Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard
A development team is deploying a new application that processes sensitive customer data. They need to ensure that the data at rest in Azure Storage accounts is always encrypted using customer-managed keys (CMK) for enhanced control. Which Azure feature allows them to mandate this requirement across all relevant storage accounts?
- AAzure Key Vault
- BAzure Disk Encryption
- CAzure Policy
- DAzure Security Center
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Policy
Azure Policy can be used to mandate the use of customer-managed keys for encryption at rest in Azure Storage accounts. It allows defining rules that prevent the creation or modification of storage accounts that do not meet this encryption requirement.
Why the other options are wrong
- A. Azure Key Vault securely stores encryption keys, but Azure Policy is needed to enforce their usage for specific services.
- B. Azure Disk Encryption encrypts OS and data disks for VMs, not data at rest in Azure Storage accounts directly.
- D. Azure Security Center provides security posture management and threat protection, but not the direct enforcement of encryption key types for storage accounts.
Azure Policy for Encryption Enforcement
Azure Policy helps enforce organizational standards and assess compliance at scale. It can be used to mandate specific encryption configurations, such as requiring customer-managed keys.
- Define rules for resource configurations.
- Prevents non-compliant resource creation/updates.
- Can audit existing resources for compliance.
Memory trick: Policy Pushes Private Keys.