Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionHard
A company is deploying a new set of Azure Virtual Machines that will host critical business applications. These VMs will store sensitive customer data on their data disks. The company's compliance policy mandates that all data at rest, including OS and data disks, must be encrypted using customer-managed keys (CMK) stored in Azure Key Vault. Which Azure encryption solution should be implemented to meet this requirement?
- AStorage Service Encryption for Data at Rest
- BEncryption at host
- CAzure Disk Encryption (ADE)
- DServer-Side Encryption (SSE) with Platform-Managed Keys
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Disk Encryption (ADE)
Azure Disk Encryption (ADE) is the solution that encrypts OS and data disks for Azure IaaS VMs. When combined with Azure Key Vault, it allows for the use of customer-managed keys (CMK) for encryption, directly addressing the requirement for CMK for both OS and data disks.
Why the other options are wrong
- A. Storage Service Encryption (SSE) is for storage accounts, not directly for VM disks with CMK managed via Key Vault for both OS and data.
- B. Encryption at host encrypts data at the host level, but ADE directly encrypts the VM disks and integrates with Key Vault for CMK more specifically for this scenario.
- D. SSE with Platform-Managed Keys is Azure Storage's default encryption, but it uses Microsoft-managed keys and doesn't encrypt the OS disk.
Azure Disk Encryption (ADE)
Azure Disk Encryption (ADE) helps protect your Azure IaaS VM disks by encrypting your OS and data disks using the industry-standard BitLocker feature for Windows and DM-Crypt for Linux.
- Encrypts both OS and data disks.
- Uses customer-managed keys (CMK) from Azure Key Vault.
- Integrates with Azure Active Directory for key management.
- Supports Windows and Linux VMs.
Memory trick: ADE + Key Vault: Your VM's disk, locked by your own key.