Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

A company stores confidential data in Azure Blob Storage. They need to ensure that all data at rest is encrypted and they must be able to quickly rotate the encryption key on demand in case of a security breach. They also want to minimize administrative overhead. Which encryption option should they use?

⚠ Common exam trap

Watch out — candidates often confuse Azure Disk Encryption (which encrypts VM disks) with Azure Storage encryption, or assume that Microsoft-managed keys support on-demand rotation, when in fact only customer-managed keys allow the customer to control the key lifecycle.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Server-side encryption with customer-managed keys (CMK) stored in Azure Key Vault

Server-side encryption with customer-managed keys (CMK) stored in Azure Key Vault allows the organization to control and rotate the encryption key on demand, meeting the security breach response requirement. This option encrypts data at rest in Azure Blob Storage while minimizing administrative overhead because Azure manages the encryption process, and the customer only manages the key lifecycle in Key Vault.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Server-side encryption with Microsoft-managed keys

    Why it's wrong here

    Server-side encryption with Microsoft-managed keys encrypts Azure Blob Storage at rest using AES-256, and the platform handles all key management, including automatic rotation. However, because Microsoft controls the keys, customers cannot perform on-demand key rotation, cannot revoke a key independently, and cannot meet compliance or audit requirements that mandate customer control over key lifecycle. While this option does protect data against unauthorized external access, it fails the requirement for customer-managed key control.

  • ✓

    Server-side encryption with customer-managed keys (CMK) stored in Azure Key Vault

    Why this is correct

    Server-side encryption with customer-managed keys (CMK) stored in Azure Key Vault allows your organization to control the root encryption key used for encrypting Azure Blob Storage. With CMK, you can rotate keys on your own schedule, disable or revoke a key immediately if compromised, and audit key usage through Key Vault diagnostics, which helps meet compliance and governance requirements. Azure Storage implements CMK through envelope encryption, where the key in Key Vault encrypts the data encryption key, providing both strong encryption and operational flexibility without requiring application changes.

  • ✗

    Client-side encryption

    Why it's wrong here

    Client-side encryption encrypts data in the application before it is uploaded to Azure Blob Storage, meaning the service only ever receives already-encrypted bytes. While this offers data confidentiality throughout the entire pipeline, it requires significant application code changes to implement and maintain encryption and decryption logic, and it shifts key management and versioning responsibilities to the client. This approach increases overhead, complexity, and the risk of developer errors, and it is not the Azure-native server-side solution implied by the requirement.

  • ✗

    Azure Disk Encryption

    Why it's wrong here

    Azure Disk Encryption is designed for encrypting OS and data disks on Azure virtual machines using BitLocker (Windows) or DM-Crypt (Linux) — it does not apply to Azure Blob Storage. Because blobs are not attached virtual hard disks, configuring Azure Disk Encryption would have no effect on the stored data in blob containers. Thus, although Azure Disk Encryption is a valid encryption control for IaaS workloads, it is the wrong tool for encrypting Azure Blob Storage files.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.