Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You deploy an Azure virtual machine that uses Premium SSD managed OS and data disks. Security policy requires that every write to the OS disk, data disks, the VM's temporary disk, and the host cache be encrypted at rest with your own customer-managed key (CMK) stored in Azure Key Vault. You must meet the requirement without installing any additional agents inside the guest operating system and with the least possible performance overhead.

Which disk-level encryption option should you enable for the virtual machine?

  • Encryption at host with a customer-managed key

  • Azure Disk Encryption (BitLocker or dm-crypt) on each managed disk

  • Default server-side encryption with Microsoft-managed keys

  • Confidential disk encryption

Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot