Microsoft Azure Fundamentals (AZ-900)Describe Azure architecture and servicesHard

An organization is evaluating Azure for its compliance needs. They need to ensure that all data stored in Azure Blob Storage is encrypted at rest by default, without requiring any additional configuration by developers or administrators. Which Azure feature ensures this baseline level of encryption for Blob Storage?

  1. AAzure Disk Encryption
  2. BClient-side encryption
  3. CAzure Storage Service Encryption (SSE)
  4. DAzure Key Vault
Show answer & explanation

Correct answer: C. Azure Storage Service Encryption (SSE)

Azure Storage Service Encryption (SSE) for data at rest is enabled for all new and existing storage accounts and cannot be disabled. It automatically encrypts all data stored in Azure Blob Storage using Microsoft-managed keys by default, fulfilling the requirement of encryption at rest without additional configuration.

Why the other options are wrong

  • A. Azure Disk Encryption is for VMs, not Blob Storage.
  • B. Client-side encryption requires developer implementation and is not a default, automatic Azure service feature for data at rest.
  • D. Azure Key Vault is for managing encryption keys, but SSE is the underlying service that performs the encryption by default.

Azure Storage Service Encryption (SSE)

Azure Storage Service Encryption (SSE) automatically encrypts data at rest when it's written to Azure Storage, including Blob Storage.

  • Enabled by default for all Azure Storage accounts.
  • Encrypts data at rest using 256-bit AES encryption.
  • Can use Microsoft-managed keys or customer-managed keys (CMK) via Key Vault.

Memory trick: SSE is like an invisible, always-on security guard for your storage, locking everything up automatically.

More Describe Azure architecture and services questions