You have an Azure VM named VM1 and an Azure Key Vault named Vault1. You plan to enable Azure Disk Encryption on VM1 using a key encryption key (KEK). What two actions must you perform on Vault1 to prepare it for Azure Disk Encryption?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new key., Select Azure Disk Encryption for volume encryption..
Why this is the answer
To enable Azure Disk Encryption with a KEK, you must first create the KEK within the Key Vault. This key will be used to encrypt the disk encryption keys. Additionally, you need to grant Azure Disk Encryption permission to access the Key Vault. This is done by enabling the "Azure Disk Encryption for volume encryption" access policy on the Key Vault, which allows the Azure Disk Encryption service to retrieve the KEK for encryption operations. Selecting "Azure Virtual machines for deployment" is for enabling Key Vault access for VM deployment, not disk encryption. Creating a new secret is for storing sensitive data, not for KEKs. Configuring a key rotation policy is a best practice but not a prerequisite for initial setup.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed