SC-100 Design security solutions for infrastructure Practice Question
You are the security architect for a company that uses Azure Virtual Machines (VMs) running Windows Server and Linux. The company has a regulatory requirement that all VM disks must be encrypted at rest, including temporary disks and disk caches. You need to recommend a solution that meets the requirement and minimizes administrative overhead. What should you recommend?
⚠ Common exam trap
Candidates often confuse Azure Disk Encryption with encryption at host, assuming both cover temporary disks and caches.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable encryption at host for all VMs.
Encryption at host is the only option that encrypts all VM data, including temporary disks and disk caches, at the host level. It requires no guest OS configuration and simplifies key management compared to Azure Disk Encryption. The other options either do not cover temporary disks and caches or add unnecessary administrative complexity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Azure Disk Encryption (ADE) on each VM.
Why it's wrong here
Azure Disk Encryption uses BitLocker for Windows and DM-Crypt for Linux to encrypt the OS and data disks, but it does not encrypt temporary disks or disk caches. Since the requirement explicitly includes temporary disks and disk caches, ADE alone does not meet the compliance need. Additionally, ADE requires managing key vaults and encryption keys, adding administrative overhead.
- ✗
Use Azure Storage Service Encryption (SSE) for all VM disks.
Why it's wrong here
Azure Storage Service Encryption automatically encrypts data at rest for Azure Storage services, including managed disks, but it does not encrypt temporary disks or disk caches. SSE is enabled by default and does not cover the ephemeral storage used by VMs. Therefore, it does not satisfy the requirement to encrypt temporary disks and caches.
- ✗
Configure BitLocker on Windows VMs and DM-Crypt on Linux VMs.
Why it's wrong here
Configuring BitLocker and DM-Crypt manually provides volume-level encryption within the guest OS, but it does not encrypt temporary disks or disk caches because those are not part of the OS volumes. This approach also increases administrative overhead due to key management and configuration. It fails to meet the requirement.
- ✓
Enable encryption at host for all VMs.
Why this is correct
Encryption at host encrypts all data written to the VM, including temporary disks and disk caches, at the host level. It is enabled per VM or VM scale set and does not require managing encryption keys inside the guest OS, reducing administrative overhead. This meets the requirement for all disks and caches to be encrypted at rest.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.