StudyToCert

All certifications / SC-500 / Lessons

Microsoft Certified: Cloud and AI Security Engineer Associate (replaces Azure Security Engineer Associate / AZ-500) SC-500 · Domain 3: Secure compute

Trusted launch: secure boot, vTPM and boot integrity monitoring

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Some of the most dangerous malware runs before the operating system even starts. Bootkits and rootkits tamper with the boot loader or kernel so they load first, hide from antivirus and survive reinstalls of applications. Trusted launch is an Azure security type for Generation 2 virtual machines that defends against these attacks with three features working together. It is the default security type for new Gen2 VMs in most scenarios, and it has no extra cost.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-500 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-500 study plan