Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium

A security architect is designing a data protection strategy for highly sensitive data stored in Azure Blob Storage. The data needs to be encrypted at rest, and the encryption keys must be managed by the customer to meet stringent regulatory requirements. The solution should also allow for key rotation and revocation. Which encryption method should be used?

  1. AAzure Storage Service Encryption (SSE) with Microsoft-managed keys.
  2. BAzure Storage Service Encryption (SSE) with customer-managed keys (CMK) in Azure Key Vault.
  3. CAzure Disk Encryption for the storage account's underlying disks.
  4. DClient-side encryption before uploading to Blob Storage.
Show answer & explanation

Correct answer: B. Azure Storage Service Encryption (SSE) with customer-managed keys (CMK) in Azure Key Vault.

Azure Storage Service Encryption (SSE) with customer-managed keys (CMK) in Azure Key Vault allows the customer to fully control the encryption keys used for their data at rest in Blob Storage. This meets the requirement for customer-managed keys and enables key rotation and revocation capabilities through Key Vault.

Why the other options are wrong

  • A. SSE with Microsoft-managed keys encrypts data at rest, but the customer does not have control over the encryption keys, which violates the requirement for customer-managed keys.
  • C. Azure Disk Encryption is used for encrypting OS and data disks of Azure VMs. Azure Blob Storage is a PaaS service, and customers do not have direct access to or control over its underlying disks for encryption.
  • D. Client-side encryption allows the customer to manage keys, but it requires custom application development for encryption/decryption, which can be complex and may not integrate as seamlessly with Azure services as SSE with CMK.

Customer-Managed Keys (CMK) in Azure

A feature that allows customers to manage their own encryption keys for data at rest in Azure services, often using Azure Key Vault. This provides greater control over key lifecycle, including rotation and revocation, for compliance and security.

  • Customer controls encryption keys.
  • Keys stored securely in Azure Key Vault.
  • Enables key rotation and revocation.
  • Meets stringent regulatory and compliance requirements.

Memory trick: Customer-Managed Keys in Key Vault give you full control.

More Design security for infrastructure questions