Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium
A company is migrating an application that uses a custom-built certificate authority (CA) to sign internal certificates. They need to manage these certificates securely within Azure and integrate them with Azure-hosted applications without exposing the private keys. Which Azure service should be used to import and manage these custom CA-signed certificates?
- AAzure Active Directory
- BAzure DNS
- CAzure Key Vault
- DAzure CDN
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Key Vault
Azure Key Vault is the appropriate service for securely storing and managing certificates, including those issued by a custom CA. It allows you to import certificates (including their private keys, securely) and integrate them with Azure applications, ensuring the private keys are protected.
Why the other options are wrong
- A. Azure Active Directory (now Microsoft Entra ID) is an identity and access management service, not for storing cryptographic certificates.
- B. Azure DNS is a hosting service for DNS domains, not for certificate management.
- D. Azure CDN (Content Delivery Network) is used for content delivery and caching, not certificate management.
Key Vault Certificate Management
Azure Key Vault provides a secure way to store and manage X.509 certificates, including those issued by custom Certificate Authorities, enabling their use by Azure applications.
- Supports importing certificates with private keys.
- Integrates with Azure services for certificate consumption.
- Manages certificate lifecycle (renewal, expiration alerts).
- Provides secure, centralized storage for certificates.
Memory trick: Key Vault: Your custom certs' secure home in the cloud.