Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard

A development team is deploying a new application that processes highly sensitive personal identifiable information (PII). They need to ensure that all data stored in the Azure SQL Database for this application is encrypted at rest and that all access attempts are audited for compliance purposes. Which Azure database security features should they implement?

  1. ADynamic Data Masking and Always Encrypted
  2. BTransparent Data Encryption (TDE) and SQL Database Auditing
  3. CAzure Private Link and Azure DDoS Protection
  4. DAzure Firewall and Network Security Groups (NSGs)
Show answer & explanation

Correct answer: B. Transparent Data Encryption (TDE) and SQL Database Auditing

Transparent Data Encryption (TDE) encrypts the entire database, including data at rest, data files, log files, and backups, without requiring application changes. SQL Database Auditing records events in the database, such as access attempts and data modifications, which is crucial for compliance and monitoring.

Why the other options are wrong

  • A. Dynamic Data Masking obfuscates sensitive data for non-privileged users but does not encrypt data at rest. Always Encrypted encrypts sensitive data within specific columns, but TDE is for the entire database at rest, and auditing is a separate feature.
  • C. Azure Private Link provides private connectivity to Azure services, and Azure DDoS Protection defends against DDoS attacks; neither addresses data at rest encryption or auditing directly.
  • D. Azure Firewall and Network Security Groups (NSGs) control network access to the database, but they do not encrypt data at rest or audit internal database operations.

Azure SQL Database Security (TDE & Auditing)

Azure SQL Database offers Transparent Data Encryption (TDE) for data at rest encryption and SQL Database Auditing for recording database events for compliance and security monitoring.

  • TDE encrypts the entire database, backups, and transaction log files.
  • Auditing tracks database events like logins, queries, and schema changes.
  • Both are essential for PII protection and compliance requirements.

Memory trick: TDE encrypts the data, Auditing watches the access.

More Describe Azure management and governance questions