Microsoft AZ-801 Exam Preparation Guide and PDF Download Verified Correct AZ-801 Practice Test Reliable Source Aug 08, 2026 Updated Microsoft AZ-801 certification exam is intended for experienced IT professionals who are looking to validate their skills and knowledge in Windows Server hybrid advanced services. Candidates must have a minimum of three years of experience in managing Windows Server technologies [...]

Microsoft AZ-801 Exam Preparation Guide and PDF Download [Q52-Q72]

Share

Microsoft AZ-801 Exam Preparation Guide and PDF Download

Verified & Correct AZ-801 Practice Test Reliable Source Aug 08, 2026 Updated


Microsoft AZ-801 certification exam is intended for experienced IT professionals who are looking to validate their skills and knowledge in Windows Server hybrid advanced services. Candidates must have a minimum of three years of experience in managing Windows Server technologies and should be proficient in deploying and configuring cloud-based solutions. AZ-801 exam is also suitable for professionals who are seeking to advance their careers in the IT industry and enhance their expertise in cloud-based technologies.


Microsoft AZ-801 certification exam is a challenging but rewarding certification for IT professionals who work with Windows Server and Azure technologies. It validates the candidate's knowledge and skills in configuring and managing hybrid environments, and demonstrates their ability to deploy and manage advanced services. Passing AZ-801 exam is an essential step for anyone looking to advance their career in the IT industry.

 

NEW QUESTION # 52
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the servers shown in the following table.

You need to migrate Site1 from Server 1 to Server2. The solution must meet the following requirements:
* Minimize how long it takes to perform the migration.
* Minimize administrative effort.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of cations to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation:


NEW QUESTION # 53
Case Study 2 - Contoso, Ltd
Overview
Contoso, Ltd. is a manufacturing company that has a main office in Seattle and branch offices in Los Angeles and Montreal.
Existing Environment
Active Directory Environment
Contoso has an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with an Azure Active Directory (Azure AD) tenant. The AD DS domain contains the domain controllers shown in the following table.

Contoso recently purchased an Azure subscription.
The functional level of the forest is Windows Server 2012 R2. The functional level of the domain is Windows Server 2012. The forest has the Active Directory Recycle Bin enabled.
The contoso.com domain contains the users shown in the following table.

The contoso.com domain has the Group Policy Objects (GPOs) shown in the following table.

The contoso.com domain has the Password Settings Objects (PSOs) shown in the following table.

Server Infrastructure
The contoso.com domain contains servers that run Windows Server 2022 as shown in the following table.

By using Windows Firewall with Advanced Security, the servers have isolation connection security rules configured as shown in the following table.

Server4 has no connection security rules.
Server4 Configurations
Server4 has the effective Group Policy settings for user rights as shown in the following table.

Server4 has the disk configurations shown in the following exhibit.

Virtualization Infrastructure
The contoso.com domain has the Hyper-V failover clusters shown in the following table.

Technical Requirements
Contoso identifies the following technical requirements:
* Promote a new server named DC4 that runs to Windows Server 2022 to a domain controller.
* Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault.
* Centrally manage performance alerts in Azure for all the domain controllers.
* Ensure that User1 can recover objects from the Active Directory Recycle Bin.
* Migrate Share1 to Server2, including all the share and folder permissions.
* Back up Server4 and all data to an Azure Recovery Services vault.
* Use Hyper-V Replica to protect the virtual machines in Cluster3.
* Implement BitLocker Drive Encryption (BitLocker) on Server4.
* Whenever possible, use the principle of least privilege.
Hotspot Question
With which servers can Server1 and Server3 communicate? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 54
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a server named Server1 that runs Windows Server.
You need to ensure that only specific applications can modify the data in protected folders on Server1.
Solution: From App & browser control, you configure the Exploit protection settings.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: A

Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/customize-controlled-folders?view=o365-worldwide


NEW QUESTION # 55
Hotspot Question
You have 50 on-premises servers that run Windows Server.
You have an Azure subscription that contains a Microsoft Sentinel workspace.
You plan to monitor the servers by using Microsoft Sentinel
You need to perform the following actions in Microsoft Sentinel from the Azure portal:
- Add the Windows Forwarded Events data connector.
- Create a playbook that has an incident trigger.
Which two settings should you use? To answer, select the appropriate settings in the answer area NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Data connectors
Ad the Windows Forwarded Events data connector.
To add the Windows Forwarded Events data connector to Microsoft Sentinel, navigate to Configuration > Data connectors, select the Windows Security Events via AMA connector, open the connector page, and follow the instructions to create a Data Collection Rule (DCR) that targets the desired servers and event logs using the Azure Monitor Agent (AMA).
Box 2: Automation
Create a playbook that has an incident trigger.
To create a Microsoft Sentinel playbook with an incident trigger, navigate to the Automation page in the Defender or Azure portal, select Create > Playbook with incident trigger, and then follow the wizard to provide basic information, establish connections (using the default managed identity), review the settings, and create the playbook. After creation, the playbook opens in the Logic Apps designer, where you can define the automation workflow.

Reference:
https://learn.microsoft.com/en-us/azure/sentinel/automation/create-playbooks


NEW QUESTION # 56
You have an Azure virtual machine named VM1. Crash dumps for a process named Process1 are enabled for VM1.
When process1.exe on VM1 crashes, a technician must access the memory dump files on the virtual machine. The technician must be prevented from accessing the virtual machine.
To what should you provide the technician access?

  • A. an Azure Blob Storage container
  • B. a managed disk
  • C. an Azure Log Analytics workspace
  • D. an Azure file share

Answer: A

Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/azure-monitor/agents/diagnostics-extension-overview


NEW QUESTION # 57
Hotspot Question
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.
You add a user named Admin1 to the domain.
You need to ensure that Admin1 can create a Data Collector Set on Server1. The solution must follow the principle of least privilege.
To which security group should you add Admin1, and what should Admin1 use to create the Data Collector Set? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Performance Log Users
To create Data Collector Sets on a server in an Active Directory domain, a user needs to be a member of the Performance Log Users security group. This group allows users to manage performance logs, counters, and alerts locally on the server, and they can also be granted the user right to "Log on as a batch job," which is necessary for managing Data Collector Sets.
Box 2: Performance Monitor
1. On the Start screen, type Performance Monitor, and then press Enter.
2. In the console tree, expand Data Collector Sets, right-click User Defined > New, and then click Data Collector Set. The Create New Data Collector Set wizard appears.
3. Etc.
Reference:
https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-groups#performance-log-users
https://docs.rackspace.com/docs/configure-active-directory-performance-monitoring


NEW QUESTION # 58
Hotspot Question
You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server.
The network interface for VM1 is disabled in the operating system.
You need to enable the network interface by using the Azure Serial Console.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: netsh.exe
Enable the Adapter:
In the Command Prompt, type the following command: netsh interface set interface "Ethernet" admin=enable.
The Ethernet is the default name for the adapter in Windows; if your adapter has a different name, you will need to use that name.
Box 2: interface
Reference:
https://www.youtube.com/watch?v=q3IJ1k7FnyU


NEW QUESTION # 59
Hotspot Question
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains two users named User1 and User2.
You use the following tools to manage Active Directory:
- Active Directory Users and Computers
- Active Directory Administrative Center
- Ntdsutil
- Ldp
You perform the actions shown in the following table.

What can you use to undelete each user? To answer, select the appropriate options in the answer area.

Answer:

Explanation:

Explanation:
Box 1: Ldp and Ntdsautil only
You can restore a deleted Active Directory (AD) object using the ldp.exe utility, but it requires manually changing the isDeleted attribute to restore the object from the tombstone period.
However, restoring with ldp.exe is a complex, legacy method; using Active Directory Administrative Center (dsac.exe) or PowerShell with the AD Recycle Bin enabled is the recommended and much simpler approach for restoring deleted objects.
* Ntdsutil
In Active Directory, ntdsutil is the command-line tool used to initiate an authoritative restore by entering the authoritative restore context and then selecting the appropriate backup data for the restoration.
Box 2: Active Directory Administrative Center only
To undelete a user in an AD DS domain with the Recycle Bin activated, open the Active Directory Administrative Center (ADAC), navigate to your domain's Deleted Objects container, right-click the deleted user, and select Restore or Restore to... to return the account to its original location.
After restoration, you will need to enable the account and reset its password.
Note: You can only restore AD DS items that were deleted after Active Directory Recycle Bin is enabled. You can't use Active Directory Recycle Bin to recover items that were deleted before enabling this functionality.
Reference:
https://learn.microsoft.com/en-us/troubleshoot/windows-server/active-directory/retore-deleted-accounts-and-groups-in-ad
https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/adac/active-directory-recycle-bin


NEW QUESTION # 60
You have two physical servers named AppSrv1 and AppSrv2 and an unconfigured server named Server1. All the servers run Windows Server. Only Server1 can access the internet.
You plan to use Azure Site Recovery to replicate AppSrv1 and AppSrv2 to Azure.
You need to deploy the required components to AppSrv1, AppSrv2, and Server1.
Which components should you deploy? To answer, drag the appropriate components to the correct servers. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/site-recovery/physical-azure-architecture
https://docs.microsoft.com/en-us/azure/site-recovery/physical-azure-set-up-source


NEW QUESTION # 61
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains an organizational unit (OU) named 0U1.0U1 contains servers that run sensitive workloads.
You plan to add connection security rules that meet the following requirements:
* The servers in OU 1 must only accept connections from domain-joined
* The servers in OU 1 must only be able to communicate with domain-joined You create a Group Policy Object (GPO) named GP01 and link GP01 to contoso.com.
You need to configure a connection security rule in GP01 by using Windows Defender Firewall with Advanced Security.
How should you configure the rule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 62
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a failover cluster named Cluster1.
You need to configure Cluster-Aware Updating (CAU) on the cluster by using Windows Admin Center (WAC).
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

1 - Add a group managed service account (gMSA).
2 - Add Cluster1 to WAC.
3 - Enable CredSSP.
Topic 1, Contoso, Ltd
Existing Environment
Active Directory Environment
Contoso has an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with an Azure Active Directory (Azure AD) tenant. The AD DS domain contains the domain controllers shown in the following table.

Contoso recently purchased an Azure subscription.
The functional level of the forest is Windows Server 2012 R2. The functional level of the domain is Windows Server 2012. The forest has the Active Directory Recycle Bin enabled.
The contoso.com domain contains the users shown in the following table.

The contoso.com domain has the Group Policy Objects (GPOs) shown in the following table.

The contoso.com domain has the Password Settings Objects (PSOs) shown in the following table.

Server Infrastructure
The contoso.com domain contains servers that run Windows Server 2022 as shown in the following table.

By using Windows Firewall with Advanced Security, the servers have isolation connection security rules configured as shown in the following table.

Server4 has no connection security rules.
Server4 Configurations
Server4 has the effective Group Policy settings for user rights as shown in the following table.

Server4 has the disk configurations shown in the following exhibit.

Virtualization Infrastructure
The contoso.com domain has the Hyper-V failover clusters shown in the following table.

Technical Requirements
Contoso identifies the following technical requirements:
Promote a new server named DC4 that runs to Windows Server 2022 to a domain controller.
Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault.
Centrally manage performance alerts in Azure for all the domain controllers.
Ensure that User1 can recover objects from the Active Directory Recycle Bin.
Migrate Share1 to Server2, including all the share and folder permissions.
Back up Server4 and all data to an Azure Recovery Services vault.
Use Hyper-V Replica to protect the virtual machines in Cluster3.
Implement BitLocker Drive Encryption (BitLocker) on Server4.
Whenever possible, use the principle of least privilege.


NEW QUESTION # 63
Your network contains an Active Directory Domain Services (AD DS) domain that has the Active Directory Recycle Bin enabled. All domain controllers are backed up daily.
You accidentally remove all the users from a domain group.
You need to get a list of the users that were previously in the group.
Which four actions should you perform in sequence from a domain controller? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation:

Reference:
http://sysadmindoc.blogspot.com/2018/10/mount-active-directory-database-from.html


NEW QUESTION # 64
You manage 200 physical servers that run Windows Server.
You plan to migrate the servers to Azure.
You need to prepare for discovery of the servers by using Azure Migrate.
Which three actions should you perform in sequence on a physical server? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation
Graphical user interface, text, application, email Description automatically generated

Reference:
https://docs.microsoft.com/en-us/azure/migrate/tutorial-discover-physical


NEW QUESTION # 65
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a failover cluster named Cluster1 that hosts an application named App1.
The General tab in App1 Properties is shown in the General exhibit. (Click the General tab.)

The Failover tab in App1 Properties is shown in the Failover exhibit. (Click the Failover tab.)

Server1 shuts down unexpectedly.
You need to ensure that when you start Server1, App1 continues to run on Server2.
Solution: You increase Maximum failures in the specified period for the App1 cluster role.
Does this meet the goal?

  • A. No
  • B. Yes

Answer: A

Explanation:
The Maximum failures setting is used to determine when the cluster determines that a node is offline. It does not affect whether a cluster will fail back when a node comes online.


NEW QUESTION # 66
You have a server that runs Windows Server.
You plan to back up the server to an Azure Recovery Services vault once per week starting on the next Saturday.
You need to schedule the weekly backup and perform the initial backup as soon as possible.
In which order should you perform the actions? To answer, move all actions from the list of actions to the answer are and arrange them in the correct order.

Answer:

Explanation:

Explanation
Text Description automatically generated with medium confidence

Reference:
https://docs.microsoft.com/en-us/azure/backup/install-mars-agent#download-the-mars-agent
https://docs.microsoft.com/en-us/azure/backup/backup-windows-with-mars-agent


NEW QUESTION # 67
You have a failover cluster named Cluster1 that contains three Windows Server nodes named Node 1, Node2.
and Node3.
You need to deploy a Storage Spaces Direct virtual disk to Cluster1.
You add the following disks to each node:
* Three 512-6B NVMe disks
* Three 3-TB diskS
* Three 1-TB SSD disks
On Cluster1. you enable Storage Spaces Direct and add the new disks.
What is the total amount of disk space available for the Storage Spaces Direct virtual disk, and which operations are cached for the SSD and HDD disks? To answer, select the appropriate options in the answer area.

Answer:

Explanation:


NEW QUESTION # 68
Case Study 1 - Fabrikam inc
Overview
Fabrikam, Inc. is a manufacturing company that has a main office in Chicago and a branch office in Paris.
Existing Environment
Identity Infrastructure
Fabrikam has an Active Directory Domain Services (AD DS) forest that syncs with an Azure Active Directory (Azure AD) tenant. The AD DS forest contains two domains named corp.fabrikam.com and europe.fabrikam.com.
Chicago Office On-Premises Servers
The office in Chicago contains on-premises servers that run Windows Server 2016 as shown in the following table.

All the servers in the Chicago office are in the corp.fabrikam.com domain.
All the virtual machines in the Chicago office are hosted on HV1 and HV2. HV1 and HV2 are nodes in a failover cluster named Cluster1.
WEB1 and WEB2 run an Internet Information Services (IIS) website. Internet users connect to the website by using a URL of https://www.fabrikam.com.
All the users in the Chicago office run an application that connects to a UNC path of
\\Fileserver1\Data.
Paris On-Premises Servers
The office in Paris contains a physical server named dc2.europe.fabrikam.com that runs Windows Server 2016 and is a domain controller for the europe.fabrikam.com domain.
Network Infrastructure
The networks in both the Chicago and Paris offices have local internet connections. The Chicago and Paris offices are connected by using VPN connections.
The client computers in the Chicago office get IP addresses from DHCP1.
Security Risks
Fabrikam identifies the following security risks:
* Some accounts connect to AD DS resources by using insecure protocols such as NTLMv1, SMB1, and unsigned LDAP.
* Servers have Windows Defender Firewall enabled. Server administrators sometimes modify firewall rules and allow risky connections.
Requirements
Security Requirements
Fabrikam identifies the following security requirements:
* Prevent server administrators from configuring Windows Defender Firewalls rules.
* Encrypt all the data disks on the servers by using BitLocker Drive Encryption (BitLocker).
* Ensure that only authorized applications can be installed or run on the servers in the forest.
* Implement Microsoft Sentinel as a reporting solution to identify all connections to the domain controllers that use insecure protocols.
On-Premises Migration Plan
Fabrikam plans to migrate all the existing servers and identifies the following migration requirements:
* Move the APP1 and APP2 virtual machines in the Chicago office to a new Hyper-V failover cluster named Cluster2 that will run Windows Server 2022.
- Cluster2 will contain two new nodes named HV3 and HV4.
- All virtual machine files will be stored on a Cluster Shared Volume (CSV).
* Migrate Archive1 to a new failover cluster named Cluster3 that will run Windows Server 2022.
- Cluster3 will contain two physical nodes named Node1 and Node2.
- The file shares on Cluster3 will be a failover cluster role in active-passive mode.
* Migrate all users, groups, and client computers from europe.fabrikam.com to corp.fabrikam.com.
- The migration will be performed by using the Active Directory Migration Tool (ADMT).
- A computer named ADMTcomputer will be deployed to the corp.fabrikam.com domain to run ADMT migration procedures.
- User accounts will retain their existing password.
* Migrate the data share from Fileserver1 to a new server named Fileserver2 that will run Windows Server 2022. After the migration, the data share must be accessible by using the existing UNC path.
Azure Migration Plan
Fabrikam plans to migrate some resources to Azure and identifies the following migration requirements:
* Create an Azure subscription named Sub1.
* Create an Azure virtual network named Vnet1.
* Use ExpressRoute to connect the Paris and Chicago offices to Vnet1.
* License all servers for Microsoft Defender for servers.
* Migrate APP3 and APP4 to Azure.
* Migrate the www.fabrikam.com website to an Azure App Service web app named WebApp1.
* Decommission WEB1 and WEB2.
DHCP Migration Plan
Fabrikam plans to replace DHCP1 with a new server named DHCP2 and identifies the following migration requirements:
* Ensure that DHCP2 provides the same IP addresses that are currently available from DHCP1.
* Prevent DHCP1 from servicing clients once services are enabled on DHCP2.
* Ensure that the existing leases and reservations are migrated.
Hotspot Question
You are planning the europe.fabrikam.com migration to support the on-premises migration plan.
Where should you install the Password Export Server (PES) service, where should you generate the encryption key? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: dc2.europe.fabrikam.com
To migrate passwords, select or install a backup domain controller in the source Windows NT 4.0 domain to act as the Secure Password Export server.
Run the PES service on the dc2 domain controller in source domain europe.fabrikam.com domain.
Scenario:
* Migrate all users, groups, and client computers from europe.fabrikam.com to corp.fabrikam.com.
* The migration will be performed by using the Active Directory Migration Tool (ADMT).
* A computer named ADMTcomputer will be deployed to the corp.fabrikam.com domain to run ADMT migration procedures.
* User accounts will retain their existing password.
Box 2: dc1.corp.fabrikam.com
dc1.corp.fabrikam.com is the target server, and we generate the encryption key on it.
To migrate passwords, select or install a backup domain controller in the source Windows NT 4.0 domain to act as the Secure Password Export server. This server will communicate with the Active Directory Migration Tool (ADMT) Server in the Target Domain.
Note: Create an encryption key to install on the Password Export server Using an Encryption Key on the Password Export Server.
The Password server encryption key is a key created on the ADMT server and is required to complete the installation of the Password Export Server. The encryption key can be created and stored in one or both of the following methods, by copying to the local floppy disk drive for transport to the password export server or by storing the encryption key in a folder on the local hard drive.
Reference:
https://www.serverbrain.org/secrets-2003/setting-up-an-admt-password-migration-server.html


NEW QUESTION # 69
You have an on-premises server named Server1 that runs Windows Server.
You have a Microsoft Sentinel workspace named sentinel.
You need to collect Windows Defender Firewall events from Server1 to sentinel.
Which two pages should you use in the Azure portal? To answer, select the appropriate pages in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 70
You have an Azure Active Directory Domain Services (Azure AD DS) domain named aadds.contoso.com.
You have an Azure virtual network named Vnet1. Vnet1 contains two virtual machines named VM1 and VM2 that run Windows Server. VMI and VM2 are joined to aadds.contoso.com.
You create a new Azure virtual network named Vnet2. You add a new server named VM3 to Vnet2.
When you attempt to join VM3 to aadds.contoso.com, you get an error message that the domain cannot be found.
You need to ensure that you can join VM3 toaadds.contoso.com.

Answer:

Explanation:

Explanation:


NEW QUESTION # 71
You have the servers shown in the following table.

You plan to migrate file shares from Server1 to Server2.

Answer:

Explanation:

Explanation:
Server 2
Server 1


NEW QUESTION # 72
......


Microsoft AZ-801 (Configuring Windows Server Hybrid Advanced Services) Certification Exam is designed to test the skills and knowledge of IT professionals who are responsible for configuring advanced Windows Server hybrid solutions. AZ-801 exam covers a wide range of topics related to hybrid identity, storage, networking, and virtualization. It is intended for individuals who have experience with Windows Server and Microsoft Azure and are looking to advance their careers in the IT industry.

 

Pass Microsoft AZ-801 exam Dumps 100 Pass Guarantee With Latest Demo: https://actualtests.realvalidexam.com/AZ-801-real-exam-dumps.html