Microsoft Azure Fundamentals (AZ-900)Describe Azure architecture and servicesMedium
An organization is evaluating Azure for its compliance needs. They need to ensure that all data stored in Azure Blob Storage is encrypted at rest by default, without requiring any additional configuration from application developers. Which Azure storage security feature guarantees this baseline encryption?
- AAzure Disk Encryption
- BClient-side encryption
- CAzure Storage Service Encryption (SSE)
- DNetwork Security Groups (NSGs)
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Storage Service Encryption (SSE)
Azure Storage Service Encryption (SSE) automatically encrypts data at rest when it's written to Azure Blob Storage, ensuring compliance without requiring developers to implement encryption.
Why the other options are wrong
- A. Azure Disk Encryption is for encrypting OS and data disks for Azure Virtual Machines, not for Blob Storage.
- B. Client-side encryption requires developers to implement encryption before data is sent to Azure, which goes against the 'without requiring any additional configuration from application developers' clause.
- D. Network Security Groups (NSGs) filter network traffic and are not related to data encryption at rest.
Azure Storage Service Encryption (SSE)
A feature that automatically encrypts all data at rest in Azure Blob Storage, Azure Files, Azure Queue Storage, and Azure Table Storage, using Microsoft-managed keys or customer-managed keys.
- Encrypts data at rest automatically.
- No developer configuration required.
- Applies to Blob, Files, Queue, Table storage.
- Uses 256-bit AES encryption.
Memory trick: SSE is like an automatic vault for all your Azure storage data.