AZ-500 · Question #91
You have an Azure subscription named Sub1 that contains the Azure key vaults shown in the following table: In Sub1, you create a virtual machine that has the following configurations: Name: VM1…
The correct answer is A. Vault1 or Vault3 only. Explanation Option A is correct because Azure Disk Encryption requires the Key Vault to be in the same region as the virtual machine (West Europe) and must have Azure Disk Encryption enabled as a vault access policy - only Vault1 and Vault3 meet both of these criteria based on…
Question
Exhibits
Options
- AVault1 or Vault3 only
- BVault1, Vault2, Vault3, or Vault4
- CVault1 only
- DVault1 or Vault2 only
How the community answered
(33 responses)- A79% (26)
- B6% (2)
- C12% (4)
- D3% (1)
Explanation
Explanation
Option A is correct because Azure Disk Encryption requires the Key Vault to be in the same region as the virtual machine (West Europe) and must have Azure Disk Encryption enabled as a vault access policy - only Vault1 and Vault3 meet both of these criteria based on the table. Options B and D are incorrect because they include Vault2 and/or Vault4, which either reside in a different region or lack the required Disk Encryption access policy enabled on the vault. Option C is incorrect because it excludes Vault3, which also satisfies both the regional and configuration requirements.
Memory Tip
Think of "Same Region + Disk Encryption Enabled" as a two-key rule - both keys must turn for Azure Disk Encryption to work. If the vault is in a different region or missing the Disk Encryption access policy, it simply won't qualify, no matter how close it looks on paper.
Topics
Community Discussion
No community discussion yet for this question.

