An organization implements virtual machine encryption using Server-Side Encryption with Customer-Managed Keys (SSE with CMK). You are configuring backups for `vm-secops-prd01`, a virtual machine running Windows Server 2022 Datacenter in the North Europe region. The disk encryption keys for this VM reside in an Azure Key Vault named `kv-secops-vault`. You have deployed a Recovery Services Vault named `rsv-secops-backups` in the same region. To enable successful backup operations for this encrypted virtual machine, which two configurations must you apply? (Select two.)
- ADeploy the Recovery Services Vault in the West Europe region to enable cross-region protection.
- Configure a system-assigned managed identity for the Recovery Services Vault.Cevap
- CAssign the Key Vault Crypto Service Encryption User role to the system-assigned managed identity of the virtual machine.
- Grant the Recovery Services Vault's managed identity the Key Vault Crypto Service Encryption User role on the Key Vault.Cevap
Cevap
Configure a system-assigned managed identity for the Recovery Services Vault, and grant the Recovery Services Vault's managed identity the Key Vault Crypto Service Encryption User role on the Key Vault.
For virtual machines using Server-Side Encryption with Customer-Managed Keys (SSE with CMK), the backup process requires the Recovery Services Vault to access the Key Vault containing the disk encryption keys. This is achieved by enabling a system-assigned managed identity on the Recovery Services Vault and assigning it the Key Vault Crypto Service Encryption User role on the Key Vault, which grants the required wrap and unwrap key permissions.
Adım Adım Çözüm
Anahtar Kavram
Backup configuration for VMs encrypted with Server-Side Encryption using Customer-Managed Keys (SSE with CMK).
Tahmini Süre:2m 0s