Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard
A global software company maintains highly confidential intellectual property in Azure Blob Storage. They require that all data, both at rest and in transit, is encrypted using strong encryption standards. They need to ensure that encryption is automatically applied and managed by Azure where possible, without requiring extensive manual configuration. Which Azure Storage encryption capabilities meet these requirements?
- AAzure Key Vault for managing encryption keys only
- BServer-side encryption (SSE) for data at rest and client-side encryption for data in transit
- CAzure Disk Encryption for VMs
- DServer-side encryption (SSE) for data at rest and HTTPS for data in transit
Show answer & explanationAnswer & explanation
Correct answer: D. Server-side encryption (SSE) for data at rest and HTTPS for data in transit
Azure Storage automatically encrypts data at rest using Server-Side Encryption (SSE) for all data written to Azure Storage. For data in transit, Azure Storage enforces HTTPS, which encrypts all communication between clients and Azure Storage. This combination ensures strong encryption for both states with minimal manual configuration.
Why the other options are wrong
- A. Azure Key Vault is used to manage encryption keys, but it doesn't *perform* the encryption of data at rest or in transit itself; Azure Storage services do that.
- B. Client-side encryption is an option for data in transit but requires manual implementation by the application. HTTPS is automatically enforced and managed by Azure for data in transit.
- C. Azure Disk Encryption is for VM disks, not Azure Blob Storage.
Azure Storage Encryption (At Rest & In Transit)
Azure Storage provides automatic encryption for data at rest (Server-Side Encryption) and encrypts data in transit (HTTPS) to protect data confidentiality.
- Data at rest is encrypted by SSE (256-bit AES).
- Data in transit is encrypted via HTTPS/TLS.
- Managed by Microsoft by default, customer-managed keys optional.
Memory trick: Resting data is safe with SSE, moving data with HTTPS.