AZ-500 Secure compute, storage, and databases Practice Question
You need to protect Azure VMs from ransomware by ensuring that encrypted file systems cannot be read by attackers. Which solution should you implement?
⚠ Common exam trap
Candidates often confuse network-level controls (NSGs) or backup solutions with data-at-rest encryption, or they assume that a security monitoring tool like Defender for Cloud provides encryption, when in fact only a dedicated disk encryption solution like Azure Disk Encryption protects the file system from being read by an attacker with access to the storage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Azure Disk Encryption on the VMs.
Azure Disk Encryption uses BitLocker (Windows) or DM-Crypt (Linux) to encrypt the OS and data disks of Azure VMs at rest. This ensures that even if an attacker gains access to the underlying storage or exports the VHD files, the encrypted file system cannot be read without the encryption keys, which are protected by Azure Key Vault. This directly addresses the requirement to prevent attackers from reading encrypted file systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply network security groups (NSGs) to block unauthorized access.
Why it's wrong here
Network security groups (NSGs) filter traffic at layers 3 and 4, blocking common ransomware command-and-control or administrative ports, but they do not encrypt disks. Ransomware often executes inside an allowed session or via compromised credentials, so network filtering alone leaves sensitive data on VHDs unencrypted. Reducing the attack surface is useful, but it does not satisfy a data-at-rest protection requirement.
- ✗
Configure Azure Backup for the VMs.
Why it's wrong here
Configuring Azure Backup gives you point-in-time recovery and immutable recovery stores, but backup does not encrypt the VM disks themselves. In an active ransomware event, a backup copy does not prevent the attacker from encrypting or exfiltrating the primary disk, and unencrypted backups could also be targeted unless they are protected by encryption and strict RBAC. Backup is a recovery control, not a data-at-rest encryption control.
- ✓
Enable Azure Disk Encryption on the VMs.
Why this is correct
Azure Disk Encryption (ADE) uses BitLocker on Windows and DM-Crypt on Linux to encrypt every OS and data disk at rest, so ransomware cannot read or recover plaintext data even if it gains storage-level access. ADE stores disk encryption keys in Azure Key Vault, optionally wrapped by a key encryption key (KEK), enabling dual encryption and stronger key governance. This directly ensures the VM disks are unreadable without proper key access, satisfying the core protection requirement.
- ✗
Enable Microsoft Defender for Cloud on the subscription.
Why it's wrong here
Microsoft Defender for Cloud continuously assesses security posture, identifies threats, and provides adaptive hardening, but it is a detection and management service, not a disk encryption mechanism. Enabling Defender for Cloud does not change how VHDs are stored, and it will not prevent a ransomware actor that has already executed from encrypting volumes. Threat detection must be paired with protective controls like Azure Disk Encryption, but it cannot replace them.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.