Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium
A healthcare organization is migrating its patient records database from an on-premises SQL Server to Azure SQL Database. Compliance regulations mandate that all sensitive patient health information (PHI) must be encrypted at the column level within the database, and the encryption keys must be managed externally by the organization, not by Microsoft. This ensures that even database administrators cannot view unencrypted PHI. Which Azure SQL Database feature should be implemented?
- AAlways Encrypted with secure enclaves
- BDynamic Data Masking
- CAzure Disk Encryption
- DTransparent Data Encryption (TDE)
Show answer & explanationAnswer & explanation
Correct answer: A. Always Encrypted with secure enclaves
Always Encrypted allows clients to encrypt sensitive data inside client applications before storing it in Azure SQL Database. The encryption keys are managed by the client, ensuring that database administrators cannot access the unencrypted data. Secure enclaves further enhance this by allowing in-place computations on encrypted data without exposing it.
Why the other options are wrong
- B. Dynamic Data Masking obfuscates data on the fly for non-privileged users but does not encrypt the underlying data.
- C. Azure Disk Encryption encrypts the underlying disks, similar to TDE, but does not prevent DBAs from seeing plaintext data within the database.
- D. TDE encrypts the entire database at rest, but data is decrypted in memory for processing, making it visible to DBAs.
Azure SQL Always Encrypted
A feature in Azure SQL Database that protects sensitive data, enabling clients to encrypt data inside client applications before storing it in the database, with encryption keys managed by the client.
- Column-level encryption.
- Client-side encryption, keys managed externally.
- Data remains encrypted in the database, even to DBAs.
- Secure enclaves allow computations on encrypted data.
Memory trick: Always Encrypted means the data stays a secret, even from the database itself.