DumpTOP AZ-800 최신 PDF 버전 시험 문제집을 무료로 Google Drive에서 다운로드하세요: https://drive.google.com/open?id=1omad1Ppz56XLAlD9ZC9Xp58Axh_LDLrG
우리 DumpTOP에서는 최고이자 최신의Microsoft 인증AZ-800덤프자료를 제공 함으로 여러분을 도와Microsoft 인증AZ-800인증자격증을 쉽게 취득할 수 있게 해드립니다.만약 아직도Microsoft 인증AZ-800시험패스를 위하여 고군분투하고 있다면 바로 우리 DumpTOP를 선택함으로 여러분의 고민을 날려버릴수 있습니다.
시험은 Azure Arc, Azure Stack HCI, Azure Stack Hub 및 Windows Admin Center를 포함한 하이브리드 코어 인프라를 관리하는 다양한 주제를 다룹니다. 이 시험은 온프레미스 및 클라우드 환경을 포함하는 하이브리드 클라우드 솔루션을 관리하는 데 필요한 기술과 지식을 검증하여 조직이 클라우드 컴퓨팅의 유연성과 확장성을 활용하면서 온프레미스 인프라의 보안과 제어를 유지할 수 있도록 합니다.
Microsoft AZ-800 시험을 어떻게 통과할수 있을가 고민중이신 분들은DumpTOP를 선택해 주세요. DumpTOP는 많은 분들이 IT인증시험을 응시하여 성공하도록 도와주는 사이트입니다. 최고급 품질의Microsoft AZ-800시험대비 덤프는Microsoft AZ-800시험을 간단하게 패스하도록 힘이 되어드립니다. DumpTOP 의 덤프는 모두 엘리트한 전문가들이 만들어낸 만큼 시험문제의 적중률은 아주 높습니다.
Microsoft AZ-800 자격증을 취득하는 가장 큰 이점 중 하나는 하이브리드 인프라 관리에 대한 전문성을 입증할 수 있다는 것입니다. 이 자격증은 전 세계적으로 인정되며, 새로운 직업 기회와 더 높은 급여를 가져올 수 있습니다. 또한 시험 준비 과정에서 습득한 기술과 지식은 하이브리드 클라우드 프로젝트에 보다 효과적으로 기여할 수 있도록 도와줄 것입니다. 이로 인해 현재 근무 중인 회사에서 더 가치 있는 자산이 될 수 있습니다.
Microsoft AZ-800 자격증 시험은 윈도우 서버 하이브리드 코어 인프라를 관리하는 능력과 지식을 검증하고자 하는 IT 전문가를 위해 설계되었습니다. 이 시험은 온프레미스 및 클라우드 기반 자원이 모두 포함된 하이브리드 환경을 관리하고 유지보수하는 책임을 지는 개인에게 이상적입니다. 시험은 후보자의 윈도우 서버, Azure 서비스 및 하이브리드 솔루션을 배포, 관리 및 모니터링하는 능력을 시험합니다.
질문 # 160
You have an Active Directory Domain Services (AD DS) domain that contains a group named Group1.
You need to create a group managed service account (gMSA) named Account1. The solution must ensure that Group1 can use Account1.
How should you complete the script? To answer, select the appropriate options in th e answer area, NOTE: Each correct selection is worth one point.
정답:
설명:
Explanation:
In the Administering Windows Server Hybrid Core In frastructure materials for managing identity and AD DS, the guidance for creating group Managed Service Accounts (gMSAs) states that you use the New- ADServiceAccount cmdlet to create the account object and define both its service DNS identity and which pri ncipals are permitted to use it. The document explains:
"Use New-ADServiceAccount to create a group managed service account . Specify the service name with - DNSHostName for SPN/DNS association. To control which computers or groups are allowed to run services under the gMSA, provide those principals with -PrincipalsAllowedToRetrieveManagedPassword . These security principals are then authorized to retrieve the managed password and use the account on the member servers." And further:
"The -PrincipalsAllowedToRetrieveManagedPassword parameter accepts computer accounts or security groups . Adding a group simplifies delegation-any computer that is a member of that group can use the gMSA without further modification." Applying this to the scenar io, to create Account1 and ensure the domain group Group1 can use it, the correct script is:
New-ADServiceAccount " Account1 " -DNSHostName " website.contoso.com " - PrincipalsAllowedToRetrieveManagedPassword " Group1 " This satisfies the requirement by creating the gMSA and explicitly granting Group1 the right to retrieve and use the managed password on allowed hosts.
질문 # 161
Case Study 3 - ADatum Corporation
Overview
Company Information
ADatum Corporation is a manufacturing company that has a main office in Seattle and two branch offices in Los Angeles and Montreal.
Fabrikam Partnership
ADatum recently partnered with 2 company named Fabrikam, Inc.
Fabrikam is a manufacturing company that has a main office in Boston and a branch office in Orlando.
Both companies intend to collaborate on several joint projects.
Existing Environment
ADatum AD DS Environment
The on-premises network of ADatum contains an Active Directory Domain Services (AD DS) forest named adatum.com.
The forest contains two domains named adatum.com and east.adatum.com and the domain controllers shown in the following table.
Fabrikam AD DS Environment
The on-premises network of Fabrikam contains an AD DS forest named fabrikam.com.
The forest contains two domains named fabrikam.com and south.fabrikam.com.
The fabrikam.com domain contains an organizational unit (OU) named Marketing.
Server Infrastructure
The adatum.com domain contains the servers shown in the following table.
HyperV1 contains the virtual machines shown in the following table.
All the virtual machines on HyperV1 have only the default management tools installed.
SSPace1 contains the Storage Spaces virtual disks shown in the following table.
Azure Resources
ADatum has an Azure subscription that contains an Azure AD tenant. Azure AD Connect is configured to sync the adatum.com forest with Azure AD.
The subscription contains the virtual networks shown in the following table.
The subscription contains the Azure Private DNS zones shown in the following table.
The subscription contains the virtual machines shown in the following table.
All the servers are in a workgroup.
The subscription contains a storage account named storage1 that has a file share named share1.
Requirements
Planned Changes
ADatum plans to implement the following changes:
- Sync Data1 to share1.
- Configure an Azure runbook named Task1.
- Enable Azure AD users to sign in to Server1.
- Create an Azure DNS Private Resolver that has the following configurations:
- Name: Private1
- Region: West US
- Virtual network: VNet1
- Inbound endpoint: SubnetB
- Enable users in the adatum.com domain to access the resources in the south.fabrikam.com domain.
Technical Requirements
ADatum identifies the following technical requirements:
- The data on SSPace1 must be available always.
- DC2 must become the schema master if DC1 fails.
- VM3 must be configured to enable per-folder quotas.
- Trusts must allow access to only the required resources.
- The users in the Marketing OU must have access to storage1.
- Azure Automanage must be used on all supported Azure virtual machines.
- A direct SSH session must be used to manage all the supported virtual machines on HyperV1.
You need to ensure that VM3 meets the technical requirements.
What should you install first?
정답:D
질문 # 162
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains a child domain named east.contoso.com.
in the contoso.com domain, you create two users named Admin1 and Admin2.
You need to ensure that the users can perform the following tasks:
* Admin1 can create and manage Active Directory sites.
* Admin2 can deploy domain controller to the easl.conloso.com domain.
The solution must use the principle of least privilege.
To which group should you add each user? To answer, select the appropriate options in the answer area.
NOTE Each correct selection is worth one point.
정답:
설명:
Reference:
https://docs.microsoft.com/en-us/windows-server/remote/remote-access/ras/multisite/configure/step-2-configure-the-multisite-infrastructure
질문 # 163
Your network contains a two-domain on-premises Active Directory Domain Services (AD DS) forest named Contoso.com. The forest contains the domain controllers shown in the following table.
You create an Active Directory site named Site3. Site1, Site2 and Site3 each has a dedicated site link to the Hub site.
In Site3, you install a new server named Server1.
You need to promote Server1 to an ROOC in child.contoso.com by using the install from Media (IFM) option. The solution must minimize network traffic.
What should you do? To answer select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
정답:
설명:
Explanation:
Within the Administering Windows Server Hybrid Core Infrastructure content for AD DS deployment, Microsoft specifies that Install From Media (IFM) for promoting a domain controller-especially a Read- Only Domain Controller (RODC)-must be created from a writable domain controller in the same target domain. The guide explains that IFM "pre-stages the AD DS database so that the promotion consumes far less replication traffic," and it emphasizes: "RODC IFM cannot be generated from an RODC; it must be created on a writable DC of the destination domain." It also clarifies tool choice: "Use ntdsutil ifm to generate media for a writable DC or an RODC. The media is then used during promotion to avoid full initial replication across the network." Applied here: the server to be promoted (Server1) will be an RODC in child.contoso.com. The only writable DC in that domain shown is DC2 (Domain-wide FSMO holder for child.contoso.com), making it the correct and traffic-efficient source. DC1 and RODC3 are in contoso.com (parent domain), so neither meets the requirement; additionally, an RODC cannot be used as an IFM source. Regarding tooling, the documentation notes that Windows Server Backup is for system-state backup/restore and is not the supported method to generate IFM media; the prescribed tool is Ntdsutil.exe with the IFM context.
Therefore, to minimize network traffic and satisfy Azure/AD DS best practices, create the IFM media on DC2 using Ntdsutil.exe and then promote Server1 with that media.
질문 # 164
You create a new Azure subscription.
You plan to deploy Azure Active Directory Domain Services (Azure AD DS) and Azure virtual machines.
You need to ensure that the virtual machines can join Azure AD DS.
Which three actions should perform in sequence? To answer, move the appropriate actions from the list of action of the answer area and arrange them in the correct order.
정답:
설명:
Explanation:
질문 # 165
......
AZ-800인기자격증 덤프공부자료: https://www.dumptop.com/Microsoft/AZ-800-dump.html
그 외, DumpTOP AZ-800 시험 문제집 일부가 지금은 무료입니다: https://drive.google.com/open?id=1omad1Ppz56XLAlD9ZC9Xp58Axh_LDLrG