Microsoft Azure Data FundamentalsDescribe how to work with relational data on AzureEasy
A financial institution is designing a new relational database in Azure to store customer account information. Due to regulatory compliance, all data at rest must be encrypted. Which Azure SQL Database feature should be implemented to meet this requirement without requiring application changes?
- ADynamic Data Masking
- BAlways Encrypted
- CTransparent Data Encryption (TDE)
- DCell-level Encryption
Show answer & explanationAnswer & explanation
Correct answer: C. Transparent Data Encryption (TDE)
Transparent Data Encryption (TDE) encrypts the entire database, including data files and log files, at rest without requiring any changes to the application.
Why the other options are wrong
- A. Dynamic Data Masking obfuscates sensitive data for non-privileged users but does not encrypt data at rest.
- B. Always Encrypted protects sensitive data inside the database, but it requires application changes to decrypt data.
- D. Cell-level encryption allows encryption of specific columns, but it requires application changes and is more granular than needed for all data at rest.
Transparent Data Encryption (TDE)
TDE encrypts entire database files at rest, protecting data on storage media without requiring application modifications.
- Encrypts data at rest (data files, log files, backups).
- No application changes required.
- Protects against unauthorized access to physical storage.
Memory trick: TDE: Total Database Encrypted, Transparently Done.