You must deploy a new Windows Server 2022 VM that will use BitLocker inside the guest and enforce Secure Boot. An existing template is Generation 1. What two configuration changes are required for the VM?
Choose an answer
Tap an option to check your answer.
Correct answer: Create the VM as Generation 2., Add a virtual TPM to the VM..
Why this is the answer
To use BitLocker inside a guest VM and enforce Secure Boot, the VM must be Generation 2. Generation 1 VMs do not support Secure Boot. BitLocker, especially when integrated with Secure Boot for measured boot, requires a Trusted Platform Module (TPM). For virtual machines, this means adding a virtual TPM (vTPM). Disabling Secure Boot would contradict the requirement to enforce it. Dynamic memory is unrelated to vTPM functionality. IDE-attached disks are a legacy option and are not required for measured boot; SCSI or NVMe are preferred for performance and modern features.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed