Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium
A media company uses Azure Blob Storage to store large volumes of video assets. They need to ensure that all data written to the storage account is encrypted using a customer-managed key (CMK) from Azure Key Vault. This key must be rotated annually. Which configuration should be implemented for the Azure Storage account?
- AUse client-side encryption before uploading blobs.
- BConfigure encryption scope with a customer-managed key and auto-rotation.
- CEnable default encryption with Microsoft-managed keys.
- DEnable Azure Disk Encryption on the storage account.
Show answer & explanationAnswer & explanation
Correct answer: B. Configure encryption scope with a customer-managed key and auto-rotation.
Encryption scope allows granular control over encryption settings, including using customer-managed keys from Key Vault with auto-rotation, which directly meets the requirement for CMK and annual rotation.
Why the other options are wrong
- A. Client-side encryption is an option, but it requires application-level changes and doesn't leverage the storage account's native CMK capabilities with auto-rotation.
- C. Microsoft-managed keys are default and don't meet the CMK requirement.
- D. Azure Disk Encryption is for Virtual Machine disks, not for Azure Blob Storage accounts.
Azure Storage Encryption Scope with CMK and auto-rotation
An Azure Storage feature that allows defining encryption settings (including using Customer-Managed Keys from Azure Key Vault) at a container or blob level, with the ability to automatically rotate the CMK.
- Provides granular encryption control within a storage account.
- Supports Customer-Managed Keys (CMK) from Azure Key Vault.
- Can be configured for automatic key rotation to enhance security posture.
Memory trick: Encryption Scope: your key, your rules, auto-rotated.