Microsoft Certified: Azure Developer Associate (AZ-204)Develop for Azure storageMedium

A company is developing a new application that will store highly sensitive customer data, including personally identifiable information (PII), in Azure Blob Storage. The company has a strict security policy requiring that all data at rest be encrypted using customer-managed keys (CMK) for enhanced control and compliance. The application will use a .NET SDK to interact with Azure Blob Storage.

  1. AConfigure the storage account to use customer-managed keys from Azure Key Vault and assign a default encryption scope.
  2. BEnable Azure Storage Service Encryption (SSE) with platform-managed keys on the storage account.
  3. CSet the default encryption scope on the storage account to use a Microsoft-managed key.
  4. DImplement client-side encryption in the application before uploading data to Azure Blob Storage.
Show answer & explanation

Correct answer: A. Configure the storage account to use customer-managed keys from Azure Key Vault and assign a default encryption scope.

To meet the requirement of using customer-managed keys (CMK) for data at rest encryption in Azure Blob Storage, the storage account must be configured to integrate with Azure Key Vault. Assigning a default encryption scope ensures that all new blobs uploaded without specifying an encryption scope will automatically use the CMK.

Why the other options are wrong

  • B. This option uses platform-managed keys, which does not meet the requirement for customer-managed keys.
  • C. This option uses Microsoft-managed keys, which does not meet the requirement for customer-managed keys.
  • D. While client-side encryption uses customer keys, the requirement specifies encrypting 'data at rest' using CMK, which typically refers to server-side encryption with CMK managed by Azure Storage.

Azure Storage Customer-Managed Keys (CMK)

Customer-managed keys (CMK) allow you to use your own encryption keys from Azure Key Vault to encrypt data at rest in Azure Storage, providing greater control over your encryption keys.

  • Keys are stored and managed in Azure Key Vault.
  • Provides enhanced control over encryption key lifecycle.
  • Applies to data at rest encryption for Azure Blob, File, Table, and Queue storage.

Memory trick: Customer's Keys (CMK) give Control.

More Develop for Azure storage questions