Soru

Zorluk: OrtaAzure Virtual Machine Backup Configuration

An enterprise administrator is setting up the initial backup configuration for an Azure virtual machine with the following specifications:
- Name: vm-finance-prod
- Operating System: Red Hat Enterprise Linux 8.8
- Azure Region: East US
- Disk Type: Premium SSD (LRS)
- Recovery Services Vault: rsv-finance-prod (located in East US)

The disks of vm-finance-prod are encrypted using Azure Disk Encryption (ADE) with customer-managed keys (CMK) stored in an Azure Key Vault named kv-finance-prod (located in East US). The firewall of kv-finance-prod is enabled and configured to allow access from selected networks only.

During the initial backup configuration, the administrator notices that the backup jobs fail with an error indicating that Azure Backup cannot access the key vault.

Which configuration change should the administrator implement to resolve this issue?

  1. Modify the network security settings of the key vault to enable the bypass option for trusted Microsoft services.Cevap
  2. B
    Provision a Recovery Services Vault in a different Azure region than the key vault to enable cross-region key replication.
  3. C
    Assign the Storage Blob Data Contributor role to the Recovery Services Vault's system-assigned managed identity on the key vault.
  4. D
    Configure a diagnostic setting on the key vault to forward resource logs to the Recovery Services Vault.

Cevap

Modify the network security settings of the key vault to enable the bypass option for trusted Microsoft services.
When a virtual machine is encrypted using Azure Disk Encryption (ADE), Azure Backup must access the associated Azure Key Vault to retrieve the encryption keys during backup and restore operations. If the key vault's firewall is enabled to restrict access, the administrator must configure the key vault's firewall settings to allow trusted Microsoft services, which includes Azure Backup, to bypass the restriction.

Adım Adım Çözüm

1
Identify the encryption status of the virtual machine and the storage of its encryption keys.
The VM uses Azure Disk Encryption with keys stored in an Azure Key Vault.
Azure Backup needs access to the Key Vault to back up encrypted VMs.
2
Determine the network access configuration on the Key Vault.
The Key Vault firewall is enabled, restricting network access.
A restricted Key Vault firewall blocks external access, including from the Azure Backup service.
3
Apply the appropriate security bypass configuration on the Key Vault network settings.
The bypass option for trusted Microsoft services is enabled on the Key Vault.
This allows Azure Backup to retrieve the required encryption keys and complete the backup.

Anahtar Kavram

Azure Backup configuration for Azure Disk Encryption (ADE) enabled virtual machines requires Key Vault firewall bypass for trusted Microsoft services.
Bu soruyu puanla