AZ-801 Configuring Windows Server Hybrid Advanced Services Exam
Updates to the exam
Our exams are updated periodically to reflect skills that are required to perform a role. We have included two versions of the Skills Measured objectives depending on when you are taking the exam.
We always update the English language version of the exam first. Some exams are localized into other languages, and those are updated approximately eight weeks after the English version is updated. While Microsoft makes every effort to update localized versions as noted, there may be times when the localized versions of an exam are not updated on this schedule. Other available languages are listed in the Schedule Exam section of the Exam Details webpage. If the exam isn’t available in your preferred language, you can request an additional 30 minutes to complete the exam.
Note
The bullets that follow each of the skills measured are intended to illustrate how we are assessing that skill. Related topics may be covered in the exam.
Note
Most questions cover features that are general availability (GA). The exam may contain questions on Preview features if those features are commonly used.
Examkingdom Microsoft AZ-801 Exam pdf,
Best Microsoft AZ-801 Downloads, Microsoft AZ-801 Dumps at Certkingdom.com
Skills measured as of August 24, 2023
Audience profile
Candidates for this exam are responsible for configuring and managing Windows Server on-premises, hybrid, and Infrastructure as a Service (IaaS) platform workloads. The Windows Server Hybrid Administrator is tasked with integrating Windows Server environments with Azure services and managing Windows Server in on-premises networks. This role manages and maintains Windows Server IaaS workloads in Azure as well as migrating and deploying workloads to Azure. This role typically collaborates with Azure Administrators, Enterprise Architects, Microsoft 365 administrators, and network engineers.
Candidates for this exam deploy, package, secure, update, and configure Windows Server workloads using on-premises, hybrid, and cloud technologies. This role implements and manages on-premises and hybrid solutions, such as identity, security, management, compute, networking, storage, monitoring, high availability, and disaster recovery. This role uses administrative tools and technologies such as Windows Admin Center, PowerShell, Azure Arc, Azure Policy, Azure Monitor, Azure Automation Update Management, Microsoft Defender for Identity, Microsoft Defender for Cloud, and IaaS VM administration.
Candidates for this exam have several years of experience with Windows Server operating systems.
Secure Windows Server on-premises and hybrid infrastructures (25–30%)
Implement and manage Windows Server high availability (10–15%)
Implement disaster recovery (10–15%)
Migrate servers and workloads (20–25%)
Monitor and troubleshoot Windows Server environments (20–25%)
Secure Windows Server on-premises and hybrid infrastructures (25–30%)
Secure Windows Server operating system
Configure and manage Exploit Protection
Configure and manage Windows Defender Application Control
Configure and manage Microsoft Defender for Servers
Configure and manage Windows Defender Credential Guard
Configure SmartScreen
Implement operating system security by using Group Policies
Secure a hybrid Active Directory infrastructure
Configure password policies
Enable password block lists
Manage protected users
Manage account security on an RODC
Harden domain controllers
Configure authentication policy silos
Restrict access to domain controllers
Configure account security
Manage AD built-in administrative groups
Manage AD delegation
Implement and manage Microsoft Defender for Identity
Identify and remediate Windows Server security issues by using Azure services
Monitor on-premises servers and Azure IaaS VMs by using Microsoft Sentinel
Identify and remediate security issues on-premises servers and Azure IaaS VMs by using Microsoft Defender for Cloud
Secure Windows Server networking
Manage Windows Defender Firewall
Implement domain isolation
Implement connection security rules
Secure Windows Server storage
Manage Windows BitLocker Drive Encryption (BitLocker)
Manage and recover encrypted volumes
Enable storage encryption by using Azure Disk Encryption
Manage disk encryption keys for IaaS virtual machines
Implement and Manage Windows Server high availability (10–15%)
Implement a Windows Server failover cluster
Implement a failover cluster on-premises, hybrid, or cloud-only
Create a Windows failover cluster
Implement a stretch cluster across datacenters or Azure regions
Configure storage for failover clustering
Modify quorum options
Configure network adapters for failover clustering
Configure cluster workload options
Configure cluster sets
Configure Scale-Out File servers
Create an Azure witness
Configure a floating IP address for the cluster
Implement load balancing for the failover cluster
Manage failover clustering
Implement cluster-aware updating
Recover a failed cluster node
Upgrade a node to Windows Server 2022
Failover workloads between nodes
Install Windows updates on cluster nodes
Manage failover clusters using Windows Admin Center
Implement and manage Storage Spaces Direct
Create a failover cluster using Storage Spaces Direct
Upgrade a Storage Spaces Direct node
Implement networking for Storage Spaces Direct
Configure Storage Spaces Direct
Implement disaster recovery (10–15%)
Manage backup and recovery for Windows Server
Back up and restore files and folders to Azure Recovery Services Vault
Install and manage Azure Backup Server
Back up and recover using Azure Backup Server
Manage backups in Azure Recovery Services Vault
Create a backup policy
Configure backup for Azure VM using the built-in backup agent
Recover VM using temporary snapshots
Recover VMs to new Azure VMs
Restore a VM
Implement disaster recovery by using Azure Site Recovery
Configure Azure Site Recovery networking
Configure Site Recovery for on-premises VMs
Configure a recovery plan
Configure Site Recovery for Azure VMs
Implement VM replication to secondary datacenter or Azure region
Configure Azure Site Recovery policies
Protect virtual machines by using Hyper-V replicas
Configure Hyper-V hosts for replication
Manage Hyper-V replica servers
Configure VM replication
Perform a failover
Migrate servers and workloads (20–25%)
Migrate on-premises storage to on-premises servers or Azure
Transfer data and share
Cut over to a new server by using Storage Migration Service (SMS)
Use Storage Migration Service to migrate to Azure VMs
Migrate to Azure file shares
Migrate on-premises servers to Azure
Deploy and configure Azure Migrate appliance
Migrate VM workloads to Azure IaaS
Migrate physical workloads to Azure IaaS
Migrate by using Azure Migrate
Migrate workloads from previous versions to Windows Server 2022
Migrate IIS
Migrate Hyper-V hosts
Migrate RDS host servers
Migrate DHCP
Migrate print servers
Migrate IIS workloads to Azure
Migrate IIS workloads to Azure Web Apps
Migrate IIS workloads to containers
Migrate an AD DS infrastructure to Windows Server 2022 AD DS
Migrate AD DS objects, including users, groups and Group Policies using AD Migration Tool
Migrate to a new Active Directory forest
Upgrade an existing forest
Monitor and troubleshoot Windows Server environments (20–25%)
Monitor Windows Server by using Windows Server tools and Azure services
Monitor Windows Server by using Performance Monitor
Create and configure Data Collector Sets
Monitor servers and configure alerts by using Windows Admin Center
Analyze Windows Server system data by using System Insights
Manage event logs
Deploy Azure Monitor agents
Collect performance counters to Azure
Create alerts
Monitor Azure VMs by using Azure diagnostics extension
Monitor Azure VMs performance by using VM Insights
Troubleshoot Windows Server on-premises and hybrid networking
Troubleshoot hybrid network connectivity
Troubleshoot on-premises connectivity
Troubleshoot Windows Server virtual machines in Azure
Troubleshoot deployment failures
Troubleshoot booting failures
Troubleshoot VM performance issues
Troubleshoot VM extension issues
Troubleshoot disk encryption issues
Troubleshoot storage
Troubleshoot VM connection issues
Troubleshoot Active Directory
Restore objects from AD recycle bin
Recover Active Directory database using Directory Services Restore mode
Recover SYSVOL
Troubleshoot Active Directory replication
Troubleshoot Hybrid authentication issues
Troubleshoot on-premises Active Directory
QUESTION 1
DRAG DROP
You are planning the implementation of Cluster2 to support the on-premises migration plan.
You need to ensure that the disks on Cluster2 meet the security requirements.
In which order should you perform the actions? To answer, move all actions from the list of actions to
the answer area and arrange them in the correct order.
Answer:
QUESTION 2
HOTSPOT
You need to implement a security policy solution to authorize the applications. The solution must
meet the security requirements.
Which service should you use to enforce the security policy, and what should you use to manage the
policy settings? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
QUESTION 3
You are remediating the firewall security risks to meet the security requirements.
What should you configure to reduce the risks?
A. a Group Policy Object (GPO)
B. adaptive network hardening in Microsoft Defender for Cloud
C. a network security group (NSG) in Sub1
D. an Azure Firewall policy
Answer: A
QUESTION 4
You are planning the deployment of Microsoft Sentinel.
Which type of Microsoft Sentinel data connector should you use to meet the security requirements?
A. Threat Intelligence – TAXII
B. Azure Active Directory
C. Microsoft Defender for Cloud
D. Microsoft Defender for Identity
Answer: D
QUESTION 5
You are planning the migration of Archive1 to support the on-premises migration plan.
What is the minimum number of IP addresses required for the node and cluster roles on Cluster3?
A. 2
B. 3
C. 4
D. 5
Answer: B
Explanation:
One IP for each of the two nodes in the cluster and one IP for the cluster virtual IP (VIP).
QUESTION 6
HOTSPOT
You are planning the www.fabrikam.com website migration to support the Azure migration plan.
How should you configure WebApp1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Box 1: Add a custom domain name
To migrate www.fabrikam.com website to an Azure App Service web app, you need to add
Fabrikam.com as a custom domain in Azure. This will make the domain name available to use in the web app.
Box 2: Modify a DNS record
You need to change the DNS record for www.fabrikam.com to point to the Azure web app.
HTTP redirect rules wont work because WEB1 and WEB2 will be decommissioned.
QUESTION 7
DRAG DROP
You are planning the DHCP1 migration to support the DHCP migration plan.
Which two PowerShell cmdlets should you run on DHCP1, and which two PowerShell cmdlets should
you run on DHCP2? To answer, drag the appropriate cmdlets to the correct servers. Each cmdlet may
be used once, more than once, or not at all. You may need to drag the split bar between panes or
scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
QUESTION 8
You are planning the data share migration to support the on-premises migration plan.
What should you use to perform the migration?
A. Storage Migration Service
B. Microsoft File Server Migration Toolkit
C. File Server Resource Manager (FSRM)
D. Windows Server Migration Tools
Answer: A
QUESTION 9
HOTSPOT
You are planning the migration of APP3 and APP4 to support the Azure migration plan.
What should you do on Cluster1 and in Azure before you perform the migration? To answer, select
the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
QUESTION 10
HOTSPOT
You are planning the europe.fabrikam.com migration to support the on-premises migration plan-
Where should you install the Password Export Server (PES) service, where should you generate the
encryption key? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation: