Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium
A healthcare organization is designing a new cloud application that will process Protected Health Information (PHI) in Azure. The application's database will use Azure SQL Database. Regulatory compliance mandates that the data must be encrypted at rest using customer-managed keys (CMK) that are stored in a highly secure, FIPS 140-2 Level 3 validated hardware security module (HSM). Which Azure service should be used to store and manage these keys?
- AAzure Dedicated HSM
- BAzure Key Vault Managed HSM
- CAzure Key Vault Standard
- DAzure Storage Account with customer-managed keys
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Key Vault Managed HSM
Azure Key Vault Managed HSM provides a fully managed, single-tenant, highly available, and FIPS 140-2 Level 3 validated HSM service. This meets the stringent regulatory requirement for storing customer-managed keys for PHI with the specified FIPS level.
Why the other options are wrong
- A. Azure Dedicated HSM provides FIPS 140-2 Level 3 HSMs but is a bare-metal offering requiring more management overhead than a fully managed service.
- C. Azure Key Vault Standard is FIPS 140-2 Level 2 validated, not Level 3, and is multi-tenant.
- D. Azure Storage Account stores data, not keys at the required FIPS level. It uses Key Vault for CMK.
Azure Key Vault Managed HSM
A fully managed, highly available, single-tenant, standards-compliant cloud service that safeguards cryptographic keys.
- FIPS 140-2 Level 3 validated for cryptographic modules.
- Single-tenant HSMs provide complete cryptographic isolation.
- Simplifies compliance for highly regulated industries.
Memory trick: Managed HSM is the 'Gold Standard' for key protection.