Microsoft Azure Security Engineer Associate AZ-500 Practice Question

Your company has an Azure virtual machine that runs Windows Server 2022 and currently uses Azure Disk Encryption with a customer-managed key. You must ensure that all data written to the VM's host cache and temporary disk is also encrypted at rest. Which action should you perform?

  • Enable encryption at host on the virtual machine without changing the current disk configuration.

  • Replace the customer-managed key in Azure Key Vault with a Microsoft-managed key.

  • Disable Azure Disk Encryption, decrypt all disks, and then enable encryption at host on the virtual machine.

  • Enable Storage Service Encryption with customer-managed keys for each managed disk.

Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot