To meet compliance requiring encryption on every deployed VM, which Azure feature should enforce this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Policy.
Why this is the answer
Azure Policy is the correct choice because it allows you to define and enforce organizational standards and compliance at scale. You can create a policy definition that requires encryption on all virtual machines, and then assign this policy to a scope (e.g., a subscription or resource group). Any new or existing VM that doesn't meet this encryption requirement will be flagged as non-compliant, and you can even configure policies to automatically remediate or deny non-compliant deployments. Azure Key Vault is used for securely storing and managing cryptographic keys, but it doesn't enforce policies. Azure Advisor provides recommendations for best practices, but it doesn't enforce compliance. Azure Resource Graph is a service for exploring and querying Azure resources, not for enforcing policies.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed