AZ-801 Sample Questions

AZ-801 Sample Questions & Answers

Hardening the operating system and a hybrid Active Directory setup carries the most weight, alongside migrating servers and workloads, monitoring and troubleshooting, Storage Spaces Direct and failover clustering, and disaster recovery through Azure Site Recovery.

Launch the full AZ-801 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Migrate servers and workloads · Migrate VM workloads to Azure VMs

    A hospital is migrating its on-premises Hyper-V virtual machines to Azure using Azure Migrate. The migration team has deployed the Azure Migrate appliance and completed the discovery and assessment phase. They are now ready to begin replication. Due to HIPAA compliance, all data must be encrypted in transit from the on-premises datacenter to Azure. Which statement about encryption during the Azure Migrate replication process is true?

    Show answer & explanation

    Correct answer: A

    True. When using the agent-based or agentless migration methods with Azure Migrate (which leverages Azure Site Recovery technology), all replication traffic from on-premises to Azure is encrypted using TLS 1.2 by default. No additional configuration is required to enable this in-transit encryption, which helps meet compliance requirements like HIPAA.

  2. Question 2IntermediateSelect 2

    Implement and manage Windows Server high availability · Implement cluster-aware updating

    An IT administrator is managing a Windows Server failover cluster and needs to apply monthly Windows security updates to all cluster nodes with minimal downtime for the clustered roles. The administrator wants to automate this process. Which TWO of the following solutions are the most appropriate for this task? (Select TWO).

    Show answer & explanation

    Correct answers: A, C

    CAU in self-updating mode is a fully automated solution. The CAU clustered role runs on the failover cluster itself and updates the cluster nodes according to a defined schedule, making it an excellent choice for automated monthly patching.

    For hybrid environments, onboarding the cluster nodes to Azure Arc allows you to use Azure Update Manager. It can schedule and automate update deployments and is cluster-aware, meaning it will patch nodes one at a time to maintain service availability.

  3. Question 3Advanced

    Secure Windows Server on-premises and hybrid infrastructures · Secure a hybrid Active Directory infrastructure

    Case Study: Quantum Health Systems Hybrid Infrastructure Security Hardening

    Company Background:
    Quantum Health Systems (QHS) is a large healthcare provider subject to strict HIPAA regulations. They operate a hybrid environment with a significant on-premises footprint of Windows Server 2016 and 2019 servers, and a growing number of Windows Server 2022 VMs in Azure. Their on-premises Active Directory domain, qhs.local, is synchronized with a Microsoft Entra ID tenant using Azure AD Connect.

    Current Situation:
    A recent security audit revealed several vulnerabilities. The primary concern is the potential for pass-the-hash and other credential theft attacks against privileged accounts. The audit also highlighted inconsistent security baselines across the server fleet and a lack of visibility into advanced threats targeting Active Directory. On-premises servers are not currently managed or monitored directly from Azure, except for identity synchronization.

    Technical Requirements:

    1. Implement a solution to isolate Local Security Authority Subsystem Service (LSASS) processes for privileged accounts to prevent credential dumping. This solution must be hardware-assisted.
    2. Onboard all on-premises servers to Azure for centralized security management and threat detection without deploying new gateway servers.
    3. Deploy a cloud-native service to detect and investigate advanced attacks and malicious insider activities directed at the on-premises AD DS controllers.
    4. Enforce a consistent, Microsoft-recommended security baseline across all servers, both on-premises and in Azure, and report on compliance.

    Goal:
    Select the optimal combination of Microsoft technologies to meet all four technical requirements for hardening the QHS hybrid environment.

    Show answer & explanation

    Correct answer: B

    This is the optimal solution that meets all requirements.

    1. Credential Guard uses virtualization-based security (hardware-assisted) to isolate LSASS, directly addressing credential theft (Req 1).
    2. Azure Arc onboards on-premises servers to Azure Resource Manager, enabling centralized management without a gateway (Req 2).
    3. Microsoft Defender for Identity is the premier cloud-native service for detecting advanced threats against on-premises AD (Req 3).
    4. Azure Policy Guest Configuration, delivered via Azure Arc, can enforce and report on security baselines for both on-premises and Azure servers from a single pane of glass (Req 4).
  4. Question 4Beginner

    Migrate servers and workloads · Assess IIS workloads by using Azure Migrate

    A financial firm is migrating its on-premises Internet Information Services (IIS) web applications to Azure. The primary goal is to move to a Platform-as-a-Service (PaaS) offering to reduce infrastructure management overhead. The applications are a mix of ASP.NET and ASP.NET Core. The migration team needs to perform an initial assessment to determine compatibility with Azure App Service and get migration recommendations. Which tool is specifically designed for this purpose?

    Show answer & explanation

    Correct answer: B

    The Azure Migrate hub includes a specific tool for assessing on-premises web apps for migration to Azure App Service. This tool, often accessed via the App Service Migration Assistant, discovers IIS web servers, checks for compatibility issues, and provides a readiness report and migration guidance, making it the correct choice.

  5. Question 5Advanced

    Implement and manage Windows Server high availability · Recover a failed cluster node

    An administrator is managing a two-node Hyper-V failover cluster running on Windows Server 2022. Both nodes are part of a Storage Spaces Direct (S2D) configuration. Node1 unexpectedly crashes and will not reboot. The administrator needs to recover the cluster to a healthy state by replacing the failed node. What is the correct high-level sequence of steps to replace Node1?

    Show answer & explanation

    Correct answer: B

    This is the correct sequence. First, the failed node must be formally evicted from the cluster configuration. Then, a new server is prepared to the same standard as the existing nodes. The new node is then added to the cluster. Once added, Storage Spaces Direct will automatically start storage repair jobs to rebuild data resiliency and rebalance the data across all nodes, including the new one.

  6. Question 6Intermediate

    Monitor and troubleshoot Windows Server environments · Monitor Windows Server by using Performance Monitor

    A systems administrator is reviewing the performance of a file server using Performance Monitor. They notice that the '% Idle Time' counter for the physical disk hosting the user data is consistently below 10%, and the 'Avg. Disk Queue Length' is frequently spiking above 3. What is the most likely issue affecting the server?

    Show answer & explanation

    Correct answer: C

    This is the correct diagnosis. A consistently low '% Idle Time' (under 20%) indicates the disk is constantly busy. A high 'Avg. Disk Queue Length' (typically, a sustained value over 2 per spindle) means that I/O requests are waiting for the disk to become available. Together, these two counters are classic indicators of a storage I/O bottleneck.

  7. Question 7Intermediate

    Secure Windows Server on-premises and hybrid infrastructures · Configure and manage Windows Defender Application Control

    You are tasked with hardening a fleet of Windows Server 2022 machines. A key requirement is to prevent unauthorized code execution. You decide to implement Windows Defender Application Control (WDAC). You create a baseline policy in audit mode to gather information about applications running in the environment. After a week, you analyze the logs and are ready to create an enforcement policy. Which PowerShell cmdlet is used to finalize one or more WDAC policy XML files into a single binary file that can be deployed?

    Show answer & explanation

    Correct answer: C

    ConvertFrom-CIPolicy is the correct cmdlet. It takes the final policy XML file (or files) as input and converts it into the binary format (.cip file) that Windows uses to enforce the policy. This binary file is what gets deployed to the target machines.

  8. Question 8Intermediate

    Migrate servers and workloads · Migrate an on-premises AD forest to Windows Server 2025

    A retail company is planning to migrate its entire Active Directory infrastructure from a Windows Server 2012 R2 forest to a new, clean Windows Server 2022 forest. The project requires migrating all user accounts, security groups (including memberships), and computer accounts. The team will use the Active Directory Migration Tool (ADMT). What is a critical dependency that must be established between the source and target forests for ADMT to function correctly and migrate security principals with their SID history?

    Show answer & explanation

    Correct answer: B

    A two-way forest trust is a critical prerequisite for ADMT. It allows security principals in both forests to be authenticated and authorized, which is necessary for ADMT to read objects from the source, create them in the target, and migrate attributes like SID history, which requires high-level privileges across both forests.

  9. Question 9Intermediate

    Implement disaster recovery · Protect virtual machines by using Hyper-V replicas

    A hybrid cloud engineer is configuring Hyper-V Replica between a primary site and a disaster recovery site for a critical virtual machine. The engineer needs to ensure that if a disaster occurs, the failover process is as fast as possible and maintains application consistency. The VM is running a VSS-aware application like SQL Server. Which Hyper-V Replica setting should be configured to meet these requirements?

    Show answer & explanation

    Correct answer: B

    This is the best option. Configuring application-consistent snapshots tells Hyper-V to use the Volume Shadow Copy Service (VSS) inside the VM to create snapshots. This ensures that VSS-aware applications are in a consistent state, which is critical for services like SQL Server. Storing these points allows for recovery to a known good, application-consistent state, speeding up the recovery process.

  10. Question 10Advanced

    Implement and manage Windows Server high availability · Deploy host networking with Network ATC

    A consultant is deploying Network ATC on a new four-node Azure Stack HCI cluster to simplify host networking configuration. The goal is to configure the physical network adapters for both management and compute traffic using a single intent. The adapters are named 'pNIC1' and 'pNIC2' on all nodes. Which of the following is the correct PowerShell command to create a network intent that uses both adapters for management and compute workloads?

    Show answer & explanation

    Correct answer: B

    This is the correct syntax. The Add-NetIntent cmdlet creates a new intent. The -Name parameter gives it a friendly name. The -IntentType parameter specifies the traffic types, and you can combine them as shown. The -Adapter parameter specifies the physical NICs to which the intent will apply.

Ready for the real thing?

The full AZ-801 simulator has every exam-style question, timed mode, and instant scoring.

Go to the AZ-801 simulator →