Courseiva

Azure Disk Encryption Components for Windows VMs: BitLocker, KEK, and VEK

Which TWO components are required to enable Azure Disk Encryption for Windows VMs using Azure Key Vault? (Choose two.)

⚠ Common exam trap

The trap is that candidates often assume a KEK is mandatory because it is commonly used, but Azure Disk Encryption works without it. Additionally, candidates may confuse the requirements with those of Azure Backup, which does require a Recovery Services vault.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Key Vault with an access policy granting permissions to the Azure Disk Encryption service

Option A is correct because Azure Disk Encryption (ADE) for Windows VMs requires an Azure Key Vault that holds the BitLocker encryption keys (BEKs) and secrets, and the vault must have an access policy that grants the Azure Disk Encryption service principal the required permissions (key permissions such as wrapKey/unwrapKey and secret permissions such as get/set) so the ADE extension can read and write the secrets. Option E is correct because ADE is delivered as a VM extension (the AzureDiskEncryption extension for Windows, or AzureDiskEncryptionForLinux for Linux) that must be installed on the VM to perform the actual encryption of the OS and data disks. Option B is not required: a key encryption key (KEK) is an optional second layer of key protection used to wrap the BitLocker keys, not a mandatory component. Option C is not required: a Recovery Services vault is used for Azure Backup, not for ADE key storage. Option D is not required: ADE does not need a storage account to store encryption logs; diagnostic/audit data is handled through Azure Monitor and Key Vault logging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Key Vault with an access policy granting permissions to the Azure Disk Encryption service

    Why this is correct

    Azure Disk Encryption needs the Key Vault access policy that grants the Azure Disk Encryption service principal the wrapKey, unwrapKey and get permissions, so it can read and write the key encryption keys and secrets.

  • ✗

    A key encryption key (KEK) in Azure Key Vault

    Why it's wrong here

    A KEK is optional: Azure Disk Encryption works with a volume encryption key wrapped by the Key Vault key alone, so it is not one of the two required components. It tempts because KEKs are a legitimate Key Vault feature used for key hierarchy separation, and would be required if organisational policy mandated a two-tier key model.

  • ✗

    A Recovery Services vault

    Why it's wrong here

    A Recovery Services vault supports Azure Backup and Site Recovery, not Azure Disk Encryption key storage. It tempts because both services protect VM data and are configured per-VM, and would be the correct component if the requirement were backup or disaster recovery rather than disk encryption.

  • ✗

    A storage account to store the encryption logs

    Why it's wrong here

    Azure Disk Encryption writes no encryption logs to a storage account; that requirement belongs to Azure Disk Encryption's diagnostic extension only if explicitly configured, not to enabling encryption. It tempts because storage accounts commonly hold diagnostic logs, and would be correct for capturing boot diagnostics or audit data.

  • ✓

    The Azure Disk Encryption extension installed on the VM

    Why this is correct

    The Azure Disk Encryption extension is the on-VM agent that performs BitLocker encryption of OS and data volumes, retrieving the key-encryption key and secret URI from the key vault. Without this extension installed, Azure cannot orchestrate encryption, so it satisfies the requirement for a functional encryption component.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.