Microsoft AZ-801 - Configuring Windows Server Hybrid Advanced Services Exam

Question #6 (Topic: Question Set 1)
DRAG DROP
Your network contains an Active Directory Domain Services (AD DS) domain.
You need to implement a solution that meets the following requirements:
✑ Ensures that the members of the Domain Admins group are allowed to sign in only to domain controllers
✑ Ensures that the lifetime of Kerberos Ticket Granting Ticket (TGT) for the members of the Domain Admins group is limited to one hour
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the
correct order.
Select and Place:

Answer:
Question #7 (Topic: Question Set 1)
You have an Azure virtual machine named VM1 that runs Windows Server.
You plan to deploy a new line-of-business (LOB) application to VM1.
You need to ensure that the application can create child processes.
What should you configure on VM1?
A. Microsoft Defender Credential Guard B. Microsoft Defender Application Control C. Microsoft Defender SmartScreen D. Exploit protection
Answer: D
Question #8 (Topic: Question Set 1)
HOTSPOT
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the organizational units (OUs) shown in
the following table.

In the domain, you create the Group Policy Objects (GPOs) shown in the following table.

You need to implement IPsec authentication to ensure that only authenticated computer accounts can connect to the members in the domain. The solution must
minimize administrative effort.
Which GPOs should you apply to the Domain Controllers OU and the Domain Servers OU? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Answer:
Question #9 (Topic: Question Set 1)
You have 100 Azure virtual machines that run Windows Server. The virtual machines are onboarded to Microsoft Defender for Cloud.
You need to shut down a virtual machine automatically if Microsoft Defender for Cloud generates the "Antimalware disabled in the virtual machine" alert for the
virtual machine.
What should you use in Microsoft Defender for Cloud?
A. a logic app B. a workbook C. a security policy D. adaptive network hardening
Answer: A
Question #10 (Topic: Question Set 1)
You have a Microsoft Sentinel deployment and 100 Azure Arc-enabled on-premises servers. All the Azure Arc-enabled resources are in the same resource group.
You need to onboard the servers to Microsoft Sentinel. The solution must minimize administrative effort.
What should you use to onboard the servers to Microsoft Sentinel?
A. Azure Automation B. Azure Policy C. Azure virtual machine extensions D. Microsoft Defender for Cloud
Answer: B
Download Exam
Page: 2 / 34
Total 169 questions