|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/ms_az_801/
课程评论:没有评论
**Course Title:** Microsoft Windows Server (AZ-801) Exam Questions Jun-2025 **Course Summary:** This course prepares individuals for the AZ-801 exam, focusing on the essential skills for managing and securing Windows Server environments in both on-premises and hybrid infrastructures. The curriculum covers a broad range of topics, including: * **Security:** Implementing and managing Windows Server operating system security, including Exploit Protection, Application Control, Credential Guard, SmartScreen, Group Policies, security baselines, the Local Administrator Password Solution, and hardening domain controllers. It also delves into securing hybrid Active Directory, password policies, Microsoft Entra Password Protection, protected users, RODC account security, authentication policy silos, and access restrictions to domain controllers. Furthermore, it covers integrating with Azure services like Microsoft Sentinel and Microsoft Defender for Cloud, securing Windows Server networking with Defender Firewall and NSGs, and managing storage encryption with BitLocker and Azure Disk Encryption. * **High Availability:** Implementing and managing Windows Server failover clusters, including on-premises, hybrid, and cloud-only deployments, workgroup clusters, and stretch clusters with Storage Spaces Direct (S2D). It also covers cluster quorum, network adapters, Network ATC, Scale-Out File Servers, Azure witnesses, floating IP addresses, cluster-aware updating, node recovery, and cluster management using Windows Admin Center. * **Disaster Recovery:** Managing backup and recovery solutions for Windows Server, including Azure Recovery Services Vault and Azure Backup Server for file/folder and VM backups. It also covers implementing disaster recovery using Azure Site Recovery for on-premises and Azure VMs, configuring replication policies, Hyper-V replicas, and recovery plans. * **Server and Workload Migration:** Migrating on-premises storage to servers or Azure using Storage Migration Service (SMS), migrating to Azure VMs using Azure Migrate, and migrating various server roles and workloads such as IIS, Hyper-V hosts, Remote Desktop Services, DHCP, print servers, and Active Directory. This includes in-place upgrades and migrating Active Directory forests. * **Monitoring and Troubleshooting:** Utilizing Windows Server and Azure tools for monitoring, including Performance Monitor, Data Collector Sets, Windows Admin Center, System Insights, and Azure Monitor. It addresses troubleshooting common Windows Server issues such as connectivity, name resolution, Windows Update, Time Service, deployment and booting failures, performance problems, VM and Azure Arc extensions, disk encryption, storage, Active Directory replication, and hybrid authentication. It also covers AD object recovery and AD database restoration.
Skills at a glanceSecure Windows Server on-premises and hybrid infrastructures (25-30%)Implement and manage Windows Server high availability (15-20%)Implement disaster recovery (10-15%)Migrate servers and workloads (20-25%)Monitor and troubleshoot Windows Server environments (15-20%)Secure Windows Server on-premises and hybrid infrastructures (25-30%)Secure Windows Server operating systemConfigure and manage Exploit ProtectionConfigure and manage Windows Defender Application ControlConfigure and manage Windows Defender Credential GuardConfigure SmartScreenImplement operating system security by using Group PoliciesManage Windows Server security baseline by using OSConfigImplement Windows Local Administrator Password SolutionSecure a hybrid Active Directory infrastructureConfigure password policiesImplement Microsoft Entra Password Protection for AD DSManage protected usersManage account security on a Read-Only Domain controller (RODC)Harden domain controllersConfigure authentication policy silosRestrict access to domain controllersConfigure security options for user accountsConfigure security options for built-in administrative groupsManage AD delegationImplement and manage Microsoft Defender for IdentityAudit usage of and disable NTLMIdentify and remediate Windows Server security issues by using Azure servicesImplement ingestion of Windows Server data into Microsoft SentinelManage security for Windows Server by using Microsoft Defender for CloudManage security for Windows Server by using Microsoft Defender for ServersSecure Windows Server networkingManage Windows Defender FirewallImplement domain isolationImplement connection security rulesCreate and configure network security groups (NSGs) for Windows Server virtual machines on AzureSecure Windows Server storageManage Windows BitLocker Drive EncryptionEnable storage encryption by using Azure Disk EncryptionManage and recover encrypted volumesManage disk encryption keys for IaaS virtual machinesImplement and manage Windows Server high availability (15-20%)Implement a Windows Server failover clusterImplement a failover cluster on-premises, hybrid, or cloud-onlyCreate a Windows failover cluster, including workgroup clustersImplement a stretch cluster across datacenters or Azure regions, including Storage Spaces Direct (S2D) campus clustersConfigure storage for failover clusteringModify quorum optionsConfigure network adapters for failover clusteringDeploy host networking with Network ATCConfigure cluster workload optionsConfigure Scale-Out File serversConfigure an Azure witnessConfigure a floating IP address for the clusterManage failover clusteringImplement cluster-aware updatingRecover a failed cluster nodeUpgrade failover cluster nodesFailover workloads between nodesInstall Windows updates on cluster nodesManage failover clusters using Windows Admin CenterImplement and manage Storage Spaces DirectUpgrade an S2D nodeImplement networking for S2DConfigure S2DImplement disaster recovery (10-15%)Manage backup and recovery for Windows ServerBack up and restore files and folders to Azure Recovery Services VaultDeploy and manage Azure Backup ServerBack up and recover using Azure Backup ServerManage backups in Azure Recovery Services VaultCreate an Azure Recovery Services vault backup policyConfigure backup for Azure VM using the built-in backup agentRecover a VM using instant recovery snapshotsRecover VMs to new Azure VMsRestore a VM, including encrypted VMsImplement disaster recovery by using Azure Site RecoveryConfigure Azure Site Recovery network mappingConfigure Site Recovery for on-premises serversConfigure a recovery plan in Azure Site RecoveryConfigure Site Recovery for Azure VMsImplement VM replication to secondary datacenter or Azure regionConfigure Azure Site Recovery replication policiesProtect virtual machines by using Hyper-V replicasConfigure Hyper-V hosts for replicationManage Hyper-V replica serversConfigure VM replicationPerform a failoverMigrate servers and workloads (20-25%)Migrate on-premises storage to on-premises servers or AzureTransfer files, file shares, and security configurations by using Storage Migration Service (SMS)Cut over to a new server by using Storage Migration Service (SMS)Use Storage Migration Service to migrate to Azure VMsMigrate to Azure file sharesMigrate on-premises servers by using Azure MigrateDeploy and configure Azure Migrate applianceMigrate VM workloads to Azure VMsMigrate physical servers to Azure VMsMigrate workloads from previous Windows Server versions to the most current versionChoose an appropriate migration methodMigrate IIS workloads and configurationsMigrate Hyper-V hostsMigrate Remote Desktop Services (RDS) host serversMigrate Dynamic Host Configuration Protocol (DHCP) serversMigrate print serversMigrate by using an in-place upgradeMigrate IIS workloads to AzureAssess IIS workloads by using Azure MigrateMigrate IIS workloads to Azure Web AppsMigrate IIS workloads to containersMigrate an on-premises AD forest to Windows Server 2025Choose an appropriate migration methodImplement a forest restructureMigrate AD DS objects, including users, groups and Group Policies using AD Migration ToolMigrate to a new Active Directory forestUpgrade an existing forest, including setting functional levelsMonitor and troubleshoot Windows Server environments (15-20%)Monitor Windows Server by using Windows Server tools and Azure servicesMonitor Windows Server by using Performance MonitorCreate and configure Data Collector SetsMonitor servers and configure alerts by using Windows Admin CenterAnalyze Windows Server system data by using System InsightsManage event logsConfigure data collection rules for Azure MonitorCreate alertsMonitor Azure VM performance by using VM InsightsTroubleshoot Windows Server issuesTroubleshoot connectivityTroubleshoot name resolutionTroubleshoot Windows UpdateTroubleshoot Time ServiceTroubleshoot deployment failuresTroubleshoot booting failuresTroubleshoot performance issuesTroubleshoot VM and Azure Arc extension issuesTroubleshoot disk encryption issuesTroubleshoot storageTroubleshoot Active DirectoryRestore objects from AD recycle binRecover Active Directory database using Directory Services Restore modeRecover system volume (SYSVOL)Troubleshoot Active Directory replicationTroubleshoot hybrid authentication and synchronization issuesTroubleshoot on-premises Active Directory