Service-managed vs customer-managed vs BYOK keys
key management control versus burden.
service-managed keys are automatic but opaque; CMK gives you control over rotation, policy, and revocation in a KMS; BYOK imports your own key material for compliance.
What's really being asked
The interviewer wants to see that you understand encryption at rest as a spectrum of control and responsibility, and can pick a point on it based on compliance and operational capacity rather than defaulting to maximum control.
The full answer
Service-managed keys, sometimes called provider-managed or platform-managed, are created, stored, and rotated entirely by the cloud provider. They require no effort and data is encrypted by default, but you have no visibility into the key, cannot set custom rotation or access policies, and cannot independently revoke access. Customer-managed keys live in a managed key service like AWS KMS or Azure Key Vault, but you control them: you define rotation schedules, attach access policies, get full audit logging, and can disable or delete the key to render the data unreadable, which is powerful for incident response and offboarding. The tradeoff is that you now own key lifecycle, and a misconfigured policy or deleted key can lock you out. Bring your own key goes further: you generate key material in your own hardware security module and import it into the cloud KMS, giving cryptographic provenance and meeting strict compliance or sovereignty mandates, at the highest operational cost and the risk of import or lifecycle mistakes. Some providers also offer hold your own key, where the key never leaves your premises.
The mistakes people make
Claiming BYOK is simply the most secure and therefore always correct, ignoring its operational burden and self-lockout risk. Thinking service-managed keys mean data is unencrypted. Confusing CMK with BYOK; CMK keys can be provider-generated but customer-controlled.
What usually comes next
How does key revocation disable data access? What is envelope encryption? What happens if you delete a CMK with data still encrypted under it?
A concrete example
A regulated team uses a customer-managed key in KMS so that when an employee leaves a project, revoking that key's access instantly cuts the team's ability to decrypt the dataset, with every key use recorded in the audit log.
Interview question
A team wants to instantly revoke the ability to decrypt a dataset during an incident, with full audit logs. Which key model best supports this?
- a.Customer-managed keys in a KMS the team controlsCorrect
- b.No encryption, to avoid key-management complexity
- c.Service-managed keys, since the provider handles revocation automatically
- d.Service-managed keys, because they offer the most granular access policies
Why? this is the answer
Customer-managed keys let you set policy, audit usage, and disable the key to cut decryption on demand. Service-managed keys are opaque and offer no independent revocation or custom policy.
Just read this? Test yourself on what you have been reading.
Read the original → learn.microsoft.com
- #encryption
- #kms
- #security
- #compliance
- #cloud
You just looked this up. Could you explain it out loud?
That is the part interviews actually test. Tezvyn takes questions like this one and gives you what the interviewer is really checking, the answer that lands, and the mistake that ends the conversation, in the four minutes before your next meeting.
The iPhone app is on the way
We are building it. Until it lands, nothing here is held back from you: every interview card, your saved cards, streaks and the job board all work in Safari, plus hundreds of free practice quizzes of thirty questions each. Sign in and it all carries over to the app the day it arrives.
Want it as an icon? Tap Share at the bottom of Safari, then Add to Home Screen. It opens full screen and the cards you have read stay available offline.
We are hiring for this. Every open role lists the topics its interview covers, so you can prepare for the real thing rather than guessing.
See open roles