Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium

A startup is building a new mobile application that stores user profiles and preferences in an Azure Cosmos DB database. To enhance data privacy and meet specific regulatory requirements, the company wants to ensure that certain sensitive user data fields, such as social security numbers or health information, are encrypted by the client application BEFORE being sent to Cosmos DB. This means the data should never exist in plaintext within the database itself. Which encryption approach should be used?

  1. ATransparent Data Encryption (TDE)
  2. BServer-side encryption with service-managed keys
  3. CAlways Encrypted
  4. DClient-side encryption
Show answer & explanation

Correct answer: D. Client-side encryption

Client-side encryption involves encrypting data on the client application before it's sent to the database. This ensures that the data is encrypted before it ever reaches the database, and the database itself never sees the plaintext, which directly addresses the requirement.

Why the other options are wrong

  • A. TDE is for relational databases (like SQL Server) and encrypts the entire database file at rest, but data is decrypted in memory for processing.
  • B. Server-side encryption with service-managed keys encrypts data at rest within the database service, but the service itself can access the plaintext data.
  • C. Always Encrypted is a specific client-side encryption technology for SQL Server/Azure SQL, but 'client-side encryption' is the general approach described for any database like Cosmos DB.

Client-side Encryption

An encryption approach where data is encrypted by the application or client device before it is transmitted to and stored in a database or cloud service, ensuring the data never exists in plaintext on the server.

  • Encryption occurs at the application/client layer.
  • Database/server only receives and stores ciphertext.
  • Client (application) manages encryption keys.
  • Provides end-to-end encryption for sensitive fields.

Memory trick: Client-side encryption means the secret is locked before it even leaves your hands.

More Design security for applications and data questions