Microsoft Certified: Azure AI Engineer AssociatePlan and manage an Azure AI solutionMedium

A healthcare provider is developing an Azure AI solution to transcribe patient consultations using Azure Speech-to-Text. Due to the sensitive nature of the data, they need to ensure that all data at rest is encrypted with customer-managed keys (CMK) and that the encryption keys are stored in a highly secure hardware security module (HSM). Which Azure service should be used to manage these encryption keys?

  1. AAzure Security Center
  2. BAzure Active Directory
  3. CAzure Key Vault managed HSM
  4. DAzure Storage Account
Show answer & explanation

Correct answer: C. Azure Key Vault managed HSM

Azure Key Vault managed HSM provides a fully managed, highly available, single-tenant, standards-compliant cloud service that safeguards cryptographic keys using FIPS 140-2 Level 3 validated HSMs, specifically designed for customer-managed keys (CMK).

Why the other options are wrong

  • A. Azure Security Center (now Defender for Cloud) provides cloud security posture management and threat protection, not key management.
  • B. Azure Active Directory is an identity and access management service, not for storing encryption keys.
  • D. Azure Storage Account stores data, but not the encryption keys themselves, especially not CMK in HSMs.

Azure Key Vault Managed HSM

A fully managed, highly available, single-tenant, standards-compliant cloud service that safeguards cryptographic keys using FIPS 140-2 Level 3 validated hardware security modules (HSMs).

  • Provides dedicated HSMs for customer-managed keys.
  • FIPS 140-2 Level 3 validated for highest security.
  • Ideal for meeting strict compliance requirements for key management.

Memory trick: Managed HSM locks keys in its secure vault.

More Plan and manage an Azure AI solution questions