Customer-Managed Keys — Microsoft Azure Solutions Architect (AZ-305) Practice Questions

Customer-managed keys (CMK) allow organizations to generate, own, and control the cryptographic keys used to encrypt Azure resources, rather than relying on Microsoft-managed keys. On AZ-305, this topic covers integrating Azure Key Vault or Azure Managed HSM with services such as Azure Storage, Azure SQL Database, Azure Disk Encryption, and Cosmos DB to enforce CMK-based encryption. Architects must understand the operational responsibilities that come with CMK, including key rotation schedules, access policy design to prevent accidental key deletion, and the impact on service availability if a key is disabled or expired. Exam questions test the ability to design a CMK architecture that satisfies regulatory requirements for key custody while maintaining resilience and minimizing administrative overhead.

Free questions on customer-managed keys

You need to ensure that sensitive data stored in Azure Blob Storage is encrypted at rest and in transit, with encryption keys managed by your organization. What solution meets these requirements?
Free question · medium · full answer + explanation

More customer-managed keys questions in the full bank

Practice Microsoft Azure Solutions Architect (AZ-305) Questions Free