AZ-800 Exam Prep Free practice test →

Free AZ-800 Practice Questions

10 free, exam-style Microsoft Certified: Windows Server Hybrid Administrator Associate (AZ-800) (AZ-800) practice questions with answers and explanations. No signup required. Work through them below, then take the full free AZ-800 practice test to study every exam domain.

The AZ-800 exam has 60 questions and runs 100 minutes.

These 10 free AZ-800 questions are organized by exam domain, so you can see how each part of the Microsoft Certified: Windows Server Hybrid Administrator Associate (AZ-800) blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments (30-35%)

Question 1

Users report that they cannot change their passwords and that account lockouts are behaving inconsistently across the domain. Time on client computers has also drifted. Which FSMO role holder, if unavailable, is the MOST likely cause of these symptoms?

  1. PDC Emulator
  2. Infrastructure Master
  3. RID Master
  4. Domain Naming Master
Show answer & explanation

Correct answer: A - PDC Emulator

Question 2

A web application runs on a farm of four Windows Servers and currently uses a standard domain user account whose password must be rotated manually every 90 days. You need a single identity for all four servers that provides automatic password management. Which account type should you implement?

  1. A standalone Managed Service Account (sMSA)
  2. A local Virtual Account
  3. A group Managed Service Account (gMSA)
  4. A built-in Administrator account with a scheduled password reset
Show answer & explanation

Correct answer: C - A group Managed Service Account (gMSA)

Question 3

Before you can create the first group Managed Service Account (gMSA) in a forest, what must exist, and what timing consideration applies in a multi-domain-controller production environment?

  1. A KDS root key; wait up to 10 hours for it to replicate to all domain controllers before use
  2. A read-only domain controller; wait for the next replication cycle
  3. The Active Directory Recycle Bin; enable it forest-wide first
  4. A password settings object (PSO); apply it to the account immediately
Show answer & explanation

Correct answer: A - A KDS root key; wait up to 10 hours for it to replicate to all domain controllers before use

Question 4

A setting is configured in a GPO linked to the domain and a conflicting setting is configured in a GPO linked to an organizational unit (OU) that contains the user. By default, which setting applies, and what would guarantee the domain-linked setting wins instead?

  1. Whichever GPO has the lower link order number applies; no override option exists
  2. The OU GPO applies by default; set Enforced on the domain-linked GPO to make it win
  3. The domain GPO applies by default; set Block Inheritance on the OU to keep it that way
  4. Neither applies because the settings cancel each other out
Show answer & explanation

Correct answer: B - The OU GPO applies by default; set Enforced on the domain-linked GPO to make it win

Question 5

An organization has three separate Active Directory forests with no trusts between them. They want the simplest hybrid identity solution to synchronize all three forests to Microsoft Entra ID, with high availability if a sync agent fails. Which solution best fits these requirements?

  1. A single Microsoft Entra Connect Sync server with a staging server
  2. Active Directory Federation Services (AD FS) with a federation farm
  3. Pass-through authentication agents installed on each domain controller
  4. Microsoft Entra Cloud Sync using multiple provisioning agents
Show answer & explanation

Correct answer: D - Microsoft Entra Cloud Sync using multiple provisioning agents

Question 6

A security policy states that on-premises password hashes must NOT be stored in the cloud, yet users must sign in to Microsoft 365 with their on-premises credentials validated against on-premises Active Directory. Which authentication method meets this requirement?

  1. Password hash synchronization (PHS)
  2. Cloud-only accounts with no synchronization
  3. Pass-through authentication (PTA)
  4. Seamless single sign-on with cloud password writeback
Show answer & explanation

Correct answer: C - Pass-through authentication (PTA)

Question 7

A branch office in a shared building has no secure server room. You must place a domain controller there to speed up local logons, but you need to minimize the exposure of credentials if the server is physically stolen. What should you deploy?

  1. A writable domain controller with BitLocker only
  2. A member server running the AD LDS role
  3. A global catalog server with all passwords cached
  4. A read-only domain controller (RODC) with a restrictive Password Replication Policy
Show answer & explanation

Correct answer: D - A read-only domain controller (RODC) with a restrictive Password Replication Policy

Domain 2: Manage Windows Servers and workloads in a hybrid environment (10-15%)

Question 8

You need to manage several on-premises Windows Servers and non-Azure Linux servers from the Azure portal, including applying Azure Policy and deploying extensions. What must be installed on each server to achieve this?

  1. The Azure Connected Machine agent (Azure Arc)
  2. The Microsoft Monitoring Agent (MMA) only
  3. The Windows Admin Center gateway
  4. The Azure VM Agent used by Azure IaaS virtual machines
Show answer & explanation

Correct answer: A - The Azure Connected Machine agent (Azure Arc)

Question 9

An administrator uses Invoke-Command to run a script on Server1. The script then attempts to copy files from a share on Server2, and the access is denied even though the administrator has permissions to both servers. What is this issue called, and which is a supported way to resolve it?

  1. A WinRM listener conflict; recreate the HTTPS listener on port 5986
  2. A UAC remote restriction; disable remote UAC token filtering in the registry
  3. A trusted hosts problem; add Server2 to the WinRM TrustedHosts list
  4. A double-hop (second-hop) problem; configure resource-based Kerberos constrained delegation or CredSSP
Show answer & explanation

Correct answer: D - A double-hop (second-hop) problem; configure resource-based Kerberos constrained delegation or CredSSP

Domain 3: Manage virtual machines and containers (15-20%)

Question 10

On a Hyper-V host you need a virtual switch that allows the guest VMs to communicate with each other and with the management operating system (the host), but that does NOT provide any connectivity to the physical network. Which virtual switch type should you create?

  1. External
  2. Private
  3. Internal
  4. NAT
Show answer & explanation

Correct answer: C - Internal

The rest of the AZ-800 blueprint

The AZ-800 exam also covers these domains. Drill them in the full free practice test:

Ready for the real thing?

Practice hundreds more AZ-800 questions with instant scoring, weak-area drills, and full exam simulations.

Start the free practice test See pricing