Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planMedium
A global organization is implementing a new multi-region Azure deployment. They need to ensure that all data stored in Azure Storage Accounts is encrypted at rest and that customer-managed keys (CMK) are used for encryption, with the ability to revoke access to the keys at any time. Which specific Azure Key Vault feature is essential for meeting the 'revoke access' requirement for CMK?
- AKey Vault purge protection
- BKey Vault soft-delete
- CKey rotation
- DKey Vault access policies
Show answer & explanationAnswer & explanation
Correct answer: D. Key Vault access policies
Key Vault access policies (or Azure RBAC for Key Vault) control who or what (e.g., an Azure Storage Account's managed identity) can perform operations like 'Get' or 'Unwrap' on a key. To revoke access to a key, you modify or remove the relevant access policy entry for the Storage Account, effectively preventing it from using the key for encryption/decryption.
Why the other options are wrong
- A. Purge protection prevents immediate and permanent deletion of keys even after soft-delete, ensuring recoverability, but is not the mechanism for revoking active access.
- B. Soft-delete protects against accidental deletion of keys, allowing recovery, but doesn't directly control the revocation of *access* to an active key.
- C. Key rotation involves generating new key versions and retiring old ones, which is a key management practice, but revoking access to a *specific* key relies on access policies.
Key Vault Access Policies
Security settings in Azure Key Vault that define which users, groups, or applications (service principals/managed identities) have permissions to perform specific operations on keys, secrets, or certificates.
- Granular control over key operations (get, wrap, unwrap).
- Used to grant and revoke access to keys for services like Azure Storage.
- Can be configured with least privilege principles.
Memory trick: To 'Cut Key Access', adjust the Key Vault Access Policy.