Microsoft AZ-801 Configuring Windows Server Hybrid Advanced Services Online Training
Microsoft AZ-801 Online Training
The questions for AZ-801 were last updated at Dec 20,2024.
- Exam Code: AZ-801
- Exam Name: Configuring Windows Server Hybrid Advanced Services
- Certification Provider: Microsoft
- Latest update: Dec 20,2024
You have 100 Azure virtual machines that run Windows Server. The virtual machines are onboarded to Microsoft Defender for Cloud.
You need to shut down a virtual machine automatically if Microsoft Defender for Cloud generates the "Antimalware disabled in the virtual machine" alert for the virtual machine.
What should you use in Microsoft Defender for Cloud?
- A . a logic app
- B . a workbook
- C . a security policy
- D . adaptive network hardening
You have a Microsoft Sentinel deployment and 100 Azure Arc-enabled on-premises servers. All the Azure Arc-enabled resources are in the same resource group.
You need to onboard the servers to Microsoft Sentinel. The solution must minimize administrative effort.
What should you use to onboard the servers to Microsoft Sentinel?
- A . Azure Automation
- B . Azure Policy
- C . Azure virtual machine extensions
- D . Microsoft Defender for Cloud
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant by using password hash synchronization.
You have a Microsoft 365 subscription.
All devices are hybrid Azure AD-joined.
Users report that they must enter their password manually when accessing Microsoft 365 applications.
You need to reduce the number of times the users are prompted for their password when they access Microsoft 365 and Azure services.
What should you do?
- A . In Azure AD. configure a Conditional Access policy for the Microsoft Office 365 applications.
- B . In the DNS zone of the AD DS domain, create an autodiscover record.
- C . From Azure AD Connect, enable single sign-on (SSO).
- D . From Azure AD Connect, configure pass-through authentication.
You have an Azure subscription that has Microsoft Defender for Cloud enabled.
You have 50 Azure virtual machines that run Windows Server.
You need to ensure that any security exploits detected on the virtual machines are forwarded to Defender for Cloud.
Which extension should you enable on the virtual machines?
- A . Vulnerability assessment for machines
- B . Microsoft Dependency agent
- C . Log Analytics agent for Azure VMs
- D . Guest Configuration agent
HOTSPOT
Your network contains an Active Directory Domain Services (AD DS) forest.
The forest contains the domains shown in the following table.
You are implementing Microsoft Defender for Identity sensors.
You need to install the sensors on the minimum number of domain controllers. The solution must ensure that Defender for Identity will detect all the security risks in both the domains.
What should you identify? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
You have 10 servers that run Windows Server in a workgroup.
You need to configure the servers to encrypt all the network traffic between the servers. The solution must be as secure as possible.
Which authentication method should you configure in a connection security rule?
- A . NTLMv2
- B . pre-shared key
- C . KerberosV5
- D . computer certificate
You have an Azure virtual machine named VM1 that runs Windows Server.
You need to encrypt the contents of the disks on VM1 by using Azure Disk Encryption.
What is a prerequisite for implementing Azure Disk Encryption?
- A . Customer Lockbox for Microsoft Azure
- B . an Azure key vault
- C . a BitLocker recovery key
- D . data-link layer encryption in Azure
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains two servers named Server1 and Server2 that run Windows Server.
You need to ensure that you can use the Computer Management console to manage Server2. The solution must use the principle of least privilege.
Which two Windows Defender Firewall with Advanced Security rules should you enable on Server2? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
- A . the COM+ Network Access (DCOM-ln) rule
- B . all the rules in the Remote Event Log Management group
- C . the Windows Management Instrumentation (WMI-ln) rule
- D . the COM+ Remote Administration (DCOM-ln) rule
- E . the Windows Management Instrumentation (DCOM-ln) rule
You have a server that runs Windows Server. The server is configured to encrypt all incoming traffic by using a connection security rule.
You need to ensure that Server1 can respond to the unencrypted tracert commands initiated from computers on the same network.
What should you do from Windows Defender Firewall with Advanced Security?
- A . From the IPsec Settings, configure IPsec defaults.
- B . Create a new custom outbound rule that allows ICMPv4 protocol connections for all profiles.
- C . Change the Firewall state of the Private profile to Off.
- D . From the IPsec Settings, configure IPsec exemptions.
You have an Azure virtual machine named VM1.
You enable Microsoft Defender SmartScreen on VM1.
You need to ensure that the SmartScreen messages displayed to users are logged.
What should you do?
- A . From a command prompt, run WinRM quickconfig.
- B . From the local Group Policy, modify the Advanced Audit Policy Configuration settings.
- C . From Event Viewer, enable the Debug log.
- D . From the Windows Security app. configure the Virus & threat protection settings.