Microsoft Certified: Azure Developer Associate (AZ-204)Develop for Azure storageMedium

A developer needs to store highly sensitive customer documents in Azure Blob Storage. These documents must be encrypted at rest and in transit. The company's security policy mandates that encryption keys must be managed by the customer, not by Microsoft. Which encryption option should the developer choose?

  1. AMicrosoft-managed keys for Azure Storage encryption
  2. BClient-side encryption with Azure Storage SDK
  3. CCustomer-managed keys with Azure Key Vault
  4. DEncryption scopes
Show answer & explanation

Correct answer: C. Customer-managed keys with Azure Key Vault

Customer-managed keys (CMK) with Azure Key Vault allow the customer to control the lifecycle of their encryption keys, satisfying the requirement that Microsoft does not manage them. Azure Storage still performs the encryption, but using keys provided by the customer.

Why the other options are wrong

  • A. Microsoft-managed keys do not meet the requirement for customer key management.
  • B. Client-side encryption encrypts data before it leaves the client, but the question implies encryption at rest managed by Azure, with customer control over keys.
  • D. Encryption scopes allow granular encryption settings but don't inherently dictate whether keys are customer-managed or Microsoft-managed; they can be used with both.

Azure Storage Customer-Managed Keys (CMK)

CMK allows customers to use their own encryption keys for data at rest in Azure Storage, stored in Azure Key Vault, providing full control over key lifecycle.

  • Keys are stored in Azure Key Vault.
  • Customer controls key creation, rotation, and revocation.
  • Azure Storage uses these keys for server-side encryption.

Memory trick: Think of encryption keys as house keys; who holds them determines control.

More Develop for Azure storage questions