exam questions

Exam AZ-301 All Questions

View all questions & answers for the AZ-301 exam

Exam AZ-301 topic 3 question 3 discussion

Actual exam question from Microsoft's AZ-301
Question #: 3
Topic #: 3
[All AZ-301 Questions]

You are designing a data protection strategy for Azure virtual machines. All the virtual machines are in the Standard tier and use managed disks.
You need to recommend a solution that meets the following requirements:
✑ The use of encryption keys is audited.
✑ All the data is encrypted at rest always.
✑ You manage the encryption keys, not Microsoft.
What should you include in the recommendation?

  • A. BitLocker Drive Encryption (BitLocker)
  • B. Azure Storage Service Encryption
  • C. client-side encryption
  • D. Azure Disk Encryption
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
References:
https://docs.microsoft.com/en-us/azure/security/azure-security-disk-encryption-overview

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
examamos
Highly Voted 5 years, 5 months ago
It's correct: "Azure Disk Encryption (...) uses the Bitlocker feature (...) and (...) to help you control and manage the disk encryption keys and secrets." https://docs.microsoft.com/en-gb/azure/virtual-machines/windows/disk-encryption-overview. I.e. Bitlocker is the "tool", not the solution. D is correct.
upvoted 27 times
...
Moon
Highly Voted 5 years, 2 months ago
D is correct as in the below link: https://azure.microsoft.com/en-us/blog/preview-server-side-encryption-with-customer-managed-keys-for-azure-managed-disks/ "Customers also benefit from Azure disk encryption (ADE) that leverages the BitLocker feature of Windows and the DM-Crypt feature of Linux to encrypt Managed Disks with customer managed keys within the guest virtual machine."
upvoted 11 times
...
glam
Most Recent 4 years, 3 months ago
D. Azure Disk Encryption
upvoted 3 times
...
[Removed]
4 years, 8 months ago
Requirements: - The use of encryption keys is audited. - All the data is encrypted at rest always. - You manage the encryption keys, not Microsoft. Possible Answers: A. BitLocker Drive Encryption (BitLocker) > I think this would fullfil all requirements as well, although I am not sure about the key-usage auditing part. B. Azure Storage Service Encryption > Can be ruled out as we are using managed disks. C. client-side encryption > Doesn't make sense for managed disks, can be ruled out. D. Azure Disk Encryption > Fullfills all requirements. Keys are stored in Key Vault. To audit the encryption key usage, Key Vault monitoring can be used. Conclusion: > I am varying between A. & D. but still would choose D. as it seems the more azure-native approach. Am I missing something regarding BitLocker?
upvoted 9 times
pentium75
3 years, 8 months ago
Bitlocker (A) can't be the solution because it only runs on Windows, while we don't know which OS is used on these VMs.
upvoted 1 times
...
pentium75
3 years, 8 months ago
Azure Storage Service Encryption (B) does support managed disks since 2017.
upvoted 1 times
...
fatmaphil
4 years, 7 months ago
Azure Disk Encryption uses BitLocker for Windows and DM-Crypt for Linux.
upvoted 2 times
...
...
superbutt
4 years, 11 months ago
The Correct Answer is D.
upvoted 2 times
...
colep
4 years, 12 months ago
Its D, I did it in lab
upvoted 3 times
...
lepperboy
5 years ago
I'm guessing the rationale here is what is the service applicable to all VM types - which would be Azure disk encryption. Then features of Azure disk encryption are Bitlocker for Windows and DM_crypt for Linux - both of which can BYO key.
upvoted 4 times
...
JL412
5 years ago
how about Server-side encryption with customer-managed keys? B is also feasible
upvoted 2 times
jcarlos
4 years, 11 months ago
I also initially thought as you, but there is this requirement: All the data is encrypted at rest always and Server side encryption can’t meet this requirement since temporary disks are not encrypted by Server side encryption. From https://docs.microsoft.com/en-us/azure/virtual-machines/linux/disk-encryption “Temporary disks are not managed disks and are not encrypted by SSE” https://docs.microsoft.com/en-us/azure/virtual-machines/windows/disk-encryption-faq#how-is-azure-disk-encryption-different-from-storage-server-side-encryption-with-customer-managed-key-and-when-should-i-use-each-solution
upvoted 3 times
...
sourabh7257
4 years, 9 months ago
B is Azure storage encryption not Server-side encryption
upvoted 1 times
...
...
jokl
5 years, 1 month ago
Answer is D. See https://docs.microsoft.com/en-us/azure/virtual-machines/windows/managed-disks-overview#azure-disk-encryption
upvoted 2 times
...
SilentH
5 years, 1 month ago
Azure Disk Encryption requires an Azure Key Vault to control and manage disk encryption keys and secrets. Would this answer still qualify under the requirement that "You manage the encryption keys, not Microsoft."? I would think no. If so, that means 'D' isn't the right answer.
upvoted 3 times
Protonenpaule
5 years ago
Disk encryption is supported with customer-managed keys, see https://docs.microsoft.com/en-us/azure/virtual-machines/windows/disk-encryption
upvoted 6 times
...
satgo
4 years, 11 months ago
you can import Azure Key vault keys and managed outside of Microsoft. So, D is right.
upvoted 1 times
...
...
Jake__
5 years, 6 months ago
Reference below tells that for windows machine azure disk encryption uses bitlocker for encryption. There was no specification there was windows and linux machines, question is to vague. https://docs.microsoft.com/en-us/azure/security/azure-security-disk-encryption-overview
upvoted 1 times
...
Jake__
5 years, 6 months ago
Bitlocker does all of that. You can use it in azure, it works on managed disks, you can control the key. No reason why not
upvoted 2 times
CipherK
5 years, 1 month ago
BitLocker is only for Windows.
upvoted 6 times
tartar
4 years, 7 months ago
D is ok
upvoted 2 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago