AZ-500 Secure compute, storage, and databases Practice Question
You are deploying a new application on Azure VMs. The application must be encrypted at rest and during transmission. Which combination of features should you implement?
⚠ Common exam trap
Candidates often confuse Azure Storage Service Encryption (which applies to Azure Blob/File storage) with Azure Disk Encryption (which applies to VM disks), or they assume SSL/TLS alone covers all encryption needs, forgetting that at-rest encryption requires a separate mechanism like ADE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Disk Encryption and HTTPS
Azure Disk Encryption (ADE) provides at-rest encryption for Azure VM disks using BitLocker (Windows) or DM-Crypt (Linux), while HTTPS ensures encryption in transit between the client and the application. Together, they satisfy the requirement for encryption both at rest and during transmission.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Firewall and Azure Disk Encryption
Why it's wrong here
Azure Firewall enforces network-level access policies and can filter east-west and north-south traffic, but it does not provide any cryptographic protection for traffic passing through it—traffic remains in clear text unless the application itself uses TLS. Azure Disk Encryption protects the OS and data disks at rest with BitLocker or DM-Crypt, so the VM's stored data is safe. However, the complete requirement includes encryption during transmission between the VM and clients. This combination covers network filtering and at-rest encryption but leaves data in transit unencrypted, making it incorrect.
- ✓
Azure Disk Encryption and HTTPS
Why this is correct
This combination fully satisfies both stated requirements. Azure Disk Encryption encrypts the VM's managed OS and data disks at rest using BitLocker for Windows and DM-Crypt for Linux, integrating with Azure Key Vault to protect the disk encryption keys. HTTPS, which relies on TLS, encrypts the application traffic in transit between the VM and its clients, preventing eavesdropping and tampering along the network path. Together, they provide the required at-rest and in-transit confidentiality for an Azure VM-hosted application.
- ✗
Azure Storage Service Encryption and SSL
Why it's wrong here
Azure Storage Service Encryption (SSE) automatically encrypts data that is written to Azure Storage accounts, such as blobs, files, queues, and tables, using AES-256; it does not encrypt the OS and data disks attached to a virtual machine, which are managed by Microsoft.Compute, not Azure Storage. While SSL/TLS protects data in transit from the client to the VM, no disk-level encryption is applied to the VM itself. Therefore, data at rest on the VM's disks remains unencrypted. This combination only addresses in-transit traffic and storage-service data, not VM disk encryption, so it is incorrect.
- ✗
Azure Disk Encryption and SSL
Why it's wrong here
Azure Disk Encryption protects data at rest using BitLocker for Windows or DM-Crypt for Linux, but it does not encrypt data during transmission between the VM and clients. The stem explicitly requires encryption both at rest and during transmission, so SSL (or TLS) is needed for in-transit encryption, but Azure Disk Encryption alone provides no network-layer protection. This combination is tempting because Azure Disk Encryption is the standard choice for at-rest encryption on managed disks, and SSL is the typical solution for securing HTTP traffic; together they would satisfy the requirement only if the application’s transmission path is entirely covered by SSL, but the stem does not limit transmission to application-layer traffic, and Azure Disk Encryption does not encrypt the VM’s network communications.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.