All data written to Azure Storage is encrypted at rest automatically with 256-bit AES (Advanced Encryption Standard) encryption, a feature called Azure Storage encryption or Storage Service Encryption (SSE). You cannot turn it off, and it costs nothing extra. Encryption and decryption are transparent: applications read and write data normally, with no code changes. What you choose is who manages the keys and whether to add extra layers. That distinction, rather than whether data is encrypted, is what exam questions test.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.