Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium

A financial institution is migrating its legacy on-premises applications to Azure. These applications handle sensitive customer financial data and require highly secure, FIPS 140-2 Level 3 validated cryptographic key storage. Which Azure Key Vault offering should the institution choose to meet this compliance requirement?

  1. AAzure Key Vault Standard tier
  2. BAzure Key Vault Basic tier
  3. CAzure Key Vault Premium tier
  4. DAzure Key Vault Managed HSM
Show answer & explanation

Correct answer: D. Azure Key Vault Managed HSM

Azure Key Vault Managed HSM (Hardware Security Module) provides FIPS 140-2 Level 3 validated hardware for cryptographic key storage. This level of validation is typically required for highly sensitive data and compliance standards in financial institutions.

Why the other options are wrong

  • A. Azure Key Vault Standard tier offers FIPS 140-2 Level 2 validated software modules, which is not sufficient for Level 3 compliance.
  • B. Azure Key Vault Basic tier is not a real Azure Key Vault offering; the standard tier is the entry-level option.
  • C. Azure Key Vault Premium tier offers FIPS 140-2 Level 2 validated hardware modules, which is not sufficient for Level 3 compliance.

Azure Key Vault Managed HSM

A fully managed, highly available, single-tenant, standards-compliant cloud service that safeguards cryptographic keys using FIPS 140-2 Level 3 validated Hardware Security Modules (HSMs).

  • Dedicated HSM instances for a single tenant.
  • FIPS 140-2 Level 3 validated hardware.
  • Provides enhanced security and compliance for cryptographic keys.
  • Suitable for highly regulated industries like finance.

Memory trick: Managed HSM: The highest vault for the highest standards.

More Design security for applications and data questions