FreeQAs
 Request Exam  Contact
  • Home
  • View All Exams
  • New QA's
  • Upload
PRACTICE EXAMS:
  • Oracle
  • Fortinet
  • Juniper
  • Microsoft
  • Cisco
  • Citrix
  • CompTIA
  • VMware
  • ISC
  • SAP
  • EMC
  • PMI
  • HP
  • Salesforce
  • Other
  • Oracle
    Oracle
  • Fortinet
    Fortinet
  • Juniper
    Juniper
  • Microsoft
    Microsoft
  • Cisco
    Cisco
  • Citrix
    Citrix
  • CompTIA
    CompTIA
  • VMware
    VMware
  • ISC
    ISC
  • SAP
    SAP
  • EMC
    EMC
  • PMI
    PMI
  • HP
    HP
  • Salesforce
    Salesforce
  1. Home
  2. Microsoft Certification
  3. AZ-801 Exam
  4. Microsoft.AZ-801.v2026-09-12.q300 Dumps
  • ««
  • «
  • …
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • …
  • »
  • »»
Download Now

Question 171

You have an Azure subscription that contains an Azure key vault named Vault1.
You plan to deploy a virtual machine named VM1 that will run Windows Server.
You need to enable encryption at host for VM1. The solution must use customer-managed keys.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Correct Answer:

Explanation
insert code

Question 172

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a failover cluster named Cluster1 that hosts an application named App1.
The General tab in App1 Properties is shown in the General exhibit. (Click the General tab.)

The Failover tab in App1 Properties is shown in the Failover exhibit. (Click the Failover tab.)

Server1 shuts down unexpectedly.
You need to ensure that when you start Server1, App1 continues to run on Server2.
Solution: From the General settings, you move Server2 up.
Does this meet the goal?

Correct Answer: B
Explanation
Server1 and Server2 are both unticked so the order they are listed in has no effect on whether the cluster will fail back.
insert code

Question 173

Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains a user named User1.
You deploy a read-only domain controller (RODC) named RODC1.
You need to ensure that User1 is a local administrator on RODC1. The solution must use the principle of least privilege.
What should you use?

Correct Answer: A
Correct:
* dsmgmt.exe
Domain Controllers (including Read-Only Domain Controllers) do not have a local Security Accounts Manager (SAM) database. Because of this, traditional local group management tools (like net user or Computer Management) cannot be used to manage local administrators.
To safely delegate administrative rights on a specific RODC without granting broad domain-wide permissions, Microsoft implements a feature called Administrator Role Separation (ARS). The dsmgmt.exe command-line utility provides the local roles subcommand interface explicitly designed to manage these delegated administrative roles directly on the RODC, perfectly adhering to the principle of least privilege.
* Ntdsutil.exe
Ntdsutil.exe can be used.
Domain Controller Architecture: When a Windows server is promoted to a Domain Controller (including an RODC), it disables the SAM database. Because the local security database is gone, standard local management utilities like the Local Users and Groups snap-in (lusrmgr.msc) become completely unavailable and cannot be used to manage permissions on that machine.
Administrator Role Separation (ARS): Microsoft created the Administrator Role Separation feature specifically for RODCs. This allows domain administrators to delegate local administrative privileges on a physical RODC to a standard user (like a local branch technician) without granting them any elevated permissions over the rest of the Active Directory domain.
How it works: You use ntdsutil.exe (specifically running the local roles subcommand) or the command-line tool dsmgmt.exe to bind a domain user or group to the local administrators role on that specific RODC.
Incorrect:
* Active Directory Sites and Services
This administrative GUI tool manages replication topology, subnets, and sites across the forest. It does not have functions to manage local security roles or machine-specific administrative rights for an RODC.
* Computer Management
The Computer Management tool cannot be used to assign local administrator privileges on a Read-Only Domain Controller (RODC). Domain controllers do not have a local Security Accounts Manager (SAM) database, which means traditional local users and groups do not exist on them, making the "Local Users and Groups" section in Computer Management unavailable.
* dsamain.exe
This tool is used to expose Active Directory data stored in backup snapshots or copies as a Lightweight Directory Access Protocol (LDAP) server. It cannot modify server roles or local administrative permissions.
* net user
This command manages user accounts within a local SAM database or a writable Active Directory database. It cannot be used to inject a user into an RODC's special isolated local administrator role.
* Local Users and Groups
The Local Users and Groups tool strictly relies on a machine's local SAM database. Attempting to open lusrmgr.msc on any Domain Controller will return an error stating that the snap-in cannot be used on a domain controller.
* System Configuration
Reference:
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731885(v=ws.11)
https://community.spiceworks.com/t/read-only-domain-controller-rodc-question/522418
insert code

Question 174

You have an Azure virtual machine named VM1 that runs Windows Server.
You need to encrypt the contents of the disks on VM1 by using Azure Disk Encryption.
What is a prerequisite for implementing Azure Disk Encryption?

Correct Answer: B
Azure Disk Encryption helps protect and safeguard your data to meet your organizational security and compliance commitments. It uses the BitLocker feature of Windows to provide volume encryption for the OS and data disks of Azure virtual machines (VMs), and is integrated with Azure Key Vault to help you control and manage the disk encryption keys and secrets.
https://docs.microsoft.com/en-us/azure/virtual-machines/windows/disk-encryption-overview
insert code

Question 175

You are planning the DHCP1 migration to support the DHCP migration plan.
Which two PowerShell cmdlets should you run on DHCP1, and which two PowerShell cmdlets should you run on DHCP2? To answer, drag the appropriate cmdlets to the correct servers. Each cmdlet may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

Reference:
https://theitbros.com/how-to-migrate-dhcp-to-windows-server-2016/
insert code
  • ««
  • «
  • …
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • …
  • »
  • »»
[×]

Download PDF File

Enter your email address to download Microsoft.AZ-801.v2026-09-12.q300 Dumps

Email:

FreeQAs

Our website provides the Largest and the most Latest vendors Certification Exam materials around the world.

Using dumps we provide to Pass the Exam, we has the Valid Dumps with passing guranteed just which you need.

  • DMCA
  • About
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
©2026 FreeQAs

www.freeqas.com materials do not contain actual questions and answers from Cisco's certification exams.