Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium
A financial institution is migrating its legacy on-premises applications to Azure. One critical application uses a custom encryption module that relies on hardware security modules (HSMs) for key generation and cryptographic operations. The organization has a strict compliance requirement that mandates FIPS 140-2 Level 3 validated HSMs for all key management. Which Azure Key Vault tier should the security architect recommend to meet this specific compliance and hardware-backed key requirement?
- APremium
- BStandard
- CDeveloper
- DBasic
Show answer & explanationAnswer & explanation
Correct answer: A. Premium
Azure Key Vault Premium tier supports FIPS 140-2 Level 2 validated HSMs for cryptographic operations and offers FIPS 140-2 Level 3 validated HSMs for key generation and protection, meeting the strict compliance requirement for hardware-backed keys.
Why the other options are wrong
- B. Standard tier uses software-backed keys and does not offer FIPS 140-2 Level 3 protection for keys.
- C. Developer tier is not a real Azure Key Vault tier; it's often used metaphorically for basic testing.
- D. Basic tier is not a real Azure Key Vault tier; the lowest actual tier is Standard.
Azure Key Vault Premium Tier
The Azure Key Vault Premium tier provides hardware security module (HSM) backed keys (FIPS 140-2 Level 2 validated) and supports importing or generating keys within FIPS 140-2 Level 3 validated HSMs.
- Offers FIPS 140-2 Level 3 validated HSMs for key protection.
- Suitable for highly regulated industries requiring strict key management.
- Higher cost due to dedicated HSM resources.
Memory trick: Premium is for top-tier, hardware-backed keys and compliance.