AZ-800 Exam Question 171

Case Study 3 - ADatum Corporation
Overview
Company Information
ADatum Corporation is a manufacturing company that has a main office in Seattle and two branch offices in Los Angeles and Montreal.
Fabrikam Partnership
ADatum recently partnered with 2 company named Fabrikam, Inc.
Fabrikam is a manufacturing company that has a main office in Boston and a branch office in Orlando.
Both companies intend to collaborate on several joint projects.
Existing Environment
ADatum AD DS Environment
The on-premises network of ADatum contains an Active Directory Domain Services (AD DS) forest named adatum.com.
The forest contains two domains named adatum.com and east.adatum.com and the domain controllers shown in the following table.

Fabrikam AD DS Environment
The on-premises network of Fabrikam contains an AD DS forest named fabrikam.com.
The forest contains two domains named fabrikam.com and south.fabrikam.com.
The fabrikam.com domain contains an organizational unit (OU) named Marketing.
Server Infrastructure
The adatum.com domain contains the servers shown in the following table.

HyperV1 contains the virtual machines shown in the following table.

All the virtual machines on HyperV1 have only the default management tools installed.
SSPace1 contains the Storage Spaces virtual disks shown in the following table.

Azure Resources
ADatum has an Azure subscription that contains an Azure AD tenant. Azure AD Connect is configured to sync the adatum.com forest with Azure AD.
The subscription contains the virtual networks shown in the following table.

The subscription contains the Azure Private DNS zones shown in the following table.

The subscription contains the virtual machines shown in the following table.

All the servers are in a workgroup.
The subscription contains a storage account named storage1 that has a file share named share1.
Requirements
Planned Changes
ADatum plans to implement the following changes:
- Sync Data1 to share1.
- Configure an Azure runbook named Task1.
- Enable Azure AD users to sign in to Server1.
- Create an Azure DNS Private Resolver that has the following configurations:
- Name: Private1
- Region: West US
- Virtual network: VNet1
- Inbound endpoint: SubnetB
- Enable users in the adatum.com domain to access the resources in the south.fabrikam.com domain.
Technical Requirements
ADatum identifies the following technical requirements:
- The data on SSPace1 must be available always.
- DC2 must become the schema master if DC1 fails.
- VM3 must be configured to enable per-folder quotas.
- Trusts must allow access to only the required resources.
- The users in the Marketing OU must have access to storage1.
- Azure Automanage must be used on all supported Azure virtual machines.
- A direct SSH session must be used to manage all the supported virtual machines on HyperV1.
Drag and Drop Question
You need to implement the planned change for Data1.
Which actions should you perform in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

AZ-800 Exam Question 172

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.
You open a new branch office that contains only client computers. You need to ensure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.
Solution: You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO that is linked to Site1.
Does this meet the goal?
  • AZ-800 Exam Question 173

    You have an Active Directory domain that contains a file server named Server1. Server1 runs Windows Server and includes the file shares shown in the following table.

    When users login to the network they receive the following network drive mappings.
    * H: maps to Wserver1\users\%UserName%
    * G: maps to \\server1\%Department%
    You need to limit the amount of space consumed by user's on Server!. The solution must meet the following requirements:
    * Prevent users using more than 5GB of space on their H: drive
    * Prevent Accounts department users from using more than 10GB of space on the G: drive
    * Prevent Marketing department users from using more than 15GB of space on the G: drive
    * Prevent Customer Service department users from using more than 2GB of space on the G: drive
    * Minimize administrative effort
    What should you use?
  • AZ-800 Exam Question 174

    Your network contains a single-domain Active Directory Domain Services (AD DS) forest named conto.com. The forest contains the servers shown in the following exhibit table.

    You plan to install a line-of-business (LOB) application on Server1. The application will install a custom windows services.
    A new corporate security policy states that all custom Windows services must run under the context of a group managed service account (gMSA). You deploy a root key.
    You need to create, configure, and install the gMSA that will be used by the new application.
    Which two actions should you perform? Each correct answer presents part of the solution.
    NOTE: Each correct selection is worth one point.
  • AZ-800 Exam Question 175

    Case Study 3 - ADatum Corporation
    Overview
    Company Information
    ADatum Corporation is a manufacturing company that has a main office in Seattle and two branch offices in Los Angeles and Montreal.
    Fabrikam Partnership
    ADatum recently partnered with 2 company named Fabrikam, Inc.
    Fabrikam is a manufacturing company that has a main office in Boston and a branch office in Orlando.
    Both companies intend to collaborate on several joint projects.
    Existing Environment
    ADatum AD DS Environment
    The on-premises network of ADatum contains an Active Directory Domain Services (AD DS) forest named adatum.com.
    The forest contains two domains named adatum.com and east.adatum.com and the domain controllers shown in the following table.

    Fabrikam AD DS Environment
    The on-premises network of Fabrikam contains an AD DS forest named fabrikam.com.
    The forest contains two domains named fabrikam.com and south.fabrikam.com.
    The fabrikam.com domain contains an organizational unit (OU) named Marketing.
    Server Infrastructure
    The adatum.com domain contains the servers shown in the following table.

    HyperV1 contains the virtual machines shown in the following table.

    All the virtual machines on HyperV1 have only the default management tools installed.
    SSPace1 contains the Storage Spaces virtual disks shown in the following table.

    Azure Resources
    ADatum has an Azure subscription that contains an Azure AD tenant. Azure AD Connect is configured to sync the adatum.com forest with Azure AD.
    The subscription contains the virtual networks shown in the following table.

    The subscription contains the Azure Private DNS zones shown in the following table.

    The subscription contains the virtual machines shown in the following table.

    All the servers are in a workgroup.
    The subscription contains a storage account named storage1 that has a file share named share1.
    Requirements
    Planned Changes
    ADatum plans to implement the following changes:
    - Sync Data1 to share1.
    - Configure an Azure runbook named Task1.
    - Enable Azure AD users to sign in to Server1.
    - Create an Azure DNS Private Resolver that has the following configurations:
    - Name: Private1
    - Region: West US
    - Virtual network: VNet1
    - Inbound endpoint: SubnetB
    - Enable users in the adatum.com domain to access the resources in the south.fabrikam.com domain.
    Technical Requirements
    ADatum identifies the following technical requirements:
    - The data on SSPace1 must be available always.
    - DC2 must become the schema master if DC1 fails.
    - VM3 must be configured to enable per-folder quotas.
    - Trusts must allow access to only the required resources.
    - The users in the Marketing OU must have access to storage1.
    - Azure Automanage must be used on all supported Azure virtual machines.
    - A direct SSH session must be used to manage all the supported virtual machines on HyperV1.
    Drag and Drop Question
    DC1 fails.
    You need to meet the technical requirements for the schema master.
    You run ntdsutil.exe.
    Which five commands should you run in sequence? To answer, move the appropriate commands from the list of commands to the answer area and arrange them in the correct order?