An auditor requires lock-lab cryptographic keys in a single-tenant FIPS-validated HSM pool rather than a multi-tenant software-protected key. What should the security engineer recommend?
Select an answer to reveal the explanation.
Short Explanation
If the auditor wants a single-tenant FIPS HSM pool, point them at Managed HSM—or at least HSM-backed keys in Premium when that’s enough. Standard software keys won’t satisfy that bar.
Full Explanation
Azure Key Vault Managed HSM provides a single-tenant, FIPS-validated HSM pool for customer key material. Premium vaults can hold HSM-backed keys, which differ from software-protected keys in Standard vaults. Choosing the correct SKU and protection type is the associate-level decision; dumping keys to public storage or exporting cleartext contradicts HSM goals. Capacity-planner detail is out of scope for the control-selection item.