You have an Azure virtual machine named VM1 and plan to encrypt it using Azure Disk Encryption. Which Azure resource must you create first?
Choose an answer
Tap an option to check your answer.
Correct answer: an Azure Key Vault.
Why this is the answer
Azure Disk Encryption (ADE) uses Azure Key Vault to store and manage the encryption keys and secrets used to encrypt your virtual machine disks. Therefore, an Azure Key Vault must be created before you can enable ADE for VM1. While an Azure Storage account is used by the VM for its disks, it's not the first resource you create specifically for encryption. An Azure Information Protection policy is for data classification and protection, not VM disk encryption. An encryption key itself is stored within the Key Vault, so the Key Vault is the prerequisite.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed