Skip to content

AZ-800 Practice Questions

Prepare for AZ-800 with more than an answer.

215 questions in the full set20 sample questionsUpdated Oct 2, 2026

Unlock the full exam and previous versions

  • v1Administering Windows Server 150 questions Locked
  • 98-365Legacy Windows Server Administration Fundamentals 364 questions Locked
  • AZ-800Legacy Administering Windows Server Hybrid Core Infrastructure 215 questions Current
  • AZ-801Legacy Windows Server Hybrid Advanced Services 214 questions Locked
Exam fee
$165 USD
Level
Associate
Valid for
1 year
Domains covered on the exam 5
  1. Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments32.5%
  2. Manage Windows Servers and workloads in a hybrid environment12.5%
  3. Manage virtual machines and containers17.5%
  4. Implement and manage an on-premises and hybrid networking infrastructure17.5%
  5. Manage storage and file services17.5%
  1. 1

    Your company is implementing SMB over QUIC to provide secure file share access for remote users without requiring a traditional VPN. Which of the following are prerequisites for configuring SMB over QUIC on a Windows Server 2022 file server? (Select THREE)

    Show answer details

    Correct answer: B, C, F

    For SMB over QUIC, the SMB server must run Windows Server 2022 Datacenter: Azure Edition or any edition of Windows Server 2025, so on Windows Server 2022 the Azure Edition is required. The QUIC tunnel uses TLS 1.3, so the server needs a certificate from a PKI such as AD CS or a trusted third-party CA, with subject alternative names that match the names clients use. The client must be a Windows 11 device. Joining an Active Directory domain is recommended but not required: a workgroup server can use local user accounts with NTLM. Neither Web Application Proxy nor Azure Arc management is a prerequisite.

    For SMB over QUIC, the SMB server must run Windows Server 2022 Datacenter: Azure Edition or any edition of Windows Server 2025, so on Windows Server 2022 the Azure Edition is required. The QUIC tunnel uses TLS 1.3, so the server needs a certificate from a PKI such as AD CS or a trusted third-party CA, with subject alternative names that match the names clients use. The client must be a Windows 11 device. Joining an Active Directory domain is recommended but not required: a workgroup server can use local user accounts with NTLM. Neither Web Application Proxy nor Azure Arc management is a prerequisite.

    For SMB over QUIC, the SMB server must run Windows Server 2022 Datacenter: Azure Edition or any edition of Windows Server 2025, so on Windows Server 2022 the Azure Edition is required. The QUIC tunnel uses TLS 1.3, so the server needs a certificate from a PKI such as AD CS or a trusted third-party CA, with subject alternative names that match the names clients use. The client must be a Windows 11 device. Joining an Active Directory domain is recommended but not required: a workgroup server can use local user accounts with NTLM. Neither Web Application Proxy nor Azure Arc management is a prerequisite.

  2. 2

    You are configuring a DHCP server to provide high availability using the load balancing failover mode. What percentage of leases will each server handle by default when you configure this relationship?

    Show answer details

    Correct answer: A

    In load balancing mode for DHCP failover, the client leases from a scope are distributed evenly between the two servers. The default configuration is a 50/50 split, meaning each server is responsible for handing out half of the available addresses.

  3. 3

    A university maintains two datacenters with a high-speed, low-latency connection. They want to implement a storage solution for their Hyper-V cluster that automatically replicates block-level data for a specific volume from a server in the primary datacenter to a server in the secondary datacenter. If the primary server fails, they need to be able to manually fail over the storage to the secondary server. The solution must be synchronous. Which Windows Server feature should they implement?

    Show answer details

    Correct answer: D

    Storage Replica is the correct feature for this scenario. It provides block-level, volume-based replication between servers or clusters for disaster recovery. It supports synchronous replication, which is suitable for low-latency networks and ensures zero data loss at the file-system level during a failure. The scenario describes a server-to-server replication setup where a manual failover can be initiated. DFS-R is file-level, Hyper-V Replica is VM-level, and S2D is a hyperconverged solution, not a simple replication feature.

  4. 4

    You are configuring a new Azure VM Scale Set for a web application. The application needs to be highly available and resilient to a datacenter-level failure within an Azure region. How should you configure the scale set's availability options?

    Show answer details

    Correct answer: B

    To protect against a datacenter-level failure, you must use Availability Zones. An Availability Zone is a physically separate datacenter within an Azure region. By deploying the VM Scale Set across multiple zones (e.g., Zone 1, 2, and 3), you ensure that if one datacenter goes down, the instances in the other zones remain operational. An Availability Set only protects against hardware failures within a single datacenter (rack or server failure), not a full datacenter outage.

  5. 5

    As a Hyper-V administrator, you need to provide virtual machines with a highly available connection to the corporate network. The Hyper-V host has two 10 GbE physical network adapters. The solution must provide transparent failover for the VMs and also allow the host management operating system to share the same redundant connection. Which configuration is the most appropriate and modern solution?

    graph TD subgraph Hyper-V Host VM1 --- vSwitch VM2 --- vSwitch ManagementOS --- vSwitch end vSwitch ---|Team| pNIC1[Physical NIC 1] vSwitch ---|Team| pNIC2[Physical NIC 2] pNIC1 --- CorpNet[(Corporate Network)] pNIC2 --- CorpNet
    Show answer details

    Correct answer: A

    Switch Embedded Teaming (SET) is the recommended technology for teaming NICs in Hyper-V environments running Windows Server 2016 and later. It integrates teaming functionality directly into the Hyper-V Virtual Switch. This approach allows you to create an External switch bound to the SET, providing redundant, load-balanced connectivity for both the virtual machines and the management operating system.

  6. 6

    A financial services firm, Woodgrove Bank, is deploying a new Active Directory forest. For security reasons, they need to ensure that the administrator who installs a new Read-Only Domain Controller (RODC) in a branch office cannot use their own credentials to install other domain controllers in the forest. Which approach meets this requirement while adhering to the principle of least privilege?

    Show answer details

    Correct answer: B

    This method, known as a staged RODC installation, is the most secure approach. A member of the Domain Admins group pre-creates the RODC account and specifies which user or group has the permission to attach a server to that account. This delegates the exact permission needed without granting excessive rights like Domain Admin membership. The branch administrator can then complete the installation without needing high-level domain credentials.

  7. 7

    You are managing a hybrid environment for an e-commerce company. You need to ensure that password changes made by users on-premises are validated against the Microsoft global banned password list and your organization's custom banned password list in Azure AD before the change is committed to the on-premises Active Directory. Which TWO components are required to implement this functionality? (Select TWO)

    Show answer details

    Correct answer: A, B

    Microsoft Entra (Azure AD) Password Protection for AD DS uses two on-premises components. The DC agent (a password filter DLL plus the DC Agent service) must be installed on every domain controller, because the policy is enforced only on DCs that run it; it accepts or rejects each password change locally by using the most recently downloaded policy, which combines Microsoft's global banned password list with the tenant's custom banned password list and is cached in SYSVOL. The proxy service runs on a domain-joined member server and forwards the DC agents' policy download requests to Microsoft Entra ID, so domain controllers never need internet access and clear-text passwords never leave the DC. Password writeback, AD FS, and the Application Proxy connector aren't required.

    Microsoft Entra (Azure AD) Password Protection for AD DS uses two on-premises components. The DC agent (a password filter DLL plus the DC Agent service) must be installed on every domain controller, because the policy is enforced only on DCs that run it; it accepts or rejects each password change locally by using the most recently downloaded policy, which combines Microsoft's global banned password list with the tenant's custom banned password list and is cached in SYSVOL. The proxy service runs on a domain-joined member server and forwards the DC agents' policy download requests to Microsoft Entra ID, so domain controllers never need internet access and clear-text passwords never leave the DC. Password writeback, AD FS, and the Application Proxy connector aren't required.

  8. 8

    A manufacturing company uses Hyper-V for their on-premises virtualization. They have a critical legacy application running on a Windows Server 2016 VM that is not compatible with modern backup agents. The company needs to create application-consistent backups of this VM. You discover that the VM's VSS writers are functioning correctly. Which type of checkpoint should you use to facilitate the backup process?

    Show answer details

    Correct answer: B

    Production checkpoints use the Volume Shadow Copy Service (VSS) inside a Windows guest (File System Freeze on Linux) to create a data-consistent, application-consistent point-in-time image of the VM without capturing memory state, which is appropriate for production workloads and backup scenarios. Standard checkpoints capture the VM's disks together with its memory state, so applications are restored mid-operation; they're intended for development and test and aren't application-consistent. Production is the default checkpoint type (Set-VM -CheckpointType Production, ProductionOnly, Standard, or Disabled). 'Recovery' checkpoints are created internally by backup applications such as DPM rather than chosen by the administrator, and 'Application-Aware Checkpoint' isn't a Hyper-V checkpoint type.

  9. 9

    An administrator is configuring Storage Spaces on a Windows Server 2022 file server using twelve 4 TB SAS drives. The primary goal is to provide the best possible I/O performance for a database workload while also providing protection against a two-drive failure. Which Storage Spaces configuration should be implemented?

    Show answer details

    Correct answer: B

    For a performance-sensitive database workload that must survive two simultaneous drive failures, use a three-way mirror space. Microsoft recommends mirroring for all workloads and parity for sequential workloads such as archival. A three-way mirror keeps three copies of the data, tolerates two drive failures, and requires at least five physical disks (twelve are available). Mirror-accelerated parity combines mirror and parity in one ReFS volume, but in Windows Server it's supported only on Storage Spaces Direct and recommended only for archival and backup workloads. Dual parity also tolerates two failures but has much lower random-write performance, and a simple space has no resiliency.

  10. 10

    You are troubleshooting DNS resolution in a hybrid environment. An on-premises server (10.10.1.5) needs to resolve the name of an Azure VM (vm1.corp.azure) which is registered in an Azure Private DNS zone. The on-premises DNS server has a conditional forwarder for corp.azure pointing to an Azure DNS Private Resolver. However, resolution is failing. Which PowerShell command would you run on the on-premises DNS server to begin troubleshooting?

    Show answer details

    Correct answer: C

    The first step in troubleshooting a conditional forwarder is to verify network connectivity from the on-premises DNS server to the target resolver on the required port. The Test-NetConnection cmdlet is the correct tool for this. It will confirm whether the on-premises DNS server can reach the Azure DNS Private Resolver over port 53 (DNS). If this test fails, the issue is likely a firewall rule, a network security group (NSG) in Azure, or a routing problem over the VPN/ExpressRoute connection.

Create an account to continue.