Microsoft AZ-801: Hyper-V, Virtualization and Storage — Study Guide

Part of the Microsoft Windows Server Hybrid Administrator Associate AZ-801 — Study Guide. Practice with verified answers in the Microsoft exam hub, or take timed practice tests on ExamRoll.io.

Overview

Hyper‑V and Windows Server software‑defined storage form a cohesive platform for secure, isolated, and highly available workloads. Mastery requires understanding how guarded fabrics protect tenant VMs from fabric administrators, how Virtualization‑Based Security (VBS) hardens the OS with hardware‑rooted isolation, how Hyper‑V networking enforces isolation, and how replication, checkpoints, and clustering behave under load and failure. This section explains the security model for shielded VMs and host hardening, dives into network isolation constructs, covers durability via Hyper‑V Replica and checkpoint mechanics, and finishes with Storage Spaces Direct (S2D), Cluster Shared Volumes (CSV), and quorum design in Failover Clustering.

Secure virtualization and workload protection

Shielded VMs protect tenant assets from fabric access. Host Guardian Service (HGS) operates as the trust anchor, delivering two services: attestation (validates host health) and key protection (releases keys to unlock the VM’s virtual TPM). HGS is deployed in a dedicated, locked‑down forest or domain to minimize compromise risk. Two attestation modes exist:

Fabric and tenant roles are deliberately separated. Fabric administrators manage hosts, clusters, storage, and networking but are prevented from inspecting shielded VM disks, attaching debuggers, or using console/PowerShell Direct. Tenant administrators build the VM, own OS credentials, and create shielding data (a sealed package containing an unattend answer file, RDP certificate, and guardian keys) to control where the VM may run. Shielded VMs use BitLocker inside the guest, anchored in a vTPM, and only guarded hosts attested by HGS receive the secrets needed to boot.

Virtualization‑Based Security (VBS) raises the security boundary above the kernel by creating Virtual Secure Mode (VSM). With VBS, the hypervisor enforces Virtual Trust Levels (VTLs), isolating sensitive components in VTL1 alongside a secure kernel. Features include:

Hyper‑V network isolation, replication, and checkpoints

Hyper‑V virtual switches enforce Layer‑2/L3 isolation:

Hyper‑V Replica provides asynchronous per‑VM replication with no shared storage requirement. A server is the primary (sending change logs) and another is the replica (receiving AVHDX‑based deltas). Replication intervals are 30 seconds, 5 minutes, or 15 minutes. Authentication options:

Checkpoints capture a point‑in‑time state for recovery and dev/test. Standard checkpoints save VM memory and device state, enabling instant rollbacks but potentially disrupting app consistency. Production checkpoints use in‑guest VSS (Windows) or file system flush (Linux) to create an application‑consistent image without memory state; they are appropriate for backup workflows and long‑lived restore points. Storage is implemented as AVHDX differencing disks chained to the base VHDX. Applying or deleting a checkpoint merges the differencing chain back into its parent online; large merges create I/O pressure, so maintain adequate headroom and avoid deep trees. For domain controllers and distributed apps, production checkpoints mitigate USN rollback and related issues; standard checkpoints are best confined to short‑lived dev/test work.

Host capabilities, nested virtualization, and VM generation security

Generation 2 VMs boot via UEFI, supporting Secure Boot and vTPM. Secure Boot verifies bootloaders against a trusted database (use the Windows or appropriate Linux template). vTPM brings TPM 2.0 semantics to the guest, enabling BitLocker, Windows Hello for Business provisioning, and shielded VM scenarios. Where older guests require BIOS or legacy devices, Generation 1 VMs remain available but lack Secure Boot and vTPM.

Nested virtualization enables Hyper‑V inside a VM. Requirements include a compatible CPU (Intel VT‑x/EPT or AMD‑V/NPT), Windows Server 2016 or later on host and guest, and a VM configured with:

Software‑defined storage, CSV behavior, and quorum

Storage Spaces Direct aggregates locally attached drives into a cluster‑wide pool using SMB3, RDMA, and the clustering stack. Cluster requirements include Windows Server Datacenter edition, domain‑joined nodes with homogeneous NICs, high‑bandwidth low‑latency networking (10/25/40 GbE; RDMA via iWARP or RoCEv2 recommended), and validated hardware. Fault domains can represent nodes, chassis, and racks; configuring them improves placement and repair behavior and mitigates correlated failures. Resiliency types include:

Cluster Shared Volumes (CSV) expose a consistent namespace (C:\ClusterStorage...) to all nodes, enabling concurrent access to NTFS/ReFS volumes via CSVFS. Normal operations use direct I/O, where metadata coordination occurs over SMB, but reads/writes hit storage paths directly. Redirected I/O engages under certain conditions—maintenance, storage path failure, snapshot/backup operations, or when a volume is paused. Two redirected modes exist:

Failover Cluster quorum determines cluster liveness. Modes include:

Practical Problem Scenario

At Siemens, the OT/IT team needs to modernize a small edge site hosting three Windows Server VMs that run manufacturing telemetry. They must isolate traffic between OT and corporate networks, protect credentials on the hosts, and achieve site‑level resiliency without shared storage.

  1. Build a two‑node Hyper‑V failover cluster with Storage Spaces Direct
  1. Enable VBS with Credential Guard and HVCI on both hosts
  1. Use Generation 2 VMs with Secure Boot and vTPM
  1. Create an external Hyper‑V switch for each physical uplink and segment with VLANs and Port ACLs
  1. Configure Hyper‑V Replica from the edge site to a central datacenter replica server over HTTPS
  1. Standardize on production checkpoints only
  1. Enable CSV cache with conservative sizing

This design uses S2D for high availability, VBS/vTPM/Secure Boot for hardened trust, VLANs and Port ACLs for deterministic isolation, and Hyper‑V Replica for site resiliency—balancing security, performance, and operability in a resource‑limited edge footprint.


Windows Server Update and Patch Management · All domains · Disaster Recovery and Business Continuity

Practice these questions → · Timed practice on ExamRoll.io →

Pass the whole exam — not just this question

You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.

Pass your exam →

Browse Microsoft →

Related guides

All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product