AZ-801 Practice Exam — AZ-801: Configuring Windows Server Hybrid Advanced Services

1. The question bank is cloud-based and updates automatically, with no need for re-acquisition.

2. Available in Chinese and English. It supports online practice, mock exams and PDF downloads.

3. You can practice questions via mini-program or desktop web page. The service is valid for one year.

4. Activation codes can be purchased directly or from our official Tmall flagship store.

5. For inquiries, please contact customer service via WeChat, WhatsApp or Line.

6. Drag-and-drop, hotspot and dropdown questions are currently under development.

Exam information

AZ-801: Configuring Windows Server Hybrid Advanced Services

- Exam Overview: Targeted at advanced hybrid cloud administrators, this exam validates the ability to configure and manage advanced services (such as high availability, migration, and security) in Windows Server hybrid environments.

- Key Specifications:

 - Exam Duration: 120 minutes

 - Number of Questions: 40-60 (Including complex scenarios and advanced configuration questions)

 - Total Score / Passing Score: 1000 / 700

 - Exam Fee: Approximately $165 USD

 - Supported Languages: Simplified Chinese, English, etc.

 - Official Registration Link: https://learn.microsoft.com/zh-cn/credentials/certifications/exams/az-801/

- Core Topics:

 - Windows Server high availability configuration (25-30%)

 - Hybrid migration and disaster recovery (20-25%)

 - Security and compliance configuration (25-30%)

 - Advanced monitoring and automated management (15-20%)

Sample questions

AZ-801 · Q1
Topic 1 Question #1 Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server.You need to ensure that only specific applications can modify the data in protected folders on Server1.Solution: From Virus & threat protection, you configure Controlled folder access.Does this meet the goal?
  • A.
    Yes
  • B.
    No

Answer: A

The scenario requires restricting modification of data in protected folders on a Windows Server to only explicitly specified applications. Controlled Folder Access is a native Windows Server security feature hosted under the Virus & Threat Protection section of Microsoft Defender Antivirus, part of Microsoft Defender for Endpoint. This feature is purpose-built to block all unapproved applications from writing to or altering contents of designated protected folders by default, while permitting only pre-authorized applications added to an allowed list to modify data in those folders. The proposed solution directly aligns with the stated requirement, so it meets the goal. Option Analysis: A. Correct. Configuring Controlled Folder Access from Virus & threat protection settings lets administrators define protected folders and curate an explicit list of applications permitted to modify data in those folders. All unapproved applications, including malicious software like ransomware, are blocked from altering protected folder contents, which exactly fulfills the requirement in the scenario. This implementation aligns with the Windows Server security configuration objectives tested in the AZ-801 certification. B. Incorrect. The proposed solution leverages the exact native Windows Server feature designed to implement application-specific restrictions on protected folder modification. There are no feature limitations that prevent this solution from meeting the stated goal, so this option is invalid. Key Concepts: 1. Controlled Folder Access: A core Microsoft Defender for Endpoint feature supported on Windows Server that provides ransomware protection and data tampering prevention by restricting write access to designated protected folders to only pre-approved trusted applications. This is a key component of Windows Server threat protection covered in the AZ-801 exam. 2. Windows Server Hybrid Security Configuration: The AZ-801 exam domain includes configuring security for both on-premises Windows Servers and Azure Arc-enabled hybrid server workloads, including implementation of Defender threat protection features to prevent unauthorized data modification. 3. Application Allowlisting: A least-privilege security principle where only explicitly authorized software is permitted to perform defined actions, a core concept tested in AZ-801 security objectives. Controlled Folder Access is a targeted use case of application allowlisting for static data protection in user and system folders. References: Protect important folders with controlled folder access, https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/controlled-folders?view=o365-worldwide AZ-801: Configuring Windows Server Hybrid Advanced Services study guide, https://learn.microsoft.com/en-us/certifications/exams/az-801
AZ-801 · Q2
Topic 1 Question #2 Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server.You need to ensure that only specific applications can modify the data in protected folders on Server1.Solution: From Virus & threat protection, you configure Tamper ProtectionDoes this meet the goal?
  • A.
    Yes
  • B.
    No

Answer: B

This question aligns with the AZ-801 Configuring Windows Server Hybrid Advanced Services objective of implementing Windows Server security using Microsoft Defender Antivirus capabilities. The stated goal is to restrict write modifications to protected folders to only explicitly permitted applications, a use case specifically addressed by the Controlled Folder Access feature in Microsoft Defender. The proposed solution configures Tamper Protection, which serves an entirely separate purpose: Tamper Protection locks down core Microsoft Defender Antivirus configuration settings (such as real-time protection rules, exclusion lists, and cloud-delivered protection toggles) to prevent malicious users or malware from disabling Defender security controls. Tamper Protection has no functionality to regulate which applications can access or modify file system folders, so the proposed solution fails to meet the stated requirement. Option Analysis: A. This option is incorrect. Tamper Protection only protects Defender's own security configuration from unauthorized changes, and includes no controls for managing application access to protected file system folders. Implementing it does nothing to restrict folder modifications to specific applications, so it does not achieve the scenario's goal. B. This option is correct. The provided solution uses the wrong Microsoft Defender feature. The correct feature to meet the stated goal is Controlled Folder Access, not Tamper Protection, so the proposed solution does not satisfy the requirement. Key Concepts: 1. Controlled Folder Access: A Microsoft Defender Antivirus ransomware protection feature that lets administrators define protected folders and whitelist trusted applications that are allowed to modify content in those folders, blocking all unapproved write attempts. This is the exact feature required to meet the scenario's objective. 2. Tamper Protection: A Microsoft Defender security feature that prevents unauthorized modification of core Defender Antivirus configuration settings to stop malicious actors from disabling endpoint protection. It does not regulate application access to the file system. 3. Windows Server Security Feature Mapping: A core AZ-801 competency that requires matching specific security requirements to the appropriate built-in Windows Server security tools to avoid misconfiguration and ensure protection controls work as intended. References: Protect security settings with tamper protection, https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection?view=o365-worldwide Controlled folder access, https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/controlled-folders?view=o365-worldwide
AZ-801 · Q3
Topic 1 Question #3 Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a server named Server1 that runs Windows Server.You need to ensure that only specific applications can modify the data in protected folders on Server1.Solution: From App & browser control, you configure the Exploit protection settings.Does this meet the goal?
  • A.
    Yes
  • B.
    No

Answer: B

The requirement in the scenario is to restrict modification of data in protected folders exclusively to preapproved specific applications. This use case is addressed by the Controlled Folder Access feature, a component of Microsoft Defender Antivirus included in supported Windows Server versions. The proposed solution configures Exploit Protection settings from App & browser control. Exploit Protection is designed to mitigate common software exploit techniques such as memory corruption, heap spraying, and arbitrary code execution at the system or per-application level, and it has no native functionality to control which applications can write to designated protected folders. Since the solution uses the incorrect security feature for the stated goal, it fails to meet the requirement. Option Analysis: A. This option is incorrect. Exploit Protection does not provide folder access restriction capabilities. It focuses solely on mitigating exploit vectors used to compromise applications, not controlling write access to specified folders, so it cannot fulfill the requirement to limit folder modification to only specific approved applications. B. This option is correct. The proposed solution leverages the wrong Windows security feature. The appropriate feature to meet the stated goal is Controlled Folder Access, not Exploit Protection, so the provided solution does not meet the requirement. Key Concepts: 1. Controlled Folder Access: A Microsoft Defender Antivirus security feature covered in the AZ-801 Windows Server security domain, which blocks untrusted applications from modifying protected user and system folders, only allowing explicitly whitelisted applications to write to these folders, primarily for ransomware protection. 2. Exploit Protection: A Windows Server security feature that provides configurable mitigation for common exploit techniques, replacing the legacy Enhanced Mitigation Experience Toolkit (EMET). It operates at the application runtime level to block compromise attempts, with no folder access control functionality. 3. Windows Server Endpoint Protection Configuration: AZ-801 exam objectives require candidates to distinguish between complementary but distinct Microsoft Defender security features, to select the correct control for specific security requirements. References: Protect important folders with controlled folder access, https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/controlled-folders?view=o365-worldwide Enable and configure exploit protection, https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/enable-exploit-protection?view=o365-worldwide
AZ-801 · Q4
Topic 1 Question #4 DRAG DROP - You have an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. The AD DS domain contains a domain controller named DC1. DC1 does NOT have internet access. You need to configure password security for on-premises users. The solution must meet the following requirements: ✑ Prevent the users from using known weak passwords. ✑ Prevent the users from using the company name in passwords. What should you do? To answer, drag the appropriate configurations to the correct targets. Each configuration may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point. Select and Place: " target="_blank" rel="nofollow noopener">https://www.examtopics.com/assets/media/exam-media/04226/0002400003.png">
  • A.
    错误
  • B.
    正确

Answer: B

" target="_blank" rel="nofollow noopener">https://www.examtopics.com/assets/media/exam-media/04226/0002400004.png">
AZ-801 · Q5
Topic 1 Question #5 HOTSPOT - The Default Domain Policy Group Policy Object (GPO) is shown in the GPO exhibit. (Click the GPO tab.) " target="_blank" rel="nofollow noopener">https://www.examtopics.com/assets/media/exam-media/04226/0002600001.jpg"> The members of a group named Service Accounts are shown in the Group exhibit. (Click the Group tab.) " target="_blank" rel="nofollow noopener">https://www.examtopics.com/assets/media/exam-media/04226/0002700001.png"> An organizational unit (OU) named ServiceAccounts is shown in the OU exhibit. (Click the OU tab.) " target="_blank" rel="nofollow noopener">https://www.examtopics.com/assets/media/exam-media/04226/0002800001.png"> You create a Password Settings Object (PSO) as shown in the PSO exhibit. (Click the PSO tab.) " target="_blank" rel="nofollow noopener">https://www.examtopics.com/assets/media/exam-media/04226/0002900001.jpg"> For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Hot Area: " target="_blank" rel="nofollow noopener">https://www.examtopics.com/assets/media/exam-media/04226/0003000001.jpg">
  • A.
    错误
  • B.
    正确

Answer: B

" target="_blank" rel="nofollow noopener">https://www.examtopics.com/assets/media/exam-media/04226/0003000002.jpg">

FAQ

How many practice questions are available for AZ-801?

This question bank includes 313 AZ-801 practice questions covering single and multiple choice, each with answers and explanations.

Are AZ-801 practice questions available in Chinese and English?

Yes, AZ-801 practice questions are provided in both Chinese and English.

Can I try AZ-801 practice questions for free?

Yes. Free sample questions are available on this page, and the full question bank is available after signing up on Zhangxuetu.