.

Solution: You create a DHCP reservation for each printer.

Does this meet the requirement?

A.

Yes

B.

No

You have an Azure Active Directory Domain Services (Azure AD DS) domain.

You create a new user named Admin1.

You need Admin1 to deploy custom Group Policy settings to all the computers in the domain. The solution must use the principle of least privilege.

What should you include in the solution? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites ar e connected by using DEFAULTIPSITELINK.

You open a new branch office that contains only client computers.

You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.

Solution: You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to Site1.

Does this meet the goal?

A.

Yes

B.

No