Azure Disk Encryption Components for Windows VMs: BitLocker, KEK, and VEK
Which TWO components are required to enable Azure Disk Encryption for Windows VMs using Azure Key Vault? (Choose two.)
⚠ Common exam trap
The trap is that candidates often assume a KEK is mandatory because it is commonly used, but Azure Disk Encryption works without it. Additionally, candidates may confuse the requirements with those of Azure Backup, which does require a Recovery Services vault.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Key Vault with an access policy granting permissions to the Azure Disk Encryption service
Option A is correct because Azure Disk Encryption (ADE) for Windows VMs requires an Azure Key Vault that holds the BitLocker encryption keys (BEKs) and secrets, and the vault must have an access policy that grants the Azure Disk Encryption service principal the required permissions (key permissions such as wrapKey/unwrapKey and secret permissions such as get/set) so the ADE extension can read and write the secrets. Option E is correct because ADE is delivered as a VM extension (the AzureDiskEncryption extension for Windows, or AzureDiskEncryptionForLinux for Linux) that must be installed on the VM to perform the actual encryption of the OS and data disks. Option B is not required: a key encryption key (KEK) is an optional second layer of key protection used to wrap the BitLocker keys, not a mandatory component. Option C is not required: a Recovery Services vault is used for Azure Backup, not for ADE key storage. Option D is not required: ADE does not need a storage account to store encryption logs; diagnostic/audit data is handled through Azure Monitor and Key Vault logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Key Vault with an access policy granting permissions to the Azure Disk Encryption service
Why this is correct
Azure Disk Encryption needs the Key Vault access policy that grants the Azure Disk Encryption service principal the wrapKey, unwrapKey and get permissions, so it can read and write the key encryption keys and secrets.
- ✗
A key encryption key (KEK) in Azure Key Vault
Why it's wrong here
A KEK is optional: Azure Disk Encryption works with a volume encryption key wrapped by the Key Vault key alone, so it is not one of the two required components. It tempts because KEKs are a legitimate Key Vault feature used for key hierarchy separation, and would be required if organisational policy mandated a two-tier key model.
- ✗
A Recovery Services vault
Why it's wrong here
A Recovery Services vault supports Azure Backup and Site Recovery, not Azure Disk Encryption key storage. It tempts because both services protect VM data and are configured per-VM, and would be the correct component if the requirement were backup or disaster recovery rather than disk encryption.
- ✗
A storage account to store the encryption logs
Why it's wrong here
Azure Disk Encryption writes no encryption logs to a storage account; that requirement belongs to Azure Disk Encryption's diagnostic extension only if explicitly configured, not to enabling encryption. It tempts because storage accounts commonly hold diagnostic logs, and would be correct for capturing boot diagnostics or audit data.
- ✓
The Azure Disk Encryption extension installed on the VM
Why this is correct
The Azure Disk Encryption extension is the on-VM agent that performs BitLocker encryption of OS and data volumes, retrieving the key-encryption key and secret URI from the key vault. Without this extension installed, Azure cannot orchestrate encryption, so it satisfies the requirement for a functional encryption component.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.