AZ-801 Exam Question 16
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1.
You deploy a read-only domain controller (RODC) named RODC1.
You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege.
What should you use?
You deploy a read-only domain controller (RODC) named RODC1.
You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege.
What should you use?
AZ-801 Exam Question 17
Case Study 2 - Contoso, Ltd
Overview
Contoso, Ltd. is a manufacturing company that has a main office in Seattle and branch offices in Los Angeles and Montreal.
Existing Environment
Active Directory Environment
Contoso has an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with an Azure Active Directory (Azure AD) tenant. The AD DS domain contains the domain controllers shown in the following table.

Contoso recently purchased an Azure subscription.
The functional level of the forest is Windows Server 2012 R2. The functional level of the domain is Windows Server 2012. The forest has the Active Directory Recycle Bin enabled.
The contoso.com domain contains the users shown in the following table.

The contoso.com domain has the Group Policy Objects (GPOs) shown in the following table.

The contoso.com domain has the Password Settings Objects (PSOs) shown in the following table.

Server Infrastructure
The contoso.com domain contains servers that run Windows Server 2022 as shown in the following table.

By using Windows Firewall with Advanced Security, the servers have isolation connection security rules configured as shown in the following table.

Server4 has no connection security rules.
Server4 Configurations
Server4 has the effective Group Policy settings for user rights as shown in the following table.

Server4 has the disk configurations shown in the following exhibit.

Virtualization Infrastructure
The contoso.com domain has the Hyper-V failover clusters shown in the following table.

Technical Requirements
Contoso identifies the following technical requirements:
* Promote a new server named DC4 that runs to Windows Server 2022 to a domain controller.
* Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault.
* Centrally manage performance alerts in Azure for all the domain controllers.
* Ensure that User1 can recover objects from the Active Directory Recycle Bin.
* Migrate Share1 to Server2, including all the share and folder permissions.
* Back up Server4 and all data to an Azure Recovery Services vault.
* Use Hyper-V Replica to protect the virtual machines in Cluster3.
* Implement BitLocker Drive Encryption (BitLocker) on Server4.
* Whenever possible, use the principle of least privilege.
Drag and Drop Question
You need to meet the technical requirements for Cluster2.
Which four actions should you perform in sequence before you can enable replication? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Overview
Contoso, Ltd. is a manufacturing company that has a main office in Seattle and branch offices in Los Angeles and Montreal.
Existing Environment
Active Directory Environment
Contoso has an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with an Azure Active Directory (Azure AD) tenant. The AD DS domain contains the domain controllers shown in the following table.

Contoso recently purchased an Azure subscription.
The functional level of the forest is Windows Server 2012 R2. The functional level of the domain is Windows Server 2012. The forest has the Active Directory Recycle Bin enabled.
The contoso.com domain contains the users shown in the following table.

The contoso.com domain has the Group Policy Objects (GPOs) shown in the following table.

The contoso.com domain has the Password Settings Objects (PSOs) shown in the following table.

Server Infrastructure
The contoso.com domain contains servers that run Windows Server 2022 as shown in the following table.

By using Windows Firewall with Advanced Security, the servers have isolation connection security rules configured as shown in the following table.

Server4 has no connection security rules.
Server4 Configurations
Server4 has the effective Group Policy settings for user rights as shown in the following table.

Server4 has the disk configurations shown in the following exhibit.

Virtualization Infrastructure
The contoso.com domain has the Hyper-V failover clusters shown in the following table.

Technical Requirements
Contoso identifies the following technical requirements:
* Promote a new server named DC4 that runs to Windows Server 2022 to a domain controller.
* Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault.
* Centrally manage performance alerts in Azure for all the domain controllers.
* Ensure that User1 can recover objects from the Active Directory Recycle Bin.
* Migrate Share1 to Server2, including all the share and folder permissions.
* Back up Server4 and all data to an Azure Recovery Services vault.
* Use Hyper-V Replica to protect the virtual machines in Cluster3.
* Implement BitLocker Drive Encryption (BitLocker) on Server4.
* Whenever possible, use the principle of least privilege.
Drag and Drop Question
You need to meet the technical requirements for Cluster2.
Which four actions should you perform in sequence before you can enable replication? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

AZ-801 Exam Question 18
You have a three-node failover cluster.
You need to run pre-scripts and post-scripts when Cluster-Aware Updating (CAU) runs. The solution must minimize administrative effort.
What should you use?
You need to run pre-scripts and post-scripts when Cluster-Aware Updating (CAU) runs. The solution must minimize administrative effort.
What should you use?
AZ-801 Exam Question 19
Hotspot Question
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.
You run Get-BitLockerVolume -MountPoint C,D | fl *, which generates the following output.

You need to ensure that volume D will be unlocked automatically when Server1 restarts.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1 that runs Windows Server.
You run Get-BitLockerVolume -MountPoint C,D | fl *, which generates the following output.

You need to ensure that volume D will be unlocked automatically when Server1 restarts.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

AZ-801 Exam Question 20
You have an Azure virtual machine named VM1 that runs Windows Server.
VM1 fails to start properly.
You need to review the serial log to identify the issue.
What should you use from the VM1 blade in the Azure portal?
VM1 fails to start properly.
You need to review the serial log to identify the issue.
What should you use from the VM1 blade in the Azure portal?


