Skip to main content

AZ-801 / Q26 / T1

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains three servers named Server1, Server2, and Server3 that run Windows Server. All the servers are on the same network and have network connectivity.

On Server1, Windows Defender Firewall has a connection security rule that has the following settings:

• Rule Type: Server-to-server
• Endpoint 1: Any IP address
• Endpoint 2: Any IP address
• Requirements: Require authentication for inbound connections and request authentication for outbound connections

AZ-801 / Q23 / T1

Теґи

You have a generation 1 Azure virtual machine named VM1 that runs Windows Server and is joined to an Active Directory domain. 

You plan to enable BitLocker Drive Encryption (Bit-Locker) on volume C of VM1. 

You need to ensure that the BitLocker recovery key for VM1 is stored in Active Directory. 

Which two Group Policy settings should you configure first? To answer, select the settings in the answer area. 

NOTE: Each correct selection is worth one point.

AZ-801 / Q20 / T1

Теґи

Your network contains an on-premises Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the accounts shown in the following table.

The domain is configured to store BitLocker recovery keys in Active Directory.
Admin1 and Admin2 perform the following configurations:
1. Admin1 turns on BitLocker Drive Encryption (BitLocker) for volume C on Server1.

AZ-801 / Q19 / T1

Теґи

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.
You run Get-BitLockerVolume -MountPoint C,D | fl *, which generates the following output.

AZ-801 / Q13 / T1

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains the domains shown in the following table.

You are implementing Microsoft Defender for Identity sensors.
You need to install the sensors on the minimum number of domain controllers. The solution must ensure that Defender for Identity will detect all the security risks in both the domains.

AZ-801 / Q8 / T1

Теґи

Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the organizational units (OUs) shown in the following table.

In the domain, you create the Group Policy Objects (GPOs) shown in the following table.

AZ-800 / Q48 / T5

You have a server named Server1 that runs Windows Server 2022.

You add two 4-TB hard drives named Disk1 and Disk2 to Server1.

You need to format the drives. The solution must meet the following requirements:

• Disk1 must support disk level quotas.
• Disk2 must support Data Deduplication.

Which type of file system should you use for each drive? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.
 

AZ-800 / Q42 / T5

Теґи

Your on-premises network contains an Active Directory Domain Services (AD DS) domain.

You plan to sync the domain with an Azure AD tenant by using Azure AD Connect cloud sync.

You need to meet the following requirements:

• Install the software required to sync the domain and Azure AD.
• Enable password hash synchronization.

What should you install, and what should you use to enable password hash synchronization? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.