AZ-104 exam dumps

AZ-104 practice question 85 of 289

Microsoft Certified: Azure Administrator Associate. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-104 Question 85

Select 3

Contoso has created a new Azure Storage account to store sensitive corporate data. Due to compliance requirements, the data must be encrypted at rest using Contoso's own cryptographic keys. Which steps should you take to configure the storage account to use a customer-managed key in Azure Key Vault? (Choose three.)

  1. A

    Enable encryption with Microsoft-managed keys for the storage account

  2. B

    Generate or import a key into an Azure Key Vault

  3. C

    Grant the Azure Storage resource provider sufficient permissions to the Key Vault

  4. D

    Enable the soft delete feature for blobs in the storage account

  5. E

    Configure the storage account to use the Key Vault key under the ‘Encryption’ settings

Show answer and explanation

Correct answers: B, C, E

Explanation

Customer-managed key encryption requires a key to reside in Azure Key Vault, proper permissions for the Azure Storage resource provider, and the storage account must be configured to use that key for encryption. By importing or generating a key in Key Vault, granting the storage resource provider access, and then selecting the Key Vault key under the storage account’s encryption settings, you meet the requirement to encrypt data at rest with your own cryptographic keys.

  • A. Incorrect.

    This option configures encryption with Microsoft-managed keys, which does not fulfill the requirement to use your own cryptographic keys.

  • B. Correct.

    To use a customer-managed key, you must have a key in Azure Key Vault, either by importing an existing key or generating a new one.

  • C. Correct.

    Azure Storage must be granted appropriate permissions (such as Key Vault Crypto User or an equivalent role) to access and use the key in Azure Key Vault for encryption operations.

  • D. Incorrect.

    Soft delete provides recoverability but does not affect how the storage account is encrypted. It is not required to enable customer-managed key encryption.

  • E. Correct.

    After preparing the key and permissions, you must configure the storage account’s encryption settings to point to the customer-managed key in Key Vault.

Timed practice exam

Take a AZ-104 practice test under exam conditions

60 questions in 60 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam