Microsoft Azure Data FundamentalsDescribe how to work with relational data on AzureHard

A data architect is designing a new database for a global application that stores customer contact information. Due to compliance requirements, all sensitive customer data, including names and email addresses, must be encrypted at rest within the Azure SQL Database. The architect needs to ensure that the encryption is managed by the service and does not require application-level changes or extensive key management by the customer. Which encryption feature should be used?

  1. AAlways Encrypted
  2. BCell-level encryption
  3. CAzure Key Vault integration with customer-managed keys
  4. DTransparent Data Encryption (TDE)
Show answer & explanation

Correct answer: D. Transparent Data Encryption (TDE)

Transparent Data Encryption (TDE) encrypts the entire database, backups, and transaction log files at rest. It is managed by the Azure SQL Database service, requiring no changes to the application and minimal key management from the customer (service-managed keys are default).

Why the other options are wrong

  • A. Always Encrypted provides client-side encryption, meaning data is encrypted by the client driver before it leaves the application. This requires application changes and client-side key management, which contradicts the 'does not require application-level changes' requirement.
  • B. Cell-level encryption (or column-level encryption) is an older method that requires explicit function calls in queries for encryption/decryption, requiring significant application changes and not managed transparently by the service.
  • C. Azure Key Vault integration with customer-managed keys (CMK for TDE) allows customers to manage their own encryption keys. While a valid TDE option, the requirement states 'does not require ... extensive key management by the customer', implying service-managed keys are preferred, making basic TDE the better fit.

Transparent Data Encryption (TDE)

A feature in Azure SQL Database that encrypts the entire database, backups, and transaction log files at rest, providing encryption without application changes.

  • Encrypts data at rest (database files, backups, logs).
  • Transparent to applications (no code changes needed).
  • Managed by the Azure SQL Database service by default.
  • Can use service-managed keys or customer-managed keys (CMK) via Azure Key Vault.

Memory trick: TDE is totally transparent encryption for databases.

More Describe how to work with relational data on Azure questions