A hosting provider runs Windows Server 2022 Hyper-V hosts in a fabric domain. Some hosts lack TPM 2.0. A tenant requires shielded VMs so that fabric administrators cannot inspect the VMs’ disks or memory. You need to allow deployment of shielded VMs to all hosts, including those without TPM, while ensuring the tenant retains control of the keys protecting the VMs. What should you do? (Choose two)
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy Host Guardian Service (HGS) in Admin-trusted attestation mode and approve guarded hosts via an Active Directory security group., Have the tenant generate and sign a shielding data file using their owner guardian certificate and provide it for VM creation..
Why this is the answer
The correct options are deploying HGS in Admin-trusted attestation mode and having the tenant generate a shielding data file. Admin-trusted attestation allows guarded hosts without TPM 2.0 to be approved, meeting the requirement to support all hosts. This mode relies on Active Directory membership for host authorization. The tenant must generate and sign a shielding data file using their owner guardian certificate. This file contains the necessary key protectors and ensures the tenant retains control over the VM's encryption keys, preventing fabric administrators from accessing the VM's contents. TPM-trusted attestation (incorrect) requires TPM 2.0 on all hosts, which is not available in this scenario. Exporting the tenant's key protector private key (incorrect) would compromise the tenant's control and defeat the purpose of shielded VMs. Storing vTPM state files on the host (incorrect) is not relevant to the attestation method or key control.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed