Which ADatum Virtual Machines Can Azure Disk Encryption Encrypt?
Case study - This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided. To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study. At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section. To start the case study - To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question. Overview - ADatum Corporation is consulting firm that has a main office in Montreal and branch offices in Seattle and New York. Existing Environment - Azure Environment - ADatum has an Azure subscription that contains three resource groups named RG1, RG2, and RG3. The subscription contains the storage accounts shown in the following table. The subscription contains the virtual machines shown in the following table. The subscription has an Azure container registry that contains the images shown in the following table. The subscription contains the resources shown in the following table. Azure Key Vault - The subscription contains an Azure key vault named Vault1. Vault1 contains the certificates shown in the following table. Vault1 contains the keys shown in the following table. Microsoft Entra Environment - ADatum has a Microsoft Entra tenant named adatum.com that is linked to the Azure subscription and contains the users shown in the following table. The tenant contains the groups shown in the following table. The adatum.com tenant has a custom security attribute named Attribute1. Planned Changes - ADatum plans to implement the following changes: • Configure a data collection rule (DCR) named DCR1 to collect only system events that have an event ID of 4648 from VM2 and VM4. • In storage1, create a new container named cont2 that has the following access policies: o Three stored access policies named Stored1, Stored2, and Stored3 o A legal hold for immutable blob storage • Whenever possible, use directories to organize storage account content. • Grant User1 the permissions required to link Zone1 to VNet1. • Assign Attribute1 to supported adatum.com resources. • In storage2, create an encryption scope named Scope1. • Deploy new containers by using Image1 or Image2. Technical Requirements - ADatum must meet the following technical requirements: • Use TLS for WebApp1. • Follow the principle of least privilege. • Grant permissions at the required scope only. • Ensure that Scope1 is used to encrypt storage services. • Use Azure Backup to back up cont1 and share1 as frequently as possible. • Whenever possible, use Azure Disk Encryption and a key encryption key (KEK) to encrypt the virtual machines. You need to configure encryption for the virtual machines. The solution must meet the technical requirements. Which virtual machines can you encrypt? -
-
-
-
-
-
-
- 
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests ADE's supported-configuration limits (disk type, VM size, tier) rather than licensing or Key Vault setup, and the trap is assuming every VM listed in the case study table can be encrypted just because a KEK is available.
In the ADatum case study, Azure Disk Encryption can only be enabled on virtual machines whose OS image and disk types fall inside ADE's supported configuration list, which leaves VM2 and VM3 as the only valid pair. This page confirms option C and explains why the pairings that include VM1, VM4 or VM5 cannot meet the technical requirements.
Choosing option D (VM2 and VM4) because VM4 looks like an ordinary production VM in the table, without checking that its disk or VM configuration is one of the scenarios Azure Disk Encryption explicitly does not support.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The technical requirements state that ADatum must "use Azure Disk Encryption and a key encryption key (KEK)" to encrypt the virtual machines "whenever possible," so eligibility depends on ADE's documented list of supported operating systems, VM sizes and disk types. In ADatum's virtual machine table, VM2 and VM3 are the only pair whose OS image and disk configuration sit inside that supported list, which is why option C is the correct pairing and is the answer the source key records. The VMs that fall into an ADE "not supported" scenario are excluded regardless of how important they are to the workload, because ADE simply cannot be enabled on them. The KEK half of the requirement is a separate decision: a Key Vault key encryption key is only wrapped around a VM after that VM is confirmed encryptable, so it never changes which machines qualify. Because the question asks which VMs can be encrypted, only the supported-configuration test matters, and it yields exactly two VMs, not three or four.
Why the Other Options Are Wrong
Option A (VM1 and VM3) fails because VM1 does not meet ADE's supported scenario list, so any pair containing it is invalid no matter how well VM3 fits. Option B (VM4 and VM5) is doubly wrong: both machines are the ones the community identifies as unsupported, so neither can be encrypted at all. Option D (VM2 and VM4) keeps the valid VM2 but adds VM4, which is the specific mistake of treating VM4 as a normal encryptable VM without reading its disk configuration in the exhibit. Only C pairs two machines that both satisfy ADE prerequisites, which is why every recorded vote and every comment on this question lands on C.
Community Comment Notes
Megabyte10 states that C is correct "not D, due to the supported disk types," and alsmk2 agrees that VM4 and VM5 are ruled out because "The other disk types aren't supported." arunyadav09 links the Microsoft ADE documentation and summarizes the exclusion with the verbatim line "Azure Disk Encryption does not work for the following scenarios for window," pointing at restricted sizes such as M-series with Write Accelerator disks and dynamic volumes. astmatik raises the one open objection on the page, asking how a Basic volume could be encrypted, yet still records C, so no commenter argues for A, B or D. With 100 votes all on C, the community reasoning is consistent and is drawn from the vendor's supported-configuration page rather than from guesswork.
Official Reference
Exam Strategy
In AZ-104 case studies, filter the exhibit table against the service's supported-configuration list before you match answer pairs, since one disqualifying VM kills two options at once. Here, crossing out VM4 and VM5 for unsupported disks and VM1 for its unmet prerequisite leaves C without any guessing.
Frequently Asked Questions
Why can't VM4 and VM5 be encrypted with Azure Disk Encryption?
Their disk and VM configurations are listed among the scenarios ADE does not support, such as unsupported disk types or Write Accelerator-enabled sizes, so ADE cannot be enabled on them.
Does Azure Disk Encryption support Basic tier virtual machines?
No. Microsoft's ADE documentation lists Basic-tier VMs and VMs created with the classic deployment method as unsupported scenarios, one of the rules that narrows this case study to VM2 and VM3.
Related Analysis
Practice All AZ-104 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-104 Practice Test →