Microsoft
AZ-801 · Question #10
Contoso, Ltd. is a manufacturing company that has a main office in Seattle and branch offices in Los Angeles and Montreal. Existing Environment Active Directory Environment Contoso has an on-premises
Sign in or unlock AZ-801 to reveal the answer and full explanation for question #10. The question stem and answer options stay visible for context.
Implement disaster recovery
Question
Contoso, Ltd. is a manufacturing company that has a main office in Seattle and branch offices in Los Angeles and Montreal.
Existing Environment
Active Directory Environment
Contoso has an on-premises Active Directory Domain Services (AD DS) domain named contoso.com that syncs with an Azure Active Directory (Azure AD) tenant. The AD DS domain maintains the domain controllers shown in the following table:
Name | Operating system | Operation master role
DC1 | Windows Server 2012 R2 | RID master, schema master
DC2 | Windows Server 2016 | PDC emulator, infrastructure master
DC3 | Windows Server 2016 | Domain naming master
Contoso recently purchased an Azure subscription.
The functional level of the forest is Windows Server 2012 R2. The functional level of the domain is Windows Server 2012. The forest has the Active Directory Recycle Bin enabled.
The contoso.com domain contains the users shown in the following table.
Name | Organizational unit (OU)/Container | Member of
User1 | OU1 | Group2, Group4
User2 | Users | Group2
User3 | OU1 | Group3, Group4
Admin1 | OU1 | Domain Admins
The contoso.com domain has the Group Policy Objects (GPOs) shown in the following table.
Name | Minimum password length | Linked to
GPO1 | 8 | contoso.com
Default Domain Policy | 10 | OU1
The contoso.com domain has the Password Settings Objects (PSOs) shown in the following table.
Name | Precedence | Minimum password length | Directly applies to
PSO1 | 10 | 9 | Group2
PSO2 | 20 | 11 | Group4
Server Infrastructure
The contoso.com domain contains servers that run Windows Server 2022 as shown in the following table.
Name | Description
Server1 | Contains a shared named Share1
Server2 | None
Server3 | None
Server4 | Has Remote Desktop enabled
By using Windows Firewall with Advanced Security, the servers have isolation connection security rules configured as shown in the following table.
Name | Endpoint1 | Endpoint2 | Authentication mode
Server1 | Any | Any | Request inbound and outbound
Server2 | Any | Any | Require inbound and request outbound
Server3 | Any | Any | Request inbound and outbound
DC1 | Any | Any | Request inbound and outbound
DC2 | Any | Any | Request inbound and outbound
DC3 | Any | Any | Request inbound and outbound
Server4 has no connection security rules.
Server4 Configurations
Server4 has the effective Group Policy settings for user rights as shown in the following table.
Policy | Security Setting
Access this computer from the network | Group1, Administrators, Backup Operators, Everyone, Users
Deny access to this computer from the network | Group4
Allow log on through Remote Desktop Services | Group2, Administrators, Remote Desktop Users
Deny log on through Remote Desktop Services | Group3
Server4 has the disk configurations shown in the following exhibit.
(Disk Management screenshot showing Disk 0-3)
Virtualization Infrastructure
The Contoso.com domain has the Hyper-V failover clusters shown in the following table.
Name | Number of nodes | Number of virtual machines
Cluster1 | 6 | 18
Cluster2 | 4 | 12
Cluster3 | 2 | 6
Technical Requirements
Contoso identifies the following technical requirements:
• Promote a new server named DC4 that runs to Windows Server 2022 to a domain controller.
• Replicate the virtual machines from Cluster2 to an Azure Recovery Services vault.
• Centrally manage performance alerts in Azure for all the domain controllers.
• Ensure that User1 can recover objects from the Active Directory Recycle Bin.
• Migrate Share1 to Server2, including all the share and folder permissions.
• Back up Server4 and all data to an Azure Recovery Services vault.
• Use Hyper-V Replica to protect the virtual machines in Cluster3.
• Implement BitLocker Drive Encryption (BitLocker) on Server4.
• Whenever possible, use the principle of least privilege.
You need to back up Server 4 to meet the technical requirements. What should you do first?
Options
- ADeploy Microsoft Azure Backup (MABS).
- BConfigure Windows Server Backup.
- CInstall the Microsoft Azure Recovery Services (MARS) agent.
- DConfigure Storage Replica.
Unlock AZ-801 to see the answer
You've previewed enough free AZ-801 questions. Unlock AZ-801 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Azure Backup#MARS Agent#Disaster Recovery#Hybrid Cloud Backup