CV0-004 Security Practice Question
A security team runs workloads in Microsoft Azure and must ensure that all data stored in Azure SQL Database and Azure Storage accounts is encrypted with customer-managed keys (CMK) rather than platform-managed keys. The compliance officer requires that the organization be able to revoke access to the data by disabling the key, and that key rotation be controlled internally. Which Azure service should the team configure to meet these requirements?
⚠ Common exam trap
Test-takers frequently confuse encryption-in-use or disk-level encryption features with the key-management service that actually supplies customer-managed keys for Azure PaaS data services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Key Vault, storing the RSA keys and granting the SQL and Storage resources access via managed identities.
Azure Key Vault is the service that stores customer-managed RSA keys and integrates with Azure SQL Database and Azure Storage to encrypt data at rest with keys the organization controls. By granting the PaaS resources access through managed identities, the team can rotate or disable the key to revoke access. Disk Encryption, Information Protection labels, and Confidential Computing address other layers and cannot satisfy the CMK and revocation requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Information Protection labels applied to the database and storage resources to classify the data.
Why it's wrong here
Azure Information Protection (now part of Microsoft Purview) classifies and protects documents and emails through sensitivity labels; it does not manage the encryption keys for Azure SQL Database or Azure Storage at rest. Labels do not enable key revocation or rotation for those PaaS services, so this does not meet the compliance officer's requirement.
- ✗
Azure Confidential Computing with SGX-enabled virtual machines hosting the SQL and storage workloads.
Why it's wrong here
Confidential Computing protects data in use within hardware enclaves, not data at rest in Azure SQL Database or Azure Storage. It does not provide customer-managed key control or the ability to revoke access by disabling a key. The requirement is about encryption at rest with customer-controlled keys, which enclaves alone do not deliver.
- ✓
Azure Key Vault, storing the RSA keys and granting the SQL and Storage resources access via managed identities.
Why this is correct
Azure Key Vault holds customer-managed RSA keys and integrates with Azure SQL Database and Azure Storage through Transparent Data Encryption and storage service encryption with CMK. Granting the resources access via managed identities lets the team disable or rotate the key to revoke access. This satisfies the requirement for internal key control and revocation capability.
- ✗
Azure Disk Encryption with BitLocker and DM-Crypt extensions applied to the underlying VM disks.
Why it's wrong here
Azure Disk Encryption protects OS and data disks attached to IaaS virtual machines, not the platform-managed storage behind Azure SQL Database or Azure Storage accounts. It cannot provide CMK control for PaaS data services, and disabling a BitLocker protector does not revoke access to the SQL or blob data. It addresses a different layer entirely.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.