Your subscription contains a VM named VM1 and a key vault named KV1. You must configure encryption for VM1 so that the encryption key is stored and used from KV1, encryption remains intact if VM1 is downloaded from Azure, and both the OS disk and data disks are encrypted. Which encryption method meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Disk Encryption.
Why this is the answer
Azure Disk Encryption (ADE) uses BitLocker for Windows and dm-crypt for Linux to encrypt the OS and data disks of Azure VMs. It integrates with Azure Key Vault to manage and safeguard encryption keys and secrets, ensuring customer-managed keys are used. This method encrypts the disks at rest, meaning the encryption persists even if the VM's VHDs are downloaded from Azure. Customer-managed keys (CMK) is a broader concept that can be used with ADE, but ADE is the specific technology that performs the disk encryption. Confidential disk encryption is a feature of Azure confidential VMs, which is a different, more specialized offering. Encryption at host encrypts data at the host level, but it doesn't provide the same level of key management integration with Key Vault for VM disks, nor does it ensure encryption persists if the VHD is downloaded.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed