Free AZ-801 Exam Braindumps

DRAG DROP (Drag and Drop is not supported)
You have an Azure subscription that contains an Azure key vault named Vault1.
You plan to deploy a virtual machine named VM1 that will run Windows Server.
You need to enable encryption at host for VM1. The solution must use customer-managed keys.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

  1. See Explanation section for answer.

Answer(s): A

Explanation:



HOTSPOT (Drag and Drop is not supported)
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains three servers named Server1, Server2, and Server3 that run Windows Server. All the servers are on the same network and have network connectivity.

On Server1, Windows Defender Firewall has a connection security rule that has the following settings:

•Rule Type: Server-to-server
•Endpoint 1: Any IP address
•Endpoint 2: Any IP address
•Requirements: Require authentication for inbound connections and request authentication for outbound connections
•Authentication Method: Computer (Kerberos V5)
•Profile: Domain, Private, Public
•Name: Rule1

Server2 has no connection security rules.

On Server3, Windows Defender Firewall has a connection security rule that has the following settings:

•Rule Type: Server-to-server
•Endpoint 1: Any IP address
•Endpoint 2: Any IP address
•Requirements: Request authentication for inbound and outbound connections
•Authentication Method: Computer (Kerberos V5)
•Profile: Domain, Private, Public
•Name: Rule1

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Your network contains an Active Directory Domain Services (AD DS) forest. The forest functional level is Windows Server 2012 R2. The forest contains the domains shown in the following table.



You create a user named Admin1.

You need to ensure that Admin1 can add a new domain controller that runs Windows Server 2022 to the east.contoso.com domain. The solution must follow the principle of least privilege.

To which groups should you add Admin1?

  1. EAST\Domain Admins only
  2. CONTOSO\Enterprise Admins only
  3. CONTOSO\Schema Admins and EAST\Domain Admins
  4. CONTOSO\Enterprise Admins and CONTOSO\Schema Admins

Answer(s): D



You have an Azure subscription named Sub1 that contains a resource group named RG1. RG1 contains the resources shown in the following table.



Sub1 has Microsoft Defender for Servers enabled. You are assigned the Contributor role for Sub1.

You need to implement just-in-time (JIT) VM access for VM1.

What should you do first?

  1. Create a network security group (NSG).
  2. Enable enhanced security in Microsoft Defender for Cloud.
  3. Request the Owner role for Sub1.
  4. Create an application security group.

Answer(s): C






Post your Comments and Discuss Microsoft AZ-801 exam with other Community members:

Philippe 1/22/2023 10:24:00 AM
iam impressed with the quality of these dumps. they questions and answers were easy to understand and the xengine app was very helpful to use.
CANADA
upvote

Philippe 1/22/2023 10:24:07 AM
Iam impressed with the quality of these dumps. They questions and answers were easy to understand and the Xengine App was very helpful to use.
CANADA
upvote