Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard
A company is implementing a new security policy that requires all data at rest in Azure Storage accounts to be encrypted using customer-managed keys (CMK) from Azure Key Vault. They need to ensure this policy is consistently applied to all new and existing storage accounts. Which Azure feature helps enforce this specific encryption standard?
- AAzure Security Center
- BAzure Policy
- CAzure Resource Locks
- DAzure Disk Encryption
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Policy
Azure Policy is the appropriate tool for enforcing configuration standards like requiring customer-managed encryption keys for storage accounts. You can create a policy definition that audits for non-compliant storage accounts or even denies the creation of storage accounts that do not use CMK encryption.
Why the other options are wrong
- A. Azure Security Center (now Microsoft Defender for Cloud) provides security posture management and threat protection, but Azure Policy is the mechanism for enforcing specific configuration requirements like CMK.
- C. Azure Resource Locks prevent accidental deletion or modification of resources, not for enforcing encryption standards.
- D. Azure Disk Encryption is for encrypting VM disks, not for enforcing encryption settings on Azure Storage accounts.
Azure Policy for Encryption Enforcement
Azure Policy can enforce specific encryption standards for Azure resources, such as requiring customer-managed keys (CMK) for storage accounts or SQL databases.
- Enforces encryption standards.
- Can require CMK usage.
- Audits for non-compliance.
- Denies non-compliant resource creation.
Memory trick: Policy dictates the encryption keys your Azure resources must obey.