DummyExams LogoDummyExams
Azure logo

Free Practice · No Signup Required

30 Free Azure AZ-800 Practice Questions

Real practice questions for the Azure Azure Hybrid Admin (AZ-800) exam, with answers and detailed explanations. Updated 2026.

Free questions

30

Passing score

700 out of 1000

Exam time

120 minutes

Question pool

154+ Questions

Below are 30 real practice questions for the Azure Azure Hybrid Admin (AZ-800) exam. Each question shows the correct answer and a detailed explanation when you reveal it. Use these to benchmark your readiness — if you score below 70% on these 30 questions, plan for at least 4 more weeks of study before booking.

AZ-800 Practice Questions

  1. FreePracticeQuiz.questionLabelStorage

    You have a server named Server1 that runs Windows Server. Server1 has the storage pools shown in the following table. You plan to create a virtual disk named VDisk1 that will use storage tiers. ![Question 1](images/question1.jpg)

    A
    Pool2 and Pool3 only.
    B
    Pool2 only.
    C
    Pool1 only.
    D
    Pool1, Pool2, and Pool3.
    E
    Pool1 and Pool2 only.
    F
    Pool1 and Pool3 only.
    G
    Pool3 only.
  2. FreePracticeQuiz.questionLabelSecurity

    Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com. The domain contains a ‘He server named Server1 and three users named User1. User2 and User), Server1 contains a shared folder named Share1 that has the following configurations. The share permissions for Share1 are configured as shown in the Share Permissions exhibit. Share! contains a file named Filel.txt. The advanced security settings for Filel.txt are configured as shown in the File Permissions exhibit. When User1 connects to \\Server1.adatum.com\Share1\, the user can take ownership of File1.txt. ![Question 2 part 1](images/question2_3_4_1.jpg) ![Question 2 part 2](images/question2_3_4_2.jpg) ![Question 2 part 3](images/question2_3_4_3.jpg)

    A
    Yes.
    B
    No.
  3. FreePracticeQuiz.questionLabelSecurity

    Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com. The domain contains a ‘He server named Server1 and three users named User1. User2 and User), Server1 contains a shared folder named Share1 that has the following configurations. The share permissions for Share1 are configured as shown in the Share Permissions exhibit. Share! contains a file named Filel.txt. The advanced security settings for Filel.txt are configured as shown in the File Permissions exhibit. When User2 connects to \\Server1.adatum.com\Share1\, File1.txt is visible. ![Question 3 part 1](images/question2_3_4_1.jpg) ![Question 3 part 2](images/question2_3_4_2.jpg) ![Question 3 part 3](images/question2_3_4_3.jpg)

    A
    Yes.
    B
    No.
  4. FreePracticeQuiz.questionLabelSecurity

    Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com. The domain contains a ‘He server named Server1 and three users named User1. User2 and User), Server1 contains a shared folder named Share1 that has the following configurations. The share permissions for Share1 are configured as shown in the Share Permissions exhibit. Share! contains a file named Filel.txt. The advanced security settings for Filel.txt are configured as shown in the File Permissions exhibit. When User3 connects to \\Server1.adatum.com\Share1\, File1.txt is visible. ![Question 4 part 1](images/question2_3_4_1.jpg) ![Question 4 part 2](images/question2_3_4_2.jpg) ![Question 4 part 3](images/question2_3_4_3.jpg)

    A
    Yes.
    B
    No.
  5. FreePracticeQuiz.questionLabelIdentity

    Contoso, Ltd. is a company that has a main office in Seattle and two branch offices in Los Angeles and Montreal. The network contains an on premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com. The forest contains the domain controllers shown in the following table. All the domain controllers are global catalog servers. The network contains the servers shown in the following table. A server named Server4 runs Windows Server and is in a workgroup. Windows Firewall on Server4 uses the private profile. Server2 hosts three virtual machines named VM1, VM2, and VM3. VM3 is a file server that stores data in the volumes shown in the following table. The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table. The forest contains the users shown in the following table. The forest contains the groups shown in the following table. When an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out, another administrator can connect to the console session as the currently signed in user. Contoso identifies the following technical requirements: Change the replication schedule for all site links to 30 minutes. Promote Server1 to a domain controller in canada.contoso.com. Install and authorize Server3 as a DHCP server. Ensure that User1 can manage the membership of all the groups in Contoso\OU3. Ensure that you can manage Server4 from Server1 by using PowerShell remoting. Ensure that you can run virtual machines on VM1. Force users to provide credentials when they connect to VM2. On VM3, ensure that Data Deduplication on all volumes is possible. You need to meet the technical requirements for the site links. Which users can perform the required tasks? ![Question 5 part 1](images/question5_8_9_20_33_38_39_43_1.jpg) ![Question 5 part 2](images/question5_8_9_20_33_38_39_43_2.jpg) ![Question 5 part 3](images/question5_8_9_20_33_38_39_43_3.jpg) ![Question 5 part 4](images/question5_8_9_20_33_38_39_43_4.jpg) ![Question 5 part 5](images/question5_8_9_20_33_38_39_43_5.jpg) ![Question 5 part 6](images/question5_8_9_20_33_38_39_43_6.jpg)

    A
    Admin1 only.
    B
    Admin1 and Admin3 only.
    C
    Admin1 and Admin2 only.
    D
    Admin3 only.
    E
    Admin1, Adrrun2. and Admin3.
  6. FreePracticeQuiz.questionLabelCompute

    You have a server named Server1 that hosts Windows containers. You plan to deploy an application that will have multiple containers. Each container will be You need to create a Docker network that supports the deployment of the application. Which type of network should you create?

    A
    transparent.
    B
    I2bridge.
    C
    NAT.
    D
    I2tunnel.
  7. FreePracticeQuiz.questionLabelSecurity

    Fabrikam, Inc is a manufacturing company that has a main office in New York and a branch office in Seattle. The on-premises network contains servers that run Windows Server as shown in the following table. DC1 hosts all the operation master roles. VM1 and VM2 are connected to the internet. WEB1 and WEB2 run an Internet Information Services (IIS) web app named Webapp1. The New York and Seattle offices are connected by using redundant WAN links. The client computers in each office get IP addresses from their local DHCP server. DHCP1 contains a scope named Scope1 that has addresses for the New York office, DHCP2 contains a scope named Scope2 that has addresses for the Seattle office. The network contains a single on-premises Active Directory Domain Services (AD DS) domain named corp.falbrikam.com. Currently, all the service accounts use individual domain user accounts. All domain controllers have the DNS Server role installed and host a copy of the Active Directory integrated DNS zone of corp.fabrikam.com. The corp.fabrikam.com AD DS domain syncs with an Azure Active Directory (Azure AD) tenant. The corp.fabrikam.com domain contains the organizational units (OUs) and custom Group Policy Objects (GPOs) shown in the following table. Fabrikam identifies the following planned changes: Create a single Azure subscription named Sub1 that will contain a single Azure virtual network named Vnet1. Replace the WAN links between the Seattle and New York offices by using Azure Virtual WAN and FxpressRoute. Both on premises offices will be connected to Vnet1 by using ExpressRoute. Create three Azure file shares named newyorkfiles, seattlefiles, and companyfiles. Create a domain controller named dc3.corp.fabrikam.com in Vnet1. Deploy an Azure Virtual Desktop host pool to Vnet1. The Azure Virtual Desktop session hosts will be hybrid Azure AD-joined. License all servers for Microsoft Defender for servers. Use Azure Policy to enforce configuration management policies on the servers in Azure and on-premises. Fabrikam identifies the following networking requirements: Implement Virtual WAN and ensure that all the network traffic between the sites uses Virtual WAN. All communications must occur over ExpressRoute. If a DHCP server fails, ensure that the client computers can continue to receive their dynamic IP address and renew their existing lease. Ensure that the resources in Vnet1 can resolve the names of the on-premises servers in the corp.fabrikam.com domain. Fabrikam identifies the following security requirements: Apply GPO4 to the Azure Virtual Desktop session hosts. Ensure that Azure Virtual Desktop user sessions lock after being idle for 10 minutes. Users must be able to control the lockout time manually from their client computer. Ensure that server administrators request approval before they can establish a Remote Desktop connection to an Azure virtual machine. If the request is approved, the connection must be established within two hours. Prevent user passwords from containing all or part of words that are based on the company name, such as Fab, f@br1kAm or fabr!|. Ensure that all instances of Webapp1 use the same service account. The password of the service account must change automatically every 30 days. Prevent domain controllers from directly contacting hosts on the internet. You need to configure the synchronization of Azure files to meet the following requirements: Ensure that seattlefiles syncs to FS2. Ensure that newyorkfiles syncs to FS1. Ensure that companyfiles syncs to both FS1 and FS2. You need to configure remote administration to meet the security requirements. What should you use? ![Question 7 part 1](images/question7_16_17_19_22_29_45_1.jpg) ![Question 7 part 2](images/question7_16_17_19_22_29_45_2.jpg)

    A
    Just in time (JIT) VM access.
    B
    Azure AD Privileged Identity Management (PIM).
    C
    Remote Desktop extension for Azure Cloud Services.
    D
    Azure Bastion host.
  8. FreePracticeQuiz.questionLabelIdentity

    Contoso, Ltd. is a company that has a main office in Seattle and two branch offices in Los Angeles and Montreal. The network contains an on premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com. The forest contains the domain controllers shown in the following table. All the domain controllers are global catalog servers. The network contains the servers shown in the following table. A server named Server4 runs Windows Server and is in a workgroup. Windows Firewall on Server4 uses the private profile. Server2 hosts three virtual machines named VM1, VM2, and VM3. VM3 is a file server that stores data in the volumes shown in the following table. The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table. The forest contains the users shown in the following table. The forest contains the groups shown in the following table. When an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out, another administrator can connect to the console session as the currently signed in user. Contoso identifies the following technical requirements: Change the replication schedule for all site links to 30 minutes. Promote Server1 to a domain controller in canada.contoso.com. Install and authorize Server3 as a DHCP server. Ensure that User1 can manage the membership of all the groups in Contoso\OU3. Ensure that you can manage Server4 from Server1 by using PowerShell remoting. Ensure that you can run virtual machines on VM1. Force users to provide credentials when they connect to VM2. On VM3, ensure that Data Deduplication on all volumes is possible. Admin1 must use a password that has at least 14 characters. ![Question 8 part 1](images/question5_8_9_20_33_38_39_43_1.jpg) ![Question 8 part 2](images/question5_8_9_20_33_38_39_43_2.jpg) ![Question 8 part 3](images/question5_8_9_20_33_38_39_43_3.jpg) ![Question 8 part 4](images/question5_8_9_20_33_38_39_43_4.jpg) ![Question 8 part 5](images/question5_8_9_20_33_38_39_43_5.jpg) ![Question 8 part 6](images/question5_8_9_20_33_38_39_43_6.jpg)

    A
    Yes.
    B
    No.
  9. FreePracticeQuiz.questionLabelIdentity

    Contoso, Ltd. is a company that has a main office in Seattle and two branch offices in Los Angeles and Montreal. The network contains an on premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com. The forest contains the domain controllers shown in the following table. All the domain controllers are global catalog servers. The network contains the servers shown in the following table. A server named Server4 runs Windows Server and is in a workgroup. Windows Firewall on Server4 uses the private profile. Server2 hosts three virtual machines named VM1, VM2, and VM3. VM3 is a file server that stores data in the volumes shown in the following table. The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table. The forest contains the users shown in the following table. The forest contains the groups shown in the following table. When an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out, another administrator can connect to the console session as the currently signed in user. Contoso identifies the following technical requirements: Change the replication schedule for all site links to 30 minutes. Promote Server1 to a domain controller in canada.contoso.com. Install and authorize Server3 as a DHCP server. Ensure that User1 can manage the membership of all the groups in Contoso\OU3. Ensure that you can manage Server4 from Server1 by using PowerShell remoting. Ensure that you can run virtual machines on VM1. Force users to provide credentials when they connect to VM2. On VM3, ensure that Data Deduplication on all volumes is possible. User1 must use a password that has at least 10 characters. ![Question 9 part 1](images/question5_8_9_20_33_38_39_43_1.jpg) ![Question 9 part 2](images/question5_8_9_20_33_38_39_43_2.jpg) ![Question 9 part 3](images/question5_8_9_20_33_38_39_43_3.jpg) ![Question 9 part 4](images/question5_8_9_20_33_38_39_43_4.jpg) ![Question 9 part 5](images/question5_8_9_20_33_38_39_43_5.jpg) ![Question 9 part 6](images/question5_8_9_20_33_38_39_43_6.jpg)

    A
    Yes.
    B
    No.
  10. FreePracticeQuiz.questionLabelIdentity

    If Admin1 creates a new local user on Server1 the password for the new user must be at least eight characters.

    A
    Yes.
    B
    No.
  11. FreePracticeQuiz.questionLabelSecurity

    You have an Azure virtual machine named VM1 that runs Windows Server. You need to configure the management of VM1 to meet the following requirements: Require administrators to request access to VM1 before establishing a Remote Desktop connection. Limit access to VM1 from specific source IP addresses. Limit access to VMI to a specific management port. What should you configure?

    A
    Network Security Group (NSG).
    B
    Azure Active Directory (Azure AD) Privileged identity Management (PIM).
    C
    Azure Front Door.
    D
    Microsoft Defender for Cloud.
  12. FreePracticeQuiz.questionLabelCompute

    You plan to deploy a containerized application that requires .NET Core. You need to create a container image for the application. The image must be as small as possible. Which base image should you use?

    A
    Nano Server.
    B
    Server Cote.
    C
    Windows Server.
    D
    Windows.
  13. FreePracticeQuiz.questionLabelStorage

    You need to configure Azure File Sync to meet the file sharing requirements. What should you do? ![Question 13](images/question13.jpg)

    A
    Minimum number of sync groups to create: 2. Minimum number of Storage Sync Services to create: 2.
    B
    Minimum number of sync groups to create: 1. Minimum number of Storage Sync Services to create: 3.
    C
    Minimum number of sync groups to create: 3. Minimum number of Storage Sync Services to create: 1.
    D
    Minimum number of sync groups to create: 2. Minimum number of Storage Sync Services to create: 4.
  14. FreePracticeQuiz.questionLabelNetworking

    You need to implement an availability solution for DHCP that meets the networking requirements. Which two actions should you perform?

    A
    On DHCP1. create a scope that contains 25 percent of the IP addresses from Scope2.
    B
    On the router in each office, configure a DHCP relay.
    C
    DHCP2. configure a scope that contains 25 percent of the IP addresses from Scope 1.
    D
    On each DHCP server, install the Failover Clustering feature and add the DHCP cluster role.
    E
    On each DHCP scope, configure DHCP failover.
  15. FreePracticeQuiz.questionLabelCompute

    You have a server named Host! that has the Hyper-V server role installed. Host! hosts a virtual machine named VM1. You have a management server named Server! that runs Windows Server. You remotely manage Host1 from Server1 by using Hyper-V Manager. You need to ensure that you can access a USB hard drive connected to Server1 when you connect to VM1 by using Virtual Machine Connection. Which two actions should you perform?

    A
    From the Hyper-V Settings of Host1, select Allow enhanced session mode.
    B
    From Disk Management on Host1. attach a virtual hard disk.
    C
    From Virtual Machine Connection, switch to a basic session.
    D
    From Virtual Machine Connection select Show Options and then select the USB hard drive.
    E
    From Disk Management on Host1, select Rescan Disks.
  16. FreePracticeQuiz.questionLabelIdentity

    Fabrikam, Inc is a manufacturing company that has a main office in New York and a branch office in Seattle. The on-premises network contains servers that run Windows Server as shown in the following table. DC1 hosts all the operation master roles. VM1 and VM2 are connected to the internet. WEB1 and WEB2 run an Internet Information Services (IIS) web app named Webapp1. The New York and Seattle offices are connected by using redundant WAN links. The client computers in each office get IP addresses from their local DHCP server. DHCP1 contains a scope named Scope1 that has addresses for the New York office, DHCP2 contains a scope named Scope2 that has addresses for the Seattle office. The network contains a single on-premises Active Directory Domain Services (AD DS) domain named corp.falbrikam.com. Currently, all the service accounts use individual domain user accounts. All domain controllers have the DNS Server role installed and host a copy of the Active Directory integrated DNS zone of corp.fabrikam.com. The corp.fabrikam.com AD DS domain syncs with an Azure Active Directory (Azure AD) tenant. The corp.fabrikam.com domain contains the organizational units (OUs) and custom Group Policy Objects (GPOs) shown in the following table. Fabrikam identifies the following planned changes: Create a single Azure subscription named Sub1 that will contain a single Azure virtual network named Vnet1. Replace the WAN links between the Seattle and New York offices by using Azure Virtual WAN and FxpressRoute. Both on premises offices will be connected to Vnet1 by using ExpressRoute. Create three Azure file shares named newyorkfiles, seattlefiles, and companyfiles. Create a domain controller named dc3.corp.fabrikam.com in Vnet1. Deploy an Azure Virtual Desktop host pool to Vnet1. The Azure Virtual Desktop session hosts will be hybrid Azure AD-joined. License all servers for Microsoft Defender for servers. Use Azure Policy to enforce configuration management policies on the servers in Azure and on-premises. Fabrikam identifies the following networking requirements: Implement Virtual WAN and ensure that all the network traffic between the sites uses Virtual WAN. All communications must occur over ExpressRoute. If a DHCP server fails, ensure that the client computers can continue to receive their dynamic IP address and renew their existing lease. Ensure that the resources in Vnet1 can resolve the names of the on-premises servers in the corp.fabrikam.com domain. Fabrikam identifies the following security requirements: Apply GPO4 to the Azure Virtual Desktop session hosts. Ensure that Azure Virtual Desktop user sessions lock after being idle for 10 minutes. Users must be able to control the lockout time manually from their client computer. Ensure that server administrators request approval before they can establish a Remote Desktop connection to an Azure virtual machine. If the request is approved, the connection must be established within two hours. Prevent user passwords from containing all or part of words that are based on the company name, such as Fab, f@br1kAm or fabr!|. Ensure that all instances of Webapp1 use the same service account. The password of the service account must change automatically every 30 days. Prevent domain controllers from directly contacting hosts on the internet. You need to configure the synchronization of Azure files to meet the following requirements: Ensure that seattlefiles syncs to FS2. Ensure that newyorkfiles syncs to FS1. Ensure that companyfiles syncs to both FS1 and FS2. What should you implement for the deployment of DC3? ![Question 16 part 1](images/question7_16_17_19_22_29_45_1.jpg) ![Question 16 part 2](images/question7_16_17_19_22_29_45_2.jpg)

    A
    Azure Active Directory Domain Services (Azure AD DS).
    B
    Azure AD Application Proxy.
    C
    Azure virtual machine.
    D
    Azure AD administrative unit.
  17. FreePracticeQuiz.questionLabelIdentity

    Fabrikam, Inc is a manufacturing company that has a main office in New York and a branch office in Seattle. The on-premises network contains servers that run Windows Server as shown in the following table. DC1 hosts all the operation master roles. VM1 and VM2 are connected to the internet. WEB1 and WEB2 run an Internet Information Services (IIS) web app named Webapp1. The New York and Seattle offices are connected by using redundant WAN links. The client computers in each office get IP addresses from their local DHCP server. DHCP1 contains a scope named Scope1 that has addresses for the New York office, DHCP2 contains a scope named Scope2 that has addresses for the Seattle office. The network contains a single on-premises Active Directory Domain Services (AD DS) domain named corp.falbrikam.com. Currently, all the service accounts use individual domain user accounts. All domain controllers have the DNS Server role installed and host a copy of the Active Directory integrated DNS zone of corp.fabrikam.com. The corp.fabrikam.com AD DS domain syncs with an Azure Active Directory (Azure AD) tenant. The corp.fabrikam.com domain contains the organizational units (OUs) and custom Group Policy Objects (GPOs) shown in the following table. Fabrikam identifies the following planned changes: Create a single Azure subscription named Sub1 that will contain a single Azure virtual network named Vnet1. Replace the WAN links between the Seattle and New York offices by using Azure Virtual WAN and FxpressRoute. Both on premises offices will be connected to Vnet1 by using ExpressRoute. Create three Azure file shares named newyorkfiles, seattlefiles, and companyfiles. Create a domain controller named dc3.corp.fabrikam.com in Vnet1. Deploy an Azure Virtual Desktop host pool to Vnet1. The Azure Virtual Desktop session hosts will be hybrid Azure AD-joined. License all servers for Microsoft Defender for servers. Use Azure Policy to enforce configuration management policies on the servers in Azure and on-premises. Fabrikam identifies the following networking requirements: Implement Virtual WAN and ensure that all the network traffic between the sites uses Virtual WAN. All communications must occur over ExpressRoute. If a DHCP server fails, ensure that the client computers can continue to receive their dynamic IP address and renew their existing lease. Ensure that the resources in Vnet1 can resolve the names of the on-premises servers in the corp.fabrikam.com domain. Fabrikam identifies the following security requirements: Apply GPO4 to the Azure Virtual Desktop session hosts. Ensure that Azure Virtual Desktop user sessions lock after being idle for 10 minutes. Users must be able to control the lockout time manually from their client computer. Ensure that server administrators request approval before they can establish a Remote Desktop connection to an Azure virtual machine. If the request is approved, the connection must be established within two hours. Prevent user passwords from containing all or part of words that are based on the company name, such as Fab, f@br1kAm or fabr!|. Ensure that all instances of Webapp1 use the same service account. The password of the service account must change automatically every 30 days. Prevent domain controllers from directly contacting hosts on the internet. You need to configure the synchronization of Azure files to meet the following requirements: Ensure that seattlefiles syncs to FS2. Ensure that newyorkfiles syncs to FS1. Ensure that companyfiles syncs to both FS1 and FS2. You need to meet the security requirements for passwords. Where should you configure the components for Azure AD Password Protection? ![Question 17 part 1](images/question7_16_17_19_22_29_45_1.jpg) ![Question 17 part 2](images/question7_16_17_19_22_29_45_2.jpg) ![Question 17 part 3](images/question17_3.jpg)

    A
    The Azure AD Password Protection DC agent: All the domain controllers. The Azure AD Password Protection proxy service: VM1 and VM2. A custom banned password list: The Azure AD tenant.
    B
    The Azure AD Password Protection DC agent: DC1 only. The Azure AD Password Protection proxy service: The Azure AD tenant. A custom banned password list: VM1 and VM2.
    C
    The Azure AD Password Protection DC agent: VM1 and VM2. The Azure AD Password Protection proxy service: All the domain controllers. A custom banned password list: DC1 only.
    D
    The Azure AD Password Protection DC agent: All the domain controllers. The Azure AD Password Protection proxy service: The Azure AD tenant. A custom banned password list: VM1 and VM2.
  18. FreePracticeQuiz.questionLabelCompute

    You have an Azure virtual machine named VM1 that runs Windows Server. You perform the following actions on VM1: Create a folder named Folder1 on volume C. Create a folder named Folder2 on volume D. Add a new data disk to VM1 and create a new volume that is assigned drive letter E. Install an app named App1 on volume E. You plan to resize VM1. Which objects will present after you resize VM1?

    A
    Folder1 and Folder2 only.
    B
    Folder1, volume E, and App1 only.
    C
    Folder1 only.
    D
    Folder1, Folder2, App1, and volume E.
  19. FreePracticeQuiz.questionLabelSecurity

    Fabrikam, Inc is a manufacturing company that has a main office in New York and a branch office in Seattle. The on-premises network contains servers that run Windows Server as shown in the following table. DC1 hosts all the operation master roles. VM1 and VM2 are connected to the internet. WEB1 and WEB2 run an Internet Information Services (IIS) web app named Webapp1. The New York and Seattle offices are connected by using redundant WAN links. The client computers in each office get IP addresses from their local DHCP server. DHCP1 contains a scope named Scope1 that has addresses for the New York office, DHCP2 contains a scope named Scope2 that has addresses for the Seattle office. The network contains a single on-premises Active Directory Domain Services (AD DS) domain named corp.falbrikam.com. Currently, all the service accounts use individual domain user accounts. All domain controllers have the DNS Server role installed and host a copy of the Active Directory integrated DNS zone of corp.fabrikam.com. The corp.fabrikam.com AD DS domain syncs with an Azure Active Directory (Azure AD) tenant. The corp.fabrikam.com domain contains the organizational units (OUs) and custom Group Policy Objects (GPOs) shown in the following table. Fabrikam identifies the following planned changes: Create a single Azure subscription named Sub1 that will contain a single Azure virtual network named Vnet1. Replace the WAN links between the Seattle and New York offices by using Azure Virtual WAN and FxpressRoute. Both on premises offices will be connected to Vnet1 by using ExpressRoute. Create three Azure file shares named newyorkfiles, seattlefiles, and companyfiles. Create a domain controller named dc3.corp.fabrikam.com in Vnet1. Deploy an Azure Virtual Desktop host pool to Vnet1. The Azure Virtual Desktop session hosts will be hybrid Azure AD-joined. License all servers for Microsoft Defender for servers. Use Azure Policy to enforce configuration management policies on the servers in Azure and on-premises. Fabrikam identifies the following networking requirements: Implement Virtual WAN and ensure that all the network traffic between the sites uses Virtual WAN. All communications must occur over ExpressRoute. If a DHCP server fails, ensure that the client computers can continue to receive their dynamic IP address and renew their existing lease. Ensure that the resources in Vnet1 can resolve the names of the on-premises servers in the corp.fabrikam.com domain. Fabrikam identifies the following security requirements: Apply GPO4 to the Azure Virtual Desktop session hosts. Ensure that Azure Virtual Desktop user sessions lock after being idle for 10 minutes. Users must be able to control the lockout time manually from their client computer. Ensure that server administrators request approval before they can establish a Remote Desktop connection to an Azure virtual machine. If the request is approved, the connection must be established within two hours. Prevent user passwords from containing all or part of words that are based on the company name, such as Fab, f@br1kAm or fabr!|. Ensure that all instances of Webapp1 use the same service account. The password of the service account must change automatically every 30 days. Prevent domain controllers from directly contacting hosts on the internet. You need to configure the synchronization of Azure files to meet the following requirements: Ensure that seattlefiles syncs to FS2. Ensure that newyorkfiles syncs to FS1. Ensure that companyfiles syncs to both FS1 and FS2. Which three actions should you perform in sequence to meet the security requirements for Webapp1? ![Question 19 part 1](images/question7_16_17_19_22_29_45_1.jpg) ![Question 19 part 2](images/question7_16_17_19_22_29_45_2.jpg) ![Question 19 part 3](images/question19_3.jpeg)

    A
    Box 1: Configure the IIS application pool to run as Network Service. Box 2: Create a group managed service account (gMSA) in Active Directory. Box 3: Create the Key Distribution Services (KDS) root key in AD DS.
    B
    Box 1: Create the Key Distribution Services (KDS) root key in AD DS. Box 2: Create a group managed service account (gMSA) in Active Directory. Box 3: Configure the IIS application pool to run as Network Service.
    C
    Box 1: Create a standalone managed service account (sMSA) in AD DS. Box 2: Create a group managed service account (gMSA) in Active Directory. Box 3: Configure the IIS application pool to run as Network Service.
    D
    Box 1: Create a system-assigned managed identity in Azure AD. Box 2: Create a group managed service account (gMSA) in Active Directory. Box 3: Create the Key Distribution Services (KDS) root key in AD DS.
  20. FreePracticeQuiz.questionLabelManagement

    Contoso, Ltd. is a company that has a main office in Seattle and two branch offices in Los Angeles and Montreal. The network contains an on premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com. The forest contains the domain controllers shown in the following table. All the domain controllers are global catalog servers. The network contains the servers shown in the following table. A server named Server4 runs Windows Server and is in a workgroup. Windows Firewall on Server4 uses the private profile. Server2 hosts three virtual machines named VM1, VM2, and VM3. VM3 is a file server that stores data in the volumes shown in the following table. The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table. The forest contains the users shown in the following table. The forest contains the groups shown in the following table. When an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out, another administrator can connect to the console session as the currently signed in user. Contoso identifies the following technical requirements: Change the replication schedule for all site links to 30 minutes. Promote Server1 to a domain controller in canada.contoso.com. Install and authorize Server3 as a DHCP server. Ensure that User1 can manage the membership of all the groups in Contoso\OU3. Ensure that you can manage Server4 from Server1 by using PowerShell remoting. Ensure that you can run virtual machines on VM1. Force users to provide credentials when they connect to VM2. On VM3, ensure that Data Deduplication on all volumes is possible. You need to meet the technical requirements for Server4. Which cmdlets should you run on Server1 and Server4? ![Question 20 part 1](images/question5_8_9_20_33_38_39_43_1.jpg) ![Question 20 part 2](images/question5_8_9_20_33_38_39_43_2.jpg) ![Question 20 part 3](images/question5_8_9_20_33_38_39_43_3.jpg) ![Question 20 part 4](images/question5_8_9_20_33_38_39_43_4.jpg) ![Question 20 part 5](images/question5_8_9_20_33_38_39_43_5.jpg) ![Question 20 part 6](images/question5_8_9_20_33_38_39_43_6.jpg) ![Question 20 part 7](images/question20_7.jpg)

    A
    Server1: Enable-ServerManagerStandardUserRemoting. Server4: Enable-PSRemoting.
    B
    Server1: Enable-PSRemoting. Server4: Enable-ServerManagerStandardUserRemoting.
    C
    Server1: Set-Item. Server4: Enable-PSRemoting.
    D
    Server1: Start-Service. Server4: Enable-PSRemoting.
  21. FreePracticeQuiz.questionLabelStorage

    You have a file server named Server1 that runs Windows Server and contains the volumes shown in the following table. On which volumes can you use BitLocker Drive Encryption (BitLocker) and disk quotas? ![Question 21 part 1](images/question21_1.jpg) ![Question 21 part 2](images/question21_2.jpg)

    A
    BitLocker: C, D, and E. Disk quotas: C and D only.
    B
    BitLocker: C and D only. Disk quotas: C, D, and E.
    C
    BitLocker: C only. Disk quotas: D only.
    D
    BitLocker: D only. Disk quotas: C only.
  22. FreePracticeQuiz.questionLabelIdentity

    Fabrikam, Inc is a manufacturing company that has a main office in New York and a branch office in Seattle. The on-premises network contains servers that run Windows Server as shown in the following table. DC1 hosts all the operation master roles. VM1 and VM2 are connected to the internet. WEB1 and WEB2 run an Internet Information Services (IIS) web app named Webapp1. The New York and Seattle offices are connected by using redundant WAN links. The client computers in each office get IP addresses from their local DHCP server. DHCP1 contains a scope named Scope1 that has addresses for the New York office, DHCP2 contains a scope named Scope2 that has addresses for the Seattle office. The network contains a single on-premises Active Directory Domain Services (AD DS) domain named corp.falbrikam.com. Currently, all the service accounts use individual domain user accounts. All domain controllers have the DNS Server role installed and host a copy of the Active Directory integrated DNS zone of corp.fabrikam.com. The corp.fabrikam.com AD DS domain syncs with an Azure Active Directory (Azure AD) tenant. The corp.fabrikam.com domain contains the organizational units (OUs) and custom Group Policy Objects (GPOs) shown in the following table. Fabrikam identifies the following planned changes: Create a single Azure subscription named Sub1 that will contain a single Azure virtual network named Vnet1. Replace the WAN links between the Seattle and New York offices by using Azure Virtual WAN and FxpressRoute. Both on premises offices will be connected to Vnet1 by using ExpressRoute. Create three Azure file shares named newyorkfiles, seattlefiles, and companyfiles. Create a domain controller named dc3.corp.fabrikam.com in Vnet1. Deploy an Azure Virtual Desktop host pool to Vnet1. The Azure Virtual Desktop session hosts will be hybrid Azure AD-joined. License all servers for Microsoft Defender for servers. Use Azure Policy to enforce configuration management policies on the servers in Azure and on-premises. Fabrikam identifies the following networking requirements: Implement Virtual WAN and ensure that all the network traffic between the sites uses Virtual WAN. All communications must occur over ExpressRoute. If a DHCP server fails, ensure that the client computers can continue to receive their dynamic IP address and renew their existing lease. Ensure that the resources in Vnet1 can resolve the names of the on-premises servers in the corp.fabrikam.com domain. Fabrikam identifies the following security requirements: Apply GPO4 to the Azure Virtual Desktop session hosts. Ensure that Azure Virtual Desktop user sessions lock after being idle for 10 minutes. Users must be able to control the lockout time manually from their client computer. Ensure that server administrators request approval before they can establish a Remote Desktop connection to an Azure virtual machine. If the request is approved, the connection must be established within two hours. Prevent user passwords from containing all or part of words that are based on the company name, such as Fab, f@br1kAm or fabr!|. Ensure that all instances of Webapp1 use the same service account. The password of the service account must change automatically every 30 days. Prevent domain controllers from directly contacting hosts on the internet. You need to configure the synchronization of Azure files to meet the following requirements: Ensure that seattlefiles syncs to FS2. Ensure that newyorkfiles syncs to FS1. Ensure that companyfiles syncs to both FS1 and FS2. You need to configure the Group Policy settings to ensure that the Azure Virtual Desktop session hosts meet the security requirements. What should you configure? ![Question 22 part 1](images/question7_16_17_19_22_29_45_1.jpg) ![Question 22 part 2](images/question7_16_17_19_22_29_45_2.jpg)

    A
    Security filtering for the link of GP04.
    B
    Security filtering for the link of GPO1.
    C
    Loopback processing in GPO4.
    D
    Enforced property for the link of GP01.
    E
    Loopback processing in GPO1.
    F
    Enforced property for the link of GP04.
  23. FreePracticeQuiz.questionLabelStorage

    You have two on-premises servers named Server1 and Servet2 that run Windows Server. You have an Azure Storage account named storage1 that contains a file share named share. Server1 syncs with share1 by using Azure File Sync You need to configure Server2 to sync with share1. Which three actions should you perform in sequence? ![Question 23](images/question23.jpeg)

    A
    Box 1: Add a Storage Sync Service to the Azure Subscription. Box 2: Add a server endpoint to the sync group. Box 3: On Server2, install the Azure File Sync agent.
    B
    Box 1: Add a server endpoint to the sync group. Box 2: On Server2, install the Azure File Sync agent. Box 3: Add a cloud endpoint to the sync group.
    C
    Box 1: On Server2, install the Azure File Sync agent. Box 2: Add a cloud endpoint to the sync group. Box 3: Register Server2 with the Storage Sync Service.
    D
    Box 1: On Server2, install the Azure File Sync agent. Box 2: Register Server2 with the Storage Sync Service. Box 3: Add a server endpoint to the sync group.
  24. FreePracticeQuiz.questionLabelIdentity

    Which groups can you add to Group3 and Group5? ![Question 24](images/question24.jpg)

    A
    Group3: Group1 and Group2 only. Group5: Group4 only.
    B
    Group3: Group1 and Group4 only. Group5: Group6 only.
    C
    Group3: Group1, Group2, Group4, and Group5 only. Group5: Group4 only.
    D
    Group3: Group6 only. Group5: Group4 and Group6 only.
  25. FreePracticeQuiz.questionLabelStorage

    You have five tile servers that run Windows Server. You need to block users from uploading video files that have the .mov extension to shared folders on the file servers. All other types of files must be allowed. The solution must minimize administrative effort. What should you create?

    A
    Dynamic Access Control central access policy.
    B
    File screen.
    C
    Dynamic Access Control central access rule.
    D
    Data loss prevention (DLP) policy.
  26. FreePracticeQuiz.questionLabelSecurity

    Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com. The domain contains a server named Server1 and the users shown in the following table. Server1 contains a folder named D:Folder1. The advanced security settings for Folder 1 are configured as shown in the Permissions exhibit. Folder1 is shared by using the following configurations. The share permissions for Share1 are shown in the following table. User1 can read the files in Share1. ![Question 26 part 1](images/question26_27_28_1.jpg) ![Question 26 part 2](images/question26_27_28_2.png) ![Question 26 part 3](images/question26_27_28_3.png) ![Question 26 part 4](images/question26_27_28_4.png)

    A
    Yes.
    B
    No.
  27. FreePracticeQuiz.questionLabelSecurity

    Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com. The domain contains a server named Server1 and the users shown in the following table. Server1 contains a folder named D:Folder1. The advanced security settings for Folder 1 are configured as shown in the Permissions exhibit. Folder1 is shared by using the following configurations. The share permissions for Share1 are shown in the following table. User3 can delete files in Share1. ![Question 27 part 1](images/question26_27_28_1.jpg) ![Question 27 part 2](images/question26_27_28_2.png) ![Question 27 part 3](images/question26_27_28_3.png) ![Question 27 part 4](images/question26_27_28_4.png)

    A
    Yes.
    B
    No.
  28. FreePracticeQuiz.questionLabelSecurity

    Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com. The domain contains a server named Server1 and the users shown in the following table. Server1 contains a folder named D:Folder1. The advanced security settings for Folder 1 are configured as shown in the Permissions exhibit. Folder1 is shared by using the following configurations. The share permissions for Share1 are shown in the following table. If User2 connects to \\Server1.adatum.com from File Explorer, Share1 will be listed. ![Question 28 part 1](images/question26_27_28_1.jpg) ![Question 28 part 2](images/question26_27_28_2.png) ![Question 28 part 3](images/question26_27_28_3.png) ![Question 28 part 4](images/question26_27_28_4.png)

    A
    Yes.
    B
    No.
  29. FreePracticeQuiz.questionLabelIdentity

    Fabrikam, Inc is a manufacturing company that has a main office in New York and a branch office in Seattle. The on-premises network contains servers that run Windows Server as shown in the following table. DC1 hosts all the operation master roles. VM1 and VM2 are connected to the internet. WEB1 and WEB2 run an Internet Information Services (IIS) web app named Webapp1. The New York and Seattle offices are connected by using redundant WAN links. The client computers in each office get IP addresses from their local DHCP server. DHCP1 contains a scope named Scope1 that has addresses for the New York office, DHCP2 contains a scope named Scope2 that has addresses for the Seattle office. The network contains a single on-premises Active Directory Domain Services (AD DS) domain named corp.falbrikam.com. Currently, all the service accounts use individual domain user accounts. All domain controllers have the DNS Server role installed and host a copy of the Active Directory integrated DNS zone of corp.fabrikam.com. The corp.fabrikam.com AD DS domain syncs with an Azure Active Directory (Azure AD) tenant. The corp.fabrikam.com domain contains the organizational units (OUs) and custom Group Policy Objects (GPOs) shown in the following table. Fabrikam identifies the following planned changes: Create a single Azure subscription named Sub1 that will contain a single Azure virtual network named Vnet1. Replace the WAN links between the Seattle and New York offices by using Azure Virtual WAN and FxpressRoute. Both on premises offices will be connected to Vnet1 by using ExpressRoute. Create three Azure file shares named newyorkfiles, seattlefiles, and companyfiles. Create a domain controller named dc3.corp.fabrikam.com in Vnet1. Deploy an Azure Virtual Desktop host pool to Vnet1. The Azure Virtual Desktop session hosts will be hybrid Azure AD-joined. License all servers for Microsoft Defender for servers. Use Azure Policy to enforce configuration management policies on the servers in Azure and on-premises. Fabrikam identifies the following networking requirements: Implement Virtual WAN and ensure that all the network traffic between the sites uses Virtual WAN. All communications must occur over ExpressRoute. If a DHCP server fails, ensure that the client computers can continue to receive their dynamic IP address and renew their existing lease. Ensure that the resources in Vnet1 can resolve the names of the on-premises servers in the corp.fabrikam.com domain. Fabrikam identifies the following security requirements: Apply GPO4 to the Azure Virtual Desktop session hosts. Ensure that Azure Virtual Desktop user sessions lock after being idle for 10 minutes. Users must be able to control the lockout time manually from their client computer. Ensure that server administrators request approval before they can establish a Remote Desktop connection to an Azure virtual machine. If the request is approved, the connection must be established within two hours. Prevent user passwords from containing all or part of words that are based on the company name, such as Fab, f@br1kAm or fabr!|. Ensure that all instances of Webapp1 use the same service account. The password of the service account must change automatically every 30 days. Prevent domain controllers from directly contacting hosts on the internet. You need to configure the synchronization of Azure files to meet the following requirements: Ensure that seattlefiles syncs to FS2. Ensure that newyorkfiles syncs to FS1. Ensure that companyfiles syncs to both FS1 and FS2. You are planning the implementation Azure Arc to support the planned changes. You need to configure the environment to support configuration management policies. What should you do? ![Question 29 part 1](images/question7_16_17_19_22_29_45_1.jpg) ![Question 29 part 2](images/question7_16_17_19_22_29_45_2.jpg)

    A
    Hybrid Azure AD join all the servers.
    B
    Create a hybrid runbook worker m Azure Automation.
    C
    Deploy the Azure Connected Machine agent to all the servers.
    D
    Deploy the Azure Monitor agent to all the servers.
  30. FreePracticeQuiz.questionLabelCompute

    You have a Windows Server container host named Server 1 and a container image named Image1. You need to start a container from image1. The solution must run the container on a Hyper-V virtual machine. Which parameter should you specify when you run the docker run command?

    A
    –expose.
    B
    –privileged.
    C
    –runtime.
    D
    –entrypoint.
    E
    –isolation.
Progress: 0 of 30 questions completed

Ready for the full AZ-800 exam?

Get all 154+ Questions, timed simulation, and weak-area analytics. Plans from $2.99 — credits never expire.

See pricing

Frequently Asked Questions

Are these real AZ-800 practice questions?+
Yes. These 30 questions are taken directly from our 154+ Questions pool, written and reviewed by certified practitioners. They mirror the style, difficulty, and scope of the official Azure AZ-800 exam.
Is the AZ-800 exam hard?+
The Azure Azure Hybrid Admin (AZ-800) is considered a pass-mark exam (passing score: 700 out of 1000). Most candidates need 4–8 weeks of focused preparation. Use these free questions to gauge where you stand before committing to a full study plan.
How many questions are on the real AZ-800 exam?+
The official AZ-800 exam has 40-60 questions.
Do I need to sign up to use these questions?+
No. These 30 questions are free and require no signup. If you want timed simulation, performance analytics, and access to all 154+ Questions, our paid plans start at $2.99 per exam with credits that never expire.

Keep studying

Pass AZ-800 on your first try

Join candidates using DummyExams to practice with realistic timed exams, detailed explanations, and weak-area analytics.

Start full AZ-800 practice exam