Free Microsoft AZ-801 Practice Test & Real Exam Questions
You have 50 on-premises servers that run Windows Server.
You have an Azure subscription that contains a Recovery Services vault named Vaultl.
You plan to back up the on-premises servers to Vault1 by using Microsoft Azure Backup Server (MABS).
You need to configure prerequisites to support MABS. The solution must minimize costs.
What should you do for Vault1, and what should you deploy on-premises? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Exhibit
You have an Azure subscription that contains a Recovery Services vault named Vaultl.
You plan to back up the on-premises servers to Vault1 by using Microsoft Azure Backup Server (MABS).
You need to configure prerequisites to support MABS. The solution must minimize costs.
What should you do for Vault1, and what should you deploy on-premises? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Exhibit
Correct Answer:

Explanation:
Detailed Explanation
Microsoft Azure Backup Server (MABS) is the on-premises component you deploy to protect workloads such as file servers to a Recovery Services vault, so it must be installed on-premises before it can back up the 50 servers. To minimize cost for Vault1, you set the vault ' s storage replication type to locally redundant storage rather than the costlier geo-redundant default, since a single redundant copy is sufficient once MABS itself is managing the backup data. Configuring Azure Site Recovery, creating a private endpoint, or modifying the DefaultPolicy backup policy do not address the cost-minimization or MABS-prerequisite requirements described in this scenario.
Official Reference
About Microsoft Azure Backup Server - https://learn.microsoft.com/en-us/azure/backup/backup-azure- microsoft-azure-backup

You have a server that runs Windows Server and hosts an app named Appl.
You need to prevent App1 from accessing external SMTP servers. The solution must meet the following requirements:
* Minimize the impact on AppVs access to external HTTP servers.
* Minimize the impact on other apps on (he server.
* Minimize administrative effort
What should you implement in Windows Defender Firewall?
You need to prevent App1 from accessing external SMTP servers. The solution must meet the following requirements:
* Minimize the impact on AppVs access to external HTTP servers.
* Minimize the impact on other apps on (he server.
* Minimize administrative effort
What should you implement in Windows Defender Firewall?
Correct Answer: D
Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
You have an Azure virtual machine named VM1 that runs Windows Server.
You plan to deploy a new line-of-business (LOB) application to VM1.
You need to ensure that the application can create child processes.
What should you configure on VM1?
You plan to deploy a new line-of-business (LOB) application to VM1.
You need to ensure that the application can create child processes.
What should you configure on VM1?
Correct Answer: D
Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
You have an on-premises server named Server1 that runs Windows Server. Server1 has the Web Server (IIS) server role installed and hosts an ASP.NET web app named App1.
You have an Azure subscription.
You plan to migrate App1 to a container in Azure.
You need to export App1 to a ZIP file.
What should you install on Server1?
You have an Azure subscription.
You plan to migrate App1 to a container in Azure.
You need to export App1 to a ZIP file.
What should you install on Server1?
Correct Answer: D
Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
You have an on premises Hyper-V host named Server 1. Server! contains a virtual machine named VM1. You have a non-domain joined Hyper-V server named Server2 that is hosted in a remote location. You plan to replicate VM1 to Server2 by using Hyper-V Replica. You need to configure replication on Server1. Which authentication method can you use?
Correct Answer: C
Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
You have 10 servers that run Windows Server in a workgroup.
You need to configure the servers to encrypt all the network traffic between the servers. The solution must be as secure as possible.
Which authentication method should you configure in a connection security rule?
You need to configure the servers to encrypt all the network traffic between the servers. The solution must be as secure as possible.
Which authentication method should you configure in a connection security rule?
Correct Answer: A
Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
You have an on-premises server named Server1 and Microsoft Sentinel instance.
You plan to collect windows Defender Firewall events from Sever1 and analyze the event data by using Microsoft Sentinel.
What should you install on Server1, and which information should you provide during the instance? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You plan to collect windows Defender Firewall events from Sever1 and analyze the event data by using Microsoft Sentinel.
What should you install on Server1, and which information should you provide during the instance? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
CORRECTED ANSWER: Install: The Azure Monitor agent. Provide: The Azure Log Analytics workspace ID and the workspace key.
Detailed Explanation
Collecting Windows Firewall events from an on-premises server into Microsoft Sentinel is done through the Windows Firewall Events via AMA data connector, which relies on the Azure Monitor agent (AMA) together with a data collection rule; the Azure Log Analytics gateway is only a proxy relay for the legacy agent and the MARS agent is unrelated to event forwarding, so it is used purely for Azure Backup. When enrolling a non- Arc, non-Azure server, the setup process needs the destination Log Analytics workspace ' s ID and workspace (primary) key so the agent installer knows which workspace to report to and can authenticate to it - the same pairing Microsoft documents across its AMA- and MMA-based onboarding flows for standalone servers. A storage account and access key, a subscription ID and Sentinel workspace name, or Azure AD credentials play no role in pointing an on-premises agent at a Log Analytics workspace.
Official Reference
Windows Firewall Events via AMA connector for Microsoft Sentinel - https://learn.microsoft.com/en-us/azure/sentinel/data-connectors/windows-firewall-events-via-ama

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains a single-domain Active Directory Domain Services (AD DS) forest named contoso.
com. The functional level of the forest is Windows Server 2012 R2. All domain controllers run Windows Server 2012 R2.
Sysvol replicates by using the File Replication Service (FRS).
You plan to replace the existing domain controllers with new domain controllers that will run Windows Server 2022.
You need to ensure that you can add the first domain controller that runs Windows Server 2022.
Solution: You run the Active Directory Migration Tool (ADMT).
Does this meet the goal?
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains a single-domain Active Directory Domain Services (AD DS) forest named contoso.
com. The functional level of the forest is Windows Server 2012 R2. All domain controllers run Windows Server 2012 R2.
Sysvol replicates by using the File Replication Service (FRS).
You plan to replace the existing domain controllers with new domain controllers that will run Windows Server 2022.
You need to ensure that you can add the first domain controller that runs Windows Server 2022.
Solution: You run the Active Directory Migration Tool (ADMT).
Does this meet the goal?
Correct Answer: A
Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains an organizational unit (OU) named 0U1.0U1 contains servers that run sensitive workloads.
You plan to add connection security rules that meet the following requirements:
* The servers in OU 1 must only accept connections from domain-joined
* The servers in OU 1 must only be able to communicate with domain-joined You create a Group Policy Object (GPO) named GP01 and link GP01 to contoso.com.
You need to configure a connection security rule in GP01 by using Windows Defender Firewall with Advanced Security.
How should you configure the rule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You plan to add connection security rules that meet the following requirements:
* The servers in OU 1 must only accept connections from domain-joined
* The servers in OU 1 must only be able to communicate with domain-joined You create a Group Policy Object (GPO) named GP01 and link GP01 to contoso.com.
You need to configure a connection security rule in GP01 by using Windows Defender Firewall with Advanced Security.
How should you configure the rule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
CORRECTED ANSWER: Rule Type: Isolation. Requirements: Require authentication for inbound and outbound connections. Authentication Method: Computer (Kerberos V5).
Detailed Explanation
Restricting a set of servers so that they only accept inbound connections from, and only initiate outbound connections to, other domain-joined computers is the classic domain/server Isolation scenario, so the rule type is Isolation, not Tunnel (which secures gateway-to-gateway traffic) or Authentication exemption (which excludes hosts from having to authenticate). Because both requirements state the servers must " only " communicate with domain-joined systems in either direction - with no allowed fallback to unauthenticated traffic - the Requirements setting must be " Require authentication for inbound and outbound connections " rather than the softer inbound-required/outbound-requested default. Since every server and client involved is already domain-joined, Computer (Kerberos V5) is the appropriate authentication method, avoiding the certificate/PKI overhead that is only needed to extend trust to non-domain-joined devices.
Official Reference
Restrict server access to only trusted, domain-joined devices - https://learn.microsoft.com/en-us/windows
/security/operating-system-security/network-security/windows-firewall/restrict-access-to-only-trusted-devices
You have a Windows Server Failover Cluster (WSFQ that has the following configurations:
* Name: App1
* Owner node: Node3
* Type: Generic Application
The General settings for App1 are shown in the General exhibit. (Click the General tab.) The Failover settings for App1 are shown in the Failover exhibit. (Click the Failover tab.) The Advanced Policies settings for App1 are shown in the Advanced Policies exhibit. (Click the Advanced Policies tab.) For each of the following statements, select Yes if the statement is true Otherwise, select No.
NOTE: Each correct selection is worth one point.




* Name: App1
* Owner node: Node3
* Type: Generic Application
The General settings for App1 are shown in the General exhibit. (Click the General tab.) The Failover settings for App1 are shown in the Failover exhibit. (Click the Failover tab.) The Advanced Policies settings for App1 are shown in the Advanced Policies exhibit. (Click the Advanced Policies tab.) For each of the following statements, select Yes if the statement is true Otherwise, select No.
NOTE: Each correct selection is worth one point.




Correct Answer:

Explanation:
CORRECTED ANSWER: You can move App1 to Node4 manually: No. If Node3 fails, App1 will fail over to Node2 automatically: No. If App1 automatically fails over from Node3, App1 will fail back to Node3 automatically after Node3 is repaired: No.
Detailed Explanation
App1 ' s General tab shows its current owner as Node2, so a failure of Node3 - a node App1 is not running on - has no clustered workload to relocate, and therefore triggers no automatic failover to Node2 or any other node; failover only occurs when the node currently hosting a role fails. Automatic failback in Windows Server Failover Clustering always targets the highest-priority node that is checked in the role ' s Preferred Owners list on the General tab - never simply " whichever node it most recently ran on " - and since only Node1 and Node2 are checked as Preferred Owners for App1 (Node3 is unchecked), App1 can never automatically fail back to Node3, even though the Failover tab has " Allow failback: Immediately " configured. Whether App1 can be moved to Node4 manually is governed by the Possible Owners list on the Advanced Policies tab (a separate setting from Preferred Owners), which for this role excludes Node4 as a valid host.
Official Reference
Preferred owners, failover, and failback logic in Windows Server Failover Clustering - https://learn.
microsoft.com/en-us/troubleshoot/windows-server/high-availability/groups-fail-logic-three-more-cluster-node- members
Your network contains an Active Directory Domain Services (AD DS) domain that has the Active Directory Recycle Bin enabled. The domain contains two domain controllers named DC1 and DC2. The system state of the domain controllers is backed up daily at 23:00 by using Windows Server Backup.
You have an organizational unit (OU) named ParisUsers that contains 1,000 users.
At 08:00, DC1 shuts down for hardware maintenance. The maintenance completes, but DC1 remains shut down.
At 09:00, an administrative error causes the manager attribute of each user in ParisUsers to be deleted.
You need to recover the user account details as quickly as possible. The solution must minimize data loss.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You have an organizational unit (OU) named ParisUsers that contains 1,000 users.
At 08:00, DC1 shuts down for hardware maintenance. The maintenance completes, but DC1 remains shut down.
At 09:00, an administrative error causes the manager attribute of each user in ParisUsers to be deleted.
You need to recover the user account details as quickly as possible. The solution must minimize data loss.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Correct Answer:

Explanation:
CORRECTED ANSWER: Start DC1 in Directory Services Restore Mode > Perform an authoritative restore on DC1 > Start DC1 normally.
Detailed Explanation
Because DC1 was shut down at 08:00-before the 09:00 deletion of the manager attribute-its on-disk Active Directory database already holds the correct, pre-incident values for every affected user, making it what Microsoft ' s guidance calls a " latent " domain controller that never replicated the bad change. In this exact scenario, official troubleshooting guidance for restoring accidentally modified or deleted AD data explains that when an unaffected domain controller is available, you can skip a system state restore entirely: boot that domain controller into Directory Services Restore Mode to isolate it from inbound replication, then use ntdsutil to perform an authoritative restore, which raises the version numbers on the affected objects so they win when replicated outward. Restarting DC1 normally afterward pushes its authoritative, correct manager attribute values out to DC2 and any other domain controllers. Restoring system state from the prior night ' s
23:00 backup at this point would actually reintroduce more data loss, since it would discard any legitimate changes made between 23:00 and DC1 ' s 08:00 shutdown-exactly what the minimize-data-loss requirement is designed to avoid. The Active Directory Recycle Bin does not help here because it recovers deleted objects, not attribute values that were cleared on objects that still exist.
Official Reference
Restore deleted user accounts and groups in Active Directory - https://learn.microsoft.com/en-us
/troubleshoot/windows-server/active-directory/retore-deleted-accounts-and-groups-in-ad
You have a failover cluster named FC1 that contains two nodes named Server1 and Server2. FC1 is configured to use a file share witness.
You plan to configure FC1 to use a cloud witness.
You need to configure Azure Storage accounts for the cloud witness.
Which storage account type and authorization method should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Exhibit
You plan to configure FC1 to use a cloud witness.
You need to configure Azure Storage accounts for the cloud witness.
Which storage account type and authorization method should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Exhibit
Correct Answer:

Explanation:
Detailed Explanation
A cloud witness for a Windows Server failover cluster is configured against a standard general-purpose Azure Storage account; premium storage account types are not required or supported for this purpose.
Authentication to the storage account for the cloud witness is performed using the storage account ' s access key (primary or secondary) - the cluster uses this key to generate the token it needs to read/write the witness blob - rather than a shared access signature or an Azure AD (managed identity) credential, neither of which the cloud witness feature supports.
Official Reference
Deploy a cloud witness for a failover cluster - https://learn.microsoft.com/en-us/windows-server/failover- clustering/deploy-cloud-witness

You have three servers named Server1. Server1 and Server3 that run Windows Server and have the hyper V server rote installed. Server 1 hosts an Azure Migrate appliance named Migrate1.
You plan to migrate virtual machines to Azure.
You need to ensure that any new virtual machines created on Server 1. Server2 and Server3 are available in Azure Migrate What should you do?
You plan to migrate virtual machines to Azure.
You need to ensure that any new virtual machines created on Server 1. Server2 and Server3 are available in Azure Migrate What should you do?
Correct Answer: D
Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server.
You need to back up VM1 by using Azure Backup. The solution must minimize potential data loss.
What is the minimum backup interval you can configure for a standard backup policy and an enhanced backup policy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
You need to back up VM1 by using Azure Backup. The solution must minimize potential data loss.
What is the minimum backup interval you can configure for a standard backup policy and an enhanced backup policy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Exhibit
Correct Answer:

Explanation:
Detailed Explanation
A standard Azure VM backup policy supports only one backup per day, so its most frequent achievable schedule is every 24 hours. The enhanced backup policy, which also adds support for features like Trusted Launch VMs and multiple daily restore points, allows an hourly backup schedule with a configurable interval of 4, 6, 8, 12, or 24 hours, giving it a minimum recovery point objective of 4 hours. Selecting the enhanced policy with a 4-hour interval therefore minimizes potential data loss far more than the standard policy ' s once- daily cadence.
Official Reference
Back up Azure VMs with the enhanced policy - https://learn.microsoft.com/en-us/azure/backup/backup-azure-vms-enhanced-policy

