QuestionQ17

Implement Azure security

You are developing an Azure-hosted application that must use a key from an on-premises hardware security module (HSM). The key must be transferred to your existing Azure Key Vault through the Bring Your Own Key (BYOK) process.

You need to securely transfer the key to Azure Key Vault.

Which four actions should you perform in order?

Drag & Drop
Explanation

A KEK generated in the destination Key Vault protects the target key during transfer. Exporting the KEK public key lets the HSM vendor BYOK tool encrypt and package the on-premises key as a transfer blob; az keyvault key import uploads that blob, where Key Vault decrypts and imports it within its HSM boundary.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!