Courseiva
Manage Virtual MachineshardMultiple SelectObjective-mapped

AZ-802 Manage Virtual Machines Practice Question

You are implementing Shielded Virtual Machines in an on-premises Hyper-V environment to protect sensitive workloads from fabric administrators. Which TWO infrastructure components are required to support the deployment and health validation of Shielded VMs? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Host Guardian Service (HGS)

Shielded VMs provide a high level of security by encrypting the VM's data and state, ensuring that only authorized hosts can run them. This requires a complex infrastructure including attestation and key management. Understanding these components is essential for administrators securing highly sensitive data against unauthorized access by high-privileged users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Host Guardian Service (HGS)

    Why this is correct

    The Host Guardian Service is a central component that provides attestation and key protection services for Shielded VMs. It validates that a Hyper-V host is healthy and authorized before releasing the keys needed to start or migrate a Shielded VM, effectively acting as the security authority for the fabric.

  • Azure Key Vault

    Why it's wrong here

    While Azure Key Vault provides similar key management services in the cloud, Shielded VMs on-premises rely on the Host Guardian Service for attestation and key release. Azure Key Vault is not used directly for the health validation or key management of traditional on-premises Hyper-V Shielded VM deployments.

  • Windows Server Update Services (WSUS)

    Why it's wrong here

    WSUS is used for managing the distribution of updates and patches within a network. Although keeping hosts updated is a security best practice, WSUS is not a functional requirement for the specific architecture of Shielded VMs or the attestation process performed by the Host Guardian Service.

  • Network Controller

    Why it's wrong here

    The Network Controller is a component of Software Defined Networking (SDN) used to manage network infrastructure centrally. While it can be part of a larger Windows Server Software Defined Datacenter deployment, it does not play a role in the attestation or encryption mechanisms required for Shielded VMs.

  • Guarded Hosts

    Why this is correct

    Guarded Hosts are physical Hyper-V hosts that have been configured to run Shielded VMs. These hosts must pass an attestation check with the Host Guardian Service to prove they are running authorized software and have a secure configuration before they are permitted to host protected virtual workloads.

About these practice questions

One of 116 original AZ-802 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.