Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planMedium
A healthcare organization is migrating its on-premises applications to Azure. They need to ensure that all data stored in Azure Storage Accounts (Blob, File, Queue, Table) is encrypted at rest using customer-managed keys (CMK) from Azure Key Vault. This is a strict regulatory requirement. Which Azure Storage encryption feature should be configured to meet this specific requirement?
- AAzure Disk Encryption (ADE) for Storage Accounts
- BAzure Storage Service Encryption (SSE) with Microsoft-managed keys
- CClient-Side Encryption for Azure Storage
- DAzure Storage Service Encryption (SSE) with customer-managed keys (CMK)
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Storage Service Encryption (SSE) with customer-managed keys (CMK)
Azure Storage Service Encryption (SSE) with customer-managed keys (CMK) allows you to use your own encryption keys stored in Azure Key Vault to encrypt data at rest in Azure Storage. This meets the requirement for CMK-based encryption for all data in Storage Accounts.
Why the other options are wrong
- A. Azure Disk Encryption (ADE) is for encrypting OS and data disks of Azure Virtual Machines, not for data within Azure Storage Accounts (Blobs, Files, Queues, Tables).
- B. SSE with Microsoft-managed keys is the default and does not meet the 'customer-managed keys' requirement.
- C. Client-Side Encryption encrypts data before it leaves the client, but the question implies a server-side encryption solution for the entire storage account, not just specific client operations.
Azure Storage CMK Encryption
Using customer-managed encryption keys, stored in Azure Key Vault, to encrypt data at rest within Azure Storage accounts.
- Leverages Azure Key Vault for key management.
- Provides greater control over encryption keys.
- Applies to Blob, File, Table, and Queue storage.
Memory trick: Encrypt your Storage like a Vault, with Keys you Control!