Microsoft Certified: Azure AI Engineer AssociatePlan and manage an Azure AI solutionMedium
A healthcare provider is developing an Azure AI solution to transcribe patient consultations using Azure Speech-to-Text. Due to the sensitive nature of the data, they need to ensure that all data at rest is encrypted with customer-managed keys (CMK) and that the encryption keys are stored in a highly secure hardware security module (HSM). Which Azure service should be used to manage these encryption keys?
- AAzure Security Center
- BAzure Active Directory
- CAzure Key Vault managed HSM
- DAzure Storage Account
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Key Vault managed HSM
Azure Key Vault managed HSM provides a fully managed, highly available, single-tenant, standards-compliant cloud service that safeguards cryptographic keys using FIPS 140-2 Level 3 validated HSMs, specifically designed for customer-managed keys (CMK).
Why the other options are wrong
- A. Azure Security Center (now Defender for Cloud) provides cloud security posture management and threat protection, not key management.
- B. Azure Active Directory is an identity and access management service, not for storing encryption keys.
- D. Azure Storage Account stores data, but not the encryption keys themselves, especially not CMK in HSMs.
Azure Key Vault Managed HSM
A fully managed, highly available, single-tenant, standards-compliant cloud service that safeguards cryptographic keys using FIPS 140-2 Level 3 validated hardware security modules (HSMs).
- Provides dedicated HSMs for customer-managed keys.
- FIPS 140-2 Level 3 validated for highest security.
- Ideal for meeting strict compliance requirements for key management.
Memory trick: Managed HSM locks keys in its secure vault.