[Jun-2026] AZ-800 PDF Dumps Extremely Quick Way Of Preparation
Download AZ-800 Dumps (2026) - Free PDF Exam Demo
The Microsoft AZ-800 exam covers a range of topics, including implementing and managing hybrid identity, managing hybrid compute, implementing and managing hybrid storage solutions, and monitoring and maintaining hybrid environments. Administering Windows Server Hybrid Core Infrastructure certification is ideal for IT professionals who are looking to enhance their skills in managing and maintaining hybrid environments.
NEW QUESTION # 138
You have two servers that have the Hyper-V server role installed. The servers are joined to a failover cluster both servers can connect to the same disk on an iSCSi storage device. You plan to use the iSCSI storage to store highly available Hyper-V virtual machines that will support live migration functionality. You need to configure a storage resource in the failover cluster to store the virtual machines.
What should you configure?
- A. a mirrored volume
- B. a storage pool
- C. attributed File System (DFS) Replication
- D. Cluster Shared volumes (CSV)
Answer: D
NEW QUESTION # 139
You have servers that run Windows Server 2022 as shown in the following table.
Server2 contains a .NET app named App1.
You need to establish a WebSocket connection from App1 to the SQL Server instance on Server!. The solution must meet the following requirements:
* Minimize the number of network ports that must be open on the on-premises network firewall.
* Minimize administrative effort.
What should you create first?
- A. an Azure VPN gateway
- B. a hybrid connection
- C. an Azure Relay namespace
- D. a WFC relay connection
Answer: B
NEW QUESTION # 140
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. You plan deploy 100 new Azure virtual machines that will run Windows Server. You need to ensure that each new virtual machine is joined to the AD DS domain. What should you use?
- A. an Azure management group
- B. an Azure Resource Manager (ARM) template
- C. a Group Policy Object (GPO)
- D. Azure AD Connect
Answer: B
Explanation:
Reference:
https://www.ludovicmedard.com/create-an-arm-template-of-a-virtual-machine-automatically-joined-to-a-domain/
NEW QUESTION # 141
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.
You open a new branch office that contains only client computers.
You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.
Solution: You create a new site named Site4 and associate Site4 to DEFAULTIPSITELINK.
Does this meet the goal?
- A. Yes
- B. No
Answer: B
NEW QUESTION # 142
Drag and Drop Question
Your network contains two Active Directory Domain Services (AD DS) forests named contoso.com and fabrikam.com. Contoso.com contains three child domains named amer.contoso.com, apac.contoso.com, and emea.contoso.com. Fabrikam.com contains a child domain named apac.fabrikam.com. A bidirectional forest trust exists between contoso.com and fabrikam.com.
You need to provide users in the contoso.com forest with access to the resources in the fabrikam.com forest. The solution must meet the following requirements:
- Users in contoso.com must only be added directly to groups in the
contoso.com forest.
- Permissions to access the resources in fabrikam.com must only be
granted directly to groups in the fabrikam.com forest.
- The number of groups must be minimized.
Which type of groups should you use to organize the users and to assign permissions? To answer, drag the appropriate group types to the correct requirements. Each group may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 143
You have an on-premises server named Server 1 that runs Windows Server. Server 1 contains a file share named Share 1.
You have an Azure subscription.
You perform the following actions:
* Deploy Azure File Sync
* Install the Azure File Sync agent on Server1.
* Register Server1 with Azure File Sync
You need to ensure that you can add Share1 as an Azure File Sync server endpoint.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation:
NEW QUESTION # 144
Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com The domain contains a server named Server1 and the users shown In the following table.
Server1 contains a folder named D:\Folder1. The advanced security settings for Folder 1 are configured as shown in the Permissions exhibit. (Click the Permissions lab.)
Folder1 is shared by using the following configurations


Answer:
Explanation:
Explanation:
NEW QUESTION # 145
You have an on-premises server named Server1 that runs Windows Server 2022 and is a container host.
You have an Azure subscription.
You plan to develop custom container images.
You need to recommend a storage solution for the containers. The solution must meet the following requirements:
- Support the use of Docker commands.
- Minimize administrative effort
What should you include in the recommendation?
- A. Azure Container Registry
- B. Azure Container instances
- C. Azure Kubernetes Service (AKS)
- D. Azure Files
Answer: A
Explanation:
You can deploy a custom-configured Windows image from Visual Studio to make OS changes that your app needs. This makes it easy to migrate an on-premises app that requires a custom OS and software configuration.
Publish to Azure Container Registry
Azure Container Registry can store your images for container deployments. You can configure App Service to use images that are hosted in Azure Container Registry.
Reference:
https://learn.microsoft.com/en-us/azure/app-service/tutorial-custom-container
NEW QUESTION # 146
You have a file server named Server1 that runs Windows Server and contains the volumes shown in the following table.
On which volumes can you use BitLocker Drive Encryption (BitLocker) and disk quotas? To answer select the appropriate options in the answer are a. NOTE Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/storage/refs/refs-overview
NEW QUESTION # 147
You need to configure remote administration to meet the security requirements. What should you use?
- A. the Remote Desktop extension for Azure Cloud Services
- B. just in time (JIT) VM access
- C. an Azure Bastion host
- D. Azure AD Privileged Identity Management (PIM)
Answer: B
NEW QUESTION # 148
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains a server named Server1 that has the DFS Namespaces role service installed. Server! hosts a domain-based Distributed File System (DFS) Namespace named Files.
The domain contains a tile server named Server2. Seiver2 contains a shared folder named Share1. Share1 contains a subfolder named Folder 1.
In the Files namespace, you create a folder named Folder! that has a target of
\\Server2.contoso.com\Share1\Folder1.
You need to configure a logon script that will map drive letter M to Folder1. The solution must use the path of the DFS Namespace.
How should you complete the command to map the drive letter? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 149
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The root domain contains the domain controllers shown in the following table.
A failure of which domain controller will prevent you from creating application partitions?
- A. DC5
- B. DC3
- C. DC4
- D. DC1
- E. DC2
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/fsmo-roles
NEW QUESTION # 150
You have a server named Server1 that runs Windows Server. The disks on Server1 are configured as shown in the following exhibit.
You need to convert volume E to ReFS. The solution must meet the following requirements:
* Preserve the existing data on volume E.
* Minimize administrative effort.
What should you do first?
- A. Convert Disk 2 to a dynamic disk.
- B. Runconvert.exe.
- C. Back up the data on volume E.
- D. Take Disk 2 offline.
Answer: C
NEW QUESTION # 151
You have an Azure subscription that contains a virtual machine named VM1 as shown in the following exhibit.
The subscription has the disks shown in the following table.
Which disks can you attach as data disks to VM1?
- A. Disk2 and Disk4 only
- B. Disk4 only
- C. Disk2 only
- D. Disk1 and Disk2 only
- E. Disk1, Disk3, and Disk4 only
- F. Disk1, Disk2, Disk3. and Disk4
Answer: D
NEW QUESTION # 152
You have a server named Server1 that runs Windows Server and has the Hyper V server role installed. Server1 hosts a virtual machine named VM1.
Server1 has an NVMe storage device. The device is currently assigned to VM1 by using Discrete Device Assignment.
You need to make the device available to Server1.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation:
Graphical user interface, application Description automatically generated
Reference:
https://docs.microsoft.com/en-us/windows-server/virtualization/hyper-v/deploy/deploying-storage-devices-using
NEW QUESTION # 153
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains a child domain named east.contoso.com.
in the contoso.com domain, you create two users named Admin1 and Admin2.
You need to ensure that the users can perform the following tasks:
* Admin1 can create and manage Active Directory sites.
* Admin2 can deploy domain controller to the easl.conloso.com domain.
The solution must use the principle of least privilege.
To which group should you add each user? To answer, select the appropriate options in the answer area.
NOTE Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/remote/remote-access/ras/multisite/configure/step-2-configure-the-multisite-infrastructure
NEW QUESTION # 154
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are planning the deployment of DNS to a new network.
You have three internal DNS servers as shown in the following table.
The contoso.local zone contains zone delegations for east.conloso.local and west.contoso.local. All the DNS servers use root hints.
You need to ensure that all the DNS servers can resolve the names of all the internal namespaces and internet hosts.
Solution: On Server2 and Server3, you configure a conditional forwarder for contoso.local.
Does this meet the goal?
- A. Yes
- B. No
Answer: B
Explanation:
Explanation
https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-r2-and-2008/cc794735
NEW QUESTION # 155
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains a child domain named east.contoso.com.
in the contoso.com domain, you create two users named Admin1 and Admin2.
You need to ensure that the users can perform the following tasks:
* Admin1 can create and manage Active Directory sites.
* Admin2 can deploy domain controller to the easl.conloso.com domain.
The solution must use the principle of least privilege.
To which group should you add each user? To answer, select the appropriate options in the answer area.
NOTE Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/remote/remote-access/ras/multisite/configure/step-2-configure-the-multisite-infrastructure
NEW QUESTION # 156
You have an Active Directory Domain Services (AD DS) domain that contains the domain controllers shown in the following table.
The domain contains an app named App1 that uses a custom application partition to store configuration data.
You decommission App1.
When you attempt to remove the custom application partition, the process fails.
Which domain controller is unavailable?
- A. DC4
- B. DC2
- C. DC3
- D. DC1
Answer: C
NEW QUESTION # 157
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
No
Yes
Yes
In Administering Windows Server Hybrid Core Infrastructure, Microsoft states that the domain password policy for domain user accounts is determined by the GPO that wins at the domain root (commonly the Default Domain Policy). GPOs linked to OUs do not change the domain password policy for user accounts in those OUs; they only affect local accounts on computers within those OUs unless Fine- Grained Password Policies (PSOs) are used and scoped to users/groups. The case shows Default Domain Policy in contoso.com sets Minimum password length = 10. Therefore, both Admin1 (a domain user in Contoso\OU1) and User1 (in Contoso\OU3) fall under the 10-character minimum; the OU-linked GPO1 (14) does not override the domain password policy for their domain accounts # Admin1: No, User1: Yes.
For member servers and local accounts, the documentation explains that password policy settings in a GPO linked to the OU containing the computer apply to that computer's local Security Accounts Manager (SAM). In the scenario, Server1 resides in Member Servers and GPO2 linked to Member Servers specifies Minimum password length = 8. Thus, when Admin1 creates a local account on Server1, the enforced minimum is 8 characters # Yes. This approach follows least privilege and standard precedence: domain-level for domain accounts, OU-linked GPOs for local accounts, unless PSOs are explicitly defined.
Topic 3, Datum CorporationA. Datum Corporation is a
manufacturing company that has a main office in Seattle and two
branch offices in Los Angeles and Montreal.
A Datum recently partnered with a company named Fabrikam, Inc.
Fabrikam is a manufacturing company that has a main office in Boston and a branch office in Orlando.
Both companies intend to collaborate on several joint projects.
The on-premises network of A. Datum contains an Active Directory Domain Services (AD DS) forest named adatum.com.
The forest contains two domains named adatum.com and east.adatum.com and the domain controllers shown in the following table.
The on-premises network of Fabrikam contains an AD DS forest named fabrikam.com.
The forest contains two domains named fabrikam.com and south.fabrikam.com.
The fabrikam.com domain contains an organizational unit (OU) named Marketing.
The adatum.com domain contains the servers shown in the following table.
HyperV1 contains the virtual machines shown in the following table.
All the virtual machines on HyperV1 have only the default management tools installed.
SSPace1 contains the Storage Spaces virtual disks shown in the following table.
A Datum has an Azure subscription that contains a Microsoft Entra tenant. Microsoft Entra Connect is configured to sync the adatum.com forest with Microsoft Entra ID.
The subscription contains the virtual networks shown in the following table.
The subscription contains the Azure Private DNS zones shown in the following table.
The subscription contains the virtual machines shown in the following table.
All the servers are in a workgroup.
The subscription contains a storage account named storage1 that has a file share named share1.
A Datum plans to implement the following changes:
* Sync Data1 to share1.
* Configure an Azure runbook named Task1.
* Enable Microsoft Entra users to sign in to Server1.
* Create an Azure DNS Private Resolver that has the following configurations:
o Name: Private1
o Region: West US
o Virtual network: VNet1
o Inbound endpoint: SubnetB
* Enable users in the adatum.com domain to access the resources in the south.fabrikam.com domain.
A Datum identifies the following technical requirements:
* The data on SSPace1 must be available always.
* DC2 must become the schema master if DC1 fails.
* VMS must be configured to enable per-folder quotas.
* Trusts must allow access to only the required resources.
* The users in the Marketing OU must have access to storage!
* Azure Automanage must be used on all supported Azure virtual machines.
* A direct SSH session must be used to manage all the supported virtual machines on HyperV1.
NEW QUESTION # 158
Your network contains an Active Domain Services (AD DS) forest. The forest contains three domains. Each domain contains 10 domain controllers.
You plan to store a DNS zone in a custom active Directory partition.
You need to create the Active Directory partition for the zone. The partition replicate to only four of the domain controllers.
What should you use?
- A. DNS Manager
- B. dnscmd.exe
- C. Active Directory Administrator Center
- D. Active Directory Sites and Services
Answer: B
NEW QUESTION # 159
You need to configure network communication between the Seattle and New York offices. The solution must meet the networking requirements.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/virtual-wan/virtual-wan-expressroute-portal
NEW QUESTION # 160
You have a Windows Server 2022 container host named Host1 and a container registry that contains the container images shown in the following table.
You need to run the containers on Host1
Which isolation mode can you use for each image? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
In the Windows Server container topic of Administering Windows Server Hybrid Core Infrastructure, Microsoft states the behavior of the two Windows container isolation modes very clearly:
* Process isolation: "Windows Server containers run with process isolation and share the kernel with the host. Because the container uses the host's kernel, the container base image must match the host OS version (including build) for the container to start."
* Hyper-V isolation: "With Hyper-V isolated containers, each container runs inside a lightweight virtual machine that has its own kernel, providing kernel-level isolation. Hyper-V isolation removes the requirement for the container image version to match the host, allowing older or different Windows versions to run on a newer host." Applying those rules to Host1 (Windows Server 2022):
* Image1 (Windows Server 2022) matches the host version. Therefore, it can run with process isolation (kernel shared and versions match). Hyper-V isolation is always available as well, so either process or Hyper-V isolation can be used.
* Image2 (Windows Server 2019) does not match the host's kernel version. With process isolation this mismatch prevents startup. However, Hyper-V isolation provides its own kernel boundary, so the container can run only with Hyper-V isolation.
Thus, the correct selections are: Image1 - Hyper-V isolation or process isolation; Image2 - Hyper-V isolation only.
NEW QUESTION # 161
You have an Azure subscription that contains a virtual network named VNet1. Vnet1 contains three subnets named Subnet1, Subnet2, and Subnet3. You deploy a virtual machine that has the following settings:
* Name:VM1
* Subnet: Subnet2
* Network interface name: NIC1
* Operating system: Windows Server 2022
You need to ensure that VM1 can route traffic between Subnet1 and Subnet3. The solution must minimize administrative effort.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
<From the Azure portal: Enable IP forwarding for NIC1.
On VM1: Install and configure Routing and Remote Access
In Azure VNets, layer-3 routing between subnets is provided by the platform, but if you want a VM to act as a router (NVA) and forward traffic between subnets, two things are required: the NIC must be allowed to pass traffic not destined to itself, and the guest OS must be configured to perform IP forwarding/routing. The Administering Windows Server Hybrid Core Infrastructure guidance for "Manage and maintain Windows Server IaaS virtual machines" and "Implement on-premises and hybrid networking" explains that Azure requires IP forwarding to be enabled on the NIC for any VM acting as a router or load balancer so that the fabric will deliver transit packets to the VM instead of dropping them. The Windows Server role that provides routing is Routing and Remote Access (RRAS); enabling the LAN routing feature configures the TCP/IP stack to forward packets between interfaces (including forwarding back out the same interface when used with Azure's virtual switch). The same material notes that adding extra NICs is not mandatory for simple transit scenarios, and that user-defined routes can be used when you need to steer traffic through the router; however, to enable the VM itself to route, the minimal administrative steps are: turn on IP forwarding for the NIC in Azure and install/configure RRAS in the guest. This combination allows VM1 to route traffic between Subnet1 and Subnet3 with the least effort.
NEW QUESTION # 162
Which groups can you add lo Group3 and Groups? To answer, select the appropriate options in the answer area. NOTE Each correct selection is worth one point.
Answer:
Explanation:
Explanation
NEW QUESTION # 163
......
Microsoft AZ-800 certification exam is designed to test your skills and knowledge in administering Windows Server Hybrid Core Infrastructure. Administering Windows Server Hybrid Core Infrastructure certification is intended for IT professionals who are responsible for managing and maintaining hybrid environments that include both on-premises and cloud-based components. AZ-800 exam will measure your ability to deploy, manage, and monitor hybrid infrastructure, as well as your understanding of key concepts related to hybrid cloud computing.
Enhance your career with AZ-800 PDF Dumps - True Microsoft Exam Questions: https://examcollection.actualcollection.com/AZ-800-exam-questions.html