Microsoft Certified: Fabric Analytics Engineer AssociateGovern and administer Fabric (10-15%)Hard

A company is migrating its data analytics workloads to Microsoft Fabric. They have a strict policy that all sensitive data must be encrypted at rest using customer-managed keys (CMK) for enhanced security and compliance. How can the Fabric administrator ensure that all data stored in Fabric workspaces associated with a specific F-SKU capacity is encrypted using CMK?

  1. AConfigure CMK encryption at the individual Lakehouse or Data Warehouse item level.
  2. BImplement CMK encryption via Azure Policy assignments for Fabric resources.
  3. CEnable Azure Storage account CMK encryption for the underlying OneLake storage.
  4. DAssign an Azure Key Vault key to the Fabric capacity in the Admin portal.
Show answer & explanation

Correct answer: D. Assign an Azure Key Vault key to the Fabric capacity in the Admin portal.

Customer-managed keys (CMK) for Microsoft Fabric are configured at the capacity level. By assigning an Azure Key Vault key to a Fabric capacity in the Admin portal, all data stored within that capacity's OneLake storage will be encrypted using the specified CMK, fulfilling the requirement.

Why the other options are wrong

  • A. Fabric does not currently support configuring CMK encryption at the individual item (Lakehouse/Data Warehouse) level; it's managed at the capacity level.
  • B. While Azure Policy can enforce certain configurations, the actual CMK setup for Fabric is performed directly on the capacity in the Fabric Admin portal, not solely via policy assignment.
  • C. OneLake storage is an integral part of Fabric and does not expose a separate Azure Storage account for direct CMK configuration by customers.

Fabric Customer-Managed Keys (CMK)

Customer-Managed Keys (CMK) in Microsoft Fabric allow organizations to use their own encryption keys from Azure Key Vault to encrypt data at rest within Fabric capacities, enhancing security and compliance.

  • Configured at the Fabric capacity level.
  • Uses Azure Key Vault for key management.
  • Encrypts all data at rest within the associated capacity.

Memory trick: CMK for Fabric is like giving your 'Master Key' from Azure Key Vault to unlock your Fabric 'Data Vault'.

More Govern and administer Fabric (10-15%) questions