Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Microsoft AZ-800 - Administering Windows Server Hybrid Core Infrastructure

Page: 5 / 5
Total 249 questions

Your network contains two Active Directory Domain Services (AD DS) forests named contoso.com and fabrikam.com. Contoso.com contains three child domains named amer.contoso.com, apac.contoso.com, and emea.contoso.com. Fabrikam.com contains a child domain named apac.fabrikam.com. A bidirectional forest trust exists between contoso.com and fabrikam.com.

You need to provide users in the contoso.com forest with access to the resources in the fabrikam.com forest. The solution must meet the following requirements:

• Users in contoso.com must only be added directly to groups in the contoso.com forest.

• Permissions to access the resources in fabrikam.com must only be granted directly to groups in the fabrikam.com forest.

• The number of groups must be minimized.

Which type of groups should you use to organize the users and to assign permissions? To answer, drag the appropriate group types to the correct requirements. Each group type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Your network contains a Active Directory Domain Service (AD DS) forest named contoso.com. The forest root domain contains a server named server1. contoso.com.

A two-way forest trust exists between the contoso.com forest and an AD DS forest named fabrikam.com. The fabrikam.com forest contains 10 child domains.

You need to ensure that only the members of a group named fabrikam\Group1 can authenticate to server1.contoso.com.

What should you do first?

A.

Change the trust to a one-way external trust.

B.

Add fabrikam\Group1 to the local Users group on server1.contoso.com.

C.

Enable SID filtering for the trust.

D.

Enable Selective authentication for the trust.

You have an Azure virtual machine named VM1 that runs Windows Server.

You need to ensure that administrators request access to VM1 before establishing a Remote Desktop connection.

What should you configure?

A.

Azure Front Door

B.

Microsoft Defender for Cloud

C.

Azure AD Privileged Identity Management (PIM)

D.

a network security group (NSG)

Your on-premises network contains an Active Directory Domain Services (AD DS) domain.

You plan to sync the domain with a Microsoft Entra tenant by using Microsoft Entra Connect cloud sync.

You need to meet the following requirements:

• Install the software required to sync the domain and Microsoft Entra ID.

• Enable password hash synchronization.

What should you install, and what should you use to enable password hash synchronization? To answer, select the appropriate options in the answer area.

You have an Azure virtual machine named Server1 that runs a network management application. Server1 has the following network configuration.

* Network interface.Nic1

* IP address 10.1.1.1/24

* Connected to: Vnet1/Subnet1

You need connect Server1 to an additional subnet named Vnet1/Subnet2.

What should you do?

A.

Create a private endpoint on Subnet2

B.

Add a network interface to server1.

C.

Modify the IP configurations of Nic1.

D.

Add an IP configuration to Nic1.