Microsoft Azure Administrator Associate AZ-104 Practice Question
As an Azure administrator, you need to ensure that all virtual machine disks are encrypted at rest to comply with your company's security policies. The policies state that encryption keys must be under the company's control and not managed by Microsoft. The virtual machines are already running in Azure.
What should you do to meet these requirements?
Implement BitLocker encryption within each virtual machine and manage the keys locally.
Use Azure Disk Encryption with keys stored in Azure Key Vault using Microsoft-managed keys.
Use Azure Disk Encryption with keys stored in Azure Key Vault backed by a customer-managed HSM.
Enable server-side encryption with platform-managed keys for the storage account.
To meet the requirement of company-controlled encryption keys, you should use Azure Disk Encryption with keys stored in Azure Key Vault backed by a customer-managed Hardware Security Module (HSM). This approach allows the company to maintain full control over the encryption keys while leveraging Azure's disk encryption capabilities. Azure Disk Encryption encrypts the OS and data disks of virtual machines, and integrating it with a customer-managed HSM in Key Vault ensures that the keys are not managed by Microsoft.
Enabling server-side encryption with platform-managed keys means that Microsoft controls the keys, which does not comply with the company's policy. Implementing BitLocker within each VM and managing keys locally is not recommended because it doesn't provide centralized key management and can be less secure. Using Azure Disk Encryption with Microsoft-managed keys also places key control with Microsoft rather than the company, violating the security requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Disk Encryption?
Open an interactive chat with Bash
What is Azure Key Vault?
Open an interactive chat with Bash
What is a customer-managed Hardware Security Module (HSM)?
Open an interactive chat with Bash
Microsoft Azure Administrator Associate AZ-104
Deploy and manage Azure compute resources
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access