Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium
A financial services company is developing a highly sensitive document management system using Azure Blob Storage. Compliance regulations require that all data at rest in the storage account must be encrypted using encryption keys that are managed and controlled solely by the customer, not by Microsoft. This includes the ability to revoke access to the keys at any time. Which encryption solution should be implemented for the Azure Storage account?
- AClient-side encryption
- BCustomer-managed keys (CMK) in Azure Key Vault
- CMicrosoft-managed keys (MMK)
- DStorage Service Encryption (SSE) with platform-managed keys
Show answer & explanationAnswer & explanation
Correct answer: B. Customer-managed keys (CMK) in Azure Key Vault
Customer-managed keys (CMK) in Azure Key Vault allow customers to control their encryption keys, including the ability to revoke access. This directly addresses the requirement for customer-managed control over encryption keys for data at rest, unlike Microsoft-managed keys or client-side encryption which has different management implications.
Why the other options are wrong
- A. Client-side encryption encrypts data before it's uploaded to Azure Storage. While it offers customer control, it shifts the encryption/decryption burden to the application and doesn't directly manage the 'at rest' encryption of the storage account itself in the same way CMK does for the platform.
- C. Microsoft-managed keys (MMK) are the default for Azure Storage Service Encryption and are managed by Microsoft, failing the 'customer-controlled' requirement.
- D. Storage Service Encryption (SSE) with platform-managed keys is synonymous with Microsoft-managed keys (MMK), thus not meeting the customer control requirement.
Customer-managed keys (CMK)
Encryption keys generated and owned by the customer, stored securely in Azure Key Vault, used by Azure services to encrypt data at rest.
- Provides complete control over the key lifecycle, including rotation and revocation.
- Meets strict compliance requirements for key ownership and management.
- Azure services use these keys to encrypt/decrypt data, but the keys remain under customer control.
Memory trick: Customer's keys unlock their data vault, not Microsoft's.