Question 1
A financial services company is deploying a new SAP S/4HANA environment on Azure. For regulatory compliance, all data, including backups, must be encrypted using customer-managed keys stored in Azure Key Vault. The database is SAP HANA running on SUSE Linux Enterprise Server (SLES) 15 SP3. The backup strategy involves using Azure Backup for SAP HANA. Which configuration is required to meet the encryption requirement for the backups?
Answer and explanation
Correct answer: B
Azure Backup for SAP HANA stores backups in a Recovery Services vault. To meet the requirement of using customer-managed keys (CMK) for backup encryption, the Recovery Services vault itself must be configured with a CMK from Azure Key Vault. This ensures that the backup data is encrypted with a key that the customer controls. Azure Disk Encryption encrypts the VM's disks but does not control the encryption of the backups stored in the vault. Encrypting the storage account is a general setting and doesn't apply specifically to the Azure Backup service's managed storage. Configuring TDE on HANA encrypts the database files at rest, but not the backups managed by the Azure Backup service.