Microsoft Certified: Azure Solutions Architect ExpertDesign infrastructure solutionsHard
A healthcare provider is deploying a new application that will store highly sensitive patient health information (PHI) in Azure. Regulatory compliance requires that all encryption keys for this data are stored in a hardware security module (HSM) and are never exposed to software layers. The solution must provide exclusive access to the HSMs for the healthcare provider. Which Azure service should be used?
- AAzure Key Vault Standard
- BAzure Key Vault Premium
- CAzure Storage Account with Customer-Managed Keys
- DAzure Dedicated HSM
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Dedicated HSM
Azure Dedicated HSM provides FIPS 140-2 Level 3 validated HSMs that offer single-tenant, exclusive access to the customer. This ensures that encryption keys are stored directly in hardware and are never exposed to software, meeting stringent regulatory requirements for sensitive data like PHI. Key Vault Standard and Premium use shared HSMs or software-backed keys, which might not meet the 'exclusive access' and 'never exposed to software' requirements.
Why the other options are wrong
- A. Azure Key Vault Standard stores keys in software or shared HSMs, not dedicated HSMs with exclusive access.
- B. Azure Key Vault Premium uses FIPS 140-2 Level 2 validated HSMs, but they are shared, not dedicated and exclusively accessed by a single tenant.
- C. Azure Storage Account with Customer-Managed Keys relies on Key Vault (Standard or Premium) for key storage, which does not provide dedicated HSMs.
Azure Dedicated HSM
A cloud service that provides dedicated hardware security modules (HSMs) for cryptographic key protection, offering single-tenant, exclusive access.
- FIPS 140-2 Level 3 validated HSMs
- Single-tenant, exclusive access
- Keys never exposed to software layers
Memory trick: Dedicated HSM: Your own secure, physical key locker.