Compliance requires BitLocker encryption of the OS and data disks for all Azure Virtual Desktop session hosts. Encryption keys must be stored in Azure Key Vault with purge protection. You need to implement this for an existing host pool without redeploying the VMs. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Azure Disk Encryption on each VM using the Azure Disk Encryption VM extension and specify a Key Vault that has soft-delete and purge protection enabled..
Why this is the answer
Azure Disk Encryption (ADE) is the correct solution for encrypting existing OS and data disks on Azure VMs, including those in a host pool, without redeploying them. ADE uses the Azure Disk Encryption VM extension to integrate with BitLocker for Windows VMs, ensuring the encryption keys are stored in the specified Azure Key Vault. The Key Vault must have soft-delete and purge protection enabled to meet the compliance requirement for key security. Creating a Disk Encryption Set (DES) with a customer-managed key is for encrypting new disks or re-encrypting existing disks by creating new ones, which is not suitable for an existing host pool without redeployment. Server-side encryption with platform-managed keys encrypts data at rest but doesn't use BitLocker inside the guest OS and doesn't allow for customer-managed keys in Key Vault. Windows LAPS manages local administrator passwords, not disk encryption keys.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed