AZ-500 Secure compute, storage, and databases Practice Question
You are designing a backup strategy for Azure virtual machines. You need to ensure that backups are encrypted at rest and can be restored in a different Azure region in case of a regional disaster. Which two configurations should you use?
⚠ Common exam trap
Many candidates confuse Azure Site Recovery (disaster recovery) with backup services, or assume that enabling GRS alone allows cross-region restores, when in fact CRR is a separate configuration that must be explicitly enabled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable encryption at rest for the Recovery Services vault using platform-managed keys
Enabling encryption at rest for the Recovery Services vault using platform-managed keys ensures that backup data is encrypted when stored in Azure's storage layer. This is a default encryption mechanism that protects data at rest without requiring additional key management overhead. Option C is correct because Cross-Region Restore (CRR) allows you to restore backup data to a paired Azure region, providing disaster recovery capability if the primary region fails.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Azure Site Recovery for the VMs
Why it's wrong here
Azure Site Recovery (ASR) provides continuous replication of virtual machines to a secondary Azure region so workloads can be failed over during a disaster, but it is not a backup service. It does not create scheduled, point-in-time recovery points that are retained for weeks or months and can be used to restore from accidental deletion, file corruption, or ransomware attacks. Azure Backup is the service that captures VM snapshots and stores them in a Recovery Services vault for granular restore at a chosen point in time.
- ✓
Enable encryption at rest for the Recovery Services vault using platform-managed keys
Why this is correct
Azure Backup automatically encrypts all backup data at rest in the Recovery Services vault using Storage Service Encryption (SSE), which by default is enforced with platform-managed keys. Enabling or confirming this default protects vaulted recovery points from storage-layer threats and unauthorized physical access without requiring you to manage key lifecycle. This is a foundational security control in any backup strategy, though it does not by itself address availability or regional resilience, which is handled separately by features like Cross-Region Restore.
- ✓
Enable Cross-Region Restore (CRR) for the Recovery Services vault
Why this is correct
Cross-Region Restore (CRR) is a vault-level feature that, when enabled, copies every recovery point taken for the VM to the Azure paired region. This gives you an independent secondary location from which to restore the entire VM or individual files if the primary region suffers a full outage or disaster. CRR is only available when the vault is configured with geo-redundant storage (GRS) and must be explicitly turned on, because GRS alone does not make backup data restorable in the secondary region.
- ✗
Enable Azure Disk Encryption on the VMs
Why it's wrong here
Azure Disk Encryption (ADE) uses BitLocker on Windows and DM-Crypt on Linux to encrypt the OS and data disks of the VM itself, thereby protecting the source data at rest in the managed disks. However, it does not encrypt the backup snapshots or recovery points that Azure Backup writes to the Recovery Services vault; those are encrypted separately by the backup service at the vault level. A complete backup security posture requires both ADE for protecting the production disks and vault-level encryption for protecting the backup data.
- ✗
Use geo-redundant storage (GRS) for the Recovery Services vault
Why it's wrong here
Geo-redundant storage (GRS) for the Recovery Services vault replicates backup data to a geographically paired Azure region, providing high durability and protection against loss of the primary vault. But GRS alone does not allow the VM to be restored from that secondary copy—the restore operation still reads from the primary region unless you separately enable the Cross-Region Restore (CRR) feature. Thus, selecting GRS is a storage redundancy decision and is not a substitute for enabling CRR to actually make restores possible in the paired region.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.