Administering Windows Server Hybrid Core Infrastructure Free Sample Questions

Description

Covers deploying and managing Active Directory domain controllers and multi-site forests, hybrid server management with Azure services, Hyper-V virtual machines and containers, and storage.

20 free sample questions215 in the full practice test Other versions: AZ-802(150),98-365(364),AZ-801(214)

Try simulator

AZ-800 Sample Questions

  1. Question 1

    Intermediate

    Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments · Deploy read-only domain controllers (RODCs)

    A financial services firm, Woodgrove Bank, is deploying a new Active Directory forest. For security reasons, they need to ensure that the administrator who installs a new Read-Only Domain Controller (RODC) in a branch office cannot use their own credentials to install other domain controllers in the forest. Which approach meets this requirement while adhering to the principle of least privilege?

    Answer and explanation

    Correct answer: C

    This method, known as a staged RODC installation, is the most secure approach. A member of the Domain Admins group pre-creates the RODC account and specifies which user or group has the permission to attach a server to that account. This delegates the exact permission needed without granting excessive rights like Domain Admin membership. The branch administrator can then complete the installation without needing high-level domain credentials.

  2. Question 2

    IntermediateMultiple answers

    Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments · Implement and manage hybrid identities

    You are managing a hybrid environment for an e-commerce company. You need to ensure that password changes made by users on-premises are validated against the Microsoft global banned password list and your organization's custom banned password list in Azure AD before the change is committed to the on-premises Active Directory. Which TWO components are required to implement this functionality? (Select TWO)

    Answer and explanation

    Correct answers: A, C

    Microsoft Entra (Azure AD) Password Protection for AD DS uses two on-premises components. The DC agent (a password filter DLL plus the DC Agent service) must be installed on every domain controller, because the policy is enforced only on DCs that run it; it accepts or rejects each password change locally by using the most recently downloaded policy, which combines Microsoft's global banned password list with the tenant's custom banned password list and is cached in SYSVOL. The proxy service runs on a domain-joined member server and forwards the DC agents' policy download requests to Microsoft Entra ID, so domain controllers never need internet access and clear-text passwords never leave the DC. Password writeback, AD FS, and the Application Proxy connector aren't required.

  3. Question 3

    Intermediate

    Manage virtual machines and containers · Manage VM checkpoints

    A manufacturing company uses Hyper-V for their on-premises virtualization. They have a critical legacy application running on a Windows Server 2016 VM that is not compatible with modern backup agents. The company needs to create application-consistent backups of this VM. You discover that the VM's VSS writers are functioning correctly. Which type of checkpoint should you use to facilitate the backup process?

    Answer and explanation

    Correct answer: C

    Production checkpoints use the Volume Shadow Copy Service (VSS) inside a Windows guest (File System Freeze on Linux) to create a data-consistent, application-consistent point-in-time image of the VM without capturing memory state, which is appropriate for production workloads and backup scenarios. Standard checkpoints capture the VM's disks together with its memory state, so applications are restored mid-operation; they're intended for development and test and aren't application-consistent. Production is the default checkpoint type (Set-VM -CheckpointType Production, ProductionOnly, Standard, or Disabled). 'Recovery' checkpoints are created internally by backup applications such as DPM rather than chosen by the administrator, and 'Application-Aware Checkpoint' isn't a Hyper-V checkpoint type.

  4. Question 4

    Advanced

    Manage storage and file services · Configure and manage Storage Spaces

    An administrator is configuring Storage Spaces on a Windows Server 2022 file server using twelve 4 TB SAS drives. The primary goal is to provide the best possible I/O performance for a database workload while also providing protection against a two-drive failure. Which Storage Spaces configuration should be implemented?

    Answer and explanation

    Correct answer: A

    For a performance-sensitive database workload that must survive two simultaneous drive failures, use a three-way mirror space. Microsoft recommends mirroring for all workloads and parity for sequential workloads such as archival. A three-way mirror keeps three copies of the data, tolerates two drive failures, and requires at least five physical disks (twelve are available). Mirror-accelerated parity combines mirror and parity in one ReFS volume, but in Windows Server it's supported only on Storage Spaces Direct and recommended only for archival and backup workloads. Dual parity also tolerates two failures but has much lower random-write performance, and a simple space has no resiliency.

  5. Question 5

    Intermediate

    Implement and manage an on-premises and hybrid networking infrastructure · Implement on-premises and hybrid name resolution

    You are troubleshooting DNS resolution in a hybrid environment. An on-premises server (10.10.1.5) needs to resolve the name of an Azure VM (vm1.corp.azure) which is registered in an Azure Private DNS zone. The on-premises DNS server has a conditional forwarder for corp.azure pointing to an Azure DNS Private Resolver. However, resolution is failing. Which PowerShell command would you run on the on-premises DNS server to begin troubleshooting?

    Answer and explanation

    Correct answer: C

    The first step in troubleshooting a conditional forwarder is to verify network connectivity from the on-premises DNS server to the target resolver on the required port. The Test-NetConnection cmdlet is the correct tool for this. It will confirm whether the on-premises DNS server can reach the Azure DNS Private Resolver over port 53 (DNS). If this test fails, the issue is likely a firewall rule, a network security group (NSG) in Azure, or a routing problem over the VPN/ExpressRoute connection.

  6. Question 6

    Advanced

    Implement and manage an on-premises and hybrid networking infrastructure · Implement Microsoft Entra Application Proxy

    A hospital needs to provide secure remote access to a legacy on-premises web-based electronic health record (EHR) application for its doctors. The application does not support modern authentication protocols like SAML or OpenID Connect. The hospital's identity provider is Microsoft Entra ID. The solution must enforce Multi-Factor Authentication (MFA) before granting access and must not give the doctors' devices network-level (VPN) access to the hospital network. Which Azure service should be deployed to meet these requirements?

    Answer and explanation

    Correct answer: D

    Microsoft Entra application proxy publishes on-premises web applications to remote users without a VPN. Users are pre-authenticated by Microsoft Entra ID, so Conditional Access policies such as MFA apply even when the back-end application doesn't support modern authentication; the private network connector installed on-premises makes only outbound connections and forwards requests to the app, which can use integrated Windows authentication through Kerberos constrained delegation. A point-to-site VPN would give the doctors' devices network-level access, Azure Bastion is for RDP/SSH to Azure VMs, and WAP with AD FS doesn't use Microsoft Entra ID as the identity provider.

  7. Question 7

    Intermediate

    Manage Windows Servers and workloads in a hybrid environment · Configure Just Enough Administration (JEA) for PowerShell remoting

    You are managing a Windows Server failover cluster that hosts several highly available virtual machines. To improve security, you have been tasked with configuring Just Enough Administration (JEA) for a team of junior administrators who need to manage the VMs. They should only be able to start, stop, and restart VMs. Which field in a JEA role capability file (.psrc) is used to define these specific permissions?

    Answer and explanation

    Correct answer: B

    In a JEA role capability file (.psrc), the VisibleCmdlets field lists the PowerShell cmdlets that users can run in the JEA session (optionally restricting their parameters and values). To allow starting, stopping, and restarting VMs, you would list Start-VM, Stop-VM, and Restart-VM in this field. VisibleExternalCommands is for executables and scripts outside PowerShell, RoleDefinitions belongs in the session configuration file (.pssc) where it maps users to role capabilities, and AllowedCommandlets isn't a valid field.

  8. Question 8

    Beginner

    Manage storage and file services · Configure and manage Azure File Sync

    True or False: When using Azure File Sync, the cloud endpoint (the Azure file share) must be created in the same Azure region as the Storage Sync Service resource.

    Answer and explanation

    Correct answer: A

    This statement is true. The Storage Sync Service and the Azure file share it syncs with must be in the same Azure region. While the on-premises servers (server endpoints) can be anywhere in the world, the Azure resources must be co-located in the same region for the sync group to be created.

  9. Question 9

    Advanced

    Manage Windows Servers and workloads in a hybrid environment · Implement Azure Machine Configuration

    A retail company has deployed Azure Arc to manage its on-premises servers located in hundreds of stores. The security team wants to enforce a policy that ensures a specific antivirus service is running on all these Arc-enabled servers and automatically remediates any server where the service is stopped. Which Azure service combination should be used to achieve this?

    Answer and explanation

    Correct answer: C

    Azure Policy's Guest Configuration feature is the ideal solution. You can create a custom Desired State Configuration (DSC) that defines the required state (antivirus service running). This configuration is then packaged and applied via an Azure Policy initiative. The policy can be set to not only audit for compliance but also to deploy a remediation task that automatically starts the service if it's found to be stopped. This provides a scalable, declarative way to enforce and remediate configuration drift across all Arc-enabled servers.

  10. Question 10

    Intermediate

    Manage virtual machines and containers · Configure Discrete Device Assignment

    You are deploying a new Hyper-V host for a high-performance computing (HPC) workload. The host has a high-end GPU installed. You need to provide dedicated, full access to this GPU for a single, specific virtual machine to perform complex calculations. This VM must have direct and exclusive access to the hardware. What Hyper-V feature should you configure?

    Answer and explanation

    Correct answer: C

    Discrete Device Assignment (DDA) passes an entire PCIe device, such as a GPU, through to a single virtual machine: the device is dismounted from the host by its PCI location path and assigned to the VM, which then uses the native driver with full access to the GPU. Each physical GPU can accelerate at most one VM, which matches the requirement for dedicated, exclusive access. GPU partitioning (GPU-P, Windows Server 2025) instead shares one GPU among multiple VMs, RemoteFX vGPU has been removed from Windows Server, and Enhanced Session Mode only improves the VMConnect experience.

Register free for 10 more questions

Or unlock all 215 AZ-800 questions with explanations, timed mode and flashcards.