Compliance requires end-to-end encryption of temporary disks, caches, and the compute-to-storage path for lock VMs without burning guest CPU on BitLocker. Which control should the security engineer enable?
Select an answer to reveal the explanation.
Short Explanation
Encryption at host is the cloak around the lock house—temp disks, caches, and the ride to storage—without running BitLocker on the guest CPU.
Full Explanation
Encryption at host extends protection so temporary disks and caches are encrypted and data is encrypted on the host before it is written to Azure Storage, without the guest CPU cost of ADE BitLocker or dm-crypt. A disk encryption set can supply customer-managed keys when required. ADE is a different guest-level mechanism and is mutually exclusive with encryption at host. Confidential disk encryption targets confidential VMs with TPM-bound OS disks, not this host-path scenario.