Microsoft Azure Fundamentals (AZ-900)Describe Azure architecture and servicesMedium

A financial institution needs to ensure that all data stored in Azure Blob Storage is encrypted at rest to comply with regulatory requirements. They want to use platform-managed keys for encryption. Which Azure security feature ensures this type of encryption for Blob Storage?

  1. AAzure Key Vault
  2. BAzure Storage Service Encryption
  3. CAzure Defender for Storage
  4. DAzure Disk Encryption
Show answer & explanation

Correct answer: B. Azure Storage Service Encryption

Azure Storage Service Encryption (SSE) automatically encrypts data at rest when it's written to Azure Blob Storage, Azure Files, and Azure Queue storage. By default, it uses Microsoft-managed keys, fulfilling the requirement for platform-managed encryption keys.

Why the other options are wrong

  • A. Azure Key Vault is used to manage customer-managed encryption keys, not for automatic platform-managed encryption.
  • C. Azure Defender for Storage provides threat protection for storage accounts, not data at rest encryption.
  • D. Azure Disk Encryption encrypts OS and data disks for Azure Virtual Machines, not Blob Storage.

Azure Storage Service Encryption (SSE)

A feature that automatically encrypts data at rest when it's written to Azure Blob Storage, Azure Files, Azure Queue storage, and Azure Table storage. It's enabled by default for all new storage accounts.

  • Encrypts data at rest automatically.
  • Uses 256-bit AES encryption.
  • Enabled by default for new storage accounts.
  • Can use Microsoft-managed keys (default) or customer-managed keys (via Key Vault).

Memory trick: Storage Service Encryption protects data at rest in storage.

More Describe Azure architecture and services questions