Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You deploy an Azure virtual machine that uses Premium SSD managed OS and data disks. Security policy requires that every write to the OS disk, data disks, the VM's temporary disk, and the host cache be encrypted at rest with your own customer-managed key (CMK) stored in Azure Key Vault. You must meet the requirement without installing any additional agents inside the guest operating system and with the least possible performance overhead.
Which disk-level encryption option should you enable for the virtual machine?
Encryption at host with a customer-managed key
Azure Disk Encryption (BitLocker or dm-crypt) on each managed disk
Default server-side encryption with Microsoft-managed keys
Encryption at host encrypts all data at rest on the host machine, including the OS disk, data disks, the VM's temporary disk, and any data stored in the host cache. It can be used in combination with customer-managed keys stored in Azure Key Vault and does not rely on an agent inside the guest OS, so there is no guest-level performance impact.
Azure Disk Encryption uses BitLocker or dm-crypt inside the guest; it does not cover the host cache or the temporary disk and requires an agent. Server-side encryption with Microsoft-managed keys is enabled by default but uses platform keys, not a CMK. Confidential disk encryption is limited to confidential VMs and still relies on guest components. Therefore, enabling encryption at host with a customer-managed key is the correct choice.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is 'Encryption at Host' in Azure?
Open an interactive chat with Bash
What is the role of Azure Key Vault with customer-managed keys?
Open an interactive chat with Bash
What's the difference between Azure Disk Encryption and Encryption at Host?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .