[Feb 08, 2026] Get Unlimited Access to AZ-801 Certification Exam Cert Guide
Reliable Study Materials for AZ-801 Exam Success For Sure
Microsoft AZ-801 Exam is aimed at IT professionals who are interested in validating their knowledge and skills in managing hybrid environments, including administrators, architects, and engineers. Passing AZ-801 exam is a great way to demonstrate your expertise in managing and configuring hybrid environments and can help you advance your career in the IT industry. With the increasing demand for professionals with expertise in managing hybrid environments, earning the Microsoft AZ-801 certification can be a valuable asset in your career.
Microsoft is a leading technology company that provides a range of software and services for businesses and individuals. One of the core products offered by Microsoft is Windows Server, which is a powerful operating system designed for enterprise use. To help IT professionals demonstrate their knowledge and expertise in configuring Windows Server, Microsoft offers a range of certifications, including the Microsoft Certified: Azure Solutions Architect Expert certification. One of the exams required to earn this certification is the Microsoft AZ-801: Configuring Windows Server Hybrid Advanced Services exam.
NEW QUESTION # 85
You have a Windows Server 2022 failover cluster named Cluster1 that contains the Cluster Shared Volumes (CSV) shown in the following table.
All the nodes in Cluster1 have BitLocker Drive Encryption (BitLocker) installed.
You need to use PowerShell to enable BitLocker on Volume1.
In which order should you run the commands? To answer, drag the appropriate commands to the correct order. You may need to drag the split bar between panes or scroll to view content.
NOTE Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 86
You have a server named Server1 that runs Windows Server.
You need to ensure that only specific applications can modify the data in protected folders on Server1.
Solution: From App & browser control, you configure the Reputation-based protection.
Does this meet the goal?
- A. No
- B. Yes
Answer: A
NEW QUESTION # 87
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains servers that run Windows Server as shown in the following table.
Server1 has the connection security rules shown in the following table.
Server2 has the connection security rules shown in the following table.
.
Answer:
Explanation:
Explanation:
NEW QUESTION # 88
You have a server that runs Windows Server and hosts an app named Appl.
You need to prevent App1 from accessing external SMTP servers. The solution must meet the following requirements:
* Minimize the impact on AppVs access to external HTTP servers.
* Minimize the impact on other apps on (he server.
* Minimize administrative effort
What should you implement in Windows Defender Firewall?
- A. an outbound custom rule
- B. an inbound program rule
- C. an outbound program rule
- D. an inbound custom rule
- E. an outbound port rule
Answer: C
NEW QUESTION # 89
You have a failover cluster named FC1 that contains two nodes named Server1 and Server2. FC1 is configured to use a file share witness.
You plan to configure FC1 to use a cloud witness.
You need to configure Azure Storage accounts for the cloud witness.
Which storage account type and authorization method should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/failover-clustering/deploy-cloud-witness
NEW QUESTION # 90
You have an on-premises server that runs Windows Server and contains a folder named Folder1. Folder1 contains 50 GB of files.
You have an Azure subscription that contains an Azure Files share named share1.
You need to migrate the data in Folder1 to share1.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 91
You have 200 Azure virtual machines.
You create a recovery plan in Azure Site Recovery to fail over all the virtual machines to an Azure region.
The plan has three manual actions.
You need to replace one of the manual actions with an automated process.
What should you use?
- A. an Azure Automation runbook
- B. a Custom Script Extension on the virtual machines
- C. an Azure Desired State Configuration (DSC) virtual machine extension
- D. an Azure PowerShell function
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/site-recovery/recovery-plan-overview
NEW QUESTION # 92
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a print server named Server1. All printers are deployed to users by using a Group Policy Object (GPO) named GPO1.
You deploy a new server named Server2.
You need to decommission Server1. The solution must meet the following requirements:
* Migrate the shared printers to Server2 by using the Printer Migration Wizard.
* Ensure that the users use the printers on Server2.
* Minimize downtime for the users.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation
Graphical user interface, text, application, email Description automatically generated
Reference:
https://docs.microsoft.com/en-us/archive/blogs/canitpro/step-by-step-migrating-print-servers-from-windows-serv
NEW QUESTION # 93
You have a server named Server1 that runs Windows Server.
On Server1, you create a Data Collector Set named CollectorSet1 based on the Basic template.
You need to configure CollectorSet1 to meet the following requirements:
Older performance counter logs must be overwritten by new ones.
Performance counter logging must stop if there is less than 500 MB of free disk space.
What should you configure for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Table Description automatically generated with medium confidence
NEW QUESTION # 94
You have an on-premises server named Server1 that runs Windows Server.
You have an Azure subscription.
You plan to back up the files and folders on Server1 by using the Microsoft Azure Recovery Services (MARS) agent.
You need to identify to which location the backups can be written and the maximum number of scheduled backups that can be performed per day.
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point
Answer:
Explanation:
Explanation:
NEW QUESTION # 95
Your network contains an Active Directory Domain Services (AD DS) domain All domain members have Microsoft Defender Credential Guard with UEFI tock configured in the domain you deploy a server named Server1 that runs Windows Server. You disable Credential Guard on Server1. You need to ensure that Server1 is MOST subject to Credential Guard restrictions. What should you do next?
- A. Disable the Turn on Virtual nation Based Security group policy setting
- B. Run the Device Guard and Credential Guard hardware readiness tool
- C. Run dism and specify the /Disable-Feature and /FeatureName:IsolatedUserMode parameters
Answer: A
NEW QUESTION # 96
You have an Azure subscription. The subscription contains two virtual machines named VM1 and VM2 that run Windows Server. You need to use Azure Network Watcher to meet the following requirements;
* Identify security rules that prevent network traffic from reaching VM1.
* Identify the source region of packets sent to VM2.
What should you use for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 97
You are planning the www.fabrikam.com website migration to support the Azure migration plan.
How should you configure WebApp1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/app-service/app-service-web-tutorial-custom-domain?tabs=a%2Cazurecli
NEW QUESTION # 98
You have two physical servers named AppSrv1 and AppSrv2 and an unconfigured server named Server1. All the servers run Windows Server. Only Server1 can access the internet.
You plan to use Azure Site Recovery to replicate AppSrv1 and AppSrv2 to Azure.
You need to deploy the required components to AppSrv1, AppSrv2, and Server1.
Which components should you deploy? To answer, drag the appropriate components to the correct servers. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/site-recovery/physical-azure-architecture
https://docs.microsoft.com/en-us/azure/site-recovery/physical-azure-set-up-source
NEW QUESTION # 99
Your network contains an Active Directory Domain Services (AD DS) domain that has the Active Directory Recycle Bin enabled. The domain contains two domain controllers named DC1 and DC2. The system state of the domain controllers is backed up daily at 23:00 by using Windows Server Backup.
You have an organizational unit (OU) named ParisUsers that contains 1,000 users.
At 08:00, DC1 shuts down for hardware maintenance. The maintenance completes, but DC1 remains shut down.
At 09:00, an administrative error causes the manager attribute of each user in ParisUsers to be deleted.
You need to recover the user account details as quickly as possible. The solution must minimize data loss.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
NEW QUESTION # 100
Your network contains an Active Directory Domain Services (AD DS) domain.
You need to implement a solution that meets the following requirements:
Ensures that the members of the Domain Admins group are allowed to sign in only to domain controllers Ensures that the lifetime of Kerberos Ticket Granting Ticket (TGT) for the members of the Domain Admins group is limited to one hour Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/how-to-configure-protected-accounts
NEW QUESTION # 101
Your network contains an Active Directory Domain Services (AD DS) forest. The forest functional level is Windows Server 2012 R2. The forest contains the domains shown in the following table.
You create a user named Admin1.
You need to ensure that Admin1 can add a new domain controller that runs Windows Server 2022 to the east.
contoso.com domain. The solution must follow the principle of least privilege.
To which groups should you add Admin1?
- A. CONTOSO\Enterprise Admins and CONTOSO/Schema Admins
- B. EAST\Domain Admins only
- C. CONTOSO/Schema Admins and EAST\Domain Admins
- D. CONTOSO\Enterprise Admins only
Answer: B
NEW QUESTION # 102
You have three servers named Server1, Server2, Server3 that run Windows Server and have the Hyper-V server role installed.
You plan to create a hyper-converged cluster to host Hyper-V virtual machines.
You need to ensure that you can store virtual machines in Storage Spaces Direct.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation:
Reference:
https://docs.microsoft.com/en-us/system-center/vmm/s2d-hyper-converged?view=sc-vmm-2019
NEW QUESTION # 103
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains the domains shown in the following table.
You are implementing Microsoft Defender for Identity sensors.
You need to install the sensors on the minimum number of domain controllers. The solution must ensure that Defender for Identity will detect all the security risks in both the domains.
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Text, table Description automatically generated
Reference:
https://docs.microsoft.com/en-us/defender-for-identity/technical-faq#deployment
https://docs.microsoft.com/en-us/defender-for-identity/install-step4
NEW QUESTION # 104
You need to back up Server 4 to meet the technical requirements.
What should you do first?
- A. Deploy Microsoft Azure Backup Server (MABS).
- B. Configure Windows Server Backup.
- C. Configure Storage Replica.
- D. Install the Microsoft Azure Recovery Services (MARS) agent.
Answer: D
NEW QUESTION # 105
You need to configure BitLocker on Server4.
On which volumes can you turn on BitLocker, and on which volumes can you turn on auto-unlock? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/windows-server/storage/refs/refs-overview
https://docs.microsoft.com/en-us/powershell/module/bitlocker/enable-bitlockerautounlock?view=windowsserver
NEW QUESTION # 106
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.

Answer:
Explanation:
Explanation:
NEW QUESTION # 107
......
New Microsoft AZ-801 Dumps & Questions: https://buildazure.actualvce.com/Microsoft/AZ-801-valid-vce-dumps.html