Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataEasy
A financial services organization is designing a new customer-facing web application that will handle sensitive personal and financial information. The security architect needs to ensure that all data exchanged between the application and the client browsers is encrypted using TLS/SSL certificates managed securely. The certificates must be automatically renewed and centrally managed with robust access control. Which Azure service should be used to manage these certificates?
- AAzure Security Center
- BAzure Key Vault
- CAzure Storage Account
- DAzure App Service Certificates
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Key Vault
Azure Key Vault is designed for securely storing and managing cryptographic keys, secrets, and certificates, including automated renewal and centralized management with fine-grained access controls.
Why the other options are wrong
- A. Azure Security Center (now Defender for Cloud) provides cloud security posture management, not certificate management.
- C. Azure Storage Account is for storing data, not for managing cryptographic certificates.
- D. Azure App Service Certificates are specific to App Service and offer some management, but Key Vault is the central, robust solution for all applications.
Azure Key Vault
A cloud service for securely storing and accessing secrets, such as API keys, passwords, certificates, and cryptographic keys, with centralized management and robust access control.
- Secure storage for secrets, keys, and certificates.
- Centralized management and access control.
- Supports automated certificate renewal.
Memory trick: Key Vault is the safe deposit box for your cloud secrets.