CompTIA DataSys+ (DS0-001)Database DeploymentHard
A database administrator is planning to deploy a new database server for an application that requires highly sensitive data to be encrypted at rest and in transit. Additionally, the application developers need to perform complex queries on encrypted columns without decrypting the entire database or transferring decryption keys to the application server. Which SQL Server feature addresses these requirements?
- AAlways Encrypted with Secure Enclaves
- BCell-Level Encryption
- CTransparent Data Encryption (TDE)
- DSQL Server Encryption Hierarchy
Show answer & explanationAnswer & explanation
Correct answer: A. Always Encrypted with Secure Enclaves
Always Encrypted with Secure Enclaves allows for computations on encrypted data within the database itself, without exposing the data or encryption keys to the database server. This enables complex queries on encrypted columns while maintaining client-side encryption and strong data confidentiality.
Why the other options are wrong
- B. Cell-level encryption allows encrypting specific columns but requires decryption on the server or client side to perform operations, exposing the data.
- C. TDE encrypts the entire database data and log files at rest but does not allow computations on encrypted columns without decryption.
- D. SQL Server Encryption Hierarchy describes the overall key management structure but is not a feature for querying encrypted data without decryption.
Always Encrypted with Secure Enclaves
A SQL Server feature that enhances Always Encrypted by enabling in-database computations on encrypted data using secure enclaves, without exposing data or keys to the database engine.
- Maintains client-side encryption.
- Allows rich computations (e.g., pattern matching, range queries) on encrypted data.
- Uses hardware-based secure enclaves for enhanced security.
Memory trick: Encryption: Protect data at rest, in transit, and even during processing.