AZ-802 Secure Windows Server Infrastructure Practice Question
You are planning the deployment of Shielded Virtual Machines in a Windows Server 2022 environment. You need to ensure that the Fabric Administrators cannot access the data within the VMs. Which component of the Host Guardian Service (HGS) is responsible for verifying that a Hyper-V host is authorized to run a Shielded VM?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Attestation Service
The Host Guardian Service (HGS) is the central authority for Shielded VMs. The Attestation Service within HGS evaluates the health and identity of the Hyper-V host. If the host passes attestation, the HGS Key Protection Service then provides the keys necessary to start or migrate the Shielded VM, ensuring it only runs on trusted hardware.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Key Protection Service
Why it's wrong here
The Key Protection Service is responsible for releasing the transport keys required to unlock and run a Shielded VM. However, it only does so after the Attestation Service has successfully verified the host's health. While critical, it is the secondary step in the process, relying on the result of the attestation check.
- ✓
The Attestation Service
Why this is correct
The Attestation Service is the component that validates the Hyper-V host's identity and configuration. It ensures that the host is running approved code and has not been tampered with. Only after a host successfully completes this attestation process is it considered 'healthy' and allowed to receive the keys to run Shielded VMs.
- ✗
The Virtualization-based Security (VBS) engine
Why it's wrong here
Virtualization-based Security is a technology used on the Hyper-V host itself to protect sensitive processes, but it is not a component of the Host Guardian Service. VBS provides the environment for the secure kernel and Credential Guard, whereas HGS is the external service that manages the trust and keys for the fabric.
- ✗
The TPM 2.0 Emulator
Why it's wrong here
A virtual TPM (vTPM) is used within a Shielded VM to provide cryptographic capabilities to the guest OS, such as BitLocker. While it is a requirement for Shielded VMs to operate securely, it is not a component of the HGS nor is it responsible for verifying the authorization of the Hyper-V host.
About these practice questions
Courseiva writes every AZ-802 question from scratch — 116 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.