You created an Azure Key Vault named Vault5 (West US, resource group RG1). You must use Vault5 to enable Azure Disk Encryption on VM1 and ensure the VM can be backed up using Azure Backup. Which Key Vault setting should you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: Access policies.
Why this is the answer
To enable Azure Disk Encryption and ensure Azure Backup compatibility, you need to configure Access policies in Azure Key Vault. Specifically, you must grant the Azure Disk Encryption service principal and the Azure Backup service principal the necessary permissions (e.g., Get, Set, Delete for keys and secrets, and Wrap Key, Unwrap Key for keys). Secrets and Keys are objects stored within the Key Vault, not configuration settings for its behavior. Locks prevent accidental deletion or modification of the Key Vault itself, but do not grant permissions for services to interact with its contents.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed