A contractor tries to enable encryption at host on a lock-chamber VM that already uses Azure Disk Encryption. What should the security engineer tell them?
Select an answer to reveal the explanation.
Short Explanation
You can’t run two different locksmiths on the same chamber door. ADE and encryption at host don’t share a VM—migrate to new disks or a new VM instead of flipping both switches.
Full Explanation
Microsoft documents Azure Disk Encryption and encryption at host as mutually exclusive on a virtual machine. There is no supported in-place conversion that simply enables encryption at host atop ADE-encrypted disks; migration uses new disks or new VMs with the chosen model. Current guidance often prefers encryption at host for new deployments, while ADE remains an exam-named guest encryption option. Stacking ADE with confidential disk encryption on an unsupported size is not the remediation.