Correct, on CAPSULE bios files and other OEM securities.
Preventing this only working with extracted Intel Image or Bios region (UEFI tool) from the original bios update or spi dump of the system.
This happens more frequently on AMI V core bioses, less in AMI IV based.
EDIT:
The bios is an AMI IV core, use UEFItool_NA for extraction, UEFItool 0.25/0.28 for replacing.
Keep an eye on structure changes and/or missing pads when performing these operations.
A little more guidance here, [GUIDE] NVMe on UEFI bios lacking space volume
EDIT: The file D2939-B1.UPD doesn’t have any CAPSULE, use MMtool v4.x, not v5