Microsoft Certified: Azure Developer Associate (AZ-204)Develop for Azure storageMedium
A company is developing a new application that will store highly sensitive customer data, including personally identifiable information (PII), in Azure Blob Storage. The company has a strict security policy requiring that all data at rest be encrypted using customer-managed keys (CMK) for enhanced control and compliance. The application will use a .NET SDK to interact with Azure Blob Storage.
- AConfigure the storage account to use customer-managed keys from Azure Key Vault and assign a default encryption scope.
- BEnable Azure Storage Service Encryption (SSE) with platform-managed keys on the storage account.
- CSet the default encryption scope on the storage account to use a Microsoft-managed key.
- DImplement client-side encryption in the application before uploading data to Azure Blob Storage.
Show answer & explanationAnswer & explanation
Correct answer: A. Configure the storage account to use customer-managed keys from Azure Key Vault and assign a default encryption scope.
To meet the requirement of using customer-managed keys (CMK) for data at rest encryption in Azure Blob Storage, the storage account must be configured to integrate with Azure Key Vault. Assigning a default encryption scope ensures that all new blobs uploaded without specifying an encryption scope will automatically use the CMK.
Why the other options are wrong
- B. This option uses platform-managed keys, which does not meet the requirement for customer-managed keys.
- C. This option uses Microsoft-managed keys, which does not meet the requirement for customer-managed keys.
- D. While client-side encryption uses customer keys, the requirement specifies encrypting 'data at rest' using CMK, which typically refers to server-side encryption with CMK managed by Azure Storage.
Azure Storage Customer-Managed Keys (CMK)
Customer-managed keys (CMK) allow you to use your own encryption keys from Azure Key Vault to encrypt data at rest in Azure Storage, providing greater control over your encryption keys.
- Keys are stored and managed in Azure Key Vault.
- Provides enhanced control over encryption key lifecycle.
- Applies to data at rest encryption for Azure Blob, File, Table, and Queue storage.
Memory trick: Customer's Keys (CMK) give Control.