Microsoft Certified: Azure AI Engineer AssociatePlan and manage an Azure AI solutionMedium
A financial institution is developing an Azure AI solution that processes highly confidential customer financial documents using Azure Form Recognizer. Due to strict compliance regulations, all data must be encrypted at rest using customer-managed keys (CMK) in Azure Key Vault. Which encryption option should you configure for the Form Recognizer resource?
- AClient-side encryption before uploading documents.
- BTransport Layer Security (TLS) encryption for data in transit.
- CCustomer-managed keys (CMK) via Azure Key Vault.
- DDefault Microsoft-managed encryption keys.
Show answer & explanationAnswer & explanation
Correct answer: C. Customer-managed keys (CMK) via Azure Key Vault.
Customer-managed keys (CMK) in Azure Key Vault allow customers to control the encryption keys used to encrypt data at rest for Azure services. This meets the requirement for using customer-managed keys for compliance with strict regulations.
Why the other options are wrong
- A. Client-side encryption encrypts data before it leaves the client, but the question specifically asks for encryption of data at rest within Azure services using CMK, which is distinct.
- B. TLS encryption protects data in transit, not data at rest, and does not involve customer-managed keys for storage encryption.
- D. Microsoft-managed keys are enabled by default but do not meet the requirement for customer control over keys.
Azure Encryption Options
Azure offers various encryption options, including Microsoft-managed keys (default), customer-managed keys (CMK) for data at rest, and Transport Layer Security (TLS) for data in transit.
- CMK gives customers full control over encryption keys.
- CMK keys are stored in Azure Key Vault.
- Compliance requirements often mandate CMK.
Memory trick: CMK gives you the 'Key' to your data's 'Lock' at rest.