On VM1 (Windows Server) you plan to use Azure Disk Encryption to protect the VM's disks. Which prerequisite is required before enabling Azure Disk Encryption?
Choose an answer
Tap an option to check your answer.
Correct answer: an Azure key vault.
Why this is the answer
Azure Disk Encryption (ADE) uses Azure Key Vault to store and manage the encryption keys and secrets. This secure storage is essential because ADE encrypts the OS and data disks of Azure virtual machines using industry-standard BitLocker for Windows and DM-Crypt for Linux. Without an Azure Key Vault, there's no secure location to store the encryption keys, making it impossible to enable ADE. Customer Lockbox for Microsoft Azure is a service for requesting access to your data by Microsoft personnel, not a prerequisite for disk encryption. A BitLocker recovery key is generated during the encryption process, not a prerequisite for enabling it. Data-link layer encryption in Azure is a network security feature and unrelated to disk encryption.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed