You need to ensure that all data at rest in an Azure Storage account is encrypted using a customer-managed key. Which feature should you enable?
Customer-managed keys wrap the storage account's data encryption key in Azure Key Vault, giving you control over rotation and revocation. This satisfies the requirement for encryption at rest governed by your own key rather than a Microsoft-managed one.
Why this answer
Azure Storage Service Encryption (SSE) automatically encrypts data at rest in Azure Storage accounts. By default, it uses Microsoft-managed keys, but you can configure it to use customer-managed keys (CMK) stored in Azure Key Vault. This ensures that you control the encryption keys and can manage their lifecycle, rotation, and access policies, meeting the requirement for customer-managed key encryption.
Exam trap
The trap here is that candidates often confuse Azure Disk Encryption (which encrypts VM disks) with Storage Service Encryption (which encrypts the storage account's blob, file, queue, and table data), leading them to select Option A instead of the correct SSE with CMK.
How to eliminate wrong answers
Option A is wrong because Azure Disk Encryption (ADE) uses BitLocker (Windows) or DM-Crypt (Linux) to encrypt OS and data disks of virtual machines, not the data at rest in an Azure Storage account. Option B is wrong because SSE with platform-managed key uses Microsoft-managed keys, not customer-managed keys, so it does not satisfy the requirement for customer-managed key control. Option D is wrong because Azure Information Protection (AIP) is a classification and labeling service for documents and emails, not an encryption mechanism for data at rest in Azure Storage.