nerdexam
Microsoft

AZ-500 · Question #91

You have an Azure subscription named Sub1 that contains the Azure key vaults shown in the following table: In Sub1, you create a virtual machine that has the following configurations: Name: VM1…

The correct answer is A. Vault1 or Vault3 only. Explanation Option A is correct because Azure Disk Encryption requires the Key Vault to be in the same region as the virtual machine (West Europe) and must have Azure Disk Encryption enabled as a vault access policy - only Vault1 and Vault3 meet both of these criteria based on…

Submitted by satoshi_tk· Mar 6, 2026Secure compute, storage, and databases

Question

You have an Azure subscription named Sub1 that contains the Azure key vaults shown in the following table: In Sub1, you create a virtual machine that has the following configurations: Name: VM1 Size: DS2v2 Resource group: RG1 Region: West Europe Operating system: Windows Server 2016 You plan to enable Azure Disk Encryption on VM1. In which key vaults can you store the encryption key for VM1?

Exhibits

AZ-500 question #91 exhibit 1
AZ-500 question #91 exhibit 2

Options

  • AVault1 or Vault3 only
  • BVault1, Vault2, Vault3, or Vault4
  • CVault1 only
  • DVault1 or Vault2 only

How the community answered

(33 responses)
  • A
    79% (26)
  • B
    6% (2)
  • C
    12% (4)
  • D
    3% (1)

Explanation

Explanation

Option A is correct because Azure Disk Encryption requires the Key Vault to be in the same region as the virtual machine (West Europe) and must have Azure Disk Encryption enabled as a vault access policy - only Vault1 and Vault3 meet both of these criteria based on the table. Options B and D are incorrect because they include Vault2 and/or Vault4, which either reside in a different region or lack the required Disk Encryption access policy enabled on the vault. Option C is incorrect because it excludes Vault3, which also satisfies both the regional and configuration requirements.

Memory Tip

Think of "Same Region + Disk Encryption Enabled" as a two-key rule - both keys must turn for Azure Disk Encryption to work. If the vault is in a different region or missing the Disk Encryption access policy, it simply won't qualify, no matter how close it looks on paper.

Topics

#Azure Disk Encryption#Azure Key Vault#VM Security#Encryption Key Management

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice