Microsoft Azure Fundamentals (AZ-900)Describe Azure architecture and servicesHard

A healthcare organization is migrating patient data to Azure. Due to strict regulatory compliance requirements, they need to ensure that all data at rest in Azure Storage accounts is encrypted by default and that they have control over the encryption keys. Which Azure Storage encryption option should they choose?

  1. AStorage Service Encryption (SSE) with Customer-Managed Keys (CMK)
  2. BClient-Side Encryption
  3. CAzure Disk Encryption
  4. DAzure Key Vault only
Show answer & explanation

Correct answer: A. Storage Service Encryption (SSE) with Customer-Managed Keys (CMK)

Storage Service Encryption (SSE) with Customer-Managed Keys (CMK) allows Azure Storage to encrypt data at rest using encryption keys that you create and manage in Azure Key Vault. This gives the organization full control over the encryption keys while Azure handles the encryption and decryption processes, satisfying both default encryption and key control requirements.

Why the other options are wrong

  • B. Client-Side Encryption requires the application to encrypt data before sending it to Azure, which doesn't guarantee 'all data at rest in Azure Storage accounts is encrypted by default' by the storage service itself.
  • C. Azure Disk Encryption is for encrypting OS and data disks used by Azure Virtual Machines, not for data within Azure Storage Accounts (blobs, files, queues, tables).
  • D. Azure Key Vault is a service for managing cryptographic keys, but it doesn't itself encrypt storage data. It's used in conjunction with other services like SSE with CMK.

Storage Service Encryption (SSE) with CMK

A feature of Azure Storage that encrypts data at rest by default using Microsoft-managed keys (MMK) or customer-managed keys (CMK) stored in Azure Key Vault, providing control over encryption keys.

  • Encrypts data at rest in Azure Storage
  • Can use Microsoft-managed keys (default)
  • Can use Customer-managed keys (CMK) via Key Vault
  • Ensures compliance and data sovereignty

Memory trick: Encrypting storage is like putting your data in a safe, with keys you control.

More Describe Azure architecture and services questions