Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityHard
A company is developing a highly sensitive document processing application using Azure Kubernetes Service (AKS). The application processes confidential financial data, and regulatory compliance requires that all data at rest, including data stored in persistent volumes mounted to AKS pods, must be encrypted with customer-managed keys (CMK) from Azure Key Vault. Which solution should the developer implement to ensure that AKS persistent volumes are encrypted with CMK?
- AEnable encryption at host for the AKS node pools and configure a custom storage class with CMK for persistent volumes.
- BImplement client-side encryption within the application pods before writing data to volumes.
- CUtilize Azure Key Vault CSI Driver (Secrets Store CSI Driver) to mount secrets as volumes.
- DConfigure Azure Disk Encryption (ADE) on the underlying Virtual Machine Scale Sets used by AKS.
Show answer & explanationAnswer & explanation
Correct answer: A. Enable encryption at host for the AKS node pools and configure a custom storage class with CMK for persistent volumes.
To encrypt AKS persistent volumes (Azure Disks) with CMK, you need to configure a custom storage class that specifies the Key Vault key for encryption. Additionally, enabling 'encryption at host' for the node pools ensures that any temporary OS disks and data caches are also encrypted, providing comprehensive data at rest protection in line with strong compliance requirements.
Why the other options are wrong
- B. Client-side encryption is an option, but it places the burden on the application and doesn't guarantee that *all* data at rest in the persistent volume (e.g., if another process writes to it) is CMK-encrypted, nor does it address node-level encryption.
- C. The Azure Key Vault CSI Driver is for mounting secrets (like API keys) from Key Vault into pods as files or environment variables, not for encrypting persistent data volumes with CMK.
- D. ADE can encrypt VM disks, but it's not the primary or most integrated way to manage CMK for *persistent volumes* in AKS, which uses Azure Disk encryption at the storage account level. ADE is more for OS/data disks directly on VMs.
AKS Persistent Volume CMK Encryption
Encrypting Azure Disks used as persistent volumes in Azure Kubernetes Service (AKS) with customer-managed keys (CMK) stored in Azure Key Vault.
- Requires a custom Kubernetes StorageClass.
- The StorageClass references a Key Vault key and user-assigned managed identity.
- The managed identity needs 'Key Vault Crypto Service Encryption User' role on the Key Vault.
- Encryption at host can further enhance security for node-level data.
Memory trick: For AKS volumes, custom StorageClass and Encryption at Host handle CMK.