Microsoft

AZ-801 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 126-question bank.

Provider
Microsoft
Question bank
126
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for AZ-801, a certification listed under Microsoft. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Microsoft. The certification credential is issued by Microsoft, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a server named Server1 that runs Windows Server. You need to ensure that only specific applications can modify the data in protected folders on Server1. Solution: From Virus & threat protection, you configure Controlled folder access. Does this meet the goal?

    Choose one answer.

    • Yes
    • No
  2. Question 2 · 1

    You have a Microsoft Sentinel deployment and 100 Azure Arc-enabled on-premises servers. All the Azure Arc-enabled resources are in the same resource group. You need to onboard the servers to Microsoft Sentinel. The solution must minimize administrative effort. What should you use to onboard the servers to Microsoft Sentinel?

    Choose one answer.

    • Azure Automation
    • Azure Policy
    • Azure virtual machine extensions
    • Microsoft Defender for Cloud
  3. Question 3 · 1

    You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant by using password hash synchronization. You have a Microsoft 365 subscription. All devices are hybrid Azure AD-joined. Users report that they must enter their password manually when accessing Microsoft 365 applications. You need to reduce the number of times the users are prompted for their password when they access Microsoft 365 and Azure services. What should you do?

    Choose one answer.

    • In Azure AD, configure a Conditional Access policy for the Microsoft Office 365 applications.
    • In the DNS zone of the AD DS domain, create an autodiscover record.
    • From Azure AD Connect, enable single sign-on (SSO).
    • From Azure AD Connect, configure pass-through authentication.
  4. Question 4 · 1

    You have an Azure subscription that has Microsoft Defender for Cloud enabled. You have 50 Azure virtual machines that run Windows Server. You need to ensure that any security exploits detected on the virtual machines are forwarded to Defender for Cloud. Which extension should you enable on the virtual machines?

    Choose one answer.

    • Vulnerability assessment for machines
    • Microsoft Dependency agent
    • Log Analytics agent for Azure VMs
    • Guest Configuration agent
  5. Question 5 · 1

    You have 10 servers that run Windows Server in a workgroup. You need to configure the servers to encrypt all the network traffic between the servers. The solution must be as secure as possible. Which authentication method should you configure in a connection security rule?

    Choose one answer.

    • NTLMv2
    • pre-shared key
    • Kerberos V5
    • computer certificate
  6. Question 6 · 1

    You have an Azure virtual machine named VM1 that runs Windows Server. You need to encrypt the contents of the disks on VM1 by using Azure Disk Encryption. What is a prerequisite for implementing Azure Disk Encryption?

    Choose one answer.

    • Customer Lockbox for Microsoft Azure
    • an Azure key vault
    • a BitLocker recovery key
    • data-link layer encryption in Azure
  7. Question 7 · 1

    Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains two servers named Server1 and Server2 that run Windows Server. You need to ensure that you can use the Computer Management console to manage Server2. The solution must use the principle of least privilege. Which two Windows Defender Firewall with Advanced Security rules should you enable on Server2? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

    Choose all answers that apply.

    • the COM+ Network Access (DCOM-In) rule
    • all the rules in the Remote Event Log Management group
    • the Windows Management Instrumentation (WMI-In) rule
    • the COM+ Remote Administration (DCOM-In) rule
    • the Windows Management Instrumentation (DCOM-In) rule
  8. Question 8 · 1

    You have a server that runs Windows Server. The server is configured to encrypt all incoming traffic by using a connection security rule. You need to ensure that Server1 can respond to the unencrypted tracert commands initiated from computers on the same network. What should you do from Windows Defender Firewall with Advanced Security?

    Choose one answer.

    • From the IPsec Settings, configure IPsec defaults.
    • Create a new custom outbound rule that allows ICMPv4 protocol connections for all profiles.
    • Change the Firewall state of the Private profile to Off.
    • From the IPsec Settings, configure IPsec exemptions.
  9. Question 9 · 1

    You have an Azure virtual machine named VM1. You enable Microsoft Defender SmartScreen on VM1. You need to ensure that the SmartScreen messages displayed to users are logged. What should you do?

    Choose one answer.

    • From a command prompt, run WinRM quickconfig.
    • From the local Group Policy, modify the Advanced Audit Policy Configuration settings.
    • From Event Viewer, enable the Debug log.
    • From the Windows Security app, configure the Virus & threat protection settings.
  10. Question 10 · 1

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a server named Server1 that runs Windows Server. You need to ensure that only specific applications can modify the data in protected folders on Server1. Solution: From Virus & threat protection, you configure Tamper Protection Does this meet the goal?

    Choose one answer.

    • Yes
    • No
  11. Question 11 · 1

    You have an Azure subscription that contains a user named User1 and the resources shown in the following table. User1 has a computer named Computer1 that runs Windows 11. User1 works from home and establishes a Point-to-Site (P2S) connection to GW1 to access AppSvr1. You deploy the resources shown in the following table. User1 cannot access AppSvr2. You need to ensure that User1 can access AppSvr2. What should you do?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • On Computer1, download and reinstall the VPN client.
    • Create a route table and associate the table with GatewaySubnet on VNet1.
    • On Computer1, modify the Windows Defender Firewall settings.
    • Add a service endpoint to VNet2.
  12. Question 12 · 1

    HOTSPOT - You have a generation 1 Azure virtual machine named VM1 that runs Windows Server and is joined to an Active Directory domain. You plan to enable BitLocker Drive Encryption (Bit-Locker) on volume C of VM1. You need to ensure that the BitLocker recovery key for VM1 is stored in Active Directory. Which two Group Policy settings should you configure first? To answer, select the settings in the answer area. NOTE: Each correct selection is worth one point.

    Choose an option for each prompt.

    Question illustration 1

    Group Policy setting 1:

    • Allow network unlock at startup
    • Allow Secure Boot for integrity validation
    • Require additional authentication at startup
    • Require additional authentication at startup (Windows Server 2008 and Windows Vista)
    • Disallow standard users from changing the PIN or password
    • Allow devices compliant with InstantGo or HSTI to opt out of pre-boot PIN.
    • Enable use of BitLocker authentication requiring preboot keyboard input on slates
    • Allow enhanced PINs for startup
    • Configure minimum PIN length for startup
    • Configure use of hardware-based encryption for operating system drives
    • Enforce drive encryption type on operating system drives
    • Configure use of passwords for operating system drives
    • Choose how BitLocker-protected operating system drives can be recovered
    • Configure TPM platform validation profile for BIOS-based firmware configurations
    • Configure TPM platform validation profile (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2)
    • Configure TPM platform validation profile for native UEFI firmware configurations
    • Configure pre-boot recovery message and URL
    • Reset platform validation data after BitLocker recovery
    • Use enhanced Boot Configuration Data validation profile

    Group Policy setting 2:

    • Allow network unlock at startup
    • Allow Secure Boot for integrity validation
    • Require additional authentication at startup
    • Require additional authentication at startup (Windows Server 2008 and Windows Vista)
    • Disallow standard users from changing the PIN or password
    • Allow devices compliant with InstantGo or HSTI to opt out of pre-boot PIN.
    • Enable use of BitLocker authentication requiring preboot keyboard input on slates
    • Allow enhanced PINs for startup
    • Configure minimum PIN length for startup
    • Configure use of hardware-based encryption for operating system drives
    • Enforce drive encryption type on operating system drives
    • Configure use of passwords for operating system drives
    • Choose how BitLocker-protected operating system drives can be recovered
    • Configure TPM platform validation profile for BIOS-based firmware configurations
    • Configure TPM platform validation profile (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2)
    • Configure TPM platform validation profile for native UEFI firmware configurations
    • Configure pre-boot recovery message and URL
    • Reset platform validation data after BitLocker recovery
    • Use enhanced Boot Configuration Data validation profile
  13. Question 13 · 1

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a server named Server1 that runs Windows Server. You need to ensure that only specific applications can modify the data in protected folders on Server1. Solution: From App & browser control, you configure Reputation-based protection. Does this meet the goal?

    Choose one answer.

    • Yes
    • No
  14. Question 14 · 1

    DRAG DROP - You have an Azure subscription that contains an Azure key vault named Vault1. You plan to deploy a virtual machine named VM1 that will run Windows Server. You need to enable encryption at host for VM1. The solution must use customer-managed keys. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    Arrange the options in the correct order.

    Question illustration 1
    • Create VM1 and associate the disks of the virtual machine with the disk encryption set.
    • Enable a system-assigned managed identity on VM1.
    • Create a disk encryption set and generate RSA keys.
    • Assign the Virtual Machine Contributor role to the system-assigned managed identity of VM1.
    • Grant Vault1 the managed identity permission for the disk encryption set.
  15. Question 15 · 1

    HOTSPOT - Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains three servers named Server1, Server2, and Server3 that run Windows Server. All the servers are on the same network and have network connectivity. On Server1, Windows Defender Firewall has a connection security rule that has the following settings: • Rule Type: Server-to-server • Endpoint 1: Any IP address • Endpoint 2: Any IP address • Requirements: Require authentication for inbound connections and request authentication for outbound connections • Authentication Method: Computer (Kerberos V5) • Profile: Domain, Private, Public • Name: Rule1 Server2 has no connection security rules. On Server3, Windows Defender Firewall has a connection security rule that has the following settings: • Rule Type: Server-to-server • Endpoint 1: Any IP address • Endpoint 2: Any IP address • Requirements: Request authentication for inbound and outbound connections • Authentication Method: Computer (Kerberos V5) • Profile: Domain, Private, Public • Name: Rule1 For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

    Choose an option for each prompt.

    Question illustration 1

    Server1 can communicate with Server2 successfully.

    • Yes
    • No

    Server2 can establish a network connection with Server3.

    • Yes
    • No

    When Server3 establishes a network connection with Server1, the connection is encrypted.

    • Yes
    • No

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free