You are designing security for an Azure landing zone. Your company identifies the following compliance and privacy requirements: ? Encrypt cardholder data by using encryption keys managed by the company. ? Encrypt insurance claim files by using encryption keys hosted on-premises. Which two configurations meet the compliance and privacy requirements? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
A. Store the insurance claim data in Azure Blob storage encrypted by using customer-provided keys
B. Store the cardholder data in an Azure SQL database that is encrypted by using keys stored in Azure Key Vault Managed HSM
C. Store the insurance claim data in Azure Files encrypted by using Azure Key Vault Managed HSM
D. Store the cardholder data in an Azure SQL database that is encrypted by using Microsoft-managed Keys