Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsMedium

A healthcare provider is deploying a new application that will store highly sensitive patient data. The regulatory compliance requirements mandate that all data at rest must be encrypted using customer-managed keys (CMK) stored in a FIPS 140-2 Level 3 validated hardware security module (HSM). Which Azure service should be used to store and manage these encryption keys?

  1. AAzure Key Vault Premium
  2. BAzure Active Directory
  3. CAzure Dedicated HSM
  4. DAzure Storage Account
Show answer & explanation

Correct answer: C. Azure Dedicated HSM

Azure Dedicated HSM provides FIPS 140-2 Level 3 validated hardware security modules that are dedicated to a single customer. This meets the strict regulatory requirement for customer-managed keys in a hardware-isolated, high-assurance environment, which Azure Key Vault Premium does not fully cover at Level 3.

Why the other options are wrong

  • A. Azure Key Vault Premium uses FIPS 140-2 Level 2 validated HSMs, which does not meet the specified Level 3 requirement.
  • B. Azure Active Directory is an identity and access management service, not for storing encryption keys.
  • D. Azure Storage Account provides data storage, not key management or HSMs.

Azure Dedicated HSM

Azure Dedicated HSM provides dedicated physical hardware security modules (HSMs) for exclusive customer use, offering FIPS 140-2 Level 3 validated protection for cryptographic keys and operations.

  • Dedicated physical HSMs
  • FIPS 140-2 Level 3 validated
  • Highest level of hardware security for keys

Memory trick: Dedicated HSM is like a private vault, only for your most secret key, certified to the highest level.

More Design infrastructure solutions questions