Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium
A media company uses Azure Blob Storage to store large volumes of video assets. They require that all new and existing blobs are encrypted using a customer-managed key (CMK) from Azure Key Vault. This CMK must be automatically rotated every 90 days to meet compliance requirements, and the encryption scope should apply to the entire storage account. Which configuration should you implement?
- AConfigure the storage account to use service-managed keys with a 90-day retention policy.
- BImplement client-side encryption for all uploaded blobs and manage keys in a separate application.
- CEnable customer-managed keys on the storage account, linking to an Azure Key Vault key with auto-rotation enabled.
- DCreate an encryption scope with a service-managed key and apply it to the storage account.
Show answer & explanationAnswer & explanation
Correct answer: C. Enable customer-managed keys on the storage account, linking to an Azure Key Vault key with auto-rotation enabled.
Enabling customer-managed keys on the storage account, linked to an Azure Key Vault key with auto-rotation, directly addresses all requirements. This ensures CMK usage for all blobs, leverages Azure Key Vault for secure key management, and allows for automatic key rotation every 90 days as per compliance.
Why the other options are wrong
- A. Service-managed keys do not meet the customer-managed key requirement. Retention policies are unrelated to encryption key management.
- B. Client-side encryption places the burden of key management and rotation on the application, which is less scalable and secure than using Azure Key Vault's integrated CMK with auto-rotation.
- D. An encryption scope can be used, but specifying a service-managed key does not meet the customer-managed key requirement.
Storage Account CMK with Auto-rotation
Configuring an Azure Storage account to use Customer-Managed Keys (CMK) stored in Azure Key Vault, with the Key Vault key configured for automatic rotation, ensuring enhanced security and compliance.
- Encrypts all data at rest in the storage account.
- Customer retains full control over the encryption key lifecycle.
- Azure Key Vault automatically rotates the key at a defined interval (e.g., 90 days).
- Applies to Blobs, Files, Queues, and Tables.
Memory trick: Keep your storage data locked with your key, and let it turn itself over regularly.