Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureHard

A company is designing a new cloud-native application that will process highly sensitive customer data. The application will use Azure Cosmos DB for its database. Due to regulatory requirements, all data in Cosmos DB must be encrypted at rest with keys that are owned and managed solely by the customer, including key generation and lifecycle management. Which Cosmos DB encryption option should be chosen?

  1. AClient-side encryption
  2. BService-managed encryption keys
  3. CTransport Layer Security (TLS) encryption
  4. DCustomer-managed keys (CMK) with Azure Key Vault
Show answer & explanation

Correct answer: D. Customer-managed keys (CMK) with Azure Key Vault

Customer-managed keys (CMK) with Azure Key Vault allows the customer to retain full control over the encryption keys for Cosmos DB data at rest, including key generation, rotation, and revocation, meeting the stringent requirement for sole customer ownership and management of keys.

Why the other options are wrong

  • A. Client-side encryption encrypts data before it reaches Cosmos DB, but the question implies encryption features at rest within the database itself, managed by the service but with customer keys.
  • B. Service-managed keys are managed by Azure, not the customer, failing the 'owned and managed solely by the customer' requirement.
  • C. TLS encryption protects data in transit, not data at rest with customer-managed keys.

Cosmos DB CMK with Key Vault

Azure Cosmos DB supports customer-managed keys (CMK) for data encryption at rest. This feature allows customers to encrypt their data using encryption keys stored in Azure Key Vault, providing full control over the key lifecycle, including generation, rotation, and revocation.

  • Customer retains full control over encryption keys.
  • Keys are stored and managed in Azure Key Vault.
  • Encrypts data at rest in Cosmos DB.
  • Enhances compliance for highly sensitive data.

Memory trick: CMK is Customer's Key, Service Manages its Own, Client Encrypts Before.

More Design security for infrastructure questions