Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard
An organization is migrating an on-premises legacy application that uses a custom encryption mechanism for its data to Azure. The application must continue to use its existing encryption keys, which are stored in a Hardware Security Module (HSM) on-premises. The security architect needs to design a solution that allows the Azure-hosted application to securely access and use these HSM-protected keys for encryption/decryption operations without exposing them directly to Azure. Which Azure service and feature combination should be recommended?
- AImport the custom encryption keys into Azure Key Vault (Standard tier).
- BUse Azure Key Vault Premium tier to import or generate HSM-protected keys, and integrate with the application.
- CImplement Azure Disk Encryption for the application's virtual machines.
- DMigrate the application to Azure SQL Database with Always Encrypted, using service-managed keys.
Show answer & explanationAnswer & explanation
Correct answer: B. Use Azure Key Vault Premium tier to import or generate HSM-protected keys, and integrate with the application.
Azure Key Vault Premium tier supports HSM-backed keys, allowing the import of existing HSM-protected keys or generating new ones within an Azure HSM. This meets the requirement of using HSM-protected keys and integrating with the Azure application securely.
Why the other options are wrong
- A. Azure Key Vault Standard tier does not offer HSM-backed keys for customer control; it uses software-backed keys. Importing custom keys without HSM protection would not meet the requirement.
- C. Azure Disk Encryption encrypts OS and data disks for VMs but does not manage application-level encryption keys or integrate with a custom encryption mechanism requiring HSM-protected keys.
- D. Always Encrypted is for SQL databases, not general application encryption, and 'service-managed keys' would not use the organization's existing HSM-protected keys.
Azure Key Vault Premium Tier
A service tier of Azure Key Vault that provides FIPS 140-2 Level 2 validated hardware security modules (HSMs) for cryptographic key protection, offering enhanced security and compliance.
- Supports 'Bring Your Own Key' (BYOK) to import HSM-protected keys.
- Keys are always stored and processed within HSM boundaries.
- Required for high-security applications and strict compliance needs.
Memory trick: Premium Key Vault for your BYOK HSM Needs.