Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard

A global pharmaceutical company is migrating its research and development data to Azure. This data includes highly sensitive clinical trial results and intellectual property. The company requires a solution that ensures data remains encrypted both at rest and in transit, and also offers the ability to perform computations on encrypted data without decrypting it, thereby minimizing the risk of exposure during processing. Which Azure data security technology should the company prioritize?

  1. AAzure Confidential Computing
  2. BAzure SQL Transparent Data Encryption (TDE)
  3. CAzure Storage Service Encryption
  4. DAzure Disk Encryption
Show answer & explanation

Correct answer: A. Azure Confidential Computing

Azure Confidential Computing allows for processing data in a hardware-protected trusted execution environment (TEE), ensuring that data remains encrypted even during computation, which directly addresses the requirement for computations on encrypted data without decryption.

Why the other options are wrong

  • B. Azure SQL TDE encrypts data at rest in SQL databases but does not protect data during computation.
  • C. Azure Storage Service Encryption encrypts data at rest in storage accounts but does not protect data during computation.
  • D. Azure Disk Encryption encrypts data at rest but does not protect data during computation.

Azure Confidential Computing

A technology that protects data in use by performing computations within a hardware-based Trusted Execution Environment (TEE), ensuring data remains encrypted even during processing.

  • Protects data in use (during computation).
  • Utilizes hardware-based Trusted Execution Environments (TEEs).
  • Minimizes exposure risk during sensitive data processing.

Memory trick: Confidential Computing keeps secrets safe even while thinking.

More Design security for applications and data questions