Courseiva

Enable Azure Storage Encryption with Customer-Managed Keys

You need to ensure that all data at rest in an Azure Storage account is encrypted using a customer-managed key. Which feature should you enable?

Quick Answer

The correct feature to enable is Azure Storage Service Encryption with a customer-managed key (CMK). This is because Azure Storage automatically encrypts all data at rest using Storage Service Encryption (SSE), and by default it uses Microsoft-managed keys; however, when you need to control your own encryption key, you switch to a customer-managed key stored in Azure Key Vault, which allows you to rotate, disable, or audit key usage independently. On the AZ-500 exam, this question tests your understanding of encryption responsibilities and the distinction between SSE with PMK (platform-managed) versus CMK, and a common trap is confusing Azure Disk Encryption (which encrypts OS and data disks for VMs) or Azure Information Protection (which classifies and labels files) with storage-level encryption. Remember the memory tip: “SSE is for storage, CMK is for control”—if the scenario says “data at rest in a storage account,” your answer is always SSE with a customer-managed key, not disk encryption or labeling tools.

⚠ Common exam trap

A common mix-up: candidates confuse Azure Disk Encryption (which encrypts VM disks) with Storage Service Encryption (which encrypts the storage account's blob, file, queue, and table data), leading them to select Option A instead of the correct SSE with CMK.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Storage Service Encryption with customer-managed key

Azure Storage Service Encryption (SSE) automatically encrypts data at rest in Azure Storage accounts. By default, it uses Microsoft-managed keys, but you can configure it to use customer-managed keys (CMK) stored in Azure Key Vault. This ensures that you control the encryption keys and can manage their lifecycle, rotation, and access policies, meeting the requirement for customer-managed key encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Disk Encryption

    Why it's wrong here

    Azure Disk Encryption encrypts OS and data disks attached to virtual machines, not blobs, files, queues or tables within a storage account. It is tempting because it does support customer-managed keys via Key Vault, and it would be correct for VM disk encryption rather than storage account data at rest.

  • ✗

    Azure Storage Service Encryption (SSE) with platform-managed key

    Why it's wrong here

    Platform-managed keys are generated and held by Microsoft, so you cannot supply or rotate your own key material. It is tempting because SSE does encrypt all data at rest by default, and it would be the correct choice where regulatory obligations permit Microsoft-controlled keys rather than customer-managed ones.

  • ✓

    Azure Storage Service Encryption with customer-managed key

    Why this is correct

    Customer-managed keys wrap the storage account's data encryption key in Azure Key Vault, giving you control over rotation and revocation. This satisfies the requirement for encryption at rest governed by your own key rather than a Microsoft-managed one.

  • ✗

    Azure Information Protection

    Why it's wrong here

    Azure Information Protection classifies and labels documents, applying protection as they travel, but it does not manage the storage account's encryption key. It is tempting because it addresses data-at-rest protection and customer-controlled keys, and it would be correct for labelling and rights-managing files across endpoints and email.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-500

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You need to encrypt an Azure Storage account at rest using a customer-managed key stored in Azure Key Vault. Which feature should you enable?

easy
  • A.Azure Information Protection
  • B.Azure Confidential Computing
  • C.Azure Disk Encryption
  • ✓ D.Azure Storage Service Encryption with customer-managed keys

Why D: Azure Storage Service Encryption (SSE) encrypts data at rest automatically. By enabling customer-managed keys (CMK) in Azure Key Vault, you can control the encryption key used for SSE, meeting the requirement to encrypt the storage account with a key you manage.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.