AZ-800 Sample Questions

AZ-800 Sample Questions & Answers

AD DS domain controllers and multi-forest environments take well over a quarter of the exam, ahead of managing storage and file shares, containers and Hyper-V virtual machines, hybrid networking, and managing servers with Azure services.

Launch the full AZ-800 simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Implement and manage an on-premises and hybrid networking infrastructure · Implement Microsoft Entra Application Proxy

    A hospital needs to provide secure remote access to a legacy on-premises web-based electronic health record (EHR) application for its doctors. The application does not support modern authentication protocols like SAML or OpenID Connect. The hospital's identity provider is Microsoft Entra ID. The solution must enforce Multi-Factor Authentication (MFA) before granting access and must not give the doctors' devices network-level (VPN) access to the hospital network. Which Azure service should be deployed to meet these requirements?

    Show answer & explanation

    Correct answer: D

    Microsoft Entra application proxy publishes on-premises web applications to remote users without a VPN. Users are pre-authenticated by Microsoft Entra ID, so Conditional Access policies such as MFA apply even when the back-end application doesn't support modern authentication; the private network connector installed on-premises makes only outbound connections and forwards requests to the app, which can use integrated Windows authentication through Kerberos constrained delegation. A point-to-site VPN would give the doctors' devices network-level access, Azure Bastion is for RDP/SSH to Azure VMs, and WAP with AD FS doesn't use Microsoft Entra ID as the identity provider.

  2. Question 2Intermediate

    Manage Windows Servers and workloads in a hybrid environment · Configure Just Enough Administration (JEA) for PowerShell remoting

    You are managing a Windows Server failover cluster that hosts several highly available virtual machines. To improve security, you have been tasked with configuring Just Enough Administration (JEA) for a team of junior administrators who need to manage the VMs. They should only be able to start, stop, and restart VMs. Which field in a JEA role capability file (.psrc) is used to define these specific permissions?

    Show answer & explanation

    Correct answer: D

    In a JEA role capability file (.psrc), the VisibleCmdlets field lists the PowerShell cmdlets that users can run in the JEA session (optionally restricting their parameters and values). To allow starting, stopping, and restarting VMs, you would list Start-VM, Stop-VM, and Restart-VM in this field. VisibleExternalCommands is for executables and scripts outside PowerShell, RoleDefinitions belongs in the session configuration file (.pssc) where it maps users to role capabilities, and AllowedCommandlets isn't a valid field.

  3. Question 3Beginner

    Manage storage and file services · Configure and manage Azure File Sync

    True or False: When using Azure File Sync, the cloud endpoint (the Azure file share) must be created in the same Azure region as the Storage Sync Service resource.

    Show answer & explanation

    Correct answer: A

    This statement is true. The Storage Sync Service and the Azure file share it syncs with must be in the same Azure region. While the on-premises servers (server endpoints) can be anywhere in the world, the Azure resources must be co-located in the same region for the sync group to be created.

  4. Question 4Advanced

    Manage Windows Servers and workloads in a hybrid environment · Implement Azure Machine Configuration

    A retail company has deployed Azure Arc to manage its on-premises servers located in hundreds of stores. The security team wants to enforce a policy that ensures a specific antivirus service is running on all these Arc-enabled servers and automatically remediates any server where the service is stopped. Which Azure service combination should be used to achieve this?

    Show answer & explanation

    Correct answer: A

    Azure Policy's Guest Configuration feature is the ideal solution. You can create a custom Desired State Configuration (DSC) that defines the required state (antivirus service running). This configuration is then packaged and applied via an Azure Policy initiative. The policy can be set to not only audit for compliance but also to deploy a remediation task that automatically starts the service if it's found to be stopped. This provides a scalable, declarative way to enforce and remediate configuration drift across all Arc-enabled servers.

  5. Question 5Intermediate

    Manage virtual machines and containers · Configure Discrete Device Assignment

    You are deploying a new Hyper-V host for a high-performance computing (HPC) workload. The host has a high-end GPU installed. You need to provide dedicated, full access to this GPU for a single, specific virtual machine to perform complex calculations. This VM must have direct and exclusive access to the hardware. What Hyper-V feature should you configure?

    Show answer & explanation

    Correct answer: C

    Discrete Device Assignment (DDA) passes an entire PCIe device, such as a GPU, through to a single virtual machine: the device is dismounted from the host by its PCI location path and assigned to the VM, which then uses the native driver with full access to the GPU. Each physical GPU can accelerate at most one VM, which matches the requirement for dedicated, exclusive access. GPU partitioning (GPU-P, Windows Server 2025) instead shares one GPU among multiple VMs, RemoteFX vGPU has been removed from Windows Server, and Enhanced Session Mode only improves the VMConnect experience.

  6. Question 6Beginner

    Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments · Configure and manage AD DS sites

    A consultant is reviewing an Active Directory forest that has grown organically over many years. The forest contains multiple domains and sites connected by various WAN links. Users are complaining about slow logons and application access when working from certain branch offices. The consultant suspects that the AD Sites and Services configuration is suboptimal. What is the primary function of correctly configured AD sites?

    Show answer & explanation

    Correct answer: D

    The primary purpose of AD sites is twofold: 1) To control the replication topology, ensuring that replication traffic occurs efficiently over potentially slow or costly WAN links. 2) To enable clients to locate the nearest network services, most importantly domain controllers and Global Catalog servers, for authentication and queries. Correctly configured sites ensure clients in a branch office authenticate against a local DC instead of one across a slow WAN link, which directly addresses the user complaints.

  7. Question 7Beginner

    Manage virtual machines and containers · Configure Windows subsystem for Linux to support containers for running Linux

    You are preparing a Windows Server 2022 host to run Linux containers. You have already installed the Containers feature. Because containers share the kernel of the system that runs them, the Linux containers need a Linux kernel. Which Windows feature should you install and configure to provide a Linux kernel for the Linux containers on this host?

    Show answer & explanation

    Correct answer: C

    Containers share the kernel of the system they run on, so Linux containers can't run directly on the Windows kernel. WSL 2 supplies a genuine Linux kernel that runs inside a lightweight utility VM; on Windows Server 2022 and 2025, wsl --install enables the required optional components, downloads the latest Linux kernel, and installs a distribution, and container engines running in WSL 2 run Linux containers on that kernel. Hyper-V is a hypervisor and doesn't provide a Linux kernel by itself, while Multipath I/O and Network Controller are unrelated to containers.

  8. Question 8Advanced

    Manage storage and file services · Implement and configure Distributed File System (DFS)

    An organization uses DFS Replication to synchronize data between a primary data center and a disaster recovery site. The link between the sites is congested. They need to ensure that replication for critical business documents is prioritized over replication of large, non-critical ISO files. What should they configure?

    Show answer & explanation

    Correct answer: B

    DFS Replication schedules and bandwidth throttling are configured per replication group, where they apply to all of the group's connections, or per connection, not per replicated folder. To prioritize the critical documents, keep them in a replication group whose schedule replicates at full bandwidth during business hours. Put the ISO files in a separate replication group whose schedule restricts replication to off-hours or throttles its bandwidth. File filters on a replicated folder only exclude matching files from replication, an FSRM file screen would block saving ISO files altogether, and Remote Differential Compression reduces the data sent for changed files but doesn't prioritize one set of folders over another.

  9. Question 9Intermediate

    Manage virtual machines and containers · Configure and manage Just in Time (JIT) VM access and Azure Bastion

    You are managing a Windows Server 2022 VM in Azure. For compliance reasons, you must ensure that all administrative access to the VM over RDP is limited to a 4-hour window after an explicit request is approved. Access should be automatically revoked after the window expires. Which Azure feature should you implement?

    Show answer & explanation

    Correct answer: D

    Just-in-Time (JIT) VM access, a feature of Microsoft Defender for Cloud, is designed for this exact purpose. It works by locking down inbound traffic to your Azure VMs by default. When a user requests access, JIT evaluates the request against RBAC permissions and, if approved, configures the Network Security Group (NSG) to allow inbound traffic to the selected ports from the user's IP address for a specified amount of time. After the time expires, the NSG rules are restored, blocking access again.

  10. Question 10Intermediate

    Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments · Manage Windows Server by using domain-based Group Policies

    A systems administrator needs to create a new Group Policy Object (GPO) to configure Windows Defender settings and link it to an Organizational Unit (OU) named 'Workstations'. The administrator is a member of the 'Group Policy Creator Owners' group but not 'Domain Admins'. What will happen when the administrator tries to create and link the GPO?

    Show answer & explanation

    Correct answer: D

    Members of the 'Group Policy Creator Owners' group have permissions to create new GPOs in the domain. However, this group does not have permissions to link GPOs to any site, domain, or OU. Linking a GPO requires write permissions on the gPLink attribute of the target container (in this case, the 'Workstations' OU), which is typically held by Domain Admins or OU administrators. Therefore, the administrator can successfully create the GPO but will receive an 'Access Denied' error when attempting to link it.

Ready for the real thing?

The full AZ-800 simulator has every exam-style question, timed mode, and instant scoring.

Go to the AZ-800 simulator →