AZ-801 Exam Question 76
You have been hired as an expert member to manage the network security of the organization. In a team meeting, you need to present your views on how Windows Defender Firewall can help in addressing the organizational network security challenges. Which of the following statements fit in this context?
AZ-801 Exam Question 77
Case Study 2 - Contoso, Ltd
Overview
Contoso, Ltd. is a manufacturing company that has a main office in Seattle and branch offices in Los Angeles and Montreal.
Existing Environment
Active Directory Environment
Contoso has an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with an Azure Active Directory (Azure AD) tenant. The AD DS domain contains the domain controllers shown in the following table.

Contoso recently purchased an Azure subscription.
The functional level of the forest is Windows Server 2012 R2. The functional level of the domain is Windows Server 2012. The forest has the Active Directory Recycle Bin enabled.
The contoso.com domain contains the users shown in the following table.

The contoso.com domain has the Group Policy Objects (GPOs) shown in the following table.

The contoso.com domain has the Password Settings Objects (PSOs) shown in the following table.

Server Infrastructure
The contoso.com domain contains servers that run Windows Server 2022 as shown in the following table.

By using Windows Firewall with Advanced Security, the servers have isolation connection security rules configured as shown in the following table.

Server4 has no connection security rules.
Server4 Configurations
Server4 has the effective Group Policy settings for user rights as shown in the following table.

Server4 has the disk configurations shown in the following exhibit.

Virtualization Infrastructure
The contoso.com domain has the Hyper-V failover clusters shown in the following table.

Technical Requirements
Contoso identifies the following technical requirements:
* Promote a new server named DC4 that runs to Windows Server 2022 to a domain controller.
* Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault.
* Centrally manage performance alerts in Azure for all the domain controllers.
* Ensure that User1 can recover objects from the Active Directory Recycle Bin.
* Migrate Share1 to Server2, including all the share and folder permissions.
* Back up Server4 and all data to an Azure Recovery Services vault.
* Use Hyper-V Replica to protect the virtual machines in Cluster3.
* Implement BitLocker Drive Encryption (BitLocker) on Server4.
* Whenever possible, use the principle of least privilege.
Which domain controller should be online to meet the technical requirements for DC4?
Overview
Contoso, Ltd. is a manufacturing company that has a main office in Seattle and branch offices in Los Angeles and Montreal.
Existing Environment
Active Directory Environment
Contoso has an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with an Azure Active Directory (Azure AD) tenant. The AD DS domain contains the domain controllers shown in the following table.

Contoso recently purchased an Azure subscription.
The functional level of the forest is Windows Server 2012 R2. The functional level of the domain is Windows Server 2012. The forest has the Active Directory Recycle Bin enabled.
The contoso.com domain contains the users shown in the following table.

The contoso.com domain has the Group Policy Objects (GPOs) shown in the following table.

The contoso.com domain has the Password Settings Objects (PSOs) shown in the following table.

Server Infrastructure
The contoso.com domain contains servers that run Windows Server 2022 as shown in the following table.

By using Windows Firewall with Advanced Security, the servers have isolation connection security rules configured as shown in the following table.

Server4 has no connection security rules.
Server4 Configurations
Server4 has the effective Group Policy settings for user rights as shown in the following table.

Server4 has the disk configurations shown in the following exhibit.

Virtualization Infrastructure
The contoso.com domain has the Hyper-V failover clusters shown in the following table.

Technical Requirements
Contoso identifies the following technical requirements:
* Promote a new server named DC4 that runs to Windows Server 2022 to a domain controller.
* Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault.
* Centrally manage performance alerts in Azure for all the domain controllers.
* Ensure that User1 can recover objects from the Active Directory Recycle Bin.
* Migrate Share1 to Server2, including all the share and folder permissions.
* Back up Server4 and all data to an Azure Recovery Services vault.
* Use Hyper-V Replica to protect the virtual machines in Cluster3.
* Implement BitLocker Drive Encryption (BitLocker) on Server4.
* Whenever possible, use the principle of least privilege.
Which domain controller should be online to meet the technical requirements for DC4?
AZ-801 Exam Question 78
Hotspot Question
Your network contains an on-premises Active Directory Domain Services (AD DS) domain. The domain contains the servers shown in the following table.

For each server, Windows Defender Firewall is configured to allow only communication between servers on the same segment.
Server1 has the following connection security rule:
- Name: Rule1
- Rule type: isolation
- Requirement: Require authentication for inbound connections and request authentication for outbound connections
- Authentication method: Computer (Kerberos V5)
- Profile: Domain, Private, Public
Server2 does not have any connection security rules.
Server3 has the following connection security rule:
- Name: Rule3
- Rule type: Server-to-server
- Endpoints
- Computers in Endpoint 1: 192.168:5.0/24
- Computers in Endpoint 2: 192.168.1.0/24
- Requirement: Request authentication for inbound and outbound connections
- Authentication method: Computer (Kerberos V5)
- Profile: Domain, Private, Public
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Your network contains an on-premises Active Directory Domain Services (AD DS) domain. The domain contains the servers shown in the following table.

For each server, Windows Defender Firewall is configured to allow only communication between servers on the same segment.
Server1 has the following connection security rule:
- Name: Rule1
- Rule type: isolation
- Requirement: Require authentication for inbound connections and request authentication for outbound connections
- Authentication method: Computer (Kerberos V5)
- Profile: Domain, Private, Public
Server2 does not have any connection security rules.
Server3 has the following connection security rule:
- Name: Rule3
- Rule type: Server-to-server
- Endpoints
- Computers in Endpoint 1: 192.168:5.0/24
- Computers in Endpoint 2: 192.168.1.0/24
- Requirement: Request authentication for inbound and outbound connections
- Authentication method: Computer (Kerberos V5)
- Profile: Domain, Private, Public
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

AZ-801 Exam Question 79
Drag and Drop Question
You have a single-domain Active Directory Domain Services (AD DS) forest named contoso.com that contains two domain controllers named DC1 and DC2. DC1 and DC2 run Windows Server.
You plan to perform an authoritative restore of SYSVOL on DC1.
You isolate DC1 and restore DC1 from a backup.
You need to ensure that SYSVOL on DC1 replicates to DC2.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

You have a single-domain Active Directory Domain Services (AD DS) forest named contoso.com that contains two domain controllers named DC1 and DC2. DC1 and DC2 run Windows Server.
You plan to perform an authoritative restore of SYSVOL on DC1.
You isolate DC1 and restore DC1 from a backup.
You need to ensure that SYSVOL on DC1 replicates to DC2.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

AZ-801 Exam Question 80
You have an Azure virtual machine named VM1 that runs Windows Server.
You configure Azure Site Recovery replication for VM1.
You need to perform a test failover on VM1.
What should you use from the VM1 blade in the Azure portal?
You configure Azure Site Recovery replication for VM1.
You need to perform a test failover on VM1.
What should you use from the VM1 blade in the Azure portal?


