Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard

An organization is migrating an on-premises legacy application that uses a custom encryption mechanism for its data to Azure. The application must continue to use its existing encryption keys, which are stored in a Hardware Security Module (HSM) on-premises. The security architect needs to design a solution that allows the Azure-hosted application to securely access and use these HSM-protected keys for encryption/decryption operations without exposing them directly to Azure. Which Azure service and feature combination should be recommended?

  1. AImport the custom encryption keys into Azure Key Vault (Standard tier).
  2. BUse Azure Key Vault Premium tier to import or generate HSM-protected keys, and integrate with the application.
  3. CImplement Azure Disk Encryption for the application's virtual machines.
  4. DMigrate the application to Azure SQL Database with Always Encrypted, using service-managed keys.
Show answer & explanation

Correct answer: B. Use Azure Key Vault Premium tier to import or generate HSM-protected keys, and integrate with the application.

Azure Key Vault Premium tier supports HSM-backed keys, allowing the import of existing HSM-protected keys or generating new ones within an Azure HSM. This meets the requirement of using HSM-protected keys and integrating with the Azure application securely.

Why the other options are wrong

  • A. Azure Key Vault Standard tier does not offer HSM-backed keys for customer control; it uses software-backed keys. Importing custom keys without HSM protection would not meet the requirement.
  • C. Azure Disk Encryption encrypts OS and data disks for VMs but does not manage application-level encryption keys or integrate with a custom encryption mechanism requiring HSM-protected keys.
  • D. Always Encrypted is for SQL databases, not general application encryption, and 'service-managed keys' would not use the organization's existing HSM-protected keys.

Azure Key Vault Premium Tier

A service tier of Azure Key Vault that provides FIPS 140-2 Level 2 validated hardware security modules (HSMs) for cryptographic key protection, offering enhanced security and compliance.

  • Supports 'Bring Your Own Key' (BYOK) to import HSM-protected keys.
  • Keys are always stored and processed within HSM boundaries.
  • Required for high-security applications and strict compliance needs.

Memory trick: Premium Key Vault for your BYOK HSM Needs.

More Design security for applications and data questions