Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityEasy

A financial institution is developing a new serverless application using Azure Functions. This application will process sensitive customer financial data and must comply with stringent regulatory requirements for data encryption at rest. Specifically, the institution requires that encryption keys for the Azure Storage Account used by the Function App are managed by the institution itself, not by Microsoft. Which Azure security feature should be implemented to meet this requirement?

  1. AAzure Key Vault secrets for connection strings
  2. BServer-side encryption with Microsoft-managed keys
  3. CCustomer-managed keys (CMK) for Azure Storage
  4. DAzure Disk Encryption
Show answer & explanation

Correct answer: C. Customer-managed keys (CMK) for Azure Storage

To meet the requirement of managing encryption keys for data at rest in Azure Storage, customer-managed keys (CMK) must be used. This allows the institution to control the lifecycle of the encryption keys stored in Azure Key Vault.

Why the other options are wrong

  • A. Azure Key Vault secrets for connection strings secures the connection string itself, but does not dictate the encryption key management for the data within the storage account.
  • B. Server-side encryption with Microsoft-managed keys is the default and does not meet the requirement for institution-managed keys.
  • D. Azure Disk Encryption is used for encrypting OS and data disks of Azure VMs, not for Azure Storage Accounts.

Customer-Managed Keys (CMK)

Customer-Managed Keys (CMK) for Azure Storage allows customers to manage their own encryption keys, typically stored in Azure Key Vault, for data at rest in Azure Storage, providing greater control over the encryption process.

  • Keys are stored and managed in Azure Key Vault.
  • Provides greater control over the encryption key lifecycle.
  • Applies to data at rest in Azure Storage, such as Blobs, Files, Queues, and Tables.

Memory trick: Keys for data: who holds the lock?

More Implement Azure security questions