Microsoft AZ-800 Exam Actual Questions
Administering Windows Server Hybrid Core Infrastructure (Page 2 )

Updated On: 13-Aug-2026
View Related Case Study

DRAG DROP (Drag and Drop is not supported)
DC1 fails.
You need to meet the technical requirements for the schema master.
You run ntdsutil.exe.
Which five commands should you run in sequence? To answer, move the appropriate commands from the list of commands to the answer area and arrange them in the correct order?
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Step 1: roles A. Datum identifies the following technical requirements: DC2 must become the schema master if DC1 fails.
To seize or transfer the Operation Master roles by using the Ntdsutil utility, follow these steps:
1. Sign in to a member computer that has the AD RSAT tools installed, or a DC that is located in the forest where Operation Master roles are being transferred.
2. Select Start > Run, type ntdsutil in the Open box, and then select OK.
3. Type roles, and then press Enter.
Step 2: connect
4. Type connections, and then press Enter.
Step 3: connect to server dc2.adatumcom
5. Type connect to server <servername>, and then press Enter.

Note: In this command, <servername> is the name of the DC that you want to assign the Operation Master role to.
Step 4: quit
6. At the server connections prompt, type q, and then press Enter.
Step 5: seize schema master
7. Do one of the following actions:
To transfer the role: Type transfer <role>, and then press Enter.
Note In this command, <role> is the role that you want to transfer.
To seize the role: Type seize <role>, and then press Enter.
Note In this command, <role> is the role that you want to seize.
8. At the fsmo maintenance prompt, type q, and then press Enter to gain access to the ntdsutil prompt. Type q, and then press Enter to quit the Ntdsutil utility.


Reference:

https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/transfer-or-seize-operation-master-roles-in-ad-ds



View Related Case Study

You need to ensure that access to storage1 for the Marketing OU users meets the technical requirements.
What should you implement?

  1. Active Directory Federation Services (AD FS)
  2. Microsoft Entra Connect sync in staging mode
  3. Microsoft Entra Connect Cloud sync
  4. Microsoft Entra Connect sync in active mode

Answer(s): C

Explanation:

Azure AD Connect cloud sync is a new offering from Microsoft designed to meet and accomplish your hybrid identity goals for synchronization of users, groups, and contacts to Azure AD. It accomplishes this by using the Azure AD cloud provisioning agent instead of the Azure AD Connect application. However, it can be used alongside Azure AD Connect sync and it provides the following benefits:
* Support for synchronizing to an Azure AD tenant from a multi-forest disconnected Active Directory forest environment: The common scenarios include merger & acquisition (where the acquired company's AD forests are isolated from the parent company's AD forests), and companies that have historically had multiple AD forests.
* Etc.

How is Azure AD Connect cloud sync different from Azure AD Connect sync? With Azure AD Connect cloud sync, provisioning from AD to Azure AD is orchestrated in Microsoft Online Services. An organization only needs to deploy, in their on-premises or IaaS-hosted environment, a light-weight agent that acts as a bridge between Azure AD and AD. The provisioning configuration is stored in Azure AD and managed as part of the service.
Comparison between Azure AD Connect and cloud sync The following table provides a comparison between Azure AD Connect and Azure AD Connect cloud sync:

Scenario: The users in the Marketing OU must have access to storage1. The subscription contains a storage account named storage1 that has a file share named share1. The fabrikam.com domain contains an organizational unit (OU) named Marketing. The on-premises network of Fabrikam contains an AD DS forest named fabrikam.com. The on-premises network of A. Datum contains an Active Directory Domain Services (AD DS) forest named adatum.com.
Incorrect:
* Azure AD Connect in staging mode With a server in staging mode, you can make changes to the configuration and preview the changes before you make the server active.
Staging mode Staging mode can be used for several scenarios, including:
High availability. Test and deploy new configuration changes. Introduce a new server and decommission the old.
During installation, you can select the server to be in staging mode. This action makes the server active for import and synchronization, but it does not run any exports. A server in staging mode is not running password sync or password writeback, even if you selected these features during installation.


Reference:

https://learn.microsoft.com/en-us/azure/active-directory/hybrid/cloud-sync/what-is-cloud-sync https://learn.microsoft.com/en-us/azure/active-directory/hybrid/connect/how-to-connect-sync-staging-server



View Related Case Study

You need to configure the Group Policy settings to ensure that the Azure Virtual Desktop session hosts meet the security requirements.
What should you configure?

  1. loopback processing in GPO4
  2. security filtering for the link of GPO1
  3. loopback processing in GPO1
  4. the Enforced property for the link of GPO4
  5. the Enforced property for the link of GPO1
  6. security filtering for the link of GPO4

Answer(s): A



View Related Case Study

What should you implement for the deployment of DC3?

  1. Microsoft Entra Domain Services
  2. an Azure virtual machine
  3. a Microsoft Entra administrative unit
  4. Microsoft Entra Application Proxy

Answer(s): B

Explanation:

Create a domain controller named dc3.corp.fabrikam.com in Vnet1. In a hybrid network, you can configure Azure virtual machines as domain controllers. The domain controllers in Azure communicate with the on-premises domain controllers in the same way that on-premises domain controllers communicate with each other.



View Related Case Study

DRAG DROP (Drag and Drop is not supported)
Which three actions should you perform in sequence to meet the security requirements for Webapp1? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/windows-server/security/group-managed-service-accounts/group-managed-service-accounts-overview



View Related Case Study

DRAG DROP (Drag and Drop is not supported)
You need to meet the security requirements for passwords.
Where should you configure the components for Microsoft Entra Password Protection? To answer, drag the appropriate components to the correct locations. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Note: Each correct selection is worth one point.
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad-on-premises



View Related Case Study

You need to meet the technical requirements for Server1.
Which users can currently perform the required tasks?

  1. Admin3 only
  2. Admin1 and Admin3 only
  3. Admin1 only
  4. Admin1, Admin2, and Admin3

Answer(s): B



View Related Case Study

You need to meet the technical requirements for the site links.
Which users can perform the required tasks?

  1. Admin1, Admin2, and Admin3
  2. Admin1 and Admin3 only
  3. Admin1 only
  4. Admin1 and Admin2 only
  5. Admin3 only

Answer(s): C



Viewing page 2 of 39
Viewing questions 9 - 16 out of 302 questions


Post your Comments and Discuss Microsoft AZ-800 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!