Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceMedium
A financial services company is storing highly sensitive customer data in Azure Blob Storage. Due to strict regulatory requirements, they need to ensure that this data is encrypted both at rest and in transit. They also require auditing of all access to this data. Which combination of Azure services would best meet these requirements?
- AAzure Security Center for vulnerability assessments, Azure Firewall for network protection, and Azure AD Identity Protection for user authentication.
- BAzure Policy for compliance enforcement, Azure Monitor for activity logging, and Azure Advisor for security recommendations.
- CAzure Key Vault for encryption keys, Azure Storage Service Encryption for data at rest, and HTTPS for data in transit.
- DAzure Sentinel for threat detection, Azure DDoS Protection for network attacks, and Azure Information Protection for data classification.
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Key Vault for encryption keys, Azure Storage Service Encryption for data at rest, and HTTPS for data in transit.
Azure Key Vault helps manage encryption keys. Azure Storage Service Encryption encrypts data at rest automatically for Blob Storage. HTTPS (TLS) ensures data is encrypted while in transit between the client and Azure services.
Why the other options are wrong
- A. These services focus on broader security posture, network protection, and identity, but not specifically data encryption at rest and in transit for Blob Storage.
- B. These services focus on compliance, monitoring, and recommendations, not the core encryption requirements for data in Blob Storage.
- D. These services focus on threat detection, network attack protection, and data classification, not direct encryption mechanisms for data at rest and in transit.
Data Encryption in Azure Storage
Azure provides multiple layers of encryption for data at rest and in transit to protect sensitive information stored within its services.
- Data at rest is encrypted by default using Azure Storage Service Encryption.
- Data in transit is protected using HTTPS/TLS.
- Customer-managed keys can be used with Azure Key Vault for greater control over encryption keys.
Memory trick: Keys guard the vault, the vault holds the data, and HTTPS secures the journey.