AZ-801 Practice Exam: Windows Server Administrator Associate (Advanced Infrastructure)
Windows Server advanced: failover clusters, migration to Azure, hardening, and fixing what broke.
What you'll be tested on
- High Availability and DR
- Migration
- Security
- Monitoring and Troubleshooting
Sample AZ-801 questions
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a server named Server1 that runs Windows Server. You need to ensure that only specific applications can modify the data in protected folders on Server1. Solution: From Virus & threat protection, you configure Controlled folder access. Does this meet the goal?
- Yes
- No
Show answer
A — YesYes, this meets the goal. Controlled folder access is a Microsoft Defender feature (configured under Virus and threat protection) that protects designated folders from unauthorized changes. Only trusted, allowed applications can modify files in protected folders; all other apps, including ransomware, are blocked and audited. You can add custom folders and explicitly allow specific applications, which matches the requirement exactly. Tamper Protection only guards Defender security settings, and exploit protection mitigates process exploits, so those alternatives would not restrict which applications can write to protected folders.
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a server named Server1 that runs Windows Server. You need to ensure that only specific applications can modify the data in protected folders on Server1. Solution: From Virus & threat protection, you configure Tamper Protection Does this meet the goal?
- Yes
- No
Show answer
B — NoNo, this does not meet the goal. Tamper Protection prevents unauthorized changes to Microsoft Defender security features themselves, such as disabling real-time protection or turning off cloud-delivered protection. It does not control which applications can modify data in folders. The correct feature is Controlled folder access, also found under Virus and threat protection, which blocks untrusted applications from writing to protected folders while allowing explicitly approved apps. Exploit protection and reputation-based protection address exploit techniques and app reputation, not per-folder write restrictions.
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a server named Server1 that runs Windows Server. You need to ensure that only specific applications can modify the data in protected folders on Server1. Solution: From App & browser control, you configure the Exploit protection settings. Does this meet the goal?
- Yes
- No
Show answer
B — NoNo, this does not meet the goal. Exploit protection, configured under App and browser control, applies mitigations such as DEP, ASLR, and control flow guard to processes to make them harder to exploit. It does not restrict which applications can modify files in specific folders. The correct solution is Controlled folder access under Virus and threat protection, which protects designated folders and only allows explicitly trusted applications to modify their contents. Reputation-based protection also fails because it only blocks low-reputation apps from running, not writes to folders.
Access plans
| Access | Price |
|---|---|
| 3 months | |
| 1 year | |
| Lifetime |
Free preview inside — try 5 questions before you pay anything.
FAQ
How many practice questions are in this AZ-801 bank?
246 questions covering the current AZ-801 Windows Server Administrator Associate (Advanced Infrastructure) syllabus, every one with the correct answer and an explanation.How long is the real AZ-801 exam?
The official AZ-801 exam gives you 100 minutes. Our timed exam mode uses the same limit so the pace feels familiar.What does AZ-801 access cost?
Plans start at $3.99 for 3 months. One payment, no subscription — and far cheaper than retaking the real exam.