Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsHard

A global media company uses Azure Blob Storage to store large volumes of video assets. They require that encryption for these assets uses a customer-managed key (CMK) stored in Azure Key Vault. Furthermore, the company mandates that the CMK should automatically rotate without requiring manual intervention or downtime for the storage account. Which configuration combination ensures these requirements are met?

  1. AImplement Shared Access Signatures (SAS) with stored access policies.
  2. BConfigure an Azure Storage encryption scope with Customer-Managed Keys and enable auto-rotation.
  3. CEnable Microsoft Defender for Storage and configure encryption at rest with platform-managed keys.
  4. DEnable blob soft delete and configure a time-based retention policy.
Show answer & explanation

Correct answer: B. Configure an Azure Storage encryption scope with Customer-Managed Keys and enable auto-rotation.

An Azure Storage encryption scope allows granular control over encryption settings, including using Customer-Managed Keys (CMK) from Azure Key Vault. Crucially, when configuring CMK for a storage account, you can enable automatic key rotation, which integrates with Key Vault's key rotation capabilities to ensure the CMK is updated automatically without manual intervention or downtime.

Why the other options are wrong

  • A. SAS tokens are for delegated access to storage resources, not for managing encryption keys.
  • C. Platform-managed keys (PMK) do not meet the customer-managed key requirement, and Defender for Storage is for threat protection, not encryption key management.
  • D. Soft delete and retention policies are for data protection against accidental deletion/modification, not encryption key management or rotation.

Storage Account CMK with Auto-rotation

Configuring an Azure Storage account to use Customer-Managed Keys (CMK) from Azure Key Vault, with an additional setting to automatically rotate the CMK. This ensures enhanced security and compliance without manual key management.

  • Uses customer-managed encryption keys for storage.
  • Keys stored in Azure Key Vault.
  • Automatically rotates CMK without downtime or manual effort.

Memory trick: CMK with auto-rotation is like having a 'smart lock' that changes its own key regularly.

More Secure data and applications questions