CompTIA DataSys+ (DS0-001)Database DeploymentHard

A company is migrating an on-premise SQL Server database to Azure SQL Database. The database contains sensitive customer information and must comply with industry regulations that mandate data encryption at rest. During the planning phase, the database administrator also wants to ensure that data remains encrypted while in use by the database engine for query processing and during backups. Which encryption technology BEST addresses these combined requirements?

  1. ASSL/TLS for database connections
  2. BAlways Encrypted
  3. CAzure Disk Encryption
  4. DTransparent Data Encryption (TDE)
Show answer & explanation

Correct answer: B. Always Encrypted

Always Encrypted is specifically designed to encrypt sensitive data within the database client application before it's sent to the database, and decrypt it only on the client side. This means data is encrypted at rest (in the database files), in motion (over the network), and crucially, in use (by the database engine itself, as the engine processes encrypted data without decrypting it). TDE only encrypts data at rest and backup files, not data in use. SSL/TLS encrypts data in motion. Azure Disk Encryption encrypts the entire disk, but data is decrypted in memory for the database engine.

Why the other options are wrong

  • A. SSL/TLS encrypts data in transit over the network but does not address encryption at rest or in use by the database engine.
  • C. Azure Disk Encryption encrypts the entire disk, including database files, covering 'at rest'. However, data is decrypted in the server's memory for the database engine to process, failing the 'encrypted while in use' requirement.
  • D. TDE encrypts data at rest (database files, backups) but data is decrypted in memory for processing by the database engine, failing the 'encrypted while in use' requirement.

Always Encrypted

A SQL Server and Azure SQL Database feature that allows clients to encrypt sensitive data inside client applications and never reveal the encryption keys to the database engine.

  • Protects data at rest, in motion, and in use.
  • Decryption occurs only on the client side.
  • Requires client-side application changes to handle encrypted columns.

Memory trick: To be truly secure, encrypt from client to disk, even in use.

More Database Deployment questions