Microsoft Certified: Azure Administrator AssociateImplement and manage storageEasy

A security auditor requires that all Azure storage accounts containing sensitive data must be encrypted with 256-bit AES encryption at rest. Additionally, the encryption keys must be managed by the customer. You need to configure a new storage account to meet these requirements.

  1. ACreate a General-purpose v2 storage account and enable Azure Storage Service Encryption (SSE) with Microsoft-managed keys.
  2. BCreate a General-purpose v2 storage account and configure encryption with customer-managed keys (CMK) from Azure Key Vault.
  3. CCreate a General-purpose v1 storage account and configure encryption with customer-managed keys (CMK) from Azure Key Vault.
  4. DCreate a Premium block blob storage account and enable Azure Storage Service Encryption (SSE) with Microsoft-managed keys.
Show answer & explanation

Correct answer: B. Create a General-purpose v2 storage account and configure encryption with customer-managed keys (CMK) from Azure Key Vault.

All Azure Storage accounts inherently use 256-bit AES encryption at rest (Azure Storage Service Encryption). The key requirement here is that the encryption keys must be customer-managed. This is achieved by configuring the storage account to use Customer-Managed Keys (CMK) from Azure Key Vault.

Why the other options are wrong

  • A. Microsoft-managed keys do not meet the customer-managed key (CMK) requirement.
  • C. GPv1 is a legacy account and while it supports CMK, GPv2 is the recommended and more feature-rich account type for new deployments.
  • D. Premium block blob storage accounts also use SSE, but Microsoft-managed keys do not meet the CMK requirement.

Customer-Managed Keys (CMK)

Customer-Managed Keys (CMK) allow you to use your own encryption keys from Azure Key Vault to encrypt data at rest in Azure Storage, providing greater control over the encryption process.

  • Keys are stored and managed in Azure Key Vault (or Key Vault Managed HSM).
  • Provides an additional layer of encryption over Microsoft-managed keys.
  • You control the lifecycle of the encryption keys (creation, rotation, revocation).
  • Supported for General-purpose v2 (GPv2) and Blob storage accounts.

Memory trick: Encryption: SSE is default, CMK gives control, HSM for hardware.

More Implement and manage storage questions