Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard
A global financial institution is migrating its core banking applications to Azure. These applications handle highly sensitive customer financial data, including transaction histories, account balances, and personally identifiable information (PII). The institution has a strict regulatory requirement for data residency, mandating that all primary data for European customers must remain within the European Economic Area (EEA) and not be replicated or processed outside this region. Additionally, they require robust encryption for data at rest and in transit, and granular access control based on the principle of least privilege. The security architect must design a data storage strategy that meets these requirements while ensuring high availability and disaster recovery capabilities. Which Azure data storage service, combined with appropriate configuration, best addresses these requirements?
- AAzure Blob Storage with Geo-Redundant Storage (GRS) and customer-managed encryption keys (CMEK) via Azure Key Vault.
- BAzure Cosmos DB with 'Multi-region writes' enabled, IP firewall rules, and service-managed encryption keys.
- CAzure SQL Database with 'Zone-redundant' deployment, Always Encrypted, and Azure Private Link.
- DAzure Data Lake Storage Gen2 with Hierarchical Namespace, managed identities, and default platform-managed encryption keys.
Show answer & explanationAnswer & explanation
Correct answer: C. Azure SQL Database with 'Zone-redundant' deployment, Always Encrypted, and Azure Private Link.
Azure SQL Database with 'Zone-redundant' deployment ensures high availability within a region, and Always Encrypted provides client-side encryption for sensitive data, meeting data residency and encryption requirements. Azure Private Link secures network access, further enhancing security.
Why the other options are wrong
- A. GRS replicates data across regions, violating data residency requirements for the EEA. While CMEK is good, GRS is a dealbreaker.
- B. Multi-region writes in Azure Cosmos DB would replicate data across regions, violating data residency for the EEA. Service-managed keys might not meet the 'robust encryption' requirement as well as Always Encrypted.
- D. Azure Data Lake Storage Gen2 is suitable for big data analytics, but Azure SQL Database is generally preferred for core banking applications requiring transactional integrity. Default platform-managed encryption might not meet the 'robust encryption' standard, and it lacks the Always Encrypted feature for client-side encryption.
Azure SQL Always Encrypted
A feature of Azure SQL Database and SQL Server that protects sensitive data from unauthorized access by encrypting it on the client side before it's stored in the database.
- Data remains encrypted in the database, during processing, and in memory.
- Encryption keys are managed by the client application, not the database server.
- Protects against compromise of the database system, including DBAs.
Memory trick: Always Encrypt Your SQL for Regulatory Compliance.