AZ-801 Practice Questions
Prepare for AZ-801 with more than an answer.
Unlock the full exam and previous versions
- v1Administering Windows Server 150 questions Locked
- 98-365Legacy Windows Server Administration Fundamentals 364 questions Locked
- AZ-800Legacy Administering Windows Server Hybrid Core Infrastructure 215 questions Locked
- AZ-801Legacy Windows Server Hybrid Advanced Services 214 questions Current
- Exam fee
- $165 USD
- Level
- Associate
- Valid for
- 1 year
Domains covered on the exam 5
- Secure Windows Server on-premises and hybrid infrastructures27.5%
- Implement and manage Windows Server high availability17.5%
- Implement disaster recovery12.5%
- Migrate servers and workloads22.5%
- Monitor and troubleshoot Windows Server environments17.5%
- 1
You have onboarded your on-premises Windows Server 2019 file server to Azure using Azure Arc. You want to use Azure Policy to audit whether the server has the 'Password must meet complexity requirements' setting enabled. Which of the following components is required to achieve this?
Show answer details
Correct answer: B
Azure Policy Guest Configuration is the feature that allows Azure Policy to audit or configure settings inside a virtual machine or an Arc-enabled server. The Guest Configuration extension must be installed on the Arc-enabled server to enable this functionality.
- 2
An administrator at TerraNova Logistics has accidentally deleted a critical Organizational Unit (OU) named 'LogisticsFleet' which contained several hundred computer and user accounts. The Active Directory Recycle Bin is enabled in their Windows Server 2019 forest. The administrator needs to restore the OU and all the objects it contained, ensuring that all group memberships and object attributes are restored to their state just before deletion. Which tool or method should be used to accomplish this most effectively?
Show answer details
Correct answer: C
The Active Directory Administrative Center (ADAC) provides a graphical interface for the AD Recycle Bin. It allows you to navigate to the 'Deleted Objects' container, search for the deleted OU, and perform a recursive restore. This single action will restore the OU and all objects within it, preserving attributes and group memberships, making it the most effective method.
- 3
A manufacturing company is migrating a multi-tier application from on-premises to Azure. The application consists of several web servers and a backend database server, all running on Windows Server. The migration team is using Azure Migrate for the migration. They need to ensure that during a test failover and the final migration, the virtual machines start in the correct order: the database server must start first, followed by the web servers. How should this be configured?
Show answer details
Correct answer: B
This is the correct method. Azure Migrate uses Azure Site Recovery for replication and failover. Within ASR, you can create a Recovery Plan to orchestrate the failover of multiple machines. The plan allows you to place VMs into different groups. All VMs in Group 1 will start before Group 2, and so on. The database server would be placed in Group 1 and the web servers in Group 2.
- 4
A security administrator is hardening domain controllers according to a new security policy. The policy requires that high-privilege accounts, such as members of Domain Admins, can only authenticate to a specific set of hosts (domain controllers and bastion hosts). Furthermore, the Kerberos Ticket-Granting Ticket (TGT) lifetime for these accounts must be restricted to two hours. Which Active Directory feature should be used to enforce both of these requirements?
Show answer details
Correct answer: B
Authentication Policy Silos are specifically designed for this purpose. A silo is a container to which you can assign user accounts, computer accounts, and managed service accounts. You can then create authentication policies that apply to the members of the silo, which can restrict where accounts can authenticate from and configure specific Kerberos TGT lifetimes.
- 5
You are configuring a Windows Server failover cluster. The
Validate a Configurationwizard reports a warning for the network configuration, stating 'Node A is reachable from Node B by only one pair of interfaces'. You have confirmed that both nodes have two network adapters connected to two separate subnets intended for cluster use. What is the most likely cause of this warning?graph TD subgraph Cluster Network NodeA[Node A] -- "NIC1: 10.10.1.10/24" --> Switch1[Subnet 10.10.1.0/24] NodeA -- "NIC2: 10.10.2.10/24" --> Switch2[Subnet 10.10.2.0/24] NodeB[Node B] -- "NIC1: 10.10.1.11/24" --> Switch1 NodeB -- "NIC2: 10.10.2.11/24" --> Switch2 end subgraph Warning ValidationWarning{Validation Warning: Redundant communication path not found} end NodeA --> ValidationWarning NodeB --> ValidationWarningShow answer details
Correct answer: C
This is a common cause for this warning. For a network path to be considered fully available for cluster communication, both 'Client for Microsoft Networks' and 'File and Printer Sharing for Microsoft Networks' must be enabled on the adapters. If one of these is disabled, the cluster cannot use that path for all required communications, leading to a redundancy warning.
- 6
A financial services company is securing its on-premises Active Directory. A primary requirement is to prevent users from setting passwords that contain company-specific terms like 'Aperture' or 'QuantumFund', in addition to globally weak passwords. The domain controllers are in an isolated network segment without direct internet access. A member server, 'PROXY01', is located in a DMZ with internet access. Which sequence of actions correctly implements Microsoft Entra Password Protection for the on-premises environment?
Show answer details
Correct answer: A
This is the correct architecture. The DC agents on the isolated domain controllers communicate with the proxy service in the DMZ. The proxy service, which has internet access, then communicates with Azure AD to download the global and custom banned password lists. The proxy must be registered with Azure AD to establish this connection.
- 7
A migration specialist is using the Storage Migration Service (SMS) to move a legacy Windows Server 2012 R2 file server to an Azure VM running Windows Server 2022. The initial data transfer is complete, and the specialist is preparing for the final cutover. The source server's name is 'OLD-FS' and the new Azure VM's name is 'NEW-FS-AZ'. The goal is to perform the cutover with the least possible disruption to users who are mapped to
\\OLD-FS\Shares. What is a critical prerequisite for the SMS cutover phase to succeed in renaming the servers and assuming the source server's identity?Show answer details
Correct answer: C
This is the correct answer. The SMS Orchestrator needs delegated permissions in Active Directory to rename the source computer, rename the destination computer to the source's original name, and manage their service principal names (SPNs). Granting the orchestrator's computer object these permissions is a key prerequisite for the cutover to work seamlessly.
- 8
A systems administrator is designing a stretched failover cluster for a critical SQL Server workload that spans two physical datacenters, SiteA and SiteB. Each site has two cluster nodes. To maintain quorum during a site failure, a witness is required. The company has a strong preference for using Azure-based services to minimize on-premises infrastructure. The connection to Azure is reliable but subject to occasional latency spikes. Which witness type should be configured for the highest resilience in this scenario?
Show answer details
Correct answer: C
A Cloud Witness is the best solution for this scenario. It fulfills the requirement of using an Azure service, requires no on-premises infrastructure, and is specifically designed for multi-site clusters. It acts as the tie-breaker for quorum decisions and is resilient to latency spikes as it only requires minimal bandwidth and periodic access.
- 9
A security team is performing an audit on a hybrid Active Directory environment. They discover that several legacy applications still use NTLMv1 for authentication, which is non-compliant with security policies. The team's goal is to identify all devices and accounts using NTLM and eventually block it. Which Group Policy setting is the first and most critical step to gather this information without disrupting services?
Show answer details
Correct answer: D
This is the correct first step. Enabling this policy in audit mode will log NTLM authentication attempts in the event log (specifically, event ID 8004 in the NTLM operational log) without blocking them. This allows administrators to identify which clients, servers, and accounts are using NTLM so they can be remediated before enforcement policies are enabled.
- 10
You are troubleshooting a Windows Server 2022 boot failure. The server displays the error 'The Boot Configuration Data for your PC is missing or contains errors.' You have booted the server into the Windows Recovery Environment (WinRE). Which command-line utility should you use to scan for all Windows installations and add them to the boot configuration data?
Show answer details
Correct answer: D
The
bootrec /rebuildbcdcommand is the correct tool for this task. It scans all disks for installations of Windows that are compatible with the current operating system and provides an option to add them to the BCD store, effectively rebuilding the boot list.
