Microsoft Certified: Azure Administrator AssociateMonitor and maintain Azure resourcesHard

A company requires all Azure Virtual Machines (VMs) to have their operating system disks encrypted at rest. They are using Azure Backup to protect these VMs. To ensure that the restored VMs also have their OS disks encrypted, what additional component must be backed up along with the VM?

  1. AThe virtual network configuration
  2. BThe Resource Group containing the VM
  3. CThe associated Network Security Groups (NSGs)
  4. DThe Azure Key Vault that stores the encryption keys
Show answer & explanation

Correct answer: D. The Azure Key Vault that stores the encryption keys

When Azure VMs are encrypted using Azure Disk Encryption (ADE), the encryption keys are stored in an Azure Key Vault. For a successful restore of an encrypted VM, Azure Backup needs access to these encryption keys. Therefore, ensuring the Azure Key Vault is accessible and its keys are available is crucial for restoring encrypted VMs.

Why the other options are wrong

  • A. Virtual network configuration is important for network connectivity after restore, but not for the decryption of encrypted disks.
  • B. While the Resource Group contains the VM, backing up the Resource Group itself doesn't directly ensure the availability of encryption keys for ADE.
  • C. NSGs are network-related and not directly involved in disk encryption or the restoration of encrypted disks.

Azure Disk Encryption (ADE) and Backup

For backing up and restoring Azure VMs with Azure Disk Encryption enabled, the associated encryption keys stored in Azure Key Vault must also be managed and accessible.

  • ADE uses Azure Key Vault for encryption keys.
  • Key Vault access is critical for encrypted VM restore.
  • Backup ensures data integrity; Key Vault ensures decryption capability.

Memory trick: To unlock your restored VM data, remember where the key is kept.

More Monitor and maintain Azure resources questions