A regulator wants two independent encryption layers under Microsoft’s storage infrastructure for the lock-photo account, not only the default SSE with a platform-managed or customer-managed key. Which control meets that requirement?
Select an answer to reveal the explanation.
Short Explanation
SSE is one lock on the data at rest. Infrastructure encryption adds a second lock inside Microsoft’s storage stack—two layers, not “TLS counts as the other layer.”
Full Explanation
Infrastructure encryption provides an additional encryption layer at the Azure Storage infrastructure level, independent of the account’s service-side encryption with a Microsoft-managed or customer-managed key. Azure Disk Encryption protects VM disks, not blob infrastructure double encryption. TLS protects data in transit. Soft delete is a recoverability control, not a second encryption layer.