Your Windows Server 2019 Hyper-V host must enable virtualization-based security (VBS) with Credential Guard and HVCI. The server currently boots in legacy BIOS mode and the firmware does not have IOMMU (VT-d/AMD-Vi) enabled. Attempts to enable VBS report that the system does not meet requirements. What two changes are required before enabling VBS?
Choose an answer
Tap an option to check your answer.
Correct answer: Reinstall or convert the system to boot in UEFI mode and enable Secure Boot., Enable Intel VT-d or AMD-Vi (IOMMU) in firmware..
Why this is the answer
Virtualization-based security (VBS), including Credential Guard and HVCI, requires specific hardware and firmware configurations. UEFI firmware with Secure Boot enabled is mandatory for VBS to function, as it provides a trusted boot path and protects against rootkits. Since the server currently boots in legacy BIOS mode, it must be reinstalled or converted to UEFI and Secure Boot enabled. Additionally, VBS relies on IOMMU (Intel VT-d or AMD-Vi) to protect memory regions from unauthorized access by peripheral devices. The problem states IOMMU is not enabled in the firmware, so this must be corrected. Disabling the Hyper-V hypervisor is incorrect; VBS leverages the hypervisor. Converting VMs to Generation 1 is irrelevant to host VBS requirements. BitLocker is a disk encryption technology and not a prerequisite for VBS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed