SC-100 Practice Question 3972
Exam: SC-100
Domain: Design security solutions for infrastructure
Difficulty: easy
When designing security for virtual machines, you need to ensure that booting into unauthorized or tampered bootloader software is blocked at the hardware virtualization layer. Which VM configuration must you mandate?
Answer Options
A
Azure Generation 2 VMs with Trusted Launch (Secure Boot and vTPM)
B
Generation 1 VMs with standard legacy BIOS
C
Disabling all antivirus scanning on the virtual machine
D
Running virtual machines on unmanaged consumer laptops
Correct Answer
A: Azure Generation 2 VMs with Trusted Launch (Secure Boot and vTPM)
Explanation
Azure Generation 2 Virtual Machines with Trusted Launch enabled enforce Secure Boot and vTPM (virtual Trusted Platform Module) to protect against rootkits and bootkits.