Microsoft Certified: Azure Administrator AssociateImplement and manage storageHard

A company requires that all data stored in Azure Blob Storage be encrypted at rest using a customer-managed key (CMK) from Azure Key Vault. The solution must ensure that the storage account cannot be accessed if the Key Vault key is revoked or deleted. You need to configure the storage account to meet this requirement.

  1. AConfigure the storage account to use a customer-managed key (CMK) from Azure Key Vault and enable Key Vault soft delete.
  2. BEnable Azure Storage Service Encryption (SSE) with a Microsoft-managed key and configure an Azure Policy.
  3. CEnable Azure Storage Service Encryption (SSE) with a Microsoft-managed key.
  4. DConfigure the storage account to use a customer-managed key (CMK) from Azure Key Vault and disable Key Vault soft delete and purge protection.
Show answer & explanation

Correct answer: D. Configure the storage account to use a customer-managed key (CMK) from Azure Key Vault and disable Key Vault soft delete and purge protection.

To ensure the storage account cannot be accessed if the Key Vault key is revoked or deleted, you must disable Key Vault soft delete and purge protection. When these features are disabled, deleting or revoking the key results in immediate and permanent loss of the key, rendering data encrypted with it inaccessible, thereby meeting the security requirement.

Why the other options are wrong

  • A. Enabling soft delete still allows recovery of the key, meaning the data could be made accessible again, which doesn't meet the requirement of immediate inaccessibility upon revocation/deletion.
  • B. Microsoft-managed keys do not meet the customer-managed key (CMK) requirement, and Azure Policy alone cannot enforce the immediate inaccessibility upon key deletion.
  • C. Microsoft-managed keys do not meet the customer-managed key (CMK) requirement.

Azure Key Vault Purge Protection

Purge protection in Azure Key Vault is a feature that prevents the permanent deletion (purging) of a key vault or its contents during the soft-delete retention period, even by privileged users. Disabling it allows immediate and permanent deletion.

  • Protects against accidental or malicious key deletion.
  • Works in conjunction with soft delete.
  • When enabled, keys cannot be purged until the soft-delete retention period expires.
  • Disabling it allows immediate, permanent deletion of keys and vaults.

Memory trick: Soft delete saves, purge protection guards, but disabling both ensures immediate data lockdown.

More Implement and manage storage questions