Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard

A global manufacturing company is migrating its legacy on-premises applications to Azure. One critical application relies on hardware security modules (HSMs) for cryptographic key storage and operations, requiring FIPS 140-2 Level 3 validated protection. The security architect needs to ensure that the migrated application can continue to use HSM-backed keys in Azure with equivalent or stronger security guarantees. Which Azure Key Vault tier should the architect recommend?

  1. AAzure Key Vault Basic
  2. BAzure Key Vault Premium
  3. CAzure Key Vault Standard
  4. DAzure Key Vault Managed HSM
Show answer & explanation

Correct answer: D. Azure Key Vault Managed HSM

Azure Key Vault Managed HSM provides full control over a dedicated, single-tenant, FIPS 140-2 Level 3 validated HSM. This directly meets the requirement for HSM-backed keys with strong cryptographic assurance, offering a dedicated and highly secure solution for migrating applications dependent on on-premises HSMs.

Why the other options are wrong

  • A. Azure Key Vault Basic is not a real tier; it's often used informally to refer to the Standard tier or minimal functionality, and certainly does not meet advanced HSM requirements.
  • B. Azure Key Vault Premium stores keys in hardware-backed HSMs (FIPS 140-2 Level 2), which is better than Standard but still does not provide the dedicated, single-tenant, FIPS 140-2 Level 3 protection of Managed HSM.
  • C. Azure Key Vault Standard stores keys in software-backed HSMs (FIPS 140-2 Level 1), which does not meet the FIPS 140-2 Level 3 requirement for dedicated hardware protection.

Azure Key Vault Managed HSM

A fully managed, highly available, single-tenant, FIPS 140-2 Level 3 validated hardware security module (HSM) service for storing and managing cryptographic keys.

  • Dedicated, single-tenant HSMs
  • FIPS 140-2 Level 3 validated
  • Full control over HSMs
  • Ideal for high-value keys and regulatory compliance

Memory trick: Managed HSM is your own 'private vault' of keys.

More Design security for applications and data questions