Microsoft Azure Administrator Associate AZ-104 Practice Question
You are an Azure administrator for a company that requires all data stored in Azure Storage Accounts to be encrypted using customer-managed keys stored in Azure Key Vault. The company policy mandates that the encryption key is rotated every 90 days. You need to configure a Storage Account to meet these requirements. Which of the following steps should you perform?
Disable encryption on the Storage Account and configure the application to encrypt data before storing it
Enable Infrastructure Encryption for the Storage Account and select the customer-managed key from Key Vault
Set the default encryption key to a customer-managed key in Key Vault and configure a key rotation policy
Create a Key Vault, generate a key, and set the Storage Account to use service-managed keys in the Key Vault
To meet the requirements, you should set the Storage Account's default encryption key to a customer-managed key stored in Azure Key Vault and configure a key rotation policy. This allows the Storage Account to use the specified key from Key Vault for encryption, and setting up a rotation policy in Key Vault ensures the key is rotated every 90 days. Enabling Infrastructure Encryption adds a second layer of encryption with service-managed keys, which does not satisfy the requirement for customer-managed keys. Disabling encryption on the Storage Account is not possible, as encryption at rest is mandatory in Azure. Using service-managed keys does not meet the requirement to use customer-managed keys.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are customer-managed keys and how do they differ from service-managed keys?
Open an interactive chat with Bash
What is Azure Key Vault used for?
Open an interactive chat with Bash
What are the implications of key rotation and why is it important?
Open an interactive chat with Bash
Microsoft Azure Administrator Associate AZ-104
Implement and manage storage
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access