Which tool can a security compliance team use to automatically report all resources that are missing encryption at rest?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Policy.
Why this is the answer
Azure Policy is the correct choice because it allows you to define and enforce organizational standards and assess compliance at scale. You can create a policy definition that identifies resources not meeting specific encryption requirements, and then assign that policy to a scope (like a subscription or resource group). Azure Policy will then automatically report on non-compliant resources, including those missing encryption at rest. Azure Monitor is for collecting, analyzing, and acting on telemetry data, not for enforcing compliance policies. Azure Resource Graph is a service for exploring and querying your Azure resources at scale, useful for discovery but not for automatic compliance reporting and enforcement. Azure Defender (now part of Microsoft Defender for Cloud) provides threat protection and security posture management, but its primary function isn't to report on policy compliance for encryption at rest in the way Azure Policy does.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed