A lock-controller VM must keep its OS disk sealed so the host and hypervisor cannot read it. Which approach meets that requirement?
Select an answer to reveal the explanation.
Short Explanation
If the dockmaster’s safe must stay shut even from the pier crew, you need a confidential VM and confidential disk encryption—OS disk sealed to the TPM, not just ADE on a regular box.
Full Explanation
Confidential disk encryption is available on confidential virtual machines and binds the OS disk so it remains protected from the host and hypervisor, with keys associated to the TPM. Temporary-disk encryption on confidential VMs is a separate opt-in. ADE on conventional sizes and encryption at host do not provide that TPM-sealed confidential OS disk model. Platform SSE remains baseline at-rest encryption and is not a substitute for confidential disk encryption.