AZ-500 exam dumps

AZ-500 practice question 140 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 140

Single answer

You manage an Azure Virtual Machine that uses an ephemeral OS disk for performance reasons. Your compliance team now mandates that all production data must be encrypted with your organization’s own keys, while also ensuring the ephemeral OS disk remains encrypted. They do not want to install any VM extensions or undergo restarts. Which approach should you implement to meet these requirements?

  1. A

    Enable Azure Disk Encryption with BitLocker (for Windows) or DM-Crypt (for Linux) on both the OS disk and data disks, storing the keys in Azure Key Vault.

  2. B

    Use server-side encryption with customer-managed keys (SSE with CMK) for the data disks, while relying on platform-managed encryption for the ephemeral OS disk.

  3. C

    Deploy encryption at the host only, without enabling any form of customer-managed or platform-managed encryption on the data disks.

  4. D

    Combine encryption at host with Azure Disk Encryption for both the ephemeral OS disk and the data disks.

Show answer and explanation

Correct answer: B

Explanation

Ephemeral OS disks are automatically encrypted using platform-managed keys and cannot use Azure Disk Encryption. To meet the requirement of using your own keys for data disks, you can configure SSE with CMK, ensuring compliance without installing extensions. Azure documentation confirms that ephemeral OS disks do not support Azure Disk Encryption and are instead protected by default with platform-managed keys. For more details, see: https://docs.microsoft.com/azure/virtual-machines/windows/ephemeral-os-disks and https://docs.microsoft.com/azure/virtual-machines/disk-encryption-overview.

  • A. Incorrect.

    Option 1: Azure Disk Encryption (ADE) requires an agent and extension-based approach (BitLocker or DM-Crypt) and is not supported on ephemeral OS disks. Ephemeral OS disks cannot store encryption metadata in the same way as managed disks, so ADE cannot be applied to them. Therefore, this approach fails the requirement of using an ephemeral OS disk without extensions or reboots.

  • B. Correct.

    Option 2 (Correct): SSE with customer-managed keys (CMK) encrypts at the storage service level using your own keys, fulfilling the requirement for encrypting data disks with organization-owned keys. Ephemeral OS disks are natively encrypted at rest with platform-managed keys, and no extension is needed for ephemeral disks. This meets the compliance requirement for the data disks and avoids any agent-based approach on the OS disk.

  • C. Incorrect.

    Option 3: Encryption at the host alone ensures data is encrypted before it’s written to the disk on the host. However, this does not give you the ability to use your own customer-managed keys for the data disks. It only uses platform-managed keys. Therefore, it does not meet the compliance requirement of using your organization’s keys.

  • D. Incorrect.

    Option 4: Azure Disk Encryption and ephemeral disks are incompatible because ephemeral OS disks cannot be encrypted through ADE. Also, host-level encryption does not fix the ADE limitation and still involves extension-based encryption, which the requirement disallows.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam