CV0-004 Security Practice Question
A cloud engineer is configuring an Azure Storage account that holds regulated customer data. The compliance team requires that data is encrypted at rest with customer-managed keys stored in Azure Key Vault, and that key usage is auditable. Which configuration should the engineer apply?
⚠ Common exam trap
The trap here is applying Azure Disk Encryption, which protects VM disks, to an Azure Storage account that stores blobs and files.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a customer-managed key in Azure Key Vault and assign it as the encryption key for the storage account.
Azure Storage encryption supports customer-managed keys by referencing a key stored in Azure Key Vault or Managed HSM. Setting the account's encryption key source to that key gives the customer control over rotation and revocation, while Key Vault logging records every key operation. Microsoft-managed keys and disk encryption do not provide the same customer control or auditability for storage account data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a customer-managed key in Azure Key Vault and assign it as the encryption key for the storage account.
Why this is correct
Azure Storage supports customer-managed keys by referencing a key in Key Vault or Managed HSM. Setting the account's encryption key source to the Key Vault key makes the customer control rotation and revocation, and Key Vault diagnostic logs record key operations for audit, satisfying the regulated-data requirement.
- ✗
Set the storage account encryption key source to Microsoft-managed keys and enable soft delete.
Why it's wrong here
Microsoft-managed keys mean Microsoft controls the key lifecycle and rotation, so the customer cannot manage or audit key usage as required. Soft delete protects against accidental deletion of blobs but does not provide customer-managed encryption keys, so this configuration fails the compliance mandate.
- ✗
Enable infrastructure encryption and store keys in a managed HSM.
Why it's wrong here
Infrastructure encryption adds a second layer of encryption at the hardware level, but by itself it does not implement customer-managed keys for the storage account. The compliance requirement specifically calls for customer-managed keys in Key Vault with auditability, which requires configuring the account encryption key source, not just infrastructure encryption.
- ✗
Enable Azure Disk Encryption on the storage account and store the KEK in Key Vault.
Why it's wrong here
Azure Disk Encryption applies to virtual machine OS and data disks, not to Azure Storage accounts for blobs, files, tables, and queues. It cannot encrypt a storage account's data at rest, so it does not meet the requirement for customer-managed keys on the storage account itself.
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.