Microsoft Certified: Azure Administrator AssociateImplement and manage storageEasy
A security auditor requires that all Azure storage accounts containing sensitive data must be encrypted with 256-bit AES encryption at rest. Additionally, the encryption keys must be managed by the customer. You need to configure a new storage account to meet these requirements.
- ACreate a General-purpose v2 storage account and enable Azure Storage Service Encryption (SSE) with Microsoft-managed keys.
- BCreate a General-purpose v2 storage account and configure encryption with customer-managed keys (CMK) from Azure Key Vault.
- CCreate a General-purpose v1 storage account and configure encryption with customer-managed keys (CMK) from Azure Key Vault.
- DCreate a Premium block blob storage account and enable Azure Storage Service Encryption (SSE) with Microsoft-managed keys.
Show answer & explanationAnswer & explanation
Correct answer: B. Create a General-purpose v2 storage account and configure encryption with customer-managed keys (CMK) from Azure Key Vault.
All Azure Storage accounts inherently use 256-bit AES encryption at rest (Azure Storage Service Encryption). The key requirement here is that the encryption keys must be customer-managed. This is achieved by configuring the storage account to use Customer-Managed Keys (CMK) from Azure Key Vault.
Why the other options are wrong
- A. Microsoft-managed keys do not meet the customer-managed key (CMK) requirement.
- C. GPv1 is a legacy account and while it supports CMK, GPv2 is the recommended and more feature-rich account type for new deployments.
- D. Premium block blob storage accounts also use SSE, but Microsoft-managed keys do not meet the CMK requirement.
Customer-Managed Keys (CMK)
Customer-Managed Keys (CMK) allow you to use your own encryption keys from Azure Key Vault to encrypt data at rest in Azure Storage, providing greater control over the encryption process.
- Keys are stored and managed in Azure Key Vault (or Key Vault Managed HSM).
- Provides an additional layer of encryption over Microsoft-managed keys.
- You control the lifecycle of the encryption keys (creation, rotation, revocation).
- Supported for General-purpose v2 (GPv2) and Blob storage accounts.
Memory trick: Encryption: SSE is default, CMK gives control, HSM for hardware.