AZ-802 Manage Virtual Machines Practice Question
You are implementing Shielded Virtual Machines in an on-premises Hyper-V environment to protect sensitive workloads from fabric administrators. Which TWO infrastructure components are required to support the deployment and health validation of Shielded VMs? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Host Guardian Service (HGS)
Shielded VMs provide a high level of security by encrypting the VM's data and state, ensuring that only authorized hosts can run them. This requires a complex infrastructure including attestation and key management. Understanding these components is essential for administrators securing highly sensitive data against unauthorized access by high-privileged users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Host Guardian Service (HGS)
Why this is correct
The Host Guardian Service is a central component that provides attestation and key protection services for Shielded VMs. It validates that a Hyper-V host is healthy and authorized before releasing the keys needed to start or migrate a Shielded VM, effectively acting as the security authority for the fabric.
- ✗
Azure Key Vault
Why it's wrong here
While Azure Key Vault provides similar key management services in the cloud, Shielded VMs on-premises rely on the Host Guardian Service for attestation and key release. Azure Key Vault is not used directly for the health validation or key management of traditional on-premises Hyper-V Shielded VM deployments.
- ✗
Windows Server Update Services (WSUS)
Why it's wrong here
WSUS is used for managing the distribution of updates and patches within a network. Although keeping hosts updated is a security best practice, WSUS is not a functional requirement for the specific architecture of Shielded VMs or the attestation process performed by the Host Guardian Service.
- ✗
Network Controller
Why it's wrong here
The Network Controller is a component of Software Defined Networking (SDN) used to manage network infrastructure centrally. While it can be part of a larger Windows Server Software Defined Datacenter deployment, it does not play a role in the attestation or encryption mechanisms required for Shielded VMs.
- ✓
Guarded Hosts
Why this is correct
Guarded Hosts are physical Hyper-V hosts that have been configured to run Shielded VMs. These hosts must pass an attestation check with the Host Guardian Service to prove they are running authorized software and have a secure configuration before they are permitted to host protected virtual workloads.
About these practice questions
One of 116 original AZ-802 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.