Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard
A global manufacturing company is migrating its legacy on-premises applications to Azure. One critical application relies on hardware security modules (HSMs) for cryptographic key storage and operations, requiring FIPS 140-2 Level 3 validated protection. The security architect needs to ensure that the migrated application can continue to use HSM-backed keys in Azure with equivalent or stronger security guarantees. Which Azure Key Vault tier should the architect recommend?
- AAzure Key Vault Basic
- BAzure Key Vault Premium
- CAzure Key Vault Standard
- DAzure Key Vault Managed HSM
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Key Vault Managed HSM
Azure Key Vault Managed HSM provides full control over a dedicated, single-tenant, FIPS 140-2 Level 3 validated HSM. This directly meets the requirement for HSM-backed keys with strong cryptographic assurance, offering a dedicated and highly secure solution for migrating applications dependent on on-premises HSMs.
Why the other options are wrong
- A. Azure Key Vault Basic is not a real tier; it's often used informally to refer to the Standard tier or minimal functionality, and certainly does not meet advanced HSM requirements.
- B. Azure Key Vault Premium stores keys in hardware-backed HSMs (FIPS 140-2 Level 2), which is better than Standard but still does not provide the dedicated, single-tenant, FIPS 140-2 Level 3 protection of Managed HSM.
- C. Azure Key Vault Standard stores keys in software-backed HSMs (FIPS 140-2 Level 1), which does not meet the FIPS 140-2 Level 3 requirement for dedicated hardware protection.
Azure Key Vault Managed HSM
A fully managed, highly available, single-tenant, FIPS 140-2 Level 3 validated hardware security module (HSM) service for storing and managing cryptographic keys.
- Dedicated, single-tenant HSMs
- FIPS 140-2 Level 3 validated
- Full control over HSMs
- Ideal for high-value keys and regulatory compliance
Memory trick: Managed HSM is your own 'private vault' of keys.