Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium
A security operations team utilizes Microsoft Sentinel and needs to ensure that all sensitive data within the Log Analytics workspace is encrypted at rest using customer-managed keys (CMK) for enhanced control and compliance. Where should the team configure this encryption setting?
- AIn the Azure Key Vault where the CMK is stored.
- BIn the Azure Storage account linked to Log Analytics.
- CIn the Microsoft Sentinel instance settings.
- DIn the Log Analytics workspace settings.
Show answer & explanationAnswer & explanation
Correct answer: D. In the Log Analytics workspace settings.
Customer-managed key (CMK) encryption for data at rest in Microsoft Sentinel is configured directly within the settings of the associated Log Analytics workspace. This is because all data ingested into Sentinel resides within that Log Analytics workspace.
Why the other options are wrong
- A. Azure Key Vault stores the CMK but is not where the encryption *is configured* for Log Analytics data.
- B. Log Analytics uses its own managed storage, not a directly linked, user-configurable Azure Storage account for primary data storage.
- C. Microsoft Sentinel instance settings focus on the SIEM's operational aspects, not the underlying data storage encryption.
Log Analytics Workspace Encryption (CMK)
Customer-managed key (CMK) encryption for Log Analytics workspaces allows organizations to use their own encryption keys from Azure Key Vault to protect data at rest, providing greater control over encryption keys.
- Configured at the Log Analytics workspace level.
- Requires an Azure Key Vault to store the CMK.
- Enhances security and compliance for data at rest.
Memory trick: Workspace: The Key to Your Data's Encryption!