Storage Service Encryption — Microsoft Azure Administrator (AZ-104) Practice Questions
Storage Service Encryption (SSE), also called Azure Storage encryption, is the built-in server-side encryption that automatically encrypts all data written to Azure Storage using 256-bit AES encryption before persisting it to disk. It is enabled by default for all storage accounts and cannot be disabled, providing transparent encryption without any changes required to applications. AZ-104 tests whether candidates understand the distinction between SSE and Azure Disk Encryption, how key management options (platform-managed vs. customer-managed keys) apply to SSE, and how SSE fulfills compliance requirements.
Free questions on storage service encryption
You are managing storage accounts for your organization. You need to ensure that all data at rest is encrypted. Which encryption option is enabled by default in Azure Storage?
Free question · medium · full answer + explanation
More storage service encryption questions in the full bank
- Your organization requires that all storage accounts must be encrypted at rest. Which Azure service provides this by default? Unlock answer & explanation →
- Your organization requires all data at rest to be encrypted. Which service ensures this? Unlock answer & explanation →