Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is deploying a business workflow solution using Azure Platform as a Service (PaaS) capabilities. To satisfy strict corporate security and compliance mandates, the organization requires that all cryptographic keys and application secrets be stored in dedicated Hardware Security Modules (HSMs) validated to Federal Information Processing Standards (FIPS) 140, allowing the organization to maintain full control over key lifecycles with customer-managed keys.
Which Azure service should the organization implement to fulfill these key management and data protection requirements?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Azure Key Vault is a centralized cloud service designed for securely storing and managing application secrets, encryption keys, and TLS/SSL certificates. It provides robust security controls by safeguarding cryptographic keys and secrets within Hardware Security Modules (HSMs), ensuring sensitive configuration data and keys are not exposed in plaintext or embedded in application code.
Azure Key Vault is specifically engineered to manage encryption keys, secrets, and certificates securely while adhering to government and enterprise standards such as FIPS 140. It directly satisfies the scenario requirements by offering HSM-backed customer-controlled key protection.