📘 Free AZ-801 Sample Questions
Note: This question is part of a series of questions that present the same scenario. Each question in the series
contains a unique solution that might meet the stated goals. Some question sets might have more than one correct
solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
You have a server named Server1 that runs Windows Server.
You need to ensure that only specific applications can modify the data in protected folders on Server1.
Solution: From Virus & threat protection, you configure Controlled folder access.
Does this meet the goal?
A
yes
B
no
Correct Answer:
A. yes
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/customize-controlled-folders?vi
ew=o365-worldwide
DRAG DROP -
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active
Directory (Azure AD) tenant.
The AD DS domain contains a domain controller named DC1. DC1 does NOT have internet access.
You need to configure password security for on-premises users. The solution must meet the following
requirements:
✑ Prevent the users from using known weak passwords.
✑ Prevent the users from using the company name in passwords.
What should you do? To answer, drag the appropriate configurations to the correct targets. Each configuration
may be used once, more than once, or not at all.
You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Select and Place
A
Correct Answer:
A.
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-ban-bad-on-premise
s-deploy
: This question is part of a series of questions that present the same scenario. Each question in the series
contains a unique solution that might meet the stated goals. Some question sets might have more than one correct
solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
You have a server named Server1 that runs Windows Server.
You need to ensure that only specific applications can modify the data in protected folders on Server1.
Solution: From Virus & threat protection, you configure Tamper Protection
Does this meet the goal?
A
yes
B
no
Correct Answer:
B. no
Explanation:
Explanation:
Tamper Protection in Windows Security helps prevent malicious apps from changing important Microsoft
Defender Antivirus settings, including real-time protection and cloud-delivered protection.
Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/customize-controlled-folders?
view=o365-worldwide
This question is part of a series of questions that present the same scenario. Each question in the series
contains a unique solution that might meet the stated goals. Some question sets might have more than one correct
solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will notappear in the review screen.
You have a server named Server1 that runs Windows Server.
You need to ensure that only specific applications can modify the data in protected folders on Server1.
Solution: From App & browser control, you configure the Exploit protection settings.
Does this meet the goal?
A
no
B
yes
Correct Answer:
A. no
Explanation:
Explanation:
Exploit protection helps protect devices from malware that uses exploits to spread and infect other devices.
Mitigation can be applied to either the operating system or to an individual app
Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/customize-controlled-folders?
view=o365-worldwide
DRAG DROP -
Your network contains an Active Directory Domain Services (AD DS) domain.
You need to implement a solution that meets the following requirements:
✑ Ensures that the members of the Domain Admins group are allowed to sign in only to domain controllers
✑ Ensures that the lifetime of Kerberos Ticket Granting Ticket (TGT) for the members of the Domain Admins group
is limited to one hour
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of
actions to the answer area and arrange them in the correct order.
Select and Place:
A
Correct Answer:
A.
Explanation:
Reference:
https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/how-to-configure-protected-accou
nts
You have an Azure virtual machine named VM1 that runs Windows Server.
You plan to deploy a new line-of-business (LOB) application to VM1.You need to ensure that the application can create child processes.
What should you configure on VM1?
A
Microsoft Defender Credential Guard
B
Microsoft Defender Application Control
C
Microsoft Defender SmartScreen
Correct Answer:
Explanation:
Explanation:
Exploit protection
Reference:
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/customize-exploit-protection?
view=o365-worldwide
You have 100 Azure virtual machines that run Windows Server. The virtual machines are onboarded to Microsoft
Defender for Cloud.
You need to shut down a virtual machine automatically if Microsoft Defender for Cloud generates the
"Antimalware disabled in the virtual machine" alert for the virtual machine.
What should you use in Microsoft Defender for Cloud?
A
a logic app
B
a workbook
C
a security policy
Correct Answer:
A. a logic app
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/defender-for-cloud/managing-and-responding-alerts
You have a Microsoft Sentinel deployment and 100 Azure Arc-enabled on-premises servers. All the Azure Arcenabled resources are in the same resource group.
You need to onboard the servers to Microsoft Sentinel. The solution must minimize administrative effort.
What should you use to onboard the servers to Microsoft Sentinel?
A
Azure Automation
B
B. Azure Policy
C
Azure virtual machine extensions
Correct Answer:
B. B. Azure Policy
Explanation:
Explanation:
Enforce organization standards and assess compliance at scale for all your resources anywhere with Azure
Policy.
Reference:
https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/manage/hybrid/server/bestpractices/arc-policies-mma
You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active
Directory (Azure AD) tenant by using password hash synchronization.
You have a Microsoft 365 subscription.
All devices are hybrid Azure AD-joined.
Users report that they must enter their password manually when accessing Microsoft 365 applications.You need to reduce the number of times the users are prompted for their password when they access Microsoft
365 and Azure services.
What should you do?
A
From Azure AD Connect, enable single sign-on (SSO).
B
In Azure AD, configure a Conditional Access policy for the Microsoft Office 365 applications.
C
In the DNS zone of the AD DS domain, create an autodiscover record.
Correct Answer:
A. From Azure AD Connect, enable single sign-on (SSO).
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-quick-start
You have an Azure subscription that has Microsoft Defender for Cloud enabled.
You have 50 Azure virtual machines that run Windows Server.
You need to ensure that any security exploits detected on the virtual machines are forwarded to Defender for
Cloud.
Which extension should you enable on the virtual machines?
A
Vulnerability assessment for machines
B
Microsoft Dependency agent
C
Log Analytics agent for Azure VMs
Correct Answer:
A. Vulnerability assessment for machines
Explanation:
Explanation:
If I understand it correctly, then there's a difference between a VM extension and an agent. As the question is
about an extension and three of the four answers mention an agent, the answer must be A,
Reference:
https://docs.microsoft.com/en-us/azure/defender-for-cloud/deploy-vulnerability-assessment-vm
Questions: 1-10 out of 313
Continue Full Practice..
GET ALL 313 QUESTIONS