SC-100 Practice Question 3972

Exam: SC-100
Domain: Design security solutions for infrastructure
Difficulty: easy
When designing security for virtual machines, you need to ensure that booting into unauthorized or tampered bootloader software is blocked at the hardware virtualization layer. Which VM configuration must you mandate?

Answer Options

A
Azure Generation 2 VMs with Trusted Launch (Secure Boot and vTPM)
B
Generation 1 VMs with standard legacy BIOS
C
Disabling all antivirus scanning on the virtual machine
D
Running virtual machines on unmanaged consumer laptops

Correct Answer

A: Azure Generation 2 VMs with Trusted Launch (Secure Boot and vTPM)

Explanation

Azure Generation 2 Virtual Machines with Trusted Launch enabled enforce Secure Boot and vTPM (virtual Trusted Platform Module) to protect against rootkits and bootkits.