Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium

A security auditor requires that all new Azure Virtual Machines (VMs) deployed within a specific subscription automatically have their OS and data disks encrypted using platform-managed keys by default. The auditor also specifies that if a VM is deployed without encryption, it should be flagged for non-compliance, and ideally, the deployment should be prevented. Which Azure service should the security team use to enforce this requirement?

  1. AAzure Key Vault
  2. BAzure Security Center (now Defender for Cloud)
  3. CAzure Monitor
  4. DAzure Policy
Show answer & explanation

Correct answer: D. Azure Policy

Azure Policy is the correct service for enforcing organizational standards and assessing compliance. It can be used to define rules that require disk encryption on VMs and can audit for non-compliance or even deny deployments that don't meet the encryption standard.

Why the other options are wrong

  • A. Azure Key Vault manages encryption keys and secrets but does not enforce policies for VM deployment or compliance.
  • B. Microsoft Defender for Cloud provides security posture management and threat protection but relies on Azure Policy for enforcement of configuration standards like disk encryption for new deployments.
  • C. Azure Monitor collects and analyzes telemetry but does not enforce resource configuration policies.

Azure Policy for Compliance

Azure Policy is a service in Azure that you use to create, assign, and manage policies that enforce rules and effects over your resources to stay compliant with organizational standards.

  • Enforces organizational standards and assesses compliance.
  • Can audit, deny, or modify resource deployments.
  • Used for governance, security, and cost management.
  • Policies can be applied at subscription or resource group scope.

Memory trick: For rules and compliance, Azure Policy is the governing hand.

More Implement platform protection questions