Microsoft Certified: Azure Administrator AssociateImplement and manage storageMedium

A company is planning to deploy a new application that will store highly sensitive customer data in Azure Blob Storage. The company's security policy dictates that all data must be encrypted at rest using encryption keys that are managed and controlled solely by the company. You need to recommend a solution that meets this requirement.

  1. AEncrypt data client-side before uploading it to Azure Blob Storage.
  2. BUse Microsoft-managed keys with Storage Service Encryption (SSE).
  3. CImplement Customer-Managed Keys (CMK) using Azure Key Vault.
  4. DEnable infrastructure encryption on the storage account.
Show answer & explanation

Correct answer: C. Implement Customer-Managed Keys (CMK) using Azure Key Vault.

Customer-Managed Keys (CMK) allow organizations to use their own encryption keys, stored in Azure Key Vault, to encrypt data at rest in Azure storage services, fulfilling the requirement for company-controlled keys. This provides an additional layer of security and control beyond Microsoft-managed keys.

Why the other options are wrong

  • A. Client-side encryption can be used, but CMK provides at-rest encryption managed by Azure services with customer-controlled keys.
  • B. Microsoft-managed keys are the default and are not solely controlled by the company.
  • D. Infrastructure encryption adds another layer of encryption but still uses Microsoft-managed keys.

Customer-Managed Keys (CMK)

Customer-Managed Keys (CMK) allow Azure customers to use their own encryption keys from Azure Key Vault to encrypt data at rest for various Azure services, including Blob Storage.

  • Keys are stored and managed in Azure Key Vault.
  • Provides an additional layer of control over data encryption.
  • Can be rotated and revoked by the customer.

Memory trick: Keys Control Data's Fate.

More Implement and manage storage questions