When creating a host pool with Windows 11 session hosts, how should you configure the VM security settings to enable secure boot and vTPM?
Choose an answer
Tap an option to check your answer.
Correct answer: Set Security type to Trusted launch virtual machines..
Why this is the answer
To enable secure boot and vTPM for Windows 11 session hosts in Azure Virtual Desktop, you must set the Security type to "Trusted launch virtual machines" during the VM creation process. Trusted launch provides foundational security features like secure boot, vTPM (virtual Trusted Platform Module), and integrity monitoring, which are crucial for enhancing the security posture of your virtual machines, especially for a modern OS like Windows 11. Enabling encryption at rest and a platform-managed key is a data protection measure, not a VM security setting for secure boot or vTPM. Enabling a system-assigned managed identity is for Azure resource authentication, not VM security features. Setting the Network security group to Advanced configures network traffic rules, which is unrelated to secure boot or vTPM.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed