AZ-500 exam dumps

AZ-500 practice question 141 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 141

Single answer

You are an Azure administrator for a financial services company. The security compliance team requires that all data on new Linux virtual machines be encrypted at rest on both the OS and data disks using customer-managed keys. They also want to ensure that encryption is performed at the physical host level and that all keys are stored in Azure Key Vault. Which encryption solution should you implement?

  1. A

    Enable Azure Disk Encryption (ADE) on the VMs using platform-managed keys

  2. B

    Enable encryption at host with customer-managed keys in Azure Key Vault

  3. C

    Configure confidential disk encryption on dedicated confidential VMs

  4. D

    Enable Azure Disk Encryption (ADE) with passphrase-based key storage on each VM

Show answer and explanation

Correct answer: B

Explanation

Encryption at host with customer-managed keys ensures that data is encrypted on the physical host where the VM runs, and it integrates with Azure Key Vault for secure key management and rotation. This approach aligns with Microsoft best practices, as documented in https://learn.microsoft.com/azure/virtual-machines/linux/disks-enable-host-based-encryption. Azure Disk Encryption (ADE) is useful for enabling OS-level encryption but does not necessarily encrypt data at the hypervisor host. Confidential disk encryption targets specialized confidential VMs, which is not explicitly required in this scenario. Therefore, encryption at host with customer-managed keys is the most appropriate solution.

  • A. Incorrect.

    Option 1 is incorrect because ADE with platform-managed keys does not satisfy the requirement that your organization fully controls the keys in Azure Key Vault, nor does it guarantee encryption at the physical host layer.

  • B. Correct.

    Option 2 is correct because encryption at host with customer-managed keys allows for encryption at the physical host level and leverages Azure Key Vault for key management. This meets both the requirement for host-level encryption and the need to manage/rotate keys within the organization.

  • C. Incorrect.

    Option 3 is incorrect because confidential disk encryption is designed primarily for Azure Confidential VMs using secure hardware enclaves. While it offers strong protections, it does not specifically guarantee the organization’s requirement for host-level encryption with customer-managed keys in all scenarios.

  • D. Incorrect.

    Option 4 is incorrect because ADE with passphrase-based key storage on the VM does not provide the centralized key management or host-level encryption that the compliance requirement demands, and storing encryption secrets on the VM is less secure and more complex to manage.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam