Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsMedium

A media company uses Azure Blob Storage to store large volumes of video assets. They need to ensure that all data written to the storage account is encrypted using a customer-managed key (CMK) from Azure Key Vault. This key must be rotated annually. Which configuration should be implemented for the Azure Storage account?

  1. AUse client-side encryption before uploading blobs.
  2. BConfigure encryption scope with a customer-managed key and auto-rotation.
  3. CEnable default encryption with Microsoft-managed keys.
  4. DEnable Azure Disk Encryption on the storage account.
Show answer & explanation

Correct answer: B. Configure encryption scope with a customer-managed key and auto-rotation.

Encryption scope allows granular control over encryption settings, including using customer-managed keys from Key Vault with auto-rotation, which directly meets the requirement for CMK and annual rotation.

Why the other options are wrong

  • A. Client-side encryption is an option, but it requires application-level changes and doesn't leverage the storage account's native CMK capabilities with auto-rotation.
  • C. Microsoft-managed keys are default and don't meet the CMK requirement.
  • D. Azure Disk Encryption is for Virtual Machine disks, not for Azure Blob Storage accounts.

Azure Storage Encryption Scope with CMK and auto-rotation

An Azure Storage feature that allows defining encryption settings (including using Customer-Managed Keys from Azure Key Vault) at a container or blob level, with the ability to automatically rotate the CMK.

  • Provides granular encryption control within a storage account.
  • Supports Customer-Managed Keys (CMK) from Azure Key Vault.
  • Can be configured for automatic key rotation to enhance security posture.

Memory trick: Encryption Scope: your key, your rules, auto-rotated.

More Secure data and applications questions