Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium

A financial institution is migrating its legacy on-premises applications to Azure. One critical application uses a custom encryption module that relies on hardware security modules (HSMs) for key generation and cryptographic operations. The organization has a strict compliance requirement that mandates FIPS 140-2 Level 3 validated HSMs for all key management. Which Azure Key Vault tier should the security architect recommend to meet this specific compliance and hardware-backed key requirement?

  1. APremium
  2. BStandard
  3. CDeveloper
  4. DBasic
Show answer & explanation

Correct answer: A. Premium

Azure Key Vault Premium tier supports FIPS 140-2 Level 2 validated HSMs for cryptographic operations and offers FIPS 140-2 Level 3 validated HSMs for key generation and protection, meeting the strict compliance requirement for hardware-backed keys.

Why the other options are wrong

  • B. Standard tier uses software-backed keys and does not offer FIPS 140-2 Level 3 protection for keys.
  • C. Developer tier is not a real Azure Key Vault tier; it's often used metaphorically for basic testing.
  • D. Basic tier is not a real Azure Key Vault tier; the lowest actual tier is Standard.

Azure Key Vault Premium Tier

The Azure Key Vault Premium tier provides hardware security module (HSM) backed keys (FIPS 140-2 Level 2 validated) and supports importing or generating keys within FIPS 140-2 Level 3 validated HSMs.

  • Offers FIPS 140-2 Level 3 validated HSMs for key protection.
  • Suitable for highly regulated industries requiring strict key management.
  • Higher cost due to dedicated HSM resources.

Memory trick: Premium is for top-tier, hardware-backed keys and compliance.

More Design security for applications and data questions