nerdexam
Microsoft

74-409 · Question #60

A company has a highly-secure network infrastructure environment. All servers in the environment run Windows Server 2012 R2. You must create a new virtual machine (VM) that meets the following…

The correct answer is D. Create a Generation 2 VM with the default settings. Secure Boot is a feature that helps prevent unauthorized firmware, operating systems, or UEFI drivers (also known as option ROMs) from running at boot time. Secure Boot is enabled by default for generation 2 virtual machines. This can be modified after the virtual machine has…

Virtual Machine Settings

Question

A company has a highly-secure network infrastructure environment. All servers in the environment run Windows Server 2012 R2. You must create a new virtual machine (VM) that meets the following requirements: - The VM must minimize the risk that unauthorized firmware will run when the VM starts. - The VM must load the operating system only if all operating system files have a valid signature. You need to create the new VM. What should you do?

Options

  • ACreate a Generation 2 VM and disable Secure Boot.
  • BCreate a Generation 1 VM and use a synthetic network adapter.
  • CCreate a Generation 1 VM and enable Secure Boot.
  • DCreate a Generation 2 VM with the default settings.

How the community answered

(34 responses)
  • A
    9% (3)
  • B
    18% (6)
  • C
    3% (1)
  • D
    71% (24)

Explanation

Secure Boot is a feature that helps prevent unauthorized firmware, operating systems, or UEFI drivers (also known as option ROMs) from running at boot time. Secure Boot is enabled by default for generation 2 virtual machines. This can be modified after the virtual machine has been created.

Topics

#Secure Boot#Generation 2 VM#UEFI#firmware security

Community Discussion

No community discussion yet for this question.

Full 74-409 Practice