Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsHard
A healthcare provider is deploying a new application that will store highly sensitive patient health information (PHI). The application uses Azure SQL Database. Regulatory compliance mandates that all encryption keys for the database must be stored in a FIPS 140-2 Level 3 validated hardware security module (HSM) and managed exclusively by the customer. Which Azure security feature should be implemented for this requirement?
- AAzure Dedicated HSM
- BTransparent Data Encryption (TDE) with Service-Managed Keys
- CAlways Encrypted with Secure Enclaves
- DAzure Key Vault with Customer-Managed Keys (CMK)
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Dedicated HSM
Azure Dedicated HSM provides FIPS 140-2 Level 3 validated HSMs that are provisioned directly to the customer. This gives the customer exclusive control over the encryption keys and hardware, meeting the stringent regulatory requirement for keys to be stored in and managed solely by the customer within a FIPS 140-2 Level 3 validated HSM.
Why the other options are wrong
- B. TDE with service-managed keys uses keys managed by Azure, which does not meet the requirement for keys to be managed exclusively by the customer in a FIPS 140-2 Level 3 validated HSM.
- C. Always Encrypted protects data in use and at rest, but the key management for this is typically through Key Vault or Windows Certificate Store, which may not meet the specific FIPS 140-2 Level 3 and exclusive customer management requirement for the master key.
- D. Azure Key Vault (even with CMK) uses shared HSMs (FIPS 140-2 Level 2 validated). While customers manage the keys, the underlying hardware is shared, and the FIPS level is not 3, failing to meet the 'FIPS 140-2 Level 3 validated hardware security module (HSM) and managed exclusively by the customer' requirement.
Azure Dedicated HSM
A cloud service that provides single-tenant physical hardware security modules (HSMs) for cryptographic key storage and operations.
- FIPS 140-2 Level 3 validated hardware.
- Exclusive customer control over HSMs and keys.
- Ideal for stringent regulatory compliance like PCI DSS, HIPAA.
Memory trick: Dedicated HSM: Your 'Dedicated' 'Key' 'Safe' at the highest 'Level'.