Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionHard

A company is migrating an application that uses a custom-built certificate authority (CA) for issuing SSL/TLS certificates to its internal services. They want to integrate this existing CA with Azure to provision and manage certificates for Azure resources, such as Azure Application Gateways and Azure Front Door, while maintaining control over the private keys. Which Azure Key Vault feature enables this integration?

  1. AKey management
  2. BManaged HSM
  3. CCertificate management with integrated CA
  4. DSecrets management
Show answer & explanation

Correct answer: C. Certificate management with integrated CA

Azure Key Vault's certificate management feature allows integration with both Microsoft's trusted CAs and non-integrated CAs. By configuring a certificate issuer in Key Vault for a custom CA, you can then use Key Vault to enroll, renew, and manage certificates issued by that CA, while Key Vault handles the key generation and secure storage.

Why the other options are wrong

  • A. Key management focuses on cryptographic keys, but certificate management specifically handles the full lifecycle of certificates, including integration with CAs.
  • B. Managed HSM provides dedicated, FIPS 140-2 Level 3 validated HSMs for cryptographic keys, but doesn't directly manage certificate lifecycle with external CAs.
  • D. Secrets management is for storing arbitrary secrets like passwords and connection strings, not for managing the lifecycle of certificates with a CA.

Key Vault Certificate Management with Custom CA

Azure Key Vault can integrate with an organization's existing Certificate Authority (CA) to automate the enrollment, renewal, and deployment of certificates for Azure services and applications.

  • Supports integration with various CAs (e.g., DigiCert, GlobalSign, or custom CAs).
  • Automates certificate lifecycle from issuance to renewal.
  • Securely stores certificate private keys within Key Vault.

Memory trick: Key Vault is your certificate's personal assistant, even with custom CAs.

More Implement platform protection questions