AZ-801事前に試験練習テストで使おう(最新159問題) [Q57-Q81]

Share

AZ-801事前に試験練習テストで使おう(最新159問題)

有効なAZ-801試験解答PDF一年無料更新

質問 # 57
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains servers that run Windows Server as shown in the following table.

Server1 has the connection security rules shown in the following table.

Server2 has the connection security rules shown in the following table.
.

正解:

解説:

Explanation:


質問 # 58
You have an Azure Active Directory Domain Services (Azure AD DS) domain named aadds.contoso.com.
You have an Azure virtual network named Vnet1. Vnet1 contains two virtual machines named VM1 and VM2 that run Windows Server. VMI and VM2 are joined to aadds.contoso.com.
You create a new Azure virtual network named Vnet2. You add a new server named VM3 to Vnet2.
When you attempt to join VM3 to aadds.contoso.com, you get an error message that the domain cannot be found.
You need to ensure that you can join VM3 toaadds.contoso.com.

正解:

解説:

Explanation:


質問 # 59
You need to back up Server 4 to meet the technical requirements.
What should you do first?

  • A. Deploy Microsoft Azure Backup Server (MABS).
  • B. Configure Windows Server Backup.
  • C. Install the Microsoft Azure Recovery Services (MARS) agent.
  • D. Configure Storage Replica.

正解:C

解説:
Reference:
https://docs.microsoft.com/en-us/azure/backup/install-mars-agent
Topic 1, Contoso, Ltd
Case study
This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.
To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.
At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.
To start the case study
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.
Overview
Contoso, Ltd. is a manufacturing company that has a main office in Seattle and branch offices in Los Angeles and Montreal.
Existing Environment
Active Directory Environment
Contoso has an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with an Azure Active Directory (Azure AD) tenant. The AD DS domain contains the domain controllers shown in the following table.

Contoso recently purchased an Azure subscription.
The functional level of the forest is Windows Server 2012 R2. The functional level of the domain is Windows Server 2012. The forest has the Active Directory Recycle Bin enabled.
The contoso.com domain contains the users shown in the following table.

The contoso.com domain has the Group Policy Objects (GPOs) shown in the following table.

The contoso.com domain has the Password Settings Objects (PSOs) shown in the following table.

Server Infrastructure
The contoso.com domain contains servers that run Windows Server 2022 as shown in the following table.

By using Windows Firewall with Advanced Security, the servers have isolation connection security rules configured as shown in the following table.

Server4 has no connection security rules.
Server4 Configurations
Server4 has the effective Group Policy settings for user rights as shown in the following table.

Server4 has the disk configurations shown in the following exhibit.

Virtualization Infrastructure
The contoso.com domain has the Hyper-V failover clusters shown in the following table.

Technical Requirements
Contoso identifies the following technical requirements:
* Promote a new server named DC4 that runs to Windows Server 2022 to a domain controller.
* Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault.
* Centrally manage performance alerts in Azure for all the domain controllers.
* Ensure that User1 can recover objects from the Active Directory Recycle Bin.
* Migrate Share1 to Server2, including all the share and folder permissions.
* Back up Server4 and all data to an Azure Recovery Services vault.
* Use Hyper-V Replica to protect the virtual machines in Cluster3.
* Implement BitLocker Drive Encryption (BitLocker) on Server4.
* Whenever possible, use the principle of least privilege.


質問 # 60
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a server named Server1 that runs Windows Server.
You need to ensure that only specific applications can modify the data in protected folders on Server1.
Solution: From Virus & threat protection, you configure Controlled folder access.
Does this meet the goal?

  • A. No
  • B. Yes

正解:B

解説:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/customize-controlled-folders?view=o365-worldwide


質問 # 61
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a failover cluster named Cluster1 that hosts an application named App1.
The General tab in App1 Properties is shown in the General exhibit. (Click the General tab.)

The Failover tab in App1 Properties is shown in the Failover exhibit. (Click the Failover tab.)

Server1 shuts down unexpectedly.
You need to ensure that when you start Server1, App1 continues to run on Server2.
Solution: You increase Maximum failures in the specified period for the App1 cluster role.
Does this meet the goal?

  • A. Yes
  • B. No

正解:B

解説:
The Maximum failures setting is used to determine when the cluster determines that a node is offline. It does not affect whether a cluster will fail back when a node comes online.


質問 # 62
You have five Azure virtual machines. You have a dedicated Azure Storage account to collect performance dat
a. You need to send the collected data directly to the Azure Storage account. What should you install on the virtual machines?

  • A. the Azure Diagnostics extension
  • B. the Azure Monitor agent
  • C. the Azure Connected Machine agent
  • D. the Telegraf agent
  • E. the Dependency agent

正解:A


質問 # 63
You have an on-premises server named Server1 and Microsoft Sentinel instance.
You plan to collect windows Defender Firewall events from Sever1 and analyze the event data by using Microsoft Sentinel.
What should you install on Server1, and which information should you provide during the instance? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:

Explanation


質問 # 64
You have two physical servers named AppSrv1 and AppSrv2 and an unconfigured server named Server1. All the servers run Windows Server. Only Server1 can access the internet.
You plan to use Azure Site Recovery to replicate AppSrv1 and AppSrv2 to Azure.
You need to deploy the required components to AppSrv1, AppSrv2, and Server1.
Which components should you deploy? To answer, drag the appropriate components to the correct servers. Each component may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

正解:

解説:

Reference:
https://docs.microsoft.com/en-us/azure/site-recovery/physical-azure-architecture
https://docs.microsoft.com/en-us/azure/site-recovery/physical-azure-set-up-source


質問 # 65
You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Windows Server. The subscription contains the storage accounts shown in the following table.

You plan to enable boot diagnostics for VM1.
You need to configure storage for the boot diagnostics logs and snapshots.
Which storage account should you use?

  • A. storage3
  • B. storage1
  • C. storage2

正解:A


質問 # 66
You have an on-premises server named Server1 and Microsoft Sentinel instance.
You plan to collect windows Defender Firewall events from Sever1 and analyze the event data by using Microsoft Sentinel.
What should you install on Server1, and which information should you provide during the instance? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:
Explanation


質問 # 67
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a server named Server1 that runs Windows Server.
You need to ensure that only specific applications can modify the data in protected folders on Server1.
Solution: From Virus & threat protection, you configure Tamper Protection.
Does this meet the goal?

  • A. Yes
  • B. No

正解:B

解説:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/customize-controlled-folders?
view=o365-worldwide


質問 # 68
You need to create a Hyper-V hyper-converged cluster that stores virtual machines by using Storage Spaces Owed Which three actions should you perform in sequence? To answer, move the appropriate anions from the list of actions to the answer area and arrange them in the correct order.

正解:

解説:

1 - Create a failover cluster
2 - Enable Storage Spaces Direct.
3 - Create a volume.


質問 # 69
What is the effective minimum password length for User1 and Admin1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:


質問 # 70
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

正解:

解説:

Explanation
Text Description automatically generated


質問 # 71
You have an on-premises IIS web server that hosts a web app named Appl. You plan to migrate App1 to a container and run the container in Azure. You need to perform the following tasks:
* Export App1 to a ZIP file.
* Create a container image based on Appl.
The solution must minimize administrative effort.

正解:

解説:


質問 # 72
You need to create a Hyper-V hyper-converged cluster that stores virtual machines by using Storage Spaces Owed Which three actions should you perform in sequence? To answer, move the appropriate anions from the list of actions to the answer area and arrange them in the correct order.

正解:

解説:
Explanation


質問 # 73
You have a failover cluster named Cluster1 that contains the nodes shown in the following table.

A File Server for general use cluster role named HAFS is configured as shown in the General exhibit (Click the General tab.)

正解:

解説:

Explanation:


質問 # 74
Your network contains an Active Directory Domain Services (AD DS) domain.
You need to implement a solution that meets the following requirements:
* Ensures that the members of the Domain Admins group are allowed to sign in only to domain controllers
* Ensures that the lifetime of Kerberos Ticket Granting Ticket (TGT) for the members of the Domain Admins group is limited to one hour Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

正解:

解説:

Explanation:
Graphical user interface, text, application, email Description automatically generated

Reference:
https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/how-to-configure-protected-accounts


質問 # 75
You need to create a Hyper-V hyper-converged cluster that stores virtual machines by using Storage Spaces Owed Which three actions should you perform in sequence? To answer, move the appropriate anions from the list of actions to the answer area and arrange them in the correct order.

正解:

解説:

1 - Create a failover cluster.
2 - Enable Storage Spaces Direct.
3 - Create a volume.


質問 # 76
You have a server that runs Windows Server and has the Web Server (IIS) server role installed. Server1 hosts a single website that has the following configurations:
* Is accessible by using a URL of https://www.contoso.com:8443 and has an SSL certificate that was issued by a third-party certification authority (CA) in the Microsoft Trusted Root Program
* Uses anonymous authentication
* Was developed by using PHP
You plan to use APP Service Migration Assistant to migrate the website to Azure App Service.
You need to migrate the website. The solution must minimize the number of changes made to the existing website.
What should you do manually to ensure that the website migration is successful? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:
Explanation
Graphical user interface, text, application Description automatically generated

Reference:
https://docs.microsoft.com/en-us/learn/modules/migrate-app-service-migration-assistant/3-understand-assessmen
https://docs.microsoft.com/en-us/learn/modules/migrate-app-service-migration-assistant/5-understand-migration


質問 # 77
With which servers can Server1 and Server3 communicate? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

解説:

Explanation
Graphical user interface, text, application, chat or text message Description automatically generated


質問 # 78
You have an Azure virtual machine named VM1 that runs Windows Server.
You plan to deploy a new line-of-business (LOB) application to VM1.
You need to ensure that the application can create child processes.
What should you configure on VM1?

  • A. Microsoft Defender Credential Guard
  • B. Microsoft Defender SmartScreen
  • C. Exploit protection
  • D. Microsoft Defender Application Control

正解:C

解説:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/customize-exploit-protection?view=o


質問 # 79
You have an on-premises IIS web server that hosts a web app named Appl. You plan to migrate App1 to a container and run the container in Azure. You need to perform the following tasks:
* Export App1 to a ZIP file.
* Create a container image based on Appl.
The solution must minimize administrative effort.

正解:

解説:


質問 # 80
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains three servers named Server1, Server2, and Server3 that run Windows Server. All the servers are on the same network and have network connectivity.
On Server1, Windows Defender Firewall has a connection security rule that has the following settings:
* Rule Type: Server-to-server
* Endpoint 1: Any IP address
* Endpoint 2: Any IP address
* Requirements: Require authentication for inbound connections and request authentication for outbound connections
* Authentication Method: Computer (Kerberos V5)
* Profile: Domain, Private, Public
* Name: Rule1
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

正解:

解説:


質問 # 81
......


Microsoft AZ-801認証試験の対象となるには、候補者はMicrosoft AZ-104またはAZ-204試験のいずれかに合格している必要があります。これにより、候補者はWindows Server管理とクラウドコンピューティングの概念に強固な基盤を持っています。


Microsoft AZ-801(Windows Server Hybrid Advanced Servicess)認定試験は、Windows Server Hybrid Advanced Servicesの構成と管理に関する専門知識を実証しようとしているITの専門家にとって非常に求められている認定試験です。この認定試験は、Azure Active Directory、Azure Site Recovery、Azure Backup、Azureファイルの同期などの分野で候補者の知識とスキルをテストするように設計されています。この試験では、ハイブリッドネットワーキング、サーバーインフラストラクチャ、およびストレージソリューションに関連するトピックもカバーしています。

 

Configuring Windows Server Hybrid Advanced Services無料更新認定サンプル問題:https://www.goshiken.com/Microsoft/AZ-801-mondaishu.html

試験本場前にトレンドなMicrosoft AZ-801のPDF問題集を試そう:https://drive.google.com/open?id=18u1kegICB91Dk6Y6JTkhW8BArCK_4tkc