Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An organization stores business records in an Azure Storage account. By default, Azure automatically encrypts all data at rest using Microsoft-managed keys. To satisfy strict regulatory compliance requirements, the security team must retain full control over the encryption keys used for encrypting and decrypting data.
Which service should the organization use to store and control customer-managed keys for storage encryption?
Azure Key Vault is a centralized cloud service for securely storing, managing, and controlling access to application secrets, cryptographic keys, and digital certificates. It provides hardware security module (HSM) backed protection and robust access policies to safeguard critical credentials and cryptographic material.
When configuring Azure Storage encryption for data at rest, organizations can choose between Microsoft-managed keys (the default) and customer-managed keys (CMK). By integrating Azure Storage with Azure Key Vault, organizations can create, store, and manage their own encryption keys. This ensures that the organization maintains direct ownership and oversight of the keys used to encrypt and decrypt stored blob and file data.
Azure Key Vault is the native and optimal solution in Microsoft Azure for managing customer-managed encryption keys. It seamlessly coordinates with Azure Storage to provide envelope encryption, allowing automated data protection while leaving key governance entirely under administrative control.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.