Microsoft Certified: Azure Administrator AssociateImplement and manage storageEasy
A company is planning to implement Azure Blob Storage for storing large amounts of unstructured data. They have a strict requirement that all data at rest must be encrypted using customer-managed keys (CMK) stored in Azure Key Vault. Which encryption option should be configured for the storage account?
- AAzure Disk Encryption
- BCustomer-managed keys (CMK)
- CClient-side encryption
- DMicrosoft-managed keys (MMK)
Show answer & explanationAnswer & explanation
Correct answer: B. Customer-managed keys (CMK)
Customer-managed keys (CMK) allow organizations to use their own encryption keys, stored in Azure Key Vault, to encrypt data at rest in Azure Blob Storage, meeting the requirement for CMK.
Why the other options are wrong
- A. Azure Disk Encryption is used for encrypting virtual machine disks, not Azure Blob Storage.
- C. Client-side encryption encrypts data before it is uploaded to Azure, which is different from at-rest encryption managed by the storage account itself.
- D. Microsoft-managed keys are the default and do not meet the requirement for customer-managed keys.
Customer-Managed Keys (CMK)
Customer-managed keys allow you to use your own encryption keys in Azure Key Vault to encrypt data at rest in Azure storage services.
- Provides enhanced control over encryption keys.
- Keys are stored securely in Azure Key Vault.
- Used for data at rest encryption in services like Blob Storage.
Memory trick: Keys Control Everything for Secure Storage.