Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium

A global manufacturing company is migrating its legacy on-premises applications to Azure. One critical application uses hardware security modules (HSMs) to protect cryptographic keys. The company requires a cloud solution that provides FIPS 140-2 Level 3 validated HSMs for key protection, ensuring that keys are never exposed outside the HSM boundary, even to Azure administrators. Which tier of Azure Key Vault should be recommended?

  1. ABasic tier
  2. BPremium tier
  3. CStandard tier
  4. DDeveloper tier
Show answer & explanation

Correct answer: B. Premium tier

Azure Key Vault Premium tier provides FIPS 140-2 Level 2 validated HSMs (and Level 3 if using Managed HSMs within Premium), ensuring that keys are processed and stored within hardware boundaries and are never exposed to any software layer or Azure administrators.

Why the other options are wrong

  • A. There is no 'Basic tier' for Azure Key Vault; it's typically Standard or Premium.
  • C. The Standard tier stores keys in software, not in FIPS validated HSMs.
  • D. There is no 'Developer tier' for Azure Key Vault; it's typically Standard or Premium.

Azure Key Vault Premium Tier

The Premium tier of Azure Key Vault provides enhanced security for cryptographic keys by storing them in FIPS 140-2 Level 2 validated hardware security modules (HSMs), ensuring keys are never exposed outside the HSM boundary.

  • Uses FIPS 140-2 Level 2 validated HSMs.
  • Keys are hardware-protected.
  • Keys never leave the HSM boundary.
  • Suitable for high-security and compliance requirements.

Memory trick: Premium Key Vault is like a reinforced safe for your keys, not just a regular box.

More Design security for applications and data questions