Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionEasy

A company is deploying a new set of Azure Virtual Machines that will host critical business applications. The security policy dictates that these VMs must have their operating system and data disks encrypted at rest to protect against unauthorized access to data, even if the underlying storage is compromised. The company also needs to manage the encryption keys centrally. Which Azure service combination provides disk encryption and central key management for these VMs?

  1. AAzure Backup and Azure Monitor
  2. BAzure Storage Service Encryption and Azure Active Directory
  3. CAzure Security Center (Defender for Cloud) and Azure Policy
  4. DAzure Disk Encryption and Azure Key Vault
Show answer & explanation

Correct answer: D. Azure Disk Encryption and Azure Key Vault

Azure Disk Encryption (ADE) uses industry-standard BitLocker for Windows and DM-Crypt for Linux to encrypt the OS and data disks of Azure VMs. It integrates with Azure Key Vault to manage and control the encryption keys and secrets, providing centralized key management.

Why the other options are wrong

  • A. Azure Backup is for data recovery, and Azure Monitor is for telemetry; neither provides disk encryption or key management.
  • B. Storage Service Encryption encrypts data at rest in storage accounts, but ADE is specifically for VM disks. AAD is for identity, not key management for ADE.
  • C. Defender for Cloud provides security posture management and threat protection, and Azure Policy enforces standards, but neither directly performs disk encryption and key management for VMs.

Azure Disk Encryption (ADE)

A capability that helps encrypt the OS and data disks used by Azure Virtual Machines. It uses industry-standard encryption technology and integrates with Azure Key Vault to manage encryption keys.

  • Encrypts both OS and data disks.
  • Uses BitLocker (Windows) and DM-Crypt (Linux).
  • Key management is handled by Azure Key Vault.

Memory trick: ADE makes sure your disks are locked, and Key Vault holds the key.

More Implement platform protection questions